The Model Failed. Whose Bonus Moves?, practitioner guidance from TheAICommand
← GRC
Regulatory analysis

The Model Failed. Whose Bonus Moves?

CPS 511 already requires an APRA-regulated entity to set criteria that adjust variable remuneration downwards for a significant failure of risk management or significant adverse outcomes for customers. It never mentions artificial intelligence, and it does not need to. The gap sits in the entity file: an AI use case with no accountable person the remuneration committee can name.

·monthly

GRC content. Written for compliance, risk, and audit professionals in Australian financial services. General information. Not legal or compliance advice.

Quick answer

CPS 511 requires APRA-regulated entities to set criteria that adjust variable remuneration down for a significant risk management failure or significant adverse customer outcomes. An AI-caused failure can engage them like any other. The obstacle is evidentiary: if the AI use case register names no accountable person, the remuneration committee has nobody to hold to the outcome.

The model failed. Now find the name.

APRA Prudential Standard CPS 511 Remuneration already requires every APRA-regulated entity to set criteria, and to take reasonable steps to adjust variable remuneration downwards, when risk management fails significantly or when customers are significantly harmed. The standard never mentions artificial intelligence (AI). It does not need to: the trigger is the failure and the harm, not the tool that produced them.

When a model produces a wrong outcome at scale, the remuneration committee has one question to answer: whose variable remuneration moves. That answer is assembled from three files the entity usually already holds separately: the AI use case register, the responsibilities recorded under the Financial Accountability Regime (FAR), and the consequence management framework. Where those three do not reconcile, the committee has a failure with nobody against it, and no defensible basis for adjusting anyone, or for adjusting no one.

What CPS 511 already requires when risk management fails

APRA's Prudential Standard CPS 511 Remuneration, standard text dated January 2024 and in force as at 24 September 2026, sets five minimum criteria for downward adjustment at significant financial institutions (SFIs) in paragraph 37:

  • misconduct leading to significant adverse outcomes;
  • a significant failure of financial or non-financial risk management;
  • a significant failure or breach of accountability, fitness and propriety, or compliance obligations;
  • a significant error or a significant misstatement of criteria on which the variable remuneration determination was based; and
  • significant adverse outcomes for customers, beneficiaries or counterparties.

The second and the fifth do the work here. Entities that are not SFIs sit under paragraph 80, which sets the same five criteria in the same words.

Three further mechanics matter. Malus must apply to every person's variable remuneration arrangement, under paragraphs 35 and 79. The downward-adjustment process must operate "with clearly identified triggers to make a downward-adjustment", under paragraph 33(c)(i), or 78(c)(i) for a non-SFI. Where a person is under investigation for conduct capable of satisfying a criterion, paragraph 39, or 82 for a non-SFI, states that "variable remuneration must not vest until the investigation is closed", which makes identifying the person a live question, not a year-end one.

Two further requirements sit outside malus, inside the block paragraph 4(b) applies only to SFIs, as at 24 September 2026. Clawback is mandatory at an SFI for a senior manager, executive director or highly-paid material risk-taker, for at least two years from payment or vesting and whether or not employment has ceased, under paragraph 36. Deferral does not apply below AUD $50,000 of deferred variable remuneration in a financial year, under paragraph 43. At a non-SFI, paragraph 78(c) lists clawback among the adjustment tools, where appropriate. Neither displaces the malus obligation in paragraphs 35 and 79. Malus is defined against deferred variable remuneration before it vests, so a person with nothing deferred has nothing for malus to reduce. Commencement was staged, reaching all remaining APRA-regulated entities on 1 January 2024.

So nothing in the instrument has to change for an AI failure to count. What the entity carries is the decision, whether the failure was significant and against whom. APRA's Prudential Practice Guide CPG 511 Remuneration describes recording that decision either way as good practice.

An editorial panel naming the two CPS 511 paragraph 37 downward-adjustment criteria an AI model failure engages, a significant failure of financial or non-financial risk management and significant adverse outcomes for customers, beneficiaries or counterparties, shown as two of the five minimum criteria the paragraph sets.
CPS 511 paragraph 37 sets the triggers. The entity decides whether an AI failure satisfies one.

Why does an AI failure fall out of the remuneration file?

On the evidence below, ownership of the model sits at model or business unit level, and senior executive accountability is not always joined to it.

ASIC's Report 798 Beware the gap, governance arrangements in the face of AI innovation, published 29 October 2024 on data as at December 2023, reviewed 624 AI use cases across 23 Australian financial services and credit licensees.

ASIC's finding on ownership matters most to a remuneration committee. Some licensees "demonstrated ownership and accountability for AI at a model or business unit level, but did not always have a senior executive accountable overall". ASIC puts the question to licensees directly: "For accountable entities under the Financial Accountability Regime (FAR), have you considered the use of AI in key functions when assigning accountable persons and establishing clear lines of accountability?"

APRA's letter to industry on artificial intelligence, published 30 April 2026 after targeted engagement with selected large banks, insurers and superannuation trustees in late 2025, sets minimum governance expectations that include "ownership and accountability across the AI lifecycle, from design and development through to deployment, monitoring and decommissioning" and "an inventory of AI tooling and AI use cases". APRA states few entities have operationalised governance in practice, and that where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, it will take stronger supervisory action and, where appropriate, pursue enforcement.

The remuneration side was documented earlier. APRA's findings from the CPS 511 pre-implementation review, published 6 September 2023 and covering 39 entities across two phases between September 2021 and December 2022, recorded "insufficient rigour in the proposed processes to ensure remuneration consequences result from poor risk management outcomes". Approximately 80 percent of entities in that review identified remuneration design as the area needing the greatest uplift.

The non-prudential baseline is plainer. The National AI Centre's Guidance for AI adoption, which the Department of Industry, Science and Resources published on 21 October 2025, and which is guidance rather than a mandatory instrument, states that "AI complexity can create gaps where no one takes clear responsibility for outcomes". Its first essential practice is to decide who is accountable, across the organisation and including contractors and third-party providers.

So the failure mode is not a missing rule. It is a missing row.

Which instruments put a name on the model?

Two, and neither mentions AI.

The Financial Accountability Regime Act 2023 (Cth), Compilation No. 2 with a compilation date of 21 February 2025, defines an accountable person in section 10 by actual or effective senior executive responsibility for a significant or substantial part or aspect of operations. Section 21 sets the accountability obligations, including taking reasonable steps to prevent matters arising that would, or would be likely to, adversely affect the prudential standing or prudential reputation of the entity. Section 23 requires responsibilities to cover "all parts or aspects of the operations of the accountable entity's relevant group". Section 25 requires a remuneration policy under which, where an accountable person has failed to comply with an accountability obligation, "the person's variable remuneration is to be reduced by an amount that is proportionate to the failure".

Not an AI rule, a coverage rule: if a model sits inside a part or aspect of operations, section 23 already expects somebody's responsibilities to cover it.

APRA and ASIC's Financial Accountability Regime: Information for accountable entities, published 11 July 2024, reads the obligation the same way: accountable entities must ensure that the responsibilities of accountable persons collectively cover all parts or aspects of their operations, and key functions assist the regulators in assessing whether accountability is adequately assigned. Only accountable entities meeting the enhanced notification threshold lodge accountability maps and statements, and for them a map or statement that no longer accurately reflects operations or responsibilities is likely a material change requiring notification. A core entity lodges neither, so there the reconciliation runs against the entity's own record of accountable persons and their responsibilities under section 23.

The second hook is operational risk. Prudential Standard CPS 230 Operational Risk Management first commenced on 1 July 2025, and the version in force as at 24 September 2026 is the amended standard that commenced on 1 July 2026. Under paragraph 20 the Board must ensure the entity "sets clear roles and responsibilities for senior managers for operational risk management, including business continuity and the management of service provider arrangements". Remediation of material weaknesses must be supported by clear accountabilities under paragraph 30, and incidents and near misses must be identified, escalated, recorded and addressed in a timely manner under paragraph 31.

Neither instrument is under amendment. APRA's Corporate Plan 2026-27 plans new governance requirements from the start of 2028, and APRA and ASIC consulted until 2 October 2026 on streamlining FAR administration from early 2027, but the obligations described here are those in force as at 24 September 2026.

A timeline of five dated points: CPS 511 reaching all remaining APRA-regulated entities on 1 January 2024, the Financial Accountability Regime Act 2023 compilation of 21 February 2025, CPS 230 first commencing on 1 July 2025, the amended CPS 230 commencing on 1 July 2026, and new governance requirements planned for the start of 2028.
Three instruments, one superseded version and one planned change. None of the three names a model, and only two of them name an owner.

The reconciliation, in one table

The control reconciles three files that already exist, before the next remuneration cycle rather than after an incident. The output is one extract for the remuneration committee listing every use case with no matched accountable responsibility. The accountable person column sits immediately after the use case reference because "accountable people" is the first field of the National AI Centre's organisation-wide AI register.

ColumnWhat goes in itWhy it is there
Use case referenceThe unique identifier for the deployed use case, matching the AI inventoryAPRA expects an inventory of AI tooling and AI use cases
Accountable personRole title only, plus the FAR responsibility reference that covers itFAR section 23 requires responsibilities to cover all parts or aspects of operations
Business ownerRole title of the person running the process the model sits insideSeparates day-to-day ownership from senior executive responsibility
Critical operationYes or no, with the linked CPS 230 critical operation referenceSenior manager roles under CPS 230 paragraph 20 extend to the operational risk the use case sits inside
Vendor and tierThe provider, the supply chain tier, and the contract review dateCPG 511 paragraph 40 contemplates adverse outcomes arising from third-party service providers
Criterion engagedWhich paragraph 37 criterion, or paragraph 80 criterion for a non-SFI, a failure of this use case would engageConnects the register to the downward-adjustment process before an incident
Escalation pathNamed forum and the time to escalate an incident or near missCPS 230 paragraph 31 requires timely identification, escalation and recording
Evidence locationWhere the monitoring output, model documentation and approvals sitAn assessment without evidence cannot support an adjustment decision
Review dateWhen the row was last confirmed and by which roleAt an enhanced entity an outdated statement is likely a material change requiring notification

Three tests decide whether the reconciliation has been run. Every row has a role title in the accountable person column. Every role title in that column appears on a current accountability statement, or, at a core entity, in the entity's own record of accountable persons. Every row names at least one criterion, or records in writing why none applies.

What happens between the incident and the committee?

The path runs in order, with the instrument named where one applies.

  1. A defect is detected in a deployed model, by monitoring, a complaint, or a downstream reconciliation.
  2. The incident or near miss is recorded and escalated in a timely manner under CPS 230 paragraph 31, and where the entity determines the incident is likely to have a material financial impact or a material impact on its ability to maintain critical operations, APRA is notified within 72 hours under paragraph 32.
  3. The register is read. Where it names the accountable person by role and the responsibility reference that covers the use case, the path continues at step 5.
  4. Where that field is blank, or the role title sits on no current accountability statement, the reconstruction runs against the entity's accountability record rather than the register, and at an entity that lodges an accountability map the row is escalated the same day as a possible material change.
  5. The downward-adjustment process tests the failure against the paragraph 37 criteria, using the entity's clearly identified triggers under paragraph 33(c)(i).
  6. Where a person is under investigation for conduct capable of satisfying a criterion, vesting is suspended under paragraph 39 until the investigation is closed.
  7. Severity is assessed against a scale, and the assessment records the individual contribution of each person, including inaction.
  8. An initial adjustment is recorded and revised once the full impact is known.
  9. The decision is recorded whether or not an adjustment is made, and the unmatched register rows go to the remuneration committee paper.

Steps 7, 8 and 9 come from CPG 511, dated May 2026, which states that "in particular, senior executives should not be financially rewarded where there are failings in risk management". Better practice is a severity scale illustrated with example cases and an assessment of individual contribution that includes inaction, both at paragraph 82, and an initial adjustment revised when the full impact is known at paragraph 83. Paragraph 84 is explicit: "Good practice is to record all adjustment decisions, including where an adjustment was considered but ultimately decided against."

That line converts the reconciliation from an exercise into evidence. A committee that considered an adjustment for an AI-caused failure and decided against it holds a defensible position if the reasoning is on file. A committee that never identified whose responsibility the model sat inside has nothing to file.

A two-sided contrast of the same AI register row, one with a named accountable role and a matched FAR responsibility reference, one with both fields blank, showing what the remuneration committee can and cannot decide in each case.
The same row, twice. One version gives the committee a decision. The other gives it a question.

A worked example, de-identified

[ENTITY] deploys [MODEL_NAME], supplied by [VENDOR], inside a calculation process recorded as [USE_CASE_ID]. A parameter defect produces incorrect outputs for a period before an internal check detects it, and it is not escalated when the processing team first observes it. The customer impact is material once quantified, and the incident is raised as [INCIDENT_REF].

The register row for [USE_CASE_ID] names a business owner and the vendor. The accountable person field is blank, because the model was procured as a service and the build sat with a delivery team. The FAR accountability statements name a responsibility for the end-to-end process, held by [ACCOUNTABLE_PERSON_ROLE], but the statement is worded at the level of the process and says nothing about the models inside it, and the register carries no responsibility reference.

The consequence is procedural. At [REMCO_DATE] the committee can see an incident, a customer impact, a vendor and a responsibility for the process. It cannot see, from its own papers, whether the defect sat inside that responsibility, whether the failure to escalate was an inaction by the person holding it, or whether executive level accountability is engaged.

Three prompts for the reconciliation

TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened.

Prompt
You are assisting with a governance reconciliation for [ENTITY]. Use only the two attached extracts. Do not use outside knowledge.

Attachment A is a de-identified extract of the AI use case register, with columns: use case reference, business owner role, accountable person role, critical operation flag, vendor.
Attachment B is a de-identified extract of the responsibilities recorded under the Financial Accountability Regime, being the lodged accountability statements at an entity that lodges them, or the entity's own record of accountable persons and their responsibilities, with columns: responsibility reference, role title, part or aspect of operations covered.

No individual names appear in either extract. If a name appears, replace it with [ACCOUNTABLE_PERSON] in your output.

Task:
1. For each row in Attachment A, find the row in Attachment B whose stated part or aspect of operations covers that use case.
2. Where Attachment A states an accountable person role for the row, report whether that exact role title appears in the role title column of Attachment B, as "present on statement" or "not on statement". Where Attachment A states no accountable person role, write "blank".
3. Return a table with columns: use case reference, critical operation flag, business owner role, accountable person role, role title on statement, matched responsibility reference, match basis quoted verbatim from Attachment B, match status.
4. Match status is one of matched, partial, or not stated. Use "partial" where Attachment B covers part of the use case, for example the process but not the decision the model makes, and quote the covering words. Use "not stated" where Attachment B contains no covering responsibility. Do not infer, propose or invent an owner, a role title or a responsibility reference.
5. After the table, list the use case references under three separate headings: status partial, status not stated, and accountable person role blank or not on statement. Within each heading, list the rows flagged as supporting a critical operation first.

Where you cannot quote the match basis verbatim from Attachment B, write "not stated".

What to check: open every flagged row against the extract yourself and confirm the status, including every row reported as not on statement. Confirm that no matched responsibility reference and no match basis appears in the output that is not in Attachment B, which is the failure mode this prompt is written to prevent. A role title reported as not on statement is the finding, not an error.

Prompt
Draft an assessment template for a remuneration downward-adjustment decision at [ENTITY]. Use only the attached documents: the entity consequence management framework, the entity remuneration policy, and the attached extract of APRA Prudential Practice Guide CPG 511 Remuneration, being paragraphs 79 to 84 on downward adjustment and paragraph 40 on adverse outcomes arising from third-party service providers.

Incident: [INCIDENT_REF], a defect in [MODEL_NAME] supplied by [VENDOR], affecting [USE_CASE_ID]. Use role titles only and no individual names.

Produce:
1. A severity scale with named levels. Where the attached documents name levels, use their wording. Where they do not, write "no scale in the attached documents" and set out the levels as headings only, with the descriptive text left blank for the entity to write.
2. For each level, the factors to be weighed, including the contribution of the individual, whether that contribution was an action or an inaction, and whether the outcome arose from a third-party service provider.
3. A field recording whether the assessment is initial or revised once the full impact is known.
4. A field recording a decision where an adjustment was considered and decided against, with the reason.

Cite the paragraph of the attached guide beside each factor. Where the attached documents do not support a factor, write "not supported by the attached documents" beside that factor and continue.

What to check: test each factor against CPG 511 paragraph 82 on severity and individual contribution including inaction before the template is used. Confirm the template has a field for a decision considered and decided against.

Prompt
Turn the attached reconciliation output into the decision section of a remuneration committee paper for [ENTITY], for the meeting on [REMCO_DATE]. Use only the attached reconciliation output and the attached consequence management framework.

Write:
1. Decision sought, in one sentence, naming what the committee is being asked to approve.
2. A table of every use case the reconciliation output flags, being those with match status partial or not stated and those whose accountable person role is blank or not on statement, showing use case reference, business owner role, the flag that applied, and a blank assignment date column for the owner to complete in the meeting.
3. One paragraph stating what the committee cannot determine while a row is unmatched.
4. One paragraph stating the review point and the owner by role title.

Use role titles only, never individual names. Do not include any figure or count that does not appear in the attached reconciliation output, and do not populate the assignment date column. Where a field is missing, write "not stated".

What to check: confirm that every figure and count in the draft appears in the reconciliation output, and delete anything that does not. Confirm the assignment date column came back blank rather than filled. Confirm the paper uses role titles throughout, and that the decision sought is a decision the committee has the power to make under the entity consequence management framework, rather than one reserved to the board.

Do this Monday

The artefact is a one-page reconciliation extract for the remuneration committee, titled the AI accountability reconciliation.

The owner is the head of operational risk. The remuneration committee secretariat carries the extract into the committee paper, and the accountable person for technology confirms the role titles.

The first step fits in an hour. Take every deployed use case flagged as supporting a critical operation under CPS 230, up to ten, then fill any remainder with use cases that touch customer outcomes or payments. Add two columns: accountable person by role title, and the downward-adjustment criterion a failure of that use case would engage, one of the five in paragraph 37, or paragraph 80 for a non-SFI. Fill what the existing files support, leave the rest blank, and count the blanks. That count is the finding.

The check that proves it worked is a match test, not a completion test: every non-blank accountable person role in those rows also appears on a current accountability statement, or, at a core entity, in the entity's own record of accountable persons. A role title in the register but not on a statement is the same defect as a blank, and the one most easily missed. Set the review point before the next remuneration cycle, and carry the unmatched rows into the committee paper.

The bottom line

CPS 511 does not need an AI amendment, because the criteria in paragraph 37, and in paragraph 80 for a non-SFI, already reach a significant failure of risk management and significant adverse outcomes for customers, whatever produced them. What the entity file usually lacks is the evidentiary link between the model and a person, and that link is a reconciliation between the AI use case register, the responsibilities recorded under the FAR and the consequence management framework. Run it before an incident, because a suspended vesting decision under paragraph 39 is a poor time to discover that a use case has no owner. Record the decision either way, including where an adjustment was considered and decided against, which is the recording practice APRA describes in CPG 511. Build the register row first, then the committee paper.

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Does CPS 511 mention artificial intelligence?
No. A text search of the standard returns zero occurrences of artificial intelligence and zero of algorithm. CPS 511 is technology neutral: the trigger in paragraph 37, or paragraph 80 for an entity that is not a significant financial institution, is the failure of risk management or the adverse outcome for customers, not the tool that produced it. That is why no amendment is needed before an AI failure can engage a downward adjustment.
Does a model failure automatically trigger malus?
No. CPS 511 requires the entity to set criteria and to take reasonable steps to adjust variable remuneration downwards where a criterion is satisfied. Whether a particular model failure is a significant failure of risk management is the entity assessment against its own severity scale. CPG 511 describes recording the decision either way as good practice. Treating malus as automatic overstates the standard and produces decisions that will not survive review.
Who is accountable when the model came from a vendor?
Outsourcing the build does not vacate the row. Section 23 of the Financial Accountability Regime Act 2023 requires the responsibilities of accountable persons to collectively cover all parts or aspects of operations. CPG 511 contemplates adverse outcomes arising from third-party service providers, and CPS 230 requires clear roles and responsibilities for senior managers covering the management of service provider arrangements.
What happens if a use case has no accountable person?
The unmatched rows become the committee paper. List each one, name the date by which the responsibility is assigned, and record the decision. For an accountable entity that meets the enhanced notification threshold, APRA and ASIC state that an accountability map or statement that no longer accurately reflects operations or responsibilities is likely a material change requiring notification, so an unmatched row is a notification question as well as a remuneration question.

Context

General information and education for Australian governance, risk and compliance practitioners. Not legal, compliance or financial advice.

AI angle

A reconciliation control that gives every AI use case a named accountable person before the remuneration committee has to find one.

Primary sources

CPS 511Financial Accountability RegimeAI governanceRemunerationAPRA
← Back to GRC

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.