The Financial Accountability Regime pushes accountability to a named person. AI does not change that. AI tooling decisions sit inside the responsibilities of a named accountable person, even when they are never framed as AI decisions, so that person owns the consequence of deploying AI inside a regulated function.
Context for general readers: The Financial Accountability Regime Act 2023 makes individual senior executives in banks, insurers, and super funds personally answerable for what happens inside the parts of the business they run. It was designed in response to the Hayne Royal Commission to address a perceived gap in personal accountability at the senior executive level. Each Accountable Person has a documented set of responsibilities, and APRA and ASIC can take action against them individually if they fail to take reasonable steps to discharge those responsibilities. AI tooling has entered every part of regulated financial services, and so it has entered the accountability picture as well.
This article examines how AI tooling decisions intersect with FAR. It is written for boards, accountable persons, and the GRC professionals who support them. The framing is practical: how does an accountable person evidence that they have taken reasonable steps to address AI risk inside their portfolio?
Why does FAR matter for AI governance?
FAR's defining feature is the personal accountability dimension. A breach of an accountable person's accountability obligations can lead to disqualification by the regulators, reduction of deferred variable remuneration, and reputational consequences for that individual, and a person who is knowingly involved in the entity's contravention faces civil penalty exposure under section 81 of the Act. The regime is designed to make decisions about systems, controls, and customer outcomes traceable to a person, not a committee.
For AI specifically, this matters because the operational reality of AI deployment is often committee-driven. AI governance councils, ethics committees, technology steering committees, and risk fora all touch AI tooling decisions. FAR cuts across this committee landscape and asks who, individually, is accountable for the outcome. The committee may make the decision; the accountable person bears the consequence, the same question of ownership examined more broadly in who carries it when AI gets it wrong.
For AI tooling, this matters in two ways.
First, the procurement and deployment decision. When a regulated entity acquires an enterprise AI capability and deploys it inside a regulated function, the accountable person responsible for that function inherits accountability for the consequences. The procurement may have been led by IT or by a separate AI capability function, but the accountability sits with the line owner.
Second, the operational use decision. Even where AI tooling has been procured centrally, individual business unit decisions about how to deploy the tooling create accountability exposure. An accountable person whose team uses an AI tool in a regulated process is accountable for whether that use is fit for purpose, governed appropriately, and consistent with the entity's broader risk appetite.
Which prescribed responsibilities cover AI tooling?
FAR reaches AI tooling through two mechanisms. First, under section 10 of the Act a person is an accountable person if they hold actual or effective senior executive responsibility for management or control of the entity, or of a significant or substantial part of its operations, or if they hold a responsibility prescribed by the Financial Accountability Regime (Minister) Rules 2024, in force from 15 March 2024. The prescribed responsibilities include senior executive responsibility for management of the entity's overall risk controls or overall risk management arrangements, information management (including information technology systems), the internal audit, compliance, human resource, and dispute resolution functions, client or member remediation programs, breach reporting, and, for reporting entities, the anti-money laundering function.
Second, the Regulator Rules have required larger entities to record a list of key functions against accountable persons in the FAR register. The list includes operational risk management, data management, technology management, conduct risk management, product design and distribution obligations, and scam management. The prescribed key-functions list is slated for removal under the June 2026 relief package discussed below; the underlying responsibilities are not.
AI tooling decisions can sit inside any of these. The mapping work practitioners need to do:
- Operational risk and overall risk management. AI tooling that supports operational processes (claims, underwriting, customer service) sits inside the operational risk management key function and the prescribed responsibility for overall risk management arrangements. The accountable person is responsible for ensuring the AI tool is included in the operational risk framework.
- Compliance, breach reporting, and AML. AI tooling used in regulatory monitoring (AML/CTF transaction monitoring, conduct surveillance, complaints handling) sits inside the compliance function, breach reporting, and, where relevant, the anti-money laundering function. The accountable person is responsible for ensuring the AI tool produces compliance outcomes consistent with the regulatory regime.
- Customer-facing functions. AI tooling that influences customer experience (recommendation engines, AI-driven personalisation, automated decisioning) creates exposure through the dispute resolution function, client or member remediation programs, and the product design and distribution obligations key function. The accountable person is responsible for ensuring those outcomes are consistent with target market and conduct expectations.
- Information and technology management. AI tooling that processes entity information sits inside the prescribed responsibility for information management (including information technology systems) and the data management and technology management key functions. The accountable person is responsible for ensuring the information produced is reliable.
The supervisory expectation is that the accountability arrangements are documented, current, and reflective of how the entity actually operates. For entities that meet the enhanced notification threshold, that documentation takes the statutory form of accountability statements and an accountability map lodged with the regulators. Where AI tooling has been deployed without those arrangements being updated, the entity has a documentation gap that supervisors may pursue.
What "reasonable steps" looks like for AI
The FAR Act 2023 does not require accountable persons to prevent every adverse outcome inside their portfolio. Section 21 of the Act requires them to conduct their responsibilities by, among other things, taking reasonable steps to prevent matters arising that would adversely affect the entity's prudential standing or result in a material contravention of the listed financial services laws. Section 22 then says that taking reasonable steps includes having appropriate governance, control and risk management, safeguards against inappropriate delegations of responsibility, appropriate procedures for identifying and remediating problems, and taking appropriate action in response to non-compliance. The reasonableness standard is fact-specific, but the statutory list gives the supervisory expectation shape.
For AI tooling, four categories of reasonable step are likely to be tested.

1. Awareness
An accountable person whose portfolio uses AI tooling needs to know about it. Awareness requires the existence of a list, which in most entities takes the form of an AI use case register the board can actually use. An accountable person who cannot describe, in broad terms, the AI tools operating in their portfolio is not in a strong position to evidence reasonable steps.
The practical action: each accountable person should receive a quarterly summary of AI tooling in scope of their portfolio, with material changes flagged.
2. Governance design
Reasonable steps include ensuring that the governance framework around AI tools is adequate. This is not the accountable person personally writing the policy; it is ensuring that a policy exists, is current, and is being followed.
The practical action: the entity's AI governance framework should be visible to accountable persons, with attestations on adoption and adherence.
3. Monitoring and escalation
Reasonable steps include having a way to know when something is going wrong. For AI tooling, this means monitoring metrics that reveal degradation, including output quality, model drift, and adverse customer outcome indicators.
The practical action: AI-specific risk reporting should reach accountable persons through the existing risk reporting channels, not as a separate AI committee report. AI risk is not separate from operational risk or conduct risk; it is a manifestation of them.
4. Response capability
Reasonable steps include being able to respond when an issue emerges. For AI tooling, this means having an incident response capability that includes AI-specific failure modes (for example, output quality degradation).
The practical action: the existing incident response framework should be tested against AI-specific scenarios, not just availability and security incidents.
Who is accountable when an AI tool is shared across teams?
A specific FAR challenge worth examining is the shared accountability problem. AI tools are often selected centrally (by IT, by a separate AI capability team, or by procurement) but deployed across multiple business units, each with its own accountable person. When something goes wrong with the tool, the accountability picture can be unclear.
The FAR Act answers part of this directly. Under section 21(2), to the extent that two or more accountable persons have the same responsibility, each of them holds the accountability obligations in relation to that responsibility to the same extent as if it were solely their own. Shared use of an AI tool does not dilute anyone's accountability. The regulators' joint information paper, Financial Accountability Regime: Information for accountable entities, works through this layering for the operational risk management key function: the chief executive accountable for the entity operating within the board-approved risk appetite, the chief risk officer accountable for the framework, and a senior executive responsible for the risks inherent in specific products, activities, processes and systems. A shared AI tool invites exactly the same layering, and it still needs a clearly designated lead, even if multiple business units use the tool.
The practical pattern emerging in major institutions is to designate the accountable person responsible for the most material use of the tool as the lead accountable person for the tool itself, with the accountable persons of secondary user business units having supporting accountability for their specific use cases. This pattern works only if it is documented; an undocumented allocation is unlikely to satisfy FAR's documentation expectations.
Records and attestation
FAR's documentation obligations run through registration and notification rather than a general record-keeping duty. Every accountable entity must register its accountable persons and notify the regulators of events affecting its accountability arrangements within 30 days. Entities that meet the enhanced notification threshold must also lodge accountability statements and an accountability map and notify material changes to them; as at 15 August 2026 the thresholds sit at total assets of $20 billion for ADIs, $10 billion for general insurers and life companies, $3 billion for private health insurers, and $30 billion for RSE licensees. Where AI tooling decisions sit inside an accountable person's responsibilities, the records of those decisions are what make a reasonable-steps position evidencable.
The practice that has emerged across the industry is the periodic attestation cycle: accountable persons attest, on a defined cadence, that they have taken reasonable steps to discharge their accountabilities. This is an internal control rather than a statutory FAR requirement, but where AI tooling is in scope of an accountable person's portfolio, the attestation should explicitly cover AI risk.
The practical task for compliance teams supporting accountable persons: ensure that the attestation framework prompts the accountable person to consider AI tooling risk explicitly, with sufficient information to make the attestation meaningful. An attestation made without supporting evidence is an attestation that creates personal exposure for the accountable person without giving them protective evidence.
Insurer and trustee considerations
FAR commenced for insurers, their licensed NOHCs, and superannuation trustees on 15 March 2025, completing the regime's rollout across banking, insurance and superannuation. The architecture is the same as for ADIs, but the specific responsibilities are differently weighted: the Minister Rules add insurance-specific prescribed responsibilities, and the key-function lists for insurers and RSE licensees add functions such as underwriting, reinsurance management, insurance risk management, investment management, and member outcomes and member engagement. For insurers, AI tooling in claims management, underwriting, and policy distribution intersects directly with those functions. For trustees, AI tooling in member communication, investment recommendation (subject to the relevant licensing framework), and complaints handling sits inside the accountability picture.
The implementation lessons from ADIs transferred directly. More than a year into the insurer and trustee phase, AI tooling governance should not be running as a separate workstream. It belongs inside the accountability framework the entity already maintains, not bolted on beside it.
Practical implications this quarter
For boards, accountable persons, and the GRC teams supporting them:
- Refresh the accountability documentation for AI tooling visibility. Where AI has been deployed since the last review of the accountability map or the AI use case register, ensure the responsibility allocation is documented.
- Build AI tooling into the existing accountable person reporting cadence. Quarterly AI portfolio updates to accountable persons, with clear escalation triggers, are a sensible operational standard, and a Monday regulatory sweep keeps FAR-relevant regulatory change flowing to the same owners.
- Test reasonable-steps evidence on a sample basis. Pick one AI use case in each accountable person's portfolio and walk through what reasonable steps look like for that case. This is internal audit work in many entities; it can also be done as part of a periodic FAR health check.
- Coordinate the AI governance committee with the FAR governance framework. Where AI governance has been built as a parallel structure (for example, an AI Council reporting to the executive committee), the relationship to the FAR-defined accountability flow should be explicit.
Direction of travel
FAR is now in force across all three sectors, and the settings are still moving. On 16 June 2026 ASIC and APRA announced a package to reduce FAR's administrative burden: the prescribed key-functions list is slated for removal, accountability maps will no longer need direct-report detail, and the materiality threshold for notifying changes will rise. The regulators are consulting on the changes and aim to implement them by the end of 2026; as at 15 August 2026 they remain proposals. The relief changes what entities must file, not what a named person owns, and the site's companion analysis of what the June 2026 FAR relief means for your AI map works through the register implications in detail. Direct supervisory engagement on AI under FAR has otherwise been quiet, but the joint information paper made clear the regulators expect accountable persons to understand and comply with their obligations across everything in their remit, a posture that also runs through board AI literacy as a control expectation. AI is the most prominent emerging risk in the financial services operating environment.
The institutions that will be best placed are those that treat AI tooling decisions as a routine part of the FAR responsibility framework, not as a special category requiring its own governance overlay. The accountability runs through the line, and the documentation should follow. As AI tooling continues to embed inside regulated workflows, the accountability map and the AI use case register will need ongoing maintenance to reflect operational reality. Practitioners who treat the map as a living document, refreshed whenever material AI deployments occur, will keep their accountable persons in a defensible position. Practitioners who treat the map as an annual artefact will find it lagging behind operational reality, with the gap visible to supervisors.
Bottom line
FAR makes a named accountable person answerable for the systems and outcomes inside their portfolio, and AI tooling decisions sit inside that accountability whether or not the accountability map records them. The defensible position is to treat the map as a living document, refreshed whenever a material AI deployment occurs, and to route AI risk through the existing risk and attestation channels rather than a separate governance overlay.
Do this Monday:
- Refresh the accountability map and the AI use case register wherever AI has been deployed since the last review.
- Give each accountable person a quarterly summary of the AI tooling in their portfolio, with material changes flagged.
- Walk one AI use case in each portfolio through what reasonable steps look like: awareness, governance design, monitoring, and response.
- Route AI-specific risk reporting through existing risk channels, not a separate AI committee report.
- Make the attestation framework prompt accountable persons to consider AI tooling risk explicitly, with supporting evidence.
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.
TheAICommand. Intelligence, At Your Command.


