APRA's model risk supervisory push is no longer a forecast. When this article was first published on 22 April 2026, a thematic review was widely expected in the second half of the year. Eight days later, APRA's letter to industry on artificial intelligence reported a deep-dive on the largest banks, insurers and superannuation trustees, and confirmed that a forward plan covering entity prudential reviews, thematic activities and AI supplier engagement is being finalised. The underlying test is unchanged: whether model risk standards written for traditional statistical models stretch to cover the AI systems now embedded across credit, AML, fraud, and claims decisions in regulated entities.
Context for general readers: Model risk is the risk of financial loss, regulatory breach, or reputational harm caused by errors in mathematical models used to make business decisions. In banking, models are used everywhere: deciding who gets a loan, calculating capital requirements, detecting fraud, monitoring transactions for money laundering. APRA has supervised model risk for decades through standards like CPS 220 (Risk Management) and APS 113 (capital adequacy models). What has changed is the type of models in scope. Generative AI, large language models, and machine-learning systems are now deeply embedded in regulated entities, and the existing framework was designed for a different generation of technology.
A thematic review is APRA's deep-dive supervisory tool. It is not an enforcement action; it is a structured study of how a sector is managing a specific risk, with findings that drive expectations forward. APRA's tripartite cyber assessments under CPS 234, which covered more than 300 banks, insurers and superannuation trustees, drove material changes in supervisory expectations. The AI deep-dive reported in April 2026 is the same pattern applied to AI and model risk.
Update, 15 August 2026: this article was published as an analytical preview on 22 April 2026, before APRA showed its hand. Since then, the 30 April 2026 letter to industry has summarised the findings of a targeted engagement conducted on selected large banks, insurers and superannuation trustees in late 2025, and set minimum expectations for boards and accountable executives. The System Risk Outlook of 21 May 2026 then flagged concentration of AI providers as a system-level risk that entities are expected to actively manage. The letter states that APRA is "currently finalising its forward plan with regards to supervision of AI risks, taking a proportional approach to entity prudential reviews, thematic activities and AI supplier engagement". As at 15 August 2026, APRA has not published a terms of reference for a standalone model risk thematic review. The sections below have been updated to show where the pressure areas this article predicted have since been confirmed in APRA's own findings.
Why is APRA looking at model risk now?
Three forces are converging.
First, capability change. Today's frontier models (the GPT-5.6, Claude Sonnet 5 and Gemini 3.5 generations) are materially more capable than the systems APRA's existing supervisory expectations were built around. Use cases have expanded from narrow predictive models to generative tools embedded in customer-facing operations.
Second, deployment scale. Enterprise AI adoption inside Australia's largest regulated entities has crossed the threshold from pilot to production over the last 18 months. Use cases that were not in scope for any model risk framework two years ago (for example, generative drafting of credit memos or compliance assessments) are now operational.
Third, regulatory momentum. The APRA Corporate Plan 2025-26 committed APRA to "targeted supervisory engagements with a group of larger entities" on AI risk in the first half of 2025-26, and that is exactly the exercise the April 2026 letter reported. The Voluntary AI Safety Standard provides a voluntary baseline, and there is a practical route from those guardrails to audit evidence. ASIC has signalled active supervision of AI in financial services. The cross-regulator picture is moving in one direction.
What does "model risk" mean in this review?
The traditional model risk discipline, codified in standards like APS 113 and the supervisory expectations around the Internal Ratings-Based approach, focuses on quantitative models with stable specifications, validation cycles, and clearly defined input data. The challenge for the thematic review is that AI systems do not fit neatly inside that frame.
Three categories of model are likely to be examined.
The first is traditional models that have been augmented with AI components. A credit risk model that retains its core scoring logic but uses an AI tool to extract features from unstructured documents. The model itself is governed; the AI feature pipeline may not be.
The second is AI-native decision support systems. Generative AI tools used to draft credit memos, compliance assessments, or claims triage decisions. The output influences a material decision, but the system rarely sits inside the formal model inventory.
The third is autonomous or near-autonomous AI systems. Tools that take actions with limited human review, including automated suspicious matter triage in AML monitoring, automated underwriting in some general insurance lines, and customer service chatbots resolving complaints. These are operationally embedded but governance frameworks are inconsistent.
Where will supervisory pressure focus?
Six areas are likely to see the sharpest questions.

1. Inventory completeness
The first supervisory question for any model risk thematic review is always inventory. APRA will want a comprehensive list of models in production, with classification by materiality. This is no longer speculation: the April 2026 letter lists "an inventory of AI tooling and AI use cases" among APRA's minimum governance expectations. The challenge for AI tools is definitional: when is a generative AI assistant a model that requires inventory entry, and when is it a productivity tool? Entities that have answered this question consistently and documented the threshold will fare better than those that have not.
2. Validation methodology fit
CPS 220 requires risk management policies to cover "the process for the validation, approval and use of any models to measure components of risk", and APS 113 requires internal ratings-based rating systems to be reviewed at least annually by internal audit or an equally independent function. The standard validation methodology for traditional statistical models (back-testing against historical data, sensitivity analysis, performance monitoring) does not transfer cleanly to large language models. The supervisory question is no longer hypothetical. The April 2026 letter found entities relying on "point in time and sample based assurance methods, despite these methods being ill suited to probabilistic models that learn, adapt and degrade over time", and observed that few entities had continuous validation or monitoring in place to detect model drift, bias, failure modes, or control breakdowns in a timely manner.
3. Human-in-the-loop design
Where AI outputs influence material decisions, supervisory expectation will focus on how human review is designed. The pattern emerging from international supervisors (UK FCA, US OCC) is that nominal human review is insufficient. APRA's April 2026 letter makes the domestic position explicit: its minimum governance expectations include "human involvement for high-risk decisions and accountability". The practical question that follows is whether the human reviewer has the time, the information, and the authority to materially change the AI output. The answer in many institutions today is uneven.
4. Third-party AI provider oversight
Most enterprise AI capability is provided by third parties. CPS 230 governs the operational risk dimension of those relationships, but model risk goes further. The April 2026 letter observed some entities heavily dependent on a single provider for multiple AI use cases, with few demonstrating robust contingency planning or tested exit and substitution strategies, and found contractual arrangements often lagged practice on audit rights, model updates, and incident notification. The May 2026 System Risk Outlook then flagged concentration of AI providers as a system-level risk that entities are expected to actively manage. Supervisory questions will keep probing transparency on training data, model updates, performance monitoring data made available to the regulated entity, and the entity's own ability to detect quality drift. Where the third party will not provide this transparency, the entity needs a documented compensating control.
5. Bias, fairness, and consumer outcome testing
This is the area with the highest cross-regulator overlap. AHRC, OAIC, and ASIC all have active interests in AI fairness and consumer outcomes. APRA's prudential lens focuses on whether bias creates financial loss or regulatory exposure for the entity, but the testing methodology is largely shared across regulators. Entities that have not embedded fairness testing into their AI model lifecycle will see questions on this front.
6. Documentation of model purpose and scope creep
A traditional model risk framework treats the model's intended purpose as a stable input. The model is built for a defined use case, validated for that use case, and used inside that boundary. AI tools, particularly generative ones, have a tendency to be used beyond their original design intent. A summarisation tool deployed for one workflow gets repurposed by analysts in another workflow because it works reasonably well there too.
The supervisory expectation likely to emerge: documented model purpose statements, with controls to detect and govern scope expansion. Where a model is used outside its validated scope, the entity should know about it before the supervisor does.
How the supervisory engagement has unfolded so far
Thematic reviews follow a recognisable pattern. APRA typically begins with a survey, information request, or targeted engagement with a sample of regulated entities, designed to establish a baseline picture of practice. Deeper testing of selected entities follows. Findings are then synthesised and shared with industry through a public report, supervisory letters, or both. That is exactly how the AI engagement has run: a deep-dive exercise on a sample of the largest banks, insurers and superannuation trustees in late 2025, followed by a public letter to industry on 30 April 2026.
This article originally predicted the sample would skew toward larger ADIs and insurers. That skew has been confirmed, with one addition: superannuation trustees were in the sample too, and the letter says the lessons "will assist other entities who may be earlier in their AI adoption journey". Smaller entities may still be drawn into future review activity through specific use cases (for example, AI-driven AML/CTF or fraud detection) rather than as primary participants.
The output is unlikely to be a brand-new prudential standard in the short term. APRA's pattern is to begin with practice guides and supervisory letters, with new prudential standards reserved for cases where the existing framework cannot stretch. The April 2026 letter supports that reading: APRA describes its prudential framework as "technology and vendor agnostic", and says it will "consider whether further APRA policy action may be needed". CPS 220, CPS 230, and APS 113 between them probably reach most of the AI-relevant model risk territory; the practical work is in updated practice guidance.
What the international picture suggests
International regulators have moved at different paces. The UK FCA has issued discussion papers on AI in financial services and continues to develop its approach. The US OCC has issued model risk management guidance with specific applicability to AI components. The EU has the AI Act, which sits alongside its prudential framework. The international picture provides comparators for what supervisory expectations may look like, without binding APRA to any specific path.
The pattern across these regulators is consistent on three points: model inventory is non-negotiable, validation methodology must be fit for the model type, and human oversight quality matters more than human oversight quantity. APRA is likely to land in similar territory.
Practical implications this quarter
For GRC and risk teams in regulated entities, the stakes are now stated in writing: the April 2026 letter warns that where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, APRA "will take stronger supervisory action and, where appropriate, pursue enforcement". Four actions are sensible regardless of when the formal thematic activity lands, and a standing Monday regulatory sweep will catch the forward plan when it does:
- Run a model risk inventory completeness check covering AI tools. Apply a clear threshold for what counts as a model. Document the threshold. Be ready to defend it.
- Map your validation methodology by model type. Where the methodology was designed for traditional statistical models, identify the gap for generative AI and document the planned remediation. APRA's published guidance signals that a credible plan is likely to be accepted at supervisory review; silence on AI use is unlikely to be.
- Document human-in-the-loop adequacy for material AI outputs. Move beyond "a human reviews the output" to evidence that the human has the time, the information, and the authority to override.
- Build third-party AI transparency into procurement and ongoing oversight. Standard third-party risk management questionnaires need additional model-specific questions. The major model providers vary considerably in how much they will disclose; pricing your control framework for the disclosure you can actually obtain is the practical task.
How to structure the readiness work
Three structural choices shape the quality of model risk readiness work for the expected review.
The first is whether AI risk is housed inside the existing model risk function or treated as a separate discipline. The argument for separation is that AI capability and model risk capability are different skill sets. The argument for integration is that the supervisory expectations, validation methodology challenges, and governance structures all share substantial common ground. The pattern emerging in the major Australian institutions is integration, with AI specialists embedded in the existing model risk function rather than operating in a parallel structure.
The second is the relationship between the second line model risk function and the first line AI deployment teams. The supervisory expectation under CPS 220 and the pattern from international regulators is robust second-line oversight. Where the second line is under-resourced relative to the first line's deployment cadence, the governance picture is weaker. Practitioners should examine resourcing imbalance honestly.
The third is documentation discipline. Thematic reviews live and die on documentation quality. The institution that can produce, on request, a current model inventory with classification, validation evidence, monitoring metrics, and incident history will fare materially better than the institution that has to compile this on demand.
Direction of travel
The timeline so far follows APRA's established rhythm: targeted engagement in late 2025, a public letter to industry within about six months, and a System Risk Outlook reinforcing the message three weeks after that. If APRA's pattern of turning supervisory findings into guidance holds, updated expectations typically arrive 12 to 18 months after the fieldwork wraps up. For model risk and AI specifically, the practical path is still likely to be a refresh of CPS 220 expectations and possibly a dedicated AI-focused practice guide, rather than a brand-new prudential standard.
For GRC professionals, the work to do does not depend on the timing. The supervisory expectation is no longer forming; it is published. The institutions that will be ready are the ones that started the work in the first half of 2026, not the ones that wait for the forward plan to land.
Bottom line
APRA has already run its AI deep-dive on the largest banks, insurers and superannuation trustees, published its findings and minimum expectations in the 30 April 2026 letter to industry, and is finalising a forward plan covering entity prudential reviews, thematic activities and AI supplier engagement. The letter confirmed the pressure areas this article predicted: inventory, validation and assurance fit for probabilistic models, human involvement in high-risk decisions, and supplier concentration. The output is still more likely to be updated CPS 220 expectations and an AI-focused practice guide than a brand-new prudential standard. The institutions that will be ready are the ones that started the work in the first half of 2026, not the ones waiting for the forward plan.
Do this Monday:
- Run a model risk inventory completeness check that covers AI tools, and document the threshold for what counts as a model.
- Map your validation methodology by model type and record the gap for generative AI.
- Document human-in-the-loop adequacy for material AI outputs, evidencing time, information, and authority to override.
- Build third-party AI transparency into procurement and ongoing oversight.
- Document model purpose statements and add controls to detect scope creep beyond a model's validated use.
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.
TheAICommand. Intelligence, At Your Command.


