The model failed. Now find the name.
APRA Prudential Standard CPS 511 Remuneration already requires every APRA-regulated entity to set criteria, and to take reasonable steps to adjust variable remuneration downwards, when risk management fails significantly or when customers are significantly harmed. The standard never mentions artificial intelligence (AI). It does not need to: the trigger is the failure and the harm, not the tool that produced them.
When a model produces a wrong outcome at scale, the remuneration committee has one question to answer: whose variable remuneration moves. That answer is assembled from three files the entity usually already holds separately: the AI use case register, the responsibilities recorded under the Financial Accountability Regime (FAR), and the consequence management framework. Where those three do not reconcile, the committee has a failure with nobody against it, and no defensible basis for adjusting anyone, or for adjusting no one.
What CPS 511 already requires when risk management fails
APRA's Prudential Standard CPS 511 Remuneration, standard text dated January 2024 and in force as at 24 September 2026, sets five minimum criteria for downward adjustment at significant financial institutions (SFIs) in paragraph 37:
- misconduct leading to significant adverse outcomes;
- a significant failure of financial or non-financial risk management;
- a significant failure or breach of accountability, fitness and propriety, or compliance obligations;
- a significant error or a significant misstatement of criteria on which the variable remuneration determination was based; and
- significant adverse outcomes for customers, beneficiaries or counterparties.
The second and the fifth do the work here. Entities that are not SFIs sit under paragraph 80, which sets the same five criteria in the same words.
Three further mechanics matter. Malus must apply to every person's variable remuneration arrangement, under paragraphs 35 and 79. The downward-adjustment process must operate "with clearly identified triggers to make a downward-adjustment", under paragraph 33(c)(i), or 78(c)(i) for a non-SFI. Where a person is under investigation for conduct capable of satisfying a criterion, paragraph 39, or 82 for a non-SFI, states that "variable remuneration must not vest until the investigation is closed", which makes identifying the person a live question, not a year-end one.
Two further requirements sit outside malus, inside the block paragraph 4(b) applies only to SFIs, as at 24 September 2026. Clawback is mandatory at an SFI for a senior manager, executive director or highly-paid material risk-taker, for at least two years from payment or vesting and whether or not employment has ceased, under paragraph 36. Deferral does not apply below AUD $50,000 of deferred variable remuneration in a financial year, under paragraph 43. At a non-SFI, paragraph 78(c) lists clawback among the adjustment tools, where appropriate. Neither displaces the malus obligation in paragraphs 35 and 79. Malus is defined against deferred variable remuneration before it vests, so a person with nothing deferred has nothing for malus to reduce. Commencement was staged, reaching all remaining APRA-regulated entities on 1 January 2024.
So nothing in the instrument has to change for an AI failure to count. What the entity carries is the decision, whether the failure was significant and against whom. APRA's Prudential Practice Guide CPG 511 Remuneration describes recording that decision either way as good practice.

Why does an AI failure fall out of the remuneration file?
On the evidence below, ownership of the model sits at model or business unit level, and senior executive accountability is not always joined to it.
ASIC's Report 798 Beware the gap, governance arrangements in the face of AI innovation, published 29 October 2024 on data as at December 2023, reviewed 624 AI use cases across 23 Australian financial services and credit licensees.
ASIC's finding on ownership matters most to a remuneration committee. Some licensees "demonstrated ownership and accountability for AI at a model or business unit level, but did not always have a senior executive accountable overall". ASIC puts the question to licensees directly: "For accountable entities under the Financial Accountability Regime (FAR), have you considered the use of AI in key functions when assigning accountable persons and establishing clear lines of accountability?"
APRA's letter to industry on artificial intelligence, published 30 April 2026 after targeted engagement with selected large banks, insurers and superannuation trustees in late 2025, sets minimum governance expectations that include "ownership and accountability across the AI lifecycle, from design and development through to deployment, monitoring and decommissioning" and "an inventory of AI tooling and AI use cases". APRA states few entities have operationalised governance in practice, and that where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, it will take stronger supervisory action and, where appropriate, pursue enforcement.
The remuneration side was documented earlier. APRA's findings from the CPS 511 pre-implementation review, published 6 September 2023 and covering 39 entities across two phases between September 2021 and December 2022, recorded "insufficient rigour in the proposed processes to ensure remuneration consequences result from poor risk management outcomes". Approximately 80 percent of entities in that review identified remuneration design as the area needing the greatest uplift.
The non-prudential baseline is plainer. The National AI Centre's Guidance for AI adoption, which the Department of Industry, Science and Resources published on 21 October 2025, and which is guidance rather than a mandatory instrument, states that "AI complexity can create gaps where no one takes clear responsibility for outcomes". Its first essential practice is to decide who is accountable, across the organisation and including contractors and third-party providers.
So the failure mode is not a missing rule. It is a missing row.
Which instruments put a name on the model?
Two, and neither mentions AI.
The Financial Accountability Regime Act 2023 (Cth), Compilation No. 2 with a compilation date of 21 February 2025, defines an accountable person in section 10 by actual or effective senior executive responsibility for a significant or substantial part or aspect of operations. Section 21 sets the accountability obligations, including taking reasonable steps to prevent matters arising that would, or would be likely to, adversely affect the prudential standing or prudential reputation of the entity. Section 23 requires responsibilities to cover "all parts or aspects of the operations of the accountable entity's relevant group". Section 25 requires a remuneration policy under which, where an accountable person has failed to comply with an accountability obligation, "the person's variable remuneration is to be reduced by an amount that is proportionate to the failure".
Not an AI rule, a coverage rule: if a model sits inside a part or aspect of operations, section 23 already expects somebody's responsibilities to cover it.
APRA and ASIC's Financial Accountability Regime: Information for accountable entities, published 11 July 2024, reads the obligation the same way: accountable entities must ensure that the responsibilities of accountable persons collectively cover all parts or aspects of their operations, and key functions assist the regulators in assessing whether accountability is adequately assigned. Only accountable entities meeting the enhanced notification threshold lodge accountability maps and statements, and for them a map or statement that no longer accurately reflects operations or responsibilities is likely a material change requiring notification. A core entity lodges neither, so there the reconciliation runs against the entity's own record of accountable persons and their responsibilities under section 23.
The second hook is operational risk. Prudential Standard CPS 230 Operational Risk Management first commenced on 1 July 2025, and the version in force as at 24 September 2026 is the amended standard that commenced on 1 July 2026. Under paragraph 20 the Board must ensure the entity "sets clear roles and responsibilities for senior managers for operational risk management, including business continuity and the management of service provider arrangements". Remediation of material weaknesses must be supported by clear accountabilities under paragraph 30, and incidents and near misses must be identified, escalated, recorded and addressed in a timely manner under paragraph 31.
Neither instrument is under amendment. APRA's Corporate Plan 2026-27 plans new governance requirements from the start of 2028, and APRA and ASIC consulted until 2 October 2026 on streamlining FAR administration from early 2027, but the obligations described here are those in force as at 24 September 2026.

The reconciliation, in one table
The control reconciles three files that already exist, before the next remuneration cycle rather than after an incident. The output is one extract for the remuneration committee listing every use case with no matched accountable responsibility. The accountable person column sits immediately after the use case reference because "accountable people" is the first field of the National AI Centre's organisation-wide AI register.
Three tests decide whether the reconciliation has been run. Every row has a role title in the accountable person column. Every role title in that column appears on a current accountability statement, or, at a core entity, in the entity's own record of accountable persons. Every row names at least one criterion, or records in writing why none applies.
What happens between the incident and the committee?
The path runs in order, with the instrument named where one applies.
- A defect is detected in a deployed model, by monitoring, a complaint, or a downstream reconciliation.
- The incident or near miss is recorded and escalated in a timely manner under CPS 230 paragraph 31, and where the entity determines the incident is likely to have a material financial impact or a material impact on its ability to maintain critical operations, APRA is notified within 72 hours under paragraph 32.
- The register is read. Where it names the accountable person by role and the responsibility reference that covers the use case, the path continues at step 5.
- Where that field is blank, or the role title sits on no current accountability statement, the reconstruction runs against the entity's accountability record rather than the register, and at an entity that lodges an accountability map the row is escalated the same day as a possible material change.
- The downward-adjustment process tests the failure against the paragraph 37 criteria, using the entity's clearly identified triggers under paragraph 33(c)(i).
- Where a person is under investigation for conduct capable of satisfying a criterion, vesting is suspended under paragraph 39 until the investigation is closed.
- Severity is assessed against a scale, and the assessment records the individual contribution of each person, including inaction.
- An initial adjustment is recorded and revised once the full impact is known.
- The decision is recorded whether or not an adjustment is made, and the unmatched register rows go to the remuneration committee paper.
Steps 7, 8 and 9 come from CPG 511, dated May 2026, which states that "in particular, senior executives should not be financially rewarded where there are failings in risk management". Better practice is a severity scale illustrated with example cases and an assessment of individual contribution that includes inaction, both at paragraph 82, and an initial adjustment revised when the full impact is known at paragraph 83. Paragraph 84 is explicit: "Good practice is to record all adjustment decisions, including where an adjustment was considered but ultimately decided against."
That line converts the reconciliation from an exercise into evidence. A committee that considered an adjustment for an AI-caused failure and decided against it holds a defensible position if the reasoning is on file. A committee that never identified whose responsibility the model sat inside has nothing to file.

A worked example, de-identified
[ENTITY] deploys [MODEL_NAME], supplied by [VENDOR], inside a calculation process recorded as [USE_CASE_ID]. A parameter defect produces incorrect outputs for a period before an internal check detects it, and it is not escalated when the processing team first observes it. The customer impact is material once quantified, and the incident is raised as [INCIDENT_REF].
The register row for [USE_CASE_ID] names a business owner and the vendor. The accountable person field is blank, because the model was procured as a service and the build sat with a delivery team. The FAR accountability statements name a responsibility for the end-to-end process, held by [ACCOUNTABLE_PERSON_ROLE], but the statement is worded at the level of the process and says nothing about the models inside it, and the register carries no responsibility reference.
The consequence is procedural. At [REMCO_DATE] the committee can see an incident, a customer impact, a vendor and a responsibility for the process. It cannot see, from its own papers, whether the defect sat inside that responsibility, whether the failure to escalate was an inaction by the person holding it, or whether executive level accountability is engaged.
Three prompts for the reconciliation
TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened.
What to check: open every flagged row against the extract yourself and confirm the status, including every row reported as not on statement. Confirm that no matched responsibility reference and no match basis appears in the output that is not in Attachment B, which is the failure mode this prompt is written to prevent. A role title reported as not on statement is the finding, not an error.
What to check: test each factor against CPG 511 paragraph 82 on severity and individual contribution including inaction before the template is used. Confirm the template has a field for a decision considered and decided against.
What to check: confirm that every figure and count in the draft appears in the reconciliation output, and delete anything that does not. Confirm the assignment date column came back blank rather than filled. Confirm the paper uses role titles throughout, and that the decision sought is a decision the committee has the power to make under the entity consequence management framework, rather than one reserved to the board.
Do this Monday
The artefact is a one-page reconciliation extract for the remuneration committee, titled the AI accountability reconciliation.
The owner is the head of operational risk. The remuneration committee secretariat carries the extract into the committee paper, and the accountable person for technology confirms the role titles.
The first step fits in an hour. Take every deployed use case flagged as supporting a critical operation under CPS 230, up to ten, then fill any remainder with use cases that touch customer outcomes or payments. Add two columns: accountable person by role title, and the downward-adjustment criterion a failure of that use case would engage, one of the five in paragraph 37, or paragraph 80 for a non-SFI. Fill what the existing files support, leave the rest blank, and count the blanks. That count is the finding.
The check that proves it worked is a match test, not a completion test: every non-blank accountable person role in those rows also appears on a current accountability statement, or, at a core entity, in the entity's own record of accountable persons. A role title in the register but not on a statement is the same defect as a blank, and the one most easily missed. Set the review point before the next remuneration cycle, and carry the unmatched rows into the committee paper.
The bottom line
CPS 511 does not need an AI amendment, because the criteria in paragraph 37, and in paragraph 80 for a non-SFI, already reach a significant failure of risk management and significant adverse outcomes for customers, whatever produced them. What the entity file usually lacks is the evidentiary link between the model and a person, and that link is a reconciliation between the AI use case register, the responsibilities recorded under the FAR and the consequence management framework. Run it before an incident, because a suspended vesting decision under paragraph 39 is a poor time to discover that a use case has no owner. Record the decision either way, including where an adjustment was considered and decided against, which is the recording practice APRA describes in CPG 511. Build the register row first, then the committee paper.
TheAICommand. Intelligence, At Your Command.


