Your menu grew. Your team did not.
On 19 August 2026 the Australian Prudential Regulation Authority said it will consult in September on reforms addressing eight areas of investment management. Five of them are named in the release, and the first one is the sentence worth reading twice: "Ensuring that a trustee's investment management capability is commensurate to the complexity of their investment menu".
That is not a documentation requirement. It is a proportionality test between two numbers that most trustees have never put side by side.
What is APRA actually proposing?
A consultation package, in September 2026, covering the full investment management lifecycle. Alongside the capability proposal, the release names four more: "Addressing weaknesses in onboarding, monitoring and offboarding practices", addressing material conflicts, improving member-level diversification, and strengthening trustee oversight and accountability.
The reforms apply to all trustees. APRA is explicit that platform trustees, with broader investment menus and more complex products, will feel the most change, and that trustees with simpler models and sound practices should expect limited impact.
The proposals are not speculative in origin. As at 9 September 2026, they follow APRA's 2025 review of industry practices covering around 95 per cent of platform assets under management, after which, in APRA's words, "APRA directed trustees to urgently uplift investment governance practice. It has also taken enforcement action against five trustees for investment governance failings."
Running alongside it is the Government's proposed compensation scheme, which would give members a clearer pathway to compensation where significant losses arise because a trustee failed to meet its obligations. Under that proposal APRA would set capital requirements for trustees offering higher-risk investment options. APRA Chair John Lonsdale put the connection plainly: "The Government's proposed compensation scheme will reinforce APRA's proposals by creating a stronger incentive for trustees to remediate poor investment governance." APRA says it will consult on the detailed design once the legislation is settled.
Read the two together and the incentive changes shape. A capability gap that used to cost supervisory attention starts to carry a capital number.
Where does AI come into this?
Not from APRA. The 19 August release does not mention artificial intelligence at any point, this is not an AI initiative, and nothing in it says trustees are using models for investment monitoring. The connection drawn from here is ours.
What makes it more than a stretch is the arithmetic of the proposal itself. If capability must be commensurate with menu complexity, a trustee facing a mismatch has exactly three moves: hire, shrink the menu, or find leverage. Hiring investment professionals is slow and expensive. Shrinking a menu is commercially unpopular. Leverage, in 2026, means a model reading mandates, factsheets, holdings disclosures and manager reporting at a scale a small team cannot.
The second reason is APRA's own letter to industry on artificial intelligence, issued to all APRA-regulated entities on 30 April 2026, which states that "assurance practices are not keeping pace with the scale, speed and complexity of AI." Put that next to a proposal about capability keeping pace with menu complexity and the same failure mode appears twice: the thing being governed scales faster than the thing doing the governing.
Why is coverage not capability?
Because they answer different questions, and only one of them is what a supervisor asks.

Coverage is a count. How many options were looked at, how recently, against how many data sources. A model raises coverage dramatically, and honestly, because retrieval and comparison across a large document set is exactly the work it does faster and more consistently than a person.
Capability is a different claim. It is whether a named person can state why an option belongs on the menu, on what evidence, what they expect it to do, and what would take it off. That is a position someone holds and can be questioned on. It is not recoverable from a document set, because half of it is a view about the future.
The trap is that the two look identical in a board pack. A monitoring output covering the whole menu, current to last week, formatted consistently, reads as though the menu is understood. It demonstrates that the menu was processed. Those are not the same finding, and only the second one survives a supervisor asking why option [OPTION_CLASS_BAND] is still open.
This is the same shape as the limit on a trustee's core discretions under the SIS Act, which are owed personally to members and cannot be handed to a tool. That piece is about who may lawfully decide. This one is about a prior question: whether the trustee can defend the decision at all once the menu is larger than the team.
Which part of the lifecycle is actually testable?
Offboarding, and it is the part that gets the least attention.
Onboarding decisions are made once, deliberately, with someone arguing for the option. They tend to be well documented for that reason. Monitoring runs continuously and produces artefacts by default. Offboarding is the decision nobody is advocating for. Nobody's plan requires it. It is also the point at which member harm either stops or continues.
That makes the exit trigger the most testable control in the lifecycle, and the one worth building first.
Notice what the middle column never contains. The model reports that a criterion was met. It does not decide that the criterion was the right one, and it does not decide what happens next.
An exit criterion written before it is needed is worth more than any amount of monitoring written after. It converts an argument into a test.
What does a defensible exit trigger contain?
Five parts, and a trigger missing any of them is a sentiment rather than a control.
- A written criterion per option class, set in advance. Stated as a condition that can be observed, not as a concern to be monitored. "Underperformance against the stated benchmark over [PERIOD_BAND]" is a criterion. "Ongoing concerns about performance" is not.
- A named owner who pulls it. A role, held by a person, with the authority to start the exit without further permission. Committee-owned triggers do not fire between meetings, which is when they usually need to.
- A test cadence, and a record that the test ran. The date the criterion was last tested, not the date the option was last reviewed. Those diverge quickly, and only the first one is evidence.
- A stated response to a met criterion. Close, restrict to existing holders, place on watch with an end date. A watch with no end date is where exit decisions go to expire.
- The member-impact step. What happens to members currently invested when the trigger fires, decided before the trigger fires rather than during it.
TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened. Applied here, the model is grounded in your own mandates and reporting rather than its general knowledge of a manager, the person at the decision point is the trigger owner, and the log is the dated test record that survives them leaving.
What does this look like on one menu?
Take a single option class rather than the whole platform. [BUSINESS_AREA_BAND] holds [OPTION_COUNT_BAND] options in [OPTION_CLASS_BAND], monitored by a team of [TEAM_SIZE_BAND].
The monitoring model is grounded in the mandates, the latest manager reporting and the holdings disclosures, and produces a coverage report showing every option tested against the agreed criteria with a source locator on each field, plus an explicit list of options where a source was missing or stale. That list is the useful half, because the gaps are what a supervisor asks about.
Three options show a met exit criterion. Each goes to [OWNER_ROLE], who records a decision and a date: one closes, one moves to restricted with an end date attached, and one stays open with the reason stated, because the criterion turned out to be poorly drafted rather than met in substance. That last outcome is a finding about the criterion, and it goes back into the trigger set rather than being quietly ignored.
The capability question is answered separately and honestly. For [OPTION_COUNT_BAND] options, how many can [TEAM_SIZE_BAND] people defend on demand? If the answer is a fraction, the monitoring output has not changed it, and the register should say so rather than imply otherwise. The same discipline that makes an AI use case register readable by a board applies to a menu: the honest gap is the part that earns trust.
What should the model never assert?
Five things, each a claim about something outside the documents.
That an option is suitable for a member cohort. That a manager's process is sound, as opposed to consistently described. That an exit criterion was not met, when the truth is that the source data was unavailable. That a deviation is immaterial, which is a judgement about members rather than about numbers. And that the menu is adequately governed, which is the conclusion the whole exercise exists to test.
Anything the model does say about an option is a hypothesis carrying a source locator, in the same way that an AI-assisted vendor assessment counts as evidence only once it is traceable. The model makes the tests cheap enough to run properly. The defence stays with the person whose name is on it.
Do this Monday
- Put the two numbers on one page. The count of options on the menu, and the count of people who could defend a randomly chosen one without preparation. That ratio is what APRA's proposal is about.
- Pick one option class and find its exit criterion. If there is no written criterion, that is the finding. Write one before writing anything else.
- Date the last test, not the last review. For each criterion, the date someone actually ran it. A review that discussed performance is not a test of a trigger.
- Name the owner of each trigger. A role with a person in it, able to act between committee meetings.
- Separate coverage from capability in your reporting. Two lines, not one. How much of the menu was tested, and how much of it the trustee can defend. Reporting them as a single assurance line is how the gap disappears.
- Write the shrink option down. Model what the menu would look like at a size the current team can defend. Having the number ready is what makes it a choice in September rather than a concession later.
Bottom line
APRA is proposing to test whether a trustee's investment management capability matches the complexity of what it is selling, with a consultation due in September and a compensation scheme forming behind it that would attach capital to the answer. AI genuinely helps with the coverage half, and it will make monitoring outputs look more complete than the underlying capability is. The defensible move is to make the exit trigger the artefact: written before it is needed, owned by a named person, tested on a date, with the response to a met criterion decided in advance. Everything else is a report about a menu nobody has committed to defending.
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. APRA's consultation package had not been published at the time of writing, and nothing here anticipates its content beyond what APRA's own media release states. Obligations vary by entity type, licence and circumstance. Always refer to primary source guidance from APRA or the relevant authority.
References
- APRA, APRA to strengthen superannuation investment governance, 19 August 2026. https://www.apra.gov.au/news-and-publications/apra-strengthen-superannuation-investment-governance
- APRA, APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026. https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai
- APRA, Prudential Standard SPS 530 Investment Governance. https://www.apra.gov.au/standards/sps-530
TheAICommand. Intelligence, At Your Command.


