Answer index

Governance, risk and compliance

247 questions answered. APRA, ASIC, AML/CTF and the prudential standards.

  • Are ASIC's proposed kill-switch rules in force?

    No. ASIC released CP 386, proposing amendments to the market integrity rules for trading systems and automated trading, on 27 August 2025, with comments closing on 22 October 2025. Among the proposals are a requirement for kill switches enabling immediate suspension of aberrant trading algorithm activity, and an extension of the principles-based trading system rules to participants' development, testing, use and monitoring of their algorithms. As at the time of writing, the amended rules had not been made. Treat the items as proposals with a clear direction of travel, not obligations. From Agentic Trading and the Purpose Problem

  • Are these forecasts hiring advice?

    No. They are editorial projections based on regulator, labour-market and salary-guide signals available to 10 July 2026. Employers and candidates should refresh the evidence and obtain professional advice for their circumstances. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

  • Can a clean upload submit itself?

    Yes, by default. The APRA Connect Guide says that when a complete data file is uploaded without validation errors or warnings, default functionality automatically submits the return regardless of the uploader's role. Portal roles therefore do not supply a universal human gate, which is why a pre-upload internal release gate is a sensible proposed control. From AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

  • Can a superannuation trustee let an AI make a decision?

    A trustee can use AI to inform or support a decision, but the core discretions the SIS Act reserves to the trustee cannot be handed to a model. Section 52(2)(h) requires the trustee not to enter into any contract, or do anything else, that would prevent or hinder it from properly performing its functions, and section 52(2)(c) requires the trustee to exercise its powers in the best financial interests of beneficiaries. A decision made or effectively dictated by an AI, where the trustee cannot explain or stand behind the reasoning, is difficult to reconcile with those covenants. The safe pattern is AI supports, the trustee decides, and the reasoning is recorded. From Super Trustees, AI and the Discretion You Cannot Delegate

  • Can AI be used at all in a whistleblower program?

    Yes, in a deliberately reduced role. AI can check the public policy against section 1317AI, where it applies, and RG 270; generate empty intake, consent, protection-risk and investigation-plan templates; test whether a proposed management report contains indirect identifiers; and organise approved, high-level program metrics for human analysis. It should not classify a person as protected, validate consent, determine whether allegations are substantiated, select disciplinary action or judge detriment risk. From Do Not Put a Whistleblower Disclosure Into Your General AI Tool

  • Can AI clear a sanctions alert?

    No. AI is useful at the preparation layer: extracting aliases and identifiers, comparing scripts and transliterations, mapping payment-chain entities and assembling cited evidence. It should not infer a person from name similarity, decide that factual control is absent, release a held payment or determine whether a permit is required. A trained human with the right delegation makes the disposition. From A Sanctions Alert Is Not Cleared Because the Model Says So.

  • Can AI decide the outcome of a customer complaint?

    No. Deciding whether to uphold or reject a complaint, and explaining the reasons, is a regulated decision that a person accountable under RG 271 must own. AI can draft a response for a human to check and approve, but it cannot be the decision-maker, and letting it decide would put an unexplained, potentially unfair outcome in front of an aggrieved customer. From AI in Complaints Handling: What RG 271 Reserves for a Person

  • Can AI decide whether a declaration is accurate?

    No. AI can compare attestations with audit findings, detect different reporting periods, find actions closed without closure evidence and surface an incident that conflicts with a no exceptions response. Every result stays a lead until an authorised person verifies it against the source. The Board decides accuracy and qualification, and the required signatories decide whether they can sign. From The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

  • Can AI decide whether a regulatory change requires action?

    No. The skill file described here classifies each area as no impact, monitor or change required as a draft only, and its guardrails prohibit legal conclusions. A person who owns the obligation validates every classification before anything enters the obligations register. That human gate lines up with APRA's expectation of human involvement for high-risk decisions in its 30 April 2026 letter to industry on AI. From A Skill File for Regulatory Change: Impact Assessment On Demand

  • Can AI-assisted review sit inside an ASIC production?

    The production guidelines attached to INFO 242 recognise manual review, keyword or concept searches and technology-assisted review such as predictive coding. They encourage recipients to document the review approach, how it was conducted, decisions made and the outcome. AI-assisted classification can sit inside that review process if approved. The method, sampling, exception treatment and human decisions still need to be recorded, and the assistant must not decide that a search was sufficient. From ASIC Asked for the File. Your AI Summary Is Not the Production.

  • Can AI-generated output stand as audit evidence under Standard 14.1?

    Not on its own. Standard 14.1 requires information to be relevant, reliable and sufficient. AI output is not obtained directly by the auditor, is not an independent source, and a non-deterministic system cannot guarantee a competent person re-running the work reaches the same result. Corroboration against source records, not generation, earns it a place in the file. From AI in Internal Audit: What Still Counts as Evidence

  • Can an AI agent initiate CDR payments today?

    No. The Act is in force but no action type has been designated, so no provider, human or AI, is initiating payments or switches through the CDR yet. That gap is the opportunity. Compliance teams can design the authorisation, consent and audit controls for agent-initiated actions before any money can move, rather than retrofitting them onto a live rail under time pressure. From Governing AI Agents Before the Consumer Data Right Lets Them Act

  • Can an LLM make the decision to file a suspicious matter report?

    No. The decision to file or not file a suspicious matter report is a judgement the regulated entity makes, with consequences sitting with the entity. LLM-driven triage can support the analyst's decision, but the decision itself should sit with a human. Final certification of customer due diligence is likewise a regulated act requiring human authority. From AML/CTF and Large Language Models: A Compliance View

  • Can benchmarks verify a consumer's financial situation?

    No. RG 209.135 to RG 209.140 distinguish statistical benchmarks from information about the individual consumer. Benchmarks can test plausibility within a broader process, but they do not confirm that the consumer's information is true. A model-derived score deserves the same discipline: a useful input, never proof of the customer facts it does not contain. From Your AI Credit Score Is Not a Responsible Lending File.

  • Can competitors use the same pricing software?

    Common software use is not automatically unlawful. Risk rises when the provider combines competitively sensitive data from multiple competitors or delivers recommendations that reduce uncertainty about rivals' future conduct, the hub-and-spoke pattern regulators keep flagging. Obtain competition advice on the actual design, data flows and contractual restrictions rather than relying on a generic confidentiality clause. From Your Pricing Agent Is Still Your Competition Risk

  • Can disclaimers keep an AI interaction inside DDO and general advice?

    No. ASIC's communication emphasises that the substance of a communication matters more than the formal classification an institution applies. Disclaimers cannot, on their own, change how the law characterises a communication. If an interaction has substantively crossed into personal advice, a general information disclaimer will not recharacterise it. From DDO and AI-Driven Personalisation: Where the Boundary Sits

  • Can I use an AI model to help build the ADM register and disclosure?

    Yes, for structuring, classification logic and first-draft drafting, but only inside a dedicated project space using de-identified inputs with placeholder tokens. Never paste real personal, claim or health data. The model produces a register skeleton and disclosure language. It does not decide what is in scope. A named human checks every scope call against the primary source. From Automated Decisions Now Belong in Your Privacy Policy

  • Can I use an AI model to help review these contracts?

    Yes, for drafting a gap checklist, summarising a long agreement against the requirements and producing a first-pass register. It is a drafting aid, not the decision-maker. A named accountable person, with legal advice, decides whether a contract complies and whether an exit or fallback is genuinely feasible. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

  • Did APRA say any of this was about artificial intelligence?

    No. The 19 August 2026 release does not mention artificial intelligence at any point, and APRA has not framed the investment governance package as an AI matter. Connecting it to AI-scaled monitoring is our analysis. The primary-source AI hinge is APRA's separate letter to industry of 30 April 2026, addressed to all APRA-regulated entities. From Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

  • Do the IIA Global Internal Audit Standards mention artificial intelligence?

    No. A full-text search of the 2024 Global Internal Audit Standards returns no mention of artificial intelligence, and there is no AI Topical Requirement. The Standards are technology-neutral by design, so AI-assisted work answers to the same evidence, documentation, objectivity and due-care requirements as any other audit work. From AI in Internal Audit: What Still Counts as Evidence

  • Do the small business and employee records exemptions apply?

    No. Schedule 2 is drafted to be read on its own, and clause 6 provides that the rest of the Act is disregarded when interpreting it. Part 3 contains the Schedule's own exemption regime, covering journalists, agencies and State and Territory authorities, intelligence agencies and persons under 18. There is no small business exemption and no employee records exemption in Part 3. From Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

  • Do we need a human to review AI-generated marketing content?

    In practice, yes. Because AI-generated advertising is held to the same standard as human-written advertising, and because generative tools can produce inaccurate, outdated or biased claims, a defensible process puts AI-generated marketing through the same substantiation and sign-off you already apply to human content. The person who approves it, not the model, is accountable for whether the final claim is true and not misleading. From AI Wrote the Ad. ASIC Still Holds You to It.

  • Does a Complete status mean the return is assured?

    No. APRA's support material says a return marked Complete has all required fields populated and is ready for submission, while Submitted is a separate status. Completion is a technical workflow state, not an assurance opinion about the truth of the information. From AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

  • Does a human approval step take an automated system out of scope?

    No. APP 1.8 expressly covers decisions where a machine does something substantially and directly related to making the decision and a person finishes it. If a model ranks, scores or recommends and a human clicks approve, the system still shapes the outcome and belongs in the privacy policy. From Automated Decisions Now Belong in Your Privacy Policy

  • Does an AI complaints tool create privacy obligations?

    Yes. A complaint file routinely contains sensitive information such as health, financial hardship and family and domestic violence. An AI tool that reads and drafts on that file is processing sensitive personal information, often through a third-party service, so it carries Privacy Act obligations and needs the same governance as any high-consequence system. From AI in Complaints Handling: What RG 271 Reserves for a Person

  • Does an Australian data region mean APP 8 does not apply?

    No. Residency describes where information sits. APP 8 applies before an APP entity discloses personal information to a person who is not in Australia or an external Territory and is not the entity or the individual. That is a recipient test, so the decisive facts are which legal entity can access the information, for what purposes, and whether your organisation retains effective control. A single Australian region can still contain several legally distinct access paths. From Data Residency Does Not Settle APP 8 for Your AI Prompts.

  • Does an offline controls console satisfy APRA CPS 230 on its own?

    No. CPS 230 requires identifying and managing operational risks, maintaining and testing controls, and remediating gaps on a timely basis. A console does not satisfy it alone. It only makes the working layer of control monitoring and testing more consistent before results enter the official platform. From Build an Offline GRC Controls Console Without Creating Shadow IT

  • Does APRA CPS 230 apply to enterprise AI tools like Copilot, Gemini, Claude and ChatGPT Enterprise?

    Yes. Most enterprise AI tools sit inside the third-party arrangements CPS 230 governs. Where AI outputs feed material decisions or critical operations, the standard reaches the model lifecycle as well as the contract, so the question is no longer whether AI is in scope but how to evidence it. From CPS 230 and AI: A Practical Operational Resilience Playbook

  • Does APRA or ASIC require a validation passport?

    No. The passport is a control design proposed by TheAICommand, not a regulator-prescribed document. CPS 220 and SPS 220 set enforceable risk-management baselines within their respective scopes, CPG 235 is non-binding data-risk guidance, APRA's 30 April 2026 AI letter gives supervisory observations and expectations, and ASIC REP 798 reports thematic findings and better-practice examples. None prescribes this artefact; all inform its fields. From Your GenAI Approval Needs an Expiry Trigger.

  • Does APRA require a register of AI skill files?

    Not by that name. APRA's 30 April 2026 letter to industry names an inventory of AI tooling and use cases among the minimum practices it expects of regulated entities, alongside ownership and accountability across the AI lifecycle. A register of approved skill files, each with an owner, version, approval date and next review, is a practical way to meet that expectation for this class of tooling, and it produces the evidence a supervisor or internal auditor will ask to see. From Skill Files Are Controlled Documents. Treat Them Like It

  • Does APRA require a run-lineage packet for AI?

    No. CPG 235 is a prudential practice guide describing APRA's view of sound practice on data risk, including data lineage, metadata, lifecycle controls and auditability, and it does not itself create enforceable requirements. APRA's 30 April 2026 AI letter connects existing prudential risk management to AI, and its media release said APRA was not proposing additional requirements at that stage. The run-lineage packet is a proposed control design built from those principles. From Defensible AI Lineage Starts Before the Prompt.

  • Does APRA's AI letter apply to superannuation trustees?

    Yes. APRA's 30 April 2026 letter to industry states that APRA conducted a targeted engagement on a group of selected large banks, insurers and superannuation trustees in late 2025, and the expectations it sets out apply across regulated entities including RSE licensees. Among the minimums APRA names are ownership and accountability across the AI lifecycle, an inventory of AI tooling and use cases, human involvement for high-risk decisions and accountability, and staff training on AI use, misuse and limitations. From Super Trustees, AI and the Discretion You Cannot Delegate

  • Does ASIC's RG 234 apply to AI-generated advertising?

    Yes. ASIC's updated RG 234, published on 9 June 2026, makes clear that the law and ASIC's guidance apply to AI-generated advertising in the same way they apply to human-written advertising. Using an AI tool to generate a claim does not lower the standard or shift responsibility. The financial services misleading-conduct prohibitions in the ASIC Act and Corporations Act apply regardless of who or what produced the words. From AI Wrote the Ad. ASIC Still Holds You to It.

  • Does AUSTRAC have AI-specific guidance for AML/CTF programs?

    AUSTRAC has not published guidance dedicated to reporting entities' use of AI; its AI transparency statement covers the agency's own use of AI. AUSTRAC's obligations and guidance material makes clear the obligation is on the reporting entity to design a program proportionate to its risk profile and operate it consistently with the AML/CTF Act and Rules. LLM use sits inside that obligation, and supervisory engagement on AI is increasingly likely. From AML/CTF and Large Language Models: A Compliance View

  • Does Australia have an AI Act?

    No. The National AI Plan, launched on 2 December 2025, confirmed the government will not introduce a standalone AI Act or the mandatory guardrails for high-risk AI proposed in 2024. Australia has chosen to regulate AI through existing technology-neutral laws, sector regulators, voluntary guidance and an advisory AI Safety Institute, rather than a single dedicated statute. From Australia Will Not Pass an AI Act. You Are Still Regulated.

  • Does CPS 230 apply to AI vendors even if the contract is not labelled an AI contract?

    Yes. CPS 230 reaches any material service provider, meaning one an entity relies on to perform a critical operation or that exposes it to material operational risk. If a model helps run claims processing, fraud detection or credit decisioning, the provider behind it is captured, whatever the contract calls it. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

  • Does CPS 230 treat every foundation model as a material service provider?

    No. CPS 230 defines material service providers by reliance for a critical operation or exposure to material operational risk, subject to the standard's minimum categories and APRA's classification powers. Whether a model operator, cloud or gateway meets that test is an entity-specific assessment. A broader internal dependency graph can still record every relevant upstream dependency with an evidence status. From Your AI Vendor Count Is Hiding One Foundation Model.

  • Does CPS 234 apply to AI vendors my organisation uses?

    Yes. CPS 234 covers information assets managed by third parties, not just the entity itself. AI vendors introduce new asset categories such as prompts, fine-tuning data, embeddings, and inference logs, all of which the standard treats as in-scope and which must be identified, classified, and protected commensurate with their sensitivity. From CPS 234 and AI Vendors: A Due Diligence Framework

  • Does FAR apply to AI tooling decisions in financial services?

    Yes. AI tooling decisions sit inside FAR-prescribed responsibilities even when not framed as AI decisions. Deploying AI in compliance monitoring is a compliance system design decision; deploying it in customer-facing operations is a customer outcomes decision. The accountable person owns the consequence regardless of how procurement framed the tooling choice. From FAR and AI: How Accountability Maps to Tooling Decisions

  • Does FAR apply to insurers and superannuation trustees for AI governance?

    Yes. FAR replaced BEAR for ADIs from 15 March 2024 and commenced for insurers and superannuation trustees on 15 March 2025, so the regime now applies across banking, insurance and superannuation. The architecture is the same, though prescribed responsibilities are weighted differently. AI tooling governance belongs inside the accountability framework the entity already maintains, not in a separate workstream. From FAR and AI: How Accountability Maps to Tooling Decisions

  • Does human approval remove the competition risk?

    No. A human click is a weak control if the reviewer does not understand the inputs, the objective or the market pattern the agent is producing. Human oversight needs authority, information, materiality thresholds and the time to challenge a recommendation before it takes effect. From Your Pricing Agent Is Still Your Competition Risk

  • Does market manipulation in Australia require proof of intent?

    No. Australia's core prohibitions are drafted on effect. In DPP (Cth) v JM [2013] HCA 30; (2013) 94 ACSR 1; 298 ALR 615, the High Court took a broad view and held that a sole or dominant purpose of creating or maintaining an artificial price is not necessary to a contravention, though it can provide evidence that a transaction is likely to have the prohibited effect. Purpose is evidence rather than an element to prove. It still matters, because a legitimate trader purpose is what saves a price-moving trade. From Agentic Trading and the Purpose Problem

  • Does taking reasonable steps transfer the liability?

    No. Subject to its statutory conditions and exceptions, section 16C can treat an overseas recipient's act or practice as the APP entity's own breach. The OAIC says this accountability can apply even where the entity took reasonable steps and the overseas recipient subsequently mishandled the information. Reasonable steps are an obligation, not an indemnity. From Data Residency Does Not Settle APP 8 for Your AI Prompts.

  • Does the AUSTRAC AI update affect my firm if we already run a mature AML program?

    Yes, but differently. The starter kits are not your tool, yet the national risk assessment you must consider now names AI as an enabling capability. Revisit how your enterprise risk assessment, onboarding controls and monitoring scenarios treat AI-enabled identity fraud, document forgery and high-volume, machine-paced structuring. From AUSTRAC Just Put AI Risk Into Your AML Program Documents

  • Does the best financial interests duty apply to AI spending?

    It applies to the money the fund spends. Section 52(3A) of the SIS Act states that the best financial interests obligation applies in respect of payments to a third party by, or on behalf of, the entity. So the cost of buying or building an AI system, like any other expenditure, has to be justifiable as being in members' best financial interests, and APRA's SPS 515 reinforces the expectation that controls prevent expenditure that would be unjustifiable against that duty. From Super Trustees, AI and the Discretion You Cannot Delegate

  • Does the FAR relief reduce accountability for AI decisions?

    No. ASIC and APRA framed the package as reducing regulatory burden without lowering accountability standards. A named accountable person still owns the consequences of an AI tool deployed inside a regulated function, and the reasonable-steps duty is unchanged. What has moved is the volume of routine reporting, not the underlying obligation to be able to evidence it. From FAR Eased Up. Your AI Map Still Holds

  • Does the government mandate apply to private companies?

    No. The policy binds non-corporate Commonwealth entities, with some exceptions, not private companies. Its value to a private-sector GRC team is as a template. The field set, the accountable-owner requirement and the reporting cadence show what a government thinks a minimum viable AI register looks like, which is useful reference material for a register built under CPS 230 or the Voluntary AI Safety Standard. From Canberra's AI Register Mandate Is a Preview

  • Does the law require an obligations register?

    Not by that name. Section 912A(1) of the Corporations Act requires an AFS licensee to meet general obligations including compliance with licence conditions and financial services laws, but it does not prescribe a document called an obligations register. ASIC RG 104 discusses documented, implemented, monitored and current compliance measures, and RG 104.44 expressly allows those measures to comprise one or several documents and stand-alone or integrated IT systems. The register is a control design, not a prescribed label. From Let AI Maintain the Obligations Register. Make a Human Own Every Change.

  • Does the Notifiable Data Breaches scheme apply when the breach happens at my AI provider?

    Usually yes. Under section 6(1) of the Privacy Act an entity holds personal information if it has possession or control of a record containing it, and the OAIC guidance states that in cloud computing arrangements both the service provider possessing the records and the client controlling access hold the information. If the information you put into an AI service is exposed, your obligations under the scheme are engaged regardless of whose infrastructure failed. From Your AI Vendor's Breach Starts Your Clock

  • Does the Office of AI regulate how an organisation uses AI?

    No. The joint media release of 15 July 2026 says the Office of AI is established within the Department of the Prime Minister and Cabinet to accelerate implementation of the Australian Standards for AI at a national level. It is a coordinating body inside a central agency. The release gives it no enforcement powers, and no standard, draft or bill has been published. It changes who coordinates AI standards work, not what binds a deployer of AI. From A New AI Office Is Not a New AI Obligation

  • Does the Privacy Act say anything specific about public-facing chatbots?

    Yes. The OAIC's guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025, says businesses should update privacy policies and notifications with clear information about their use of AI, including ensuring that any public facing AI tools such as chatbots are clearly identified as such to external users. It also states that where AI systems generate or infer personal information, that is a collection. From Your Website AI Assistant Is Someone Else's Code

  • Does this change if we only use a publicly available AI tool?

    It sharpens the problem. The OAIC recommends as a matter of best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, given the privacy risks involved. Where that recommendation is not followed, the organisation still holds the information for scheme purposes but has the least contractual visibility of any arrangement it could have chosen. From Your AI Vendor's Breach Starts Your Clock

  • Does using the business's AI platform impair audit independence?

    Not automatically, much like sharing the corporate ERP or email. But Standards 2.1 and 2.2 require objectivity threats to be recognised and managed. The real risk is the dependency never gets written down. Use a dedicated audit workspace, independent validation data, and state the shared-platform dependence in engagement workpapers. From AI in Internal Audit: What Still Counts as Evidence

  • Has ASIC created new AI-specific rules or licensing conditions?

    No. ASIC has not imposed a new licensing condition, prohibited specific AI use cases, provided a safe harbour, or signalled immediate legislative change. The existing licensing framework continues to apply. Compliance is judged against existing obligations applied to the specific facts of each AI use case. From ASIC's AI Supervisory Posture, Decoded

  • How are large language models being used in AML/CTF compliance programs?

    They draft suspicious matter report narratives from structured alert data, summarise complex KYC source-of-wealth documentation, triage high-volume transaction monitoring alerts with recommended dispositions, and generate internal training and policy content. Each use case sits inside the regulated AML/CTF program and remains subject to AUSTRAC oversight and the reporting entity's responsibility. From AML/CTF and Large Language Models: A Compliance View

  • How can an organisation start an AI incident process without overbuilding?

    Create a minimum viable extension to existing incident management: an AI incident intake checklist, an evidence pack template, escalation criteria and post-incident review questions. Link these artefacts to the AI use-case register, privacy assessment, cyber incident playbook and vendor management framework, then have internal audit test consistency. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook

  • How do APRA's CPS 234 and CPS 230 standards apply to AI cyber risk?

    CPS 234 requires boards to approve information security strategies, define cyber risk roles, test and monitor controls, and manage incident reporting. CPS 230 requires operational risk frameworks to cover emerging risks, including AI. Both embed AI cyber risk into enterprise risk management as a strategic, not niche technical, issue. From AI Cyber Risk Is Now a Board Governance Issue

  • How do GRC teams triage suspected AI incidents?

    Build an AI triage layer into existing incident intake. Ask whether AI influenced a decision or communication, whether personal, confidential or regulated data was involved, whether a third party was involved, whether an automated action was performed, and whether a human reviewed the output. The triage outcome should determine escalation. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook

  • How do I prove the console is genuinely offline?

    Open the browser developer tools, switch to the Network tab, reload the file, then import, validate, filter and export. If request count stays at zero, the offline promise holds. Repeat with the machine disconnected entirely. A tool that still works with the network out is genuinely offline. From Build an Offline GRC Controls Console Without Creating Shadow IT

  • How do I set CPS 230 tolerance levels for an AI-supported operation?

    AI disruption can be partial rather than binary, so tolerance levels must express both availability and output quality. Put four answers in writing: maximum tolerable availability disruption, maximum tolerable quality degradation, the manual fallback and its throughput, and the named owner accountable for setting the level and triggering escalation when breached. From CPS 230 and AI: A Practical Operational Resilience Playbook

  • How do I start building an AI use case register?

    Start with high-risk or high-impact use cases affecting customers, employees or critical operations. Use a standard template for consistency, integrate with existing risk and compliance systems, train owners and reviewers, automate tracking and reporting, document human oversight clearly, record incidents and complaints, and review and update the register regularly. From Build an AI Use Case Register That Boards Can Actually Use

  • How do I stop an AI-built controls console from becoming shadow IT?

    Treat it as governed end-user computing. Give it a named owner, keep it offline, validate inputs, separate preparer from reviewer, ship a short governance pack, and write a retirement date before use. The code can be identical to shadow IT; only that governance keeps it on the right side. From Build an Offline GRC Controls Console Without Creating Shadow IT

  • How do I turn voluntary AI guardrails into audit evidence?

    Convert each guardrail into a control objective stating what must be true, then define controls that make it true and evidence that proves the control operated. Human oversight, for example, becomes a control objective requiring competent human review of material outputs, supported by workflow gating, reviewer training, approval records, exception logs and audit samples. From From Voluntary AI Guardrails to Audit Evidence

  • How do sanctions and AML CTF decisions relate?

    They are connected but distinct. AUSTRAC's targeted financial sanctions guidance identifies DFAT's Australian Sanctions Office as the sanctions regulator, AUSTRAC as supervisor of relevant AML CTF policies and customer due diligence, and the AFP as investigator of possible sanctions offences. An alert does not automatically prove grounds for a suspicious matter report, and closing an AML case does not determine sanctions legality. From A Sanctions Alert Is Not Cleared Because the Model Says So.

  • How do the APRA standards fit?

    CPS 220, in force since 1 July 2019, requires banking and insurance entities to maintain a risk management framework covering material risks and a designated, adequately staffed compliance function with a reporting line independent from business lines. SPS 220, in force since 1 January 2020, requires an RSE licensee's risk management strategy to include mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements. Neither prescribes a particular register product or field name. From Let AI Maintain the Obligations Register. Make a Human Own Every Change.

  • How do you avoid stereotyping in persona design?

    Do not add age, postcode, disability, cultural background or family status merely for realism. Include a characteristic only where the approved design connects it to the product, boundary or control, and require human reviewers to challenge proxies and discriminatory assumptions before any case is approved for testing. From Your TMD Needs Customers Who Do Not Exist.

  • How do you keep an AI-drafted impact assessment auditable?

    Build the evidence trail into the skill file itself. The file requires a citation to the release section or page for every statement, stamps the output with the release name, release date and the date checked, and ends with a sources list. The validator then has something checkable rather than something plausible, and the stamped, validated assessment can be retained as the record of what was assessed, by what method, against which version of the release. From A Skill File for Regulatory Change: Impact Assessment On Demand

  • How does AI incident response connect to accountability?

    A mature process connects events to accountability by identifying whether governance allocated responsibility before the incident occurred. The practical question is who was accountable for approving, monitoring and accepting residual risk for the AI use case. If that is unclear during an incident, the governance model is probably unclear during normal operations. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook

  • How does ASIC expect legal professional privilege claims to be made?

    INFO 165, updated July 2024, says a recipient of a compulsory notice must provide responsive information except information subject to a valid legal professional privilege claim. ASIC will not accept a blanket claim. Document claims must be individually itemised with specified details, including authors, recipients, date, document type, privilege category and basis, everyone claiming the right to assert the privilege, format, location and whether the claim covers all or part. Where only part is claimed, an appropriately masked version must be provided. From ASIC Asked for the File. Your AI Summary Is Not the Production.

  • How does ASIC's AI posture intersect with APRA, AUSTRAC, and OAIC?

    ASIC does not operate alone. A single AI use case can attract supervisory questions from multiple regulators: ASIC on conduct, APRA on operational risk, AUSTRAC on AML and CTF, and OAIC on privacy. Mature institutions design AI governance to map to all relevant regimes from inception rather than retrofitting compliance later. From ASIC's AI Supervisory Posture, Decoded

  • How does the qualification wording differ between the two standards?

    CPS 220 requires qualification for a significant breach of, or material deviation from, the framework or Attachment A requirements, with cause, circumstances and remediation. SPS 220 is worded differently: a qualified declaration must describe any material deviation from the framework and remediation, and it does not copy the express must-qualify trigger in CPS 220. Do not flatten that difference. From The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

  • How does the six-monthly DTA cadence compare with APRA's expectations?

    The DTA sets a fixed six-monthly reporting rhythm to a central agency. CPS 230 requires APRA-regulated entities to maintain registers and manage operational risk, and to notify APRA of material operational risk incidents, but it does not prescribe a fixed six-monthly submission of an AI register. The lesson is the discipline of a set cadence, not the specific interval. From Canberra's AI Register Mandate Is a Preview

  • How does this connect to APRA's April 2026 AI letter?

    The April letter named weak board AI literacy, overreliance on vendor summaries and gaps in AI lifecycle management as live findings. CPS 510 hands boards back time by cutting process paperwork. The practical move is to spend that time closing the gaps the April letter named. From Freed Board Bandwidth Is for AI Oversight

  • How does using an LLM in an AML/CTF program intersect with the Privacy Act?

    Customer data flowing through prompts is in scope of the Australian Privacy Principles, inference logs containing customer data raise use and disclosure questions, and cross-border transfer to an overseas-hosted LLM engages APP 8. The OAIC position is that the Privacy Act applies to AI processing, so deployments must satisfy both AUSTRAC and OAIC frameworks. From AML/CTF and Large Language Models: A Compliance View

  • How long do we actually have?

    Section 26WH(2) requires all reasonable steps to complete an assessment within 30 calendar days after the day the entity became aware of grounds suggesting a possible eligible data breach, and the Commissioner expects entities to treat that as a maximum and move faster where possible. The practical problem is that the clock starts when you become aware, so a provider that tells you on day 25 has consumed most of your window before you began. From Your AI Vendor's Breach Starts Your Clock

  • How long does a plaintiff have to sue?

    Proceedings must generally be commenced before the earlier of one year after the plaintiff became aware of the invasion and three years after the invasion occurred. A court may extend the period, but not later than six years after the invasion. Records retention settings should be checked against that window. From Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

  • How often does a skill file need review?

    On a schedule and on triggers, and the triggers matter more. A quarterly or six-monthly cycle suits most teams, but the file must also be reviewed whenever an obligation, reporting line, committee structure or source system it assumes has changed. The maintain prompt in this article runs that review: it checks currency against the approval date, drift against recent outputs, and consistency with the skill register entry. From Skill Files Are Controlled Documents. Treat Them Like It

  • How often does the government register have to be reported?

    Agencies must share their register with the Digital Transformation Agency every six months, counting from when the register is first created, by emailing it to the DTA or using a method agreed with the DTA in advance. Accountable officials must also notify the DTA whenever a new high-risk use case is identified. From Canberra's AI Register Mandate Is a Preview

  • How often should AI controls be monitored?

    AI assurance cannot be a once-a-year policy check, because models, data, user behaviour and processes all change. Organisations should define what is monitored, how often, by whom and with what escalation triggers. Useful signals include newly detected AI tools, high-risk use cases without review, unresolved red-team findings, human review exceptions, incidents and vendor model changes, fed into ordinary risk reporting. From From Voluntary AI Guardrails to Audit Evidence

  • How often should AI use cases in the register be reviewed?

    Use cases in production should be reviewed at least quarterly, while pilots should be reviewed monthly. Reviews must verify risk controls, human oversight effectiveness, incident reports, and any changes in scope or technology. Significant issues or emerging risks must be escalated promptly to the board or risk committee with clear recommendations. From Build an AI Use Case Register That Boards Can Actually Use

  • How often should I test controls for material AI vendor relationships?

    Match the testing cadence to the change cadence. Because the underlying model can change without notice, annual-only assurance is unlikely to be sufficient. Quarterly assurance with continuous output monitoring is a reasonable starting point for material vendors, with documented trigger conditions for ad hoc reassessment. From CPS 234 and AI Vendors: A Due Diligence Framework

  • How should an AI personalisation engine interact with target market determinations?

    The target market determination is the source of truth. The engine's distribution rules should derive from it as a hard filter, not run in parallel. Where an engine optimised for conversion drifts from the TMD, the entity has a control failure supervisors can pursue. Review TMDs for material products against the engine's actual operation. From DDO and AI-Driven Personalisation: Where the Boundary Sits

  • How should board AI literacy training be designed?

    Literacy should be role-specific and built around decisions the board actually makes, covering AI strategy, materiality thresholds, high-risk use cases, assurance expectations, regulatory reporting, third-party concentration, cyber exposures and incident escalation. The best programmes use scenarios, revealing whether directors understand materiality, affected stakeholders, failure modes and assurance needs rather than vocabulary recall. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

  • How should I govern AI used in transaction monitoring or screening?

    Mirror AUSTRAC's own model from its AI transparency statement: AI surfaces and prioritises while a person forms the suspicion and makes the report, sensitive data never enters public generative tools through protective-security controls, and someone is named accountable for the AI. Keep a record of why the tool is calibrated as it is. From AUSTRAC Just Put AI Risk Into Your AML Program Documents

  • How should internal audit provide assurance over AI controls under CPS 230?

    CPS 230 gives internal audit specific review duties under paragraphs 45 and 61. Three approaches are emerging: upskilling internal audit, co-sourcing with external specialists, or establishing a second line AI risk function that audit can review. None is wrong; the test is whether the assurance model produces credible findings. Silence on AI controls is what is unacceptable. From CPS 230 and AI: A Practical Operational Resilience Playbook

  • How should the change affect an AI use-case register?

    Treat it as a prompt to restructure, not to shrink. Split the register into a maintained core that a named owner keeps current and reports on, and an on-request evidence library that stays available but is not routinely filed. The lighter map means fewer scheduled updates, so the register becomes the more important record of where AI actually sits. From FAR Eased Up. Your AI Map Still Holds

  • If there is no AI Act, is AI unregulated in Australia?

    No, and that is the point most teams miss. AI is regulated by every law that already applies to what the AI does. Misleading AI marketing is caught by the ASIC Act, an AI decision affecting a person engages the Privacy Act, an AI vendor supporting a bank engages APRA's prudential standards. The absence of an AI Act does not mean an absence of obligations. It spreads them across the frameworks you already answer to. From Australia Will Not Pass an AI Act. You Are Still Regulated.

  • Is an enterprise AI licence enough to make the tool safe?

    No. An enterprise licence may improve the answer, but it does not answer it automatically. The operative questions are who can access every input and output, for what purpose, under which terms, in which locations, and for how long. Until every recipient and transfer has a documented legal basis and the exact workflow has passed internal privacy, security and program approval, treat the tool as outside the confidentiality perimeter. From Do Not Put a Whistleblower Disclosure Into Your General AI Tool

  • Is an overseas related body corporate an overseas recipient?

    Yes. An overseas office of the same APP entity is not an overseas recipient, because the recipient is the same entity. A related body corporate located outside Australia is a different entity, so it will be an overseas recipient and APP 8 will apply. Section 13B permits related bodies corporate to share personal information but does not exempt an entity from complying with APP 8 first. From Data Residency Does Not Settle APP 8 for Your AI Prompts.

  • Is data lineage the same as model explainability?

    No. Data lineage answers where the material came from, what happened to it and where it went. Model explainability asks a different question about why a model behaved as it did. A defensible workflow may need both, but one cannot substitute for the other. From Defensible AI Lineage Starts Before the Prompt.

  • Is data passing through an overseas server automatically a disclosure?

    Not necessarily, but the exception is narrow. The OAIC says routing personal information, in transit, through servers located outside Australia would usually be considered a use, and that there would not usually be a disclosure until the information is able to be accessed or modified by the overseas recipient. Overseas storage is a different question: where an entity engages an overseas contractor to perform services on its behalf, in most circumstances that provision is a disclosure, and only in limited circumstances a use. From Data Residency Does Not Settle APP 8 for Your AI Prompts.

  • Is dynamic pricing illegal in Australia?

    No. The ACCC states that surge or dynamic pricing is not illegal, but businesses must be clear about the price consumers will pay and must not make false or misleading claims about prices or the reasons for price changes. The risk depends on conduct, including misleading price representations, anti-competitive agreements, cartel provisions and misuse of market power. Independent pricing and clear customer information remain the baseline. From Your Pricing Agent Is Still Your Competition Risk

  • Is full-population testing the same as generative AI in audit?

    No, and conflating them is a common error. Full-population testing is deterministic analytics, returning the same answer every run, and predates the generative wave. Generative AI helps around the analytics by drafting query logic and threshold rationale, but the deterministic test remains the evidence engine, supported by Standard 14.1 data-reliability work. From AI in Internal Audit: What Still Counts as Evidence

  • Is synthetic persona testing an ASIC requirement?

    No. It is a proposed internal assurance technique, not an ASIC-endorsed form of evidence. RG 274 says the design and distribution obligations are objective, class-based requirements rather than an individualised suitability test, so synthetic cases test TMD logic. Real distribution and outcome data remain the evidence ASIC expects issuers to monitor. From Your TMD Needs Customers Who Do Not Exist.

  • Is the access-path map an OAIC requirement?

    No. It is a proposed internal control from TheAICommand. It is not a form prescribed by the OAIC, not a safe harbour and not a substitute for the legal assessment. It exists to make the technical and contractual facts visible enough that an authorised privacy or legal specialist can decide the APP treatment and the required controls. From Data Residency Does Not Settle APP 8 for Your AI Prompts.

  • Is the CPS 220 declaration the same as the SPS 220 declaration?

    No. CPS 220 applies to banking, general insurance, life insurance and private health insurance entities within its application, and expressly notes that an RSE licensee is not treated as an APRA-regulated institution for that standard. SPS 220 is the separate standard for all RSE licensees. The claim sets, signatories, timing and qualification wording differ, so one generic workflow is unsafe. From The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

  • Is the customer-outcome file an ASIC requirement?

    No. It is a proposed internal control from TheAICommand. It is not terminology used in the National Credit Act, an ASIC-mandated template or a safe harbour. It sits behind the formal assessment and does not replace the written copy that sections 120, 132, 143 or 155 may require for the relevant actor and product. From Your AI Credit Score Is Not a Responsible Lending File.

  • Is the dependency graph an APRA requirement?

    No. The provider-normalised dependency graph is a proposed internal control from TheAICommand, not an APRA-prescribed template. CPS 230 supplies the enforceable operational resilience and service-provider requirements, CPG 230 supplies non-binding guidance, and APRA's 2026 letter and System Risk Outlook add published supervisory observations. From Your AI Vendor Count Is Hiding One Foundation Model.

  • Is the investigation threshold 30 or 60 days?

    The Acts still print a 30-day threshold, but section 6A of the in-force ASIC instrument 2024/620 substitutes 60 days, with effect from 27 June 2025. An investigation that passes 60 days becomes a reportable situation on day 61 with its own lodgement period, and if reasonable grounds arise before day 60 the licensee must not wait for the investigation to finish. From AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

  • Is there a standard salary for an AI governance manager in Australia?

    No reliable standard series exists. Use adjacent risk, compliance, audit, privacy, cyber or model-risk benchmarks, then adjust for actual scope, technical depth, accountability, city and observed candidate scarcity. Robert Half's 2026 guide puts adjacent senior risk and compliance roles at a national median of $170,000 excluding superannuation. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

  • Should AI be allowed to edit the register directly?

    No. Give the ingestion service account write access to a candidate queue only, never to the production register. The human approver selects accept, reject or return for evidence. Acceptance creates a new version and preserves the old one, so history is never silently edited. Applicability and interpretation remain human judgements. From Let AI Maintain the Obligations Register. Make a Human Own Every Change.

  • Should internal auditors learn to code?

    Not every auditor needs to code. Internal audit does need enough technical literacy to scope the system, challenge specialists, obtain appropriate evidence and understand test limitations. Some teams will also need dedicated technical-assurance capability. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

  • What AI typologies should my AML/CTF risk assessment now address?

    The article names three shifts: identity fabrication, where convincing fakes and synthetic identities have become cheap; scale, where AI automates manual laundering and runs many machine-paced transactions; and communications, where plausible emails and supporting stories are generated cleanly, removing the sloppiness analysts once relied on to spot launderers. From AUSTRAC Just Put AI Risk Into Your AML Program Documents

  • What are ASIC's five supervisory themes on AI?

    The five themes are: personalisation crossing into personal advice; disclosure and explainability; consumer remediation and dispute resolution; market integrity for AI in trading activity; and operational risk and resilience. Together they shape how ASIC expects licensees to apply existing obligations to AI components of their operations. From ASIC's AI Supervisory Posture, Decoded

  • What are the five components of the AI cyber risk governance operating model?

    The article sets out five components: critical asset mapping, decision cadence and reporting, control validation and assurance, incident response exercises, and third-party concentration review. Together they translate ASIC and APRA expectations into actionable board and risk committee practices for managing AI-accelerated cyber risk effectively. From AI Cyber Risk Is Now a Board Governance Issue

  • What are the four planes of a run-lineage packet?

    The source plane records systems, owners, snapshot identifiers, extraction times, permitted purpose and classification. The transformation plane records filtering, redaction, chunking, retrieval settings and exclusions with their rule or code versions. The execution plane captures instructions, retrieved context, tool inputs and responses, timestamps and available model details. The decision plane preserves the raw output, human edits, reviewer, approver and actual use. From Defensible AI Lineage Starts Before the Prompt.

  • What are the key Tranche 2 deadlines I need to meet?

    Reforms for existing reporting entities commenced on 31 March 2026. The new Tranche 2 designated services switch on from 1 July 2026, and newly regulated businesses must enrol with AUSTRAC by 29 July 2026. AUSTRAC has been explicit that enrolment is the start of the obligation, not the end of it. From AML Tranche 2: What AI Can and Cannot Do for Your New Program

  • What are the three failure states to test?

    DEGRADED tests slow, incomplete or unreliable output. UNAVAILABLE removes access completely. UNTRUSTED assumes the model or pipeline still responds but its outputs cannot be relied on, which matters during data corruption, model change or security compromise. Run the test by actually removing the dependency and requiring participants to produce the action artefacts. From Your AI Fallback Is Not a Recovery Plan.

  • What are the two clocks?

    Valid time records when an obligation applies in the world, for example valid_from and valid_to. Recorded time records when your organisation captured and handled the information, for example detected_at, reviewed_at, accepted_at and superseded_at. Separating them stops announcement, publication and commencement dates being treated as interchangeable, and it exposes operational lag without rewriting the legal timeline. It is a proposed internal control, not APRA or ASIC terminology. From Let AI Maintain the Obligations Register. Make a Human Own Every Change.

  • What artefacts should GRC teams build to turn AI literacy into a control?

    GRC teams should build an AI use-case register covering owner, purpose, users, affected stakeholders, data categories, vendor dependencies, risk rating and assurance status; a board reporting pack summarising material uses, exceptions, incidents and assurance outcomes; and a literacy and attestation process for executives accountable for material AI systems. These should be tested through internal audit. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

  • What controls should compliance teams build before actions are designated?

    Five. An inventory of every CDR touchpoint marked read-only or action-capable. A policy separating propose from authorise so an agent never holds the trigger. Consent captured at the action, not just the connection. An immutable audit trail recording whether a human or an agent instructed each action. And a named accountable owner for every agent, with documented authority limits. From Governing AI Agents Before the Consumer Data Right Lets Them Act

  • What counts as personal information inside an AI service?

    More than the obvious database fields. Prompts and uploaded documents, retrieved source material, conversation history, tool call logs, agent memory stores and observability traces can all contain personal information. The OAIC guidance on commercially available AI products states that privacy obligations apply to any personal information input into an AI system as well as to output data generated by AI where it contains personal information. From Your AI Vendor's Breach Starts Your Clock

  • What counts as reasonable steps for an accountable person managing AI under FAR?

    Section 21 of the FAR Act requires accountable persons to conduct their responsibilities by, among other things, taking reasonable steps, and section 22 says reasonable steps include appropriate governance, control and risk management, safeguards against inappropriate delegations, procedures for identifying and remediating problems, and action in response to non-compliance. For AI, four categories are likely to be tested: awareness of the AI tools in the portfolio, adequate governance design, monitoring and escalation through existing risk channels, and a response capability covering AI-specific failure modes. From FAR and AI: How Accountability Maps to Tooling Decisions

  • What CPS 230 documentation gaps surface most often with AI tooling?

    Three recur. First, no documented threshold at which an AI tool becomes a material service provider. Second, a change cadence mismatch, since AI tools update frequently while review frequency is often annual. Third, human-in-the-loop claims that are nominal, lacking evidence of review time, information available, and how often outputs are modified or rejected. From CPS 230 and AI: A Practical Operational Resilience Playbook

  • What damages are available under the tort?

    Damages are capped. Non-economic loss damages plus any exemplary or punitive damages must not exceed the greater of $478,550 and the defamation non-economic loss maximum. Aggravated damages must not be awarded, emotional distress damages are available, and the remedy set also includes an account of profits, injunctions, apology and correction orders, and destruction or delivery up of material. From Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

  • What did APRA announce on 16 June 2026?

    APRA released an updated draft of CPS 510 Governance for a further round of consultation. It consolidates five existing governance, fit-and-proper and conflicts standards into a single cross-industry standard, sets consistent governance minimums, and removes routine fit-and-proper reporting that had become duplicative under the Financial Accountability Regime, covering around 6,000 individuals. From Freed Board Bandwidth Is for AI Oversight

  • What did APRA announce on 19 August 2026?

    That it will consult in September on reforms addressing eight areas of investment management. Five are named in the release: matching a trustee's investment management capability to the complexity of its investment menu, addressing weaknesses in onboarding, monitoring and offboarding practices, addressing material conflicts, improving member-level diversification, and strengthening trustee oversight and accountability. The reforms apply to all trustees, with the largest impact on platform trustees. From Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

  • What did APRA's April 2026 AI letter say about concentration?

    Following targeted engagement in late 2025 with selected large banks, insurers and superannuation trustees, APRA observed heavy dependence at some entities on a single provider across multiple AI use cases, and said few entities demonstrated robust contingency planning or tested exit and substitution strategies for critical AI providers. It also warned that embedded AI can make foundation models, training data and fourth-party dependencies opaque. From Your AI Vendor Count Is Hiding One Foundation Model.

  • What did ASIC and APRA change about FAR on 16 June 2026?

    They proposed trimming three reporting obligations under the Financial Accountability Regime: removing the prescribed list of key functions from the FAR register, no longer requiring information about accountable persons' direct reports in accountability maps, and raising the materiality threshold at which entities must notify the regulators of changes to accountability arrangements. The regulators will consult on the changes and aim to implement them by the end of 2026. From FAR Eased Up. Your AI Map Still Holds

  • What did ASIC's December 2024 review find?

    Across 14 licensees, 31 per cent of reported breaches took more than one year to identify, and the average time from first occurrence to reporting was 534 days. ASIC traced much of the delay to weaknesses in how licensees identified, escalated and recorded incidents, not to the final portal submission. From AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

  • What did ASIC's May 2026 cyber uplift warning say?

    On 8 May 2026, ASIC urged organisations to urgently enhance cyber resilience, linking the warning to frontier AI intensifying the threat landscape. It emphasised that cyber resilience is not merely an IT issue but a core licensing obligation that boards and risk committees must actively oversee and integrate into existing governance. From AI Cyber Risk Is Now a Board Governance Issue

  • What did AUSTRAC change in the AML program starter kits on 19 June 2026?

    AUSTRAC made targeted updates to the program starter kit documents, refreshing the risk assessment with new information on artificial intelligence, decentralised finance and offshore virtual asset providers. It also clarified that indicators of unusual or criminal behaviour apply during initial customer onboarding, where synthetic identities most often slip through. From AUSTRAC Just Put AI Risk Into Your AML Program Documents

  • What did the 15 July 2026 announcement actually contain?

    An office effective that day, a commitment to introduce a set of Australian Standards for AI building on the Data Centre Expectations, a first set of concrete rules aimed at large data centres covering power supply, connection costs, grid support and water efficiency, a sequence of National Cabinet consideration in August with legislation expected early next year, a commitment on Australian creative works, and a promise to outline whole-of-government AI consumer safety priorities in coming weeks. From A New AI Office Is Not a New AI Obligation

  • What did the Australian Government make mandatory for AI use?

    Under version 2.0 of the DTA's Policy for the responsible use of AI in government, effective 15 December 2025, the first new mandatory requirement took effect on 15 June 2026: a strategic position on AI adoption, communicated to staff. Mandatory staff training and AI use-case impact assessments phase in by 15 December 2026. Every in-scope AI use case must also have a named accountable owner recorded in an internal register, with the register in place within 12 months of the policy taking effect. From Canberra's AI Register Mandate Is a Preview

  • What did the Privacy Commissioner actually decide in June 2026?

    In two determinations dated 11 June 2026 and published on 24 June 2026, the Privacy Commissioner found that Medmate Australia and Monash IVF interfered with the privacy of individuals whose sensitive information was collected through third-party tracking pixels on their websites. The Commissioner's register records the Monash IVF findings against Australian Privacy Principles 3.3, 5.1, 5.2 and 7.1. The media release states the decision establishes that tracking website visitors on health-related sites and then targeting them with social media advertising amounts to a collection of sensitive information for which consent must be obtained. From Your Website AI Assistant Is Someone Else's Code

  • What do sections 128 to 133 actually require?

    For a credit provider under the Part 3-2 general rules: an assessment of unsuitability before relevant regulated conduct, reasonable inquiries about the consumer's requirements and objectives and their financial situation, and reasonable steps to verify that financial situation. Section 131 makes a contract unsuitable where it is likely the consumer could not meet the obligations, could do so only with substantial hardship, the contract would not meet their requirements or objectives, or prescribed circumstances apply. Section 133 then prohibits entry. From Your AI Credit Score Is Not a Responsible Lending File.

  • What does 'reasonable steps' mean when scams are AI-generated?

    Reasonable steps is a moving standard, judged against the risk, the available technology and the cost. As AI-assisted detection becomes standard and affordable, the floor of what counts as reasonable rises. Reactive moderation after a customer reports a scam will increasingly read as below the standard. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

  • What does a CPS 234 AI vendor due diligence framework cover?

    Eight areas: information asset identification and classification, vendor architecture and chain mapping, control commitments, data handling commitments, update and change management, incident notification and response, testing and assurance, and exit planning. Each area produces a documented artefact that becomes part of the vendor file. From CPS 234 and AI Vendors: A Due Diligence Framework

  • What does absence from the DFAT Consolidated List prove?

    Identity evidence only. The Consolidated List supports due diligence on designated persons and entities, but DFAT's ownership-and-control guidance says ownership and control depend on the factual circumstances, so an unlisted subsidiary, intermediary or asset cannot be cleared merely because its own name is absent. Country, goods, services and end-use prohibitions are separate questions again. From A Sanctions Alert Is Not Cleared Because the Model Says So.

  • What does an AI governance professional do?

    The work varies, but usually covers AI inventory, risk classification, control design, regulatory mapping, third-party oversight, monitoring, incident governance and evidence for executive or audit review. Some roles own the framework. Others provide independent challenge or technical assurance. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

  • What does APRA's April 2026 AI letter mean for board AI literacy?

    APRA's 30 April 2026 letter signals that AI literacy is now connected to risk appetite, control assurance, third-party oversight, resilience and accountability. It expects boards to hold enough literacy to understand AI opportunities, limitations and risks, including risks arising through third-party services and cyber pathways, and to interrogate management's control story. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

  • What does ASIC RG 271 require for handling complaints?

    RG 271 is ASIC's internal dispute resolution standard for financial firms. It sets an enforceable maximum of 30 calendar days to give a standard complaint an IDR response, defines a complaint broadly using the AS/NZS 10002:2014 wording, requires IDR responses to explain the reasons for the outcome, and requires firms to identify, escalate and act on systemic issues. Firms also report IDR data to ASIC. From AI in Complaints Handling: What RG 271 Reserves for a Person

  • What does ASIC say about automated decision systems?

    RG 209.253 to RG 209.254 say that where such systems compile and assess consumer information under predetermined rules, ASIC considers they should be tested prior to implementation and at reasonable regular intervals, should identify situations requiring further inquiries or verification and either complete those steps or refer the application for manual consideration, and should maintain or produce a meaningful record of the assessment. That is guidance, not a new AI-specific legal test. From Your AI Credit Score Is Not a Responsible Lending File.

  • What does ASIC's REP 835 actually say about AI in trading?

    REP 835 is a landscape review ASIC commissioned from the Digital Finance Cooperative Research Centre, published on 30 June 2026. Its fourth stream deals with AI in trading. It states that agentic AI, increasingly autonomous trading systems and trading systems with limited explainability are hard to assess through traditional notions of trader intent or fixed algorithm design, that this places pressure on ASIC's surveillance capability, and that such systems raise legal and enforcement questions about how to define and prove misconduct distinguished by intent, such as market manipulation. From Agentic Trading and the Purpose Problem

  • What does CPS 190 require for recovery and exit actions?

    A Board-approved plan showing how the entity could restore financial resilience or exit in an orderly and solvent way, with maintained execution capabilities and reasonable preparatory steps. For each action, a significant financial institution must analyse timelines, barriers, execution risks, key dependencies and preparatory measures, and must conduct operational testing as part of a comprehensive review at least every three years by operationally independent, appropriately experienced and competent persons. From Your AI Fallback Is Not a Recovery Plan.

  • What does section 1317AAE actually protect?

    More than a name. It addresses the discloser's identity and information likely to lead to their identification. Disclosure is permitted only in specified circumstances, including to ASIC, APRA, a member of the Australian Federal Police, a legal practitioner for advice about the whistleblower provisions, a prescribed person or body, or with the discloser's consent. A separate pathway in section 1317AAE(4) covers investigation use without consent, subject to strict conditions. From Do Not Put a Whistleblower Disclosure Into Your General AI Tool

  • What does the CPS 230 1 July 2026 deadline actually require?

    For contracts that already existed when CPS 230 commenced, APRA gave entities until the earlier of the next renewal date or 1 July 2026 to bring the agreement into line with the standard's service provider requirements. Those cover service levels, orderly exit, sub-contracting and fourth-party arrangements, APRA access and inspection, change notification and ongoing monitoring. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

  • What does the new APP 1.7 and 1.8 automated decision-making obligation actually require?

    It is a transparency rule, not an explainability mandate. From 10 December 2026, an entity must describe in its privacy policy the kinds of personal information its automated systems use and the kinds of decisions made or substantially shaped by those systems. You do not have to explain individual model logic or why one person was declined. From Automated Decisions Now Belong in Your Privacy Policy

  • What fields should an AI use case register include?

    Each entry should capture use case name, business unit or owner, AI type, purpose, status, risk category, human oversight, controls or mitigations, impact assessment, privacy considerations, vendor details, review frequency, last review date, and notes or issues. This detail lets boards assess risk, controls and outcomes and supports meaningful oversight. From Build an AI Use Case Register That Boards Can Actually Use

  • What governance controls should AML/CTF teams apply to LLM use?

    Map every LLM workflow to a specific obligation under the AML/CTF Act or the AML/CTF Rules 2025, default to prompt-level de-identification, keep humans accountable for each regulated act, back-test triage decisions monthly, verify every regulatory citation in generated content, capture which model version made each decision, and cover LLM use cases in the independent evaluation of the AML/CTF program. From AML/CTF and Large Language Models: A Compliance View

  • What if the model has changed since the run?

    Do not define success as reproducing the same sentence. APRA observed that point-in-time assurance can be ill-suited to probabilistic models and that model updates and supplier opacity can limit understanding of behaviour. Use two tests instead: can another authorised reviewer reconstruct exactly what the organisation supplied to the model, and can they trace each material statement in the final work product to source evidence and an accountable human decision? From Defensible AI Lineage Starts Before the Prompt.

  • What immediate actions should compliance teams take under ASIC's AI posture?

    Three actions: review AI-driven customer interactions against the personal advice test, refreshing structure where the line is blurred; refresh customer disclosure documents for AI-relevant content against the substance test; and build an internal capability to explain AI-influenced decisions within RG 271 dispute resolution timeframes. From ASIC's AI Supervisory Posture, Decoded

  • What is a boundary-pair suite?

    A controlled set of fictional consumer pairs, identical except for one TMD-relevant variable such as capacity to bear loss or premium affordability. Each case carries a pre-assigned expected state of INSIDE, OUTSIDE, BOUNDARY or UNRESOLVED, and the test asks whether the product attributes, target-market description, distribution conditions and review triggers produce the expected result. From Your TMD Needs Customers Who Do Not Exist.

  • What is a cell-to-sentence evidence chain?

    A proposed internal control from TheAICommand, not an APRA field set. Every factual clause in a draft warning comment points back to the exact return cell, the query that produced or checked it, the data owner who confirmed the source, the validation rule that triggered and the human reviewer who accepted the final wording. It adapts the auditability and lineage principles in CPG 235. From AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

  • What is a change envelope?

    An immutable AI-generated proposal containing the evidence a human needs to decide: primary-source URL and issuing body, document identifier and versions compared, authority class, legal status, publication, commencement and transition dates, the exact changed passage with its location, candidate affected register rows, confidence and unresolved ambiguity. It sits in a candidate queue and never touches the accepted register until a named reviewer accepts it. From Let AI Maintain the Obligations Register. Make a Human Own Every Change.

  • What is a claim-to-source chain?

    It is a proposed internal control from TheAICommand, not an APRA-prescribed format. For each declaration limb the signatories can move through six links: the exact claim and scope, the approved framework or control behind it, evidence that the control operated during the period, assurance coverage and findings, contradicting incidents and open actions, and the human conclusion. From The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

  • What is a clock divergence field?

    A proposed internal control, not an ASIC requirement. It displays the difference between the earliest plausible trigger date found in the evidence and the trigger date recorded in the human legal assessment. It does not change the statutory test; it forces an unresolved timing gap into view before a file is closed or reported. From AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

  • What is a common-root failure test?

    A scenario that removes or materially degrades one shared root across every connected service at once. Test at least model unavailability or material model change, a shared cloud or control-plane outage, loss of the common identity or gateway layer, and removal or alteration of an upstream service. Record affected critical operations, remaining independent capacity, actual switch time and the evidence produced. From Your AI Vendor Count Is Hiding One Foundation Model.

  • What is a mosaic test?

    A check run before any material leaves the protected disclosure environment. It asks whether a colleague who knows the business could combine the remaining details, such as role, team size, chronology, transaction value, writing style or document metadata, and infer who made the disclosure. It follows section 1317AAE's focus on information likely to identify, not merely obvious personal identifiers. From Do Not Put a Whistleblower Disclosure Into Your General AI Tool

  • What is a negative-match evidence bundle?

    TheAICommand's proposed control term for the reproducible record behind a closed alert: the activity scope, the exact list snapshot and retrieval time, the screened subject data, the matching method and every candidate, the candidate comparison, the ownership and control position, the activity analysis, and a precise disposition with a named approver. It is not DFAT terminology and not a substitute for the assessment required by law. From A Sanctions Alert Is Not Cleared Because the Model Says So.

  • What is a request-to-source ledger?

    A proposed internal control from TheAICommand, not a format prescribed by ASIC. It starts with each ASIC request item and ends with a source record, an itemised privilege treatment, a documented non-production reason or an open exception. Every item closes in one of five human-approved states, so a blank cell is never treated as evidence that nothing existed. It reconciles the regulator's words to the records searched, reviewed and produced. From ASIC Asked for the File. Your AI Summary Is Not the Production.

  • What is a skill file for regulatory change management?

    A skill file is a platform-neutral markdown instruction file that captures a repeatable method once so an AI applies it the same way every time. For regulatory change, the file tells the AI exactly how to turn a regulator release into a structured impact assessment: summarise the change, identify affected obligations, map impacted controls, classify the impact per area and draft actions, citing the release for every claim. It runs as ChatGPT project instructions, a Claude project or skill, and adapts to a Microsoft 365 Copilot agent. From A Skill File for Regulatory Change: Impact Assessment On Demand

  • What is action initiation under the Consumer Data Right?

    Action initiation, sometimes called write access, lets a consumer authorise an accredited provider to initiate actions on their behalf, such as making payments, switching providers, opening or closing accounts and submitting product applications. It became law through the Treasury Laws Amendment (Consumer Data Right) Act 2024, but individual action types must still be designated by the government before anyone can use them. From Governing AI Agents Before the Consumer Data Right Lets Them Act

  • What is AI-washing?

    AI-washing is overstating the role, sophistication or benefit of artificial intelligence in a product or service. In financial services it looks like marketing that calls a tool AI-powered when it applies simple rules, or that promises tailored AI advice when the tool considers only a couple of data points. It is a species of misleading conduct, and RG 234's update flags disclosing the real capability and limitations of AI-enabled customer tools as part of advertising them accurately. From AI Wrote the Ad. ASIC Still Holds You to It.

  • What is an offline GRC controls console and what should it be used for?

    It is a single-file HTML tool that runs locally to structure evidence, log exceptions, capture reviewer sign-off and produce a clean review pack without sending data anywhere. Use it for one narrow control test as a working layer, never to replace Archer, ServiceNow or any approved system of record. From Build an Offline GRC Controls Console Without Creating Shadow IT

  • What is APRA's model risk thematic review?

    A thematic review is APRA's deep-dive supervisory tool. It is not enforcement or consultation, but a structured study of how a sector manages a specific risk. Findings typically feed into supervisory letters, updated guidance, or new prudential standards. APRA's tripartite cyber assessments under CPS 234 followed the same pattern at sector scale. From APRA's Model Risk Thematic Review: What to Expect

  • What is ASIC's supervisory posture on AI in financial services?

    ASIC's posture is that AI is a use case to which existing law applies. The presence of AI does not change a licensee's conduct, disclosure, design and distribution, or dispute resolution obligations. It changes where the licensee needs to look to evidence compliance, not what the obligations are. From ASIC's AI Supervisory Posture, Decoded

  • What is the Australian AI Safety Institute?

    The Australian AI Safety Institute is an advisory body launched in early 2026 with about 29.9 million dollars in funding under the National AI Plan. It monitors, tests and shares information on emerging AI capabilities, risks and harms. It has no enforcement powers. For GRC its value is as an early-warning signal for where targeted regulation may eventually land. From Australia Will Not Pass an AI Act. You Are Still Regulated.

  • What is the correct order of work for a newly regulated firm?

    Build the ML/TF risk assessment first, with a person doing the thinking and AI structuring and drafting. Let that assessment drive the program. Use AI to scaffold policies, then edit to what is true. Record why calibration settings landed where they did, and keep that reasoning as a defensible governance record. From AML Tranche 2: What AI Can and Cannot Do for Your New Program

  • What is the difference between a compulsory ASIC notice and a voluntary request?

    INFO 145 explains ASIC can use compulsory powers to require documents or information and, in a formal investigation, attendance at an examination or reasonable assistance. For document production it issues a written notice describing the documents sought and the time and place for production. ASIC may also ask voluntarily, and INFO 145 says it considers voluntary production before using a compulsory document power. Do not collapse the two routes. From ASIC Asked for the File. Your AI Summary Is Not the Production.

  • What is the difference between a credit score and a suitability assessment?

    They answer different questions. A lender may decide an applicant falls outside its risk appetite even where the proposed contract is not unsuitable, and a favourable risk score does not establish compliance with the responsible lending obligations. A policy decline is not necessarily an assessment that a contract is unsuitable, and a not-unsuitable assessment is not a promise that the lender will approve credit. From Your AI Credit Score Is Not a Responsible Lending File.

  • What is the difference between an AI guardrail and a control?

    A guardrail describes what good practice looks like, while a control describes how an organisation makes that true and produces evidence that can be tested. A principle such as humans remaining in the loop is not assurance evidence. A workflow plus sampled records showing a reviewer checked output before a decision is finalised is evidence. From From Voluntary AI Guardrails to Audit Evidence

  • What is the difference between an error and a warning in APRA Connect?

    An error is mandatory: it must be corrected and revalidated, and a return containing an error cannot be submitted. A warning flags a discrepancy or abnormal variation that may still be correct. All warnings require a response, retained data needs an explanatory comment, and revised data must be validated again. From AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

  • What is the difference between coverage and capability here?

    Coverage is how many options were looked at and how recently. Capability is whether someone can state why an option belongs on the menu, on what evidence, and what would take it off. A monitoring model raises coverage to whatever the data supports. It leaves the second question untouched, because the answer to it is a judgement rather than a retrieval. From Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

  • What is the difference between DDO and personal advice for AI personalisation?

    DDO is conceptually about classes of consumer. The issuer defines a target market and the distribution chain operates within it. Personal advice concerns a specific person. Under section 766B it is triggered where the provider has considered the person's objectives, financial situation or needs, or a reasonable person might expect it to have done so, attracting licensing and best-interests obligations. From DDO and AI-Driven Personalisation: Where the Boundary Sits

  • What is the difference between expiry and stop-use?

    Expiry says the approval has run out and use cannot continue until a human renews it. Stop-use is an immediate control response to a defined event, such as a critical test failure, unexplained data exposure, a prohibited tool action or an output that could cause material customer harm. The passport should name the safe fallback and who may restore service after the evidence is reviewed. From Your GenAI Approval Needs an Expiry Trigger.

  • What is the first thing a compliance function should do about this?

    Build an inventory of every third-party component running on customer-facing pages, including analytics, advertising, session recording, support widgets and AI assistants. For each one, record who supplies it, what it receives, where that goes, whether the categories can include sensitive information, and which notice or consent covers it. Most organisations discover components nobody currently owns. From Your Website AI Assistant Is Someone Else's Code

  • What is the minimum an in-scope AI use-case register must record?

    The DTA's Standard for accountability sets a thirteen-field minimum, including a description of what the AI does, its business objective and, where relevant, the underpinning product name; the AI technology type, being generative AI, machine learning, natural language processing or computer vision; the lifecycle stage; the accountable use case owner's details; and inherent and residual risk ratings from the impact assessment. High-risk use cases also record review dates. From Canberra's AI Register Mandate Is a Preview

  • What is the new triennial board performance review?

    Draft CPS 510 strengthens annual board, committee and director performance assessments and requires significant financial institutions to commission an independent external assessment of board performance at least every three years. That assessment is a natural place to test whether the board can genuinely challenge AI risk. From Freed Board Bandwidth Is for AI Oversight

  • What is the practical control for AI in a super fund?

    An AI-decision register. List every current and proposed AI use case, and classify each one as either supporting a trustee discretion or making or dictating it. Put a hard human-involvement gate on anything in the second group, require a documented best financial interests business case for the spend, and keep an accountable owner for each use case under the accountability regime. That register is the evidence APRA and your board will ask for. From Super Trustees, AI and the Discretion You Cannot Delegate

  • What is the practical task list for compliance teams after this update?

    Check which starter kit version your documents were built from and whether it predates 19 June 2026. Update the risk assessment for AI typologies, revisit onboarding controls, document any AI used in monitoring against AUSTRAC's model, and keep the reasoning and version history as a defensible record. From AUSTRAC Just Put AI Risk Into Your AML Program Documents

  • What is the risk of reading this relief as less AI documentation?

    Under-documentation exactly where supervisors look. Lighter filing does not reduce the need to explain an adverse automated decision or show who owns an AI tool in a regulated process. If a register decays because the map now needs fewer updates, the entity loses the evidence that made an accountable person's position defensible in the first place. From FAR Eased Up. Your AI Map Still Holds

  • What is the Scams Prevention Framework and when does it bite?

    The SPF is the Commonwealth regime created by the Scams Prevention Framework Act 2025, which amended the Competition and Consumer Act 2010 to make banks, telcos and digital platforms responsible for preventing, detecting and disrupting scams. Treasury released the exposure-draft codes and rules on 28 May 2026, consultation closed on 25 June 2026, and substantive sector obligations are proposed from 31 March 2027. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

  • What is the statutory tort for serious invasions of privacy?

    A direct cause of action in Schedule 2 of the Privacy Act 1988, commenced 10 June 2025. A plaintiff must prove five elements under clause 7(1): an invasion by intrusion upon seclusion or misuse of information, a reasonable expectation of privacy, intentional or reckless fault, seriousness, and that the plaintiff's privacy interest outweighed any countervailing public interest. The OAIC states it does not have a direct role in administering the tort. From Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

  • What is validation half-life?

    A working governance concept, not a regulatory metric. It says the evidence behind an approval decays at a rate set by the use case's criticality, uncertainty and exposure to change. A low-risk drafting assistant may tolerate minor wording changes; claims, credit, prudential reporting or member-servicing workflows may need revalidation before a material change reaches production. A named owner decides the rate. From Your GenAI Approval Needs an Expiry Trigger.

  • What law sits behind RG 234?

    RG 234 is guidance on how to comply with the misleading-conduct prohibitions, principally section 12DB of the ASIC Act, which prohibits false or misleading representations about financial services, and section 1041H of the Corporations Act, which prohibits misleading or deceptive conduct in relation to financial products. RG 234 does not create new law. It sets ASIC's expectations for how advertising, now including AI-generated advertising, meets that existing law. From AI Wrote the Ad. ASIC Still Holds You to It.

  • What makes a register entry useful rather than poor?

    A useful entry provides clear accountability, detailed controls, documented human oversight, evidence of impact assessment and privacy considerations, and an appropriate review rhythm with an escalation process. A poor entry lacks control detail, has no impact assessment, reviews too infrequently for the risk level, and cannot support meaningful board oversight. From Build an AI Use Case Register That Boards Can Actually Use

  • What makes a skill file a controlled document?

    The output it shapes. The moment a skill file's drafts feed a board pack, an obligations register entry, a breach assessment or anything else a regulator, auditor or committee will rely on, the file has crossed from personal tooling into the controlled-document category. From that point it needs the same discipline as any other controlled document: a version number and change log inside the file, a named owner and approver, retained testing evidence, scheduled review with defined triggers, and a line in a register of approved skills. From Skill Files Are Controlled Documents. Treat Them Like It

  • What makes a substitute genuinely independent?

    Four proofs. Capability: it performs the minimum function needed during disruption. Infrastructure: it does not share the failed model, cloud control plane, gateway or identity dependency. Data and control: required data, context, access controls and records remain available on an independent path. Execution: authorised people can activate and operate it within tolerance using tested instructions. From Your AI Vendor Count Is Hiding One Foundation Model.

  • What makes an AI dependency fatal to a recovery action?

    Its failure prevents the action from starting, completing within its approved timeline, producing its required decision evidence or remaining within the authority model. A tool that only improves the style of a pre-approved communication adds time when lost. A tool that is the only way to produce a portfolio extract or generate transfer files can stop the action entirely. From Your AI Fallback Is Not a Recovery Plan.

  • What must a target market determination contain?

    Section 994B(5) of the Corporations Act requires a TMD to describe the class of retail clients comprising the target market, specify distribution conditions, identify review triggers, set review periods and state reporting arrangements. Section 994B(8) adds the objective appropriateness requirements about likely objectives, financial situation and needs of consumers in the target market. From Your TMD Needs Customers Who Do Not Exist.

  • What parts of AML compliance must a person keep, not AI?

    Three lines stay with people: the formation of suspicion and decision to report, the calibration of risk appetite, and accountability, which rests on the reporting entity, its governing body and AML compliance officer. There is also a confidentiality duty: do not feed privileged client detail into a general consumer AI tool. From AML Tranche 2: What AI Can and Cannot Do for Your New Program

  • What practical actions should GRC teams take for AI personalisation under DDO?

    Map every AI-driven customer touchpoint against the DDO and personal advice framework, tagging each as general information, general advice, or personal advice. Test that operational behaviour matches the tag through monthly sampling. Govern recommendation logic, not just outputs. Set a clear policy on generative AI customer interactions and apply CPS 234-style vendor due diligence. From DDO and AI-Driven Personalisation: Where the Boundary Sits

  • What readiness work should a GRC team do before December 2026?

    Four moves. Inventory every system that makes or substantially shapes a decision about a person, including older and vendor systems. Classify each by whether it significantly affects rights. Draft the disclosure under the three APP 1.8 categories. Evidence it with the inventory, impact assessments and policy version history. The inventory is the long pole, not the drafting. From Automated Decisions Now Belong in Your Privacy Policy

  • What reporting cadence should boards use for AI cyber risk?

    The article recommends the board review cyber risk posture, incident summaries and strategic decisions quarterly; the risk committee review control effectiveness, risk trends and third-party risks monthly or bi-monthly; and IT security and AI ops review operational incidents, patching status and threat intelligence weekly or fortnightly to ensure timely escalation. From AI Cyber Risk Is Now a Board Governance Issue

  • What should a GRC team do before 1 July 2026?

    Four passes over your AI estate. Find the AI inside your material arrangements, starting from the service provider register. Test each contract against the CPS 230 service provider requirements. Build and actually exercise a fallback where AI supports a critical operation. Then manage and document the concentration risk. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

  • What should a GRC team do before deploying AI in IDR?

    Map every RG 271 obligation to what AI may touch and what stays human, keep a person accountable for the outcome and the reasons, log what the AI drafted versus what the person decided, govern the tool as a system that handles sensitive data, and confirm the deployment against the current RG 271 and Instrument 2020/98 before go-live. From AI in Complaints Handling: What RG 271 Reserves for a Person

  • What should a GRC team do before the framework applies in 2027?

    Confirm scope, build a principle-to-control map across the six principles with named owners and evidence, inventory every AI model in the detection stack, stand up the dispute and reporting pipelines, govern the detection AI as a high-consequence system, and keep the board across the govern principle. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

  • What should a trustee do before the consultation opens?

    Count the menu, then count the people who can defend it. Write the exit criterion for each option class and name who pulls it. Date the last time each criterion was actually tested rather than reviewed. If the honest answer is that the menu cannot be defended at its current size, shrinking the menu is a legitimate response to APRA's proposal and is often the cheaper one. From Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

  • What should AI vendor due diligence cover beyond security questionnaires?

    Due diligence should cover data use, model changes, logging, incident notification, subcontractors, service availability, exit arrangements and the ability to explain or test outputs. For critical operations, resilience testing should consider what happens if the provider changes the model, the service fails, logs are unavailable or data must be removed quickly, with fallback processes and exit plans documented. From From Voluntary AI Guardrails to Audit Evidence

  • What should an AI incident evidence pack contain?

    It should capture the incident timeline, AI system involved, business process, stakeholders affected, data categories, prompts and outputs, model or vendor details, access permissions, human review steps, containment, root cause, control failures, customer or employee impact, regulatory assessment and remediation. It should also record confirmed facts, working assumptions and unresolved questions. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook

  • What should an audit workpaper record when AI is used?

    Standard 14.6 documentation must let another auditor reach the same conclusions. Record five things: the tool and version, the prompt given, the raw output before editing, the corroboration performed against source records and by whom, and the corrections made. Keep it proportionate: log only where output influenced an audit judgement. From AI in Internal Audit: What Still Counts as Evidence

  • What should go on the regulatory watch list after a machinery announcement?

    Four entries, each with a named owner, an observable trigger and a review date: National Cabinet consideration in August 2026, the Australian Standards for AI text itself, the legislation flagged for early next year, and the whole-of-government AI consumer safety priorities promised in coming weeks. Record against each that there is no current obligation, no control change and no spend, so the assessment is visible rather than assumed. From A New AI Office Is Not a New AI Obligation

  • What should GRC teams do about CPS 230 and AI in the next ninety days?

    Four actions. Re-run critical operations mapping with AI treated as a first-class component. Inventory the AI stack against material service provider criteria. Define quality tolerance levels alongside availability ones. Map each material tool's model and infrastructure chain, documenting the contracting party, model provider, inference infrastructure, and data residency. From CPS 230 and AI: A Practical Operational Resilience Playbook

  • What should GRC teams do given there is no AI Act?

    Build a map from each AI use case to the existing obligations it touches, adopt the Voluntary AI Safety Standard as a practical framework, watch the AI Safety Institute and the coming Privacy Act reforms as the direction of travel, and name an accountable owner for each material AI system. The work is compliance mapping and governance, not waiting for a law that is not coming. From Australia Will Not Pass an AI Act. You Are Still Regulated.

  • What should GRC teams do now to prepare?

    Four actions are sensible regardless of timing: run a model risk inventory completeness check covering AI tools with a documented threshold, map validation methodology by model type, document human-in-the-loop adequacy for material AI outputs, and build third-party AI transparency into procurement and ongoing oversight. From APRA's Model Risk Thematic Review: What to Expect

  • What should trigger an automatic pause of a pricing agent?

    Examples include unexplained convergence with competitors, abnormal retaliation against discounting, use of unapproved data sources, missing logs, a material vendor change or prices outside approved bounds. Triggers should be tailored to the market and reviewed by competition specialists, and the pause owner must be named, including outside business hours. From Your Pricing Agent Is Still Your Competition Risk

  • When does an AI customer service assistant cross into personal advice?

    If a generative AI assistant considers a customer's circumstances, such as account holdings, balance, or transaction patterns, and is presented in a way the customer reasonably expects to take those circumstances into account, it can be personal advice regardless of any disclaimer. Knowing the customer's holdings creates a strong expectation of personalisation. From DDO and AI-Driven Personalisation: Where the Boundary Sits

  • When does CPS 510 commence?

    Consultation on the draft is open until 28 August 2026. APRA expects to finalise CPS 510 and a unified practice guide, CPG 510, by the end of 2026, with the new requirements expected to take effect from early 2028. From Freed Board Bandwidth Is for AI Oversight

  • When does CPS 900 apply to an entity?

    Only following notification from APRA. CPS 900 applies to significant financial institutions and to non-SFIs that APRA determines provide a critical function, meaning one important to financial-system stability or the availability of essential financial services to a particular industry or community. CPG 900 says that before notification there are no CPS 900 requirements the entity must meet. From Your AI Fallback Is Not a Recovery Plan.

  • When does the 30-day reporting clock start?

    Under section 912DAA of the Corporations Act and section 50B of the National Credit Act, the report must be lodged within 30 days after the licensee first knows that, or is reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen. Whether reasonable grounds exist is objective, and knowledge held by an employee or agent within actual or apparent authority can be attributed to the licensee. From AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

  • When does the CDR expand beyond banking?

    The read side is widening now. Under the CDR rules, product data sharing obligations apply to non-bank lenders from 13 July 2026, with consumer data sharing from 9 November 2026 for initial providers and 10 May 2027 for large providers. Every new accredited connection is a potential future action surface, which makes the expansion a useful dress rehearsal for the action layer. From Governing AI Agents Before the Consumer Data Right Lets Them Act

  • When is the APRA model risk review expected to land?

    APRA's 30 April 2026 letter to industry confirmed it is finalising its forward plan for supervising AI risks, covering entity prudential reviews, thematic activities and AI supplier engagement. As at 15 August 2026, no terms of reference for a standalone model risk thematic review has been published. The preparation work does not depend on the timing. From APRA's Model Risk Thematic Review: What to Expect

  • Where can AI genuinely help a newly regulated firm build its AML program?

    AI fits four jobs: drafting the program scaffolding, structuring the ML/TF risk assessment by interviewing the practitioner toward an answer, tuning customer due diligence and monitoring for firms with existing data, and drafting suspicious matter reports once a suspicion is formed. Point it at administrative load, not judgement. From AML Tranche 2: What AI Can and Cannot Do for Your New Program

  • Where can AI genuinely help in complaints handling?

    AI can acknowledge and triage incoming complaints, summarise a long file, draft a first-pass plain-English response for review, keep the language consistent and readable, and analyse complaint data sets to surface possible systemic issues for a human to investigate. Each of these is admin or pattern-spotting that a person still signs off. From AI in Complaints Handling: What RG 271 Reserves for a Person

  • Where will supervisory pressure focus in the review?

    Six areas are likely to see sharp questions: model inventory completeness, validation methodology fit for AI, human-in-the-loop design quality, third-party AI provider oversight, bias and consumer outcome testing, and documentation of model purpose to detect scope creep beyond a model's validated use. From APRA's Model Risk Thematic Review: What to Expect

  • Which AI assurance skills are hardest to hire?

    The difficult combination is regulatory interpretation, technical-system literacy, test design, evidence judgement and executive communication. Organisations often find pieces of this profile in different people rather than one complete candidate. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

  • Which AI obligations actually bind an Australian business right now?

    The ones that already did. The Privacy Act, including the automated decision-making transparency obligation in APP 1.7 commencing 10 December 2026, the misleading and deceptive conduct prohibitions in the ASIC Act, the Australian Consumer Law, APRA prudential standards such as CPS 230 and CPS 234 for regulated entities, and the AML/CTF regime. The 15 July announcement does not add to or subtract from that list. From A New AI Office Is Not a New AI Obligation

  • Which AI platforms can run a skill file?

    Both OpenAI and Anthropic now ship a native Skills feature built on the same convention, a folder with a SKILL.md instruction file. ChatGPT Skills are generally available on Business, Enterprise, Healthcare and Edu plans, and Claude skills are available across Claude plans, including Free per the Claude help centre, with code execution enabled. On other plans the same file runs as project instructions plus uploaded knowledge, and it adapts to a Microsoft 365 Copilot agent's Instructions field. From A Skill File for Regulatory Change: Impact Assessment On Demand

  • Which AI systems will the review likely examine?

    Three categories: traditional models augmented with AI components, AI-native decision support systems such as generative tools drafting credit memos or compliance assessments, and autonomous or near-autonomous systems like automated AML triage and underwriting. Many of these are operationally embedded but sit outside the formal model inventory. From APRA's Model Risk Thematic Review: What to Expect

  • Which AI-specific failure modes should I assess in vendor due diligence?

    Three the article highlights: prompt injection, where inputs cause unintended behaviour or data exposure; data leakage between customers in multi-tenant inference infrastructure; and training data contamination, where customer data used for training may surface in responses to others. Standard questionnaires omit these, so add them deliberately. From CPS 234 and AI Vendors: A Due Diligence Framework

  • Which APRA standard covers an AI outage in a critical operation?

    Ordinarily CPS 230 Operational Risk Management, through its business continuity and operational resilience controls. The narrower CPS 190 case examined here arises when the AI dependency is needed to execute a financial-viability recovery or exit action, or contributes to the viability stress itself. The two regimes answer different questions and should not be blurred. From Your AI Fallback Is Not a Recovery Plan.

  • Which changes should force revalidation?

    At minimum, changes to the provider model or version, system prompt, retrieval corpus or schema, transformation logic, tool or connector permissions, safety settings, intended users, affected population and approved purpose, plus incidents, complaints, control breaches, abnormal performance, legal or policy changes and scheduled expiry. Triage each event into record only, targeted test, full revalidation or immediate stop-use. From Your GenAI Approval Needs an Expiry Trigger.

  • Which companies must have a whistleblower policy?

    ASIC Information Sheet 247 identifies public companies, large proprietary companies and corporate trustees of registrable superannuation entities as the entities that must have a whistleblower policy under section 1317AI. Other companies remain subject to the whistleblower protection provisions in Part 9.4AAA even when the policy duty does not apply to them. From Do Not Put a Whistleblower Disclosure Into Your General AI Tool

  • Which five standards does draft CPS 510 consolidate?

    The reforms bring together CPS 510 and SPS 510 Governance, CPS 520 and SPS 520 Fit and Proper, and SPS 521 Conflicts of Interest into one cross-industry CPS 510, applying consistent governance minimums across banks, insurers and superannuation trustees. From Freed Board Bandwidth Is for AI Oversight

  • Which prescribed responsibilities can AI tooling decisions fall under?

    The Minister Rules prescribe responsibilities including management of the entity's overall risk management arrangements, information management (including information technology systems), the compliance and dispute resolution functions, client or member remediation programs, breach reporting, and the anti-money laundering function. AI in claims or underwriting touches risk management, AI in AML monitoring touches the AML and compliance functions, and AI in personalisation or automated decisioning creates exposure through dispute resolution and remediation. From FAR and AI: How Accountability Maps to Tooling Decisions

  • Which provision catches an AI that learns to place and cancel orders?

    Orders that never become transactions sit awkwardly with a prohibition framed around creating an artificial price for entering a transaction. In his paper published by the Supreme Court of NSW, Justice Ashley Black records that DPP (Cth) v JM confirms a significant degree of overlap between sections 1041A and 1041B, and that other conduct with a price effect, including the placing of orders that did not give rise to transactions, would typically fall within the scope of section 1041B. That is the provision an AI-learned order-and-cancel pattern most naturally engages. From Agentic Trading and the Purpose Problem

  • Which risk standard applies to superannuation trustees?

    SPS 220, in force since 1 January 2020. CPS 220 expressly excludes RSE licensees from its definition of an APRA-regulated institution and refers readers to SPS 220, so a group template written for the banking and insurance standard should not be silently applied to a trustee. From Your GenAI Approval Needs an Expiry Trigger.

  • Who approves a skill file before use in regulated processes?

    Someone accountable for the process the skill supports, and ideally not the person who wrote the file. The owner maintains the file and proposes changes. The approver reads the file, reviews the retained test outputs, and records the approval with a date. The two roles can sit close together in a small team, but the approval step itself is never skipped, because it is the point where the organisation, rather than an individual, stands behind the instruction set. From Skill Files Are Controlled Documents. Treat Them Like It

  • Who becomes AML regulated under Tranche 2 from 1 July 2026?

    From 1 July 2026, around 80,000 to 90,000 businesses move inside the perimeter: lawyers, accountants, conveyancers, real estate agents and developers, and dealers in precious metals, stones and products. These professions handle the transactions launderers favour and had no prior reporting obligation, pushing the total regulated count toward 100,000. From AML Tranche 2: What AI Can and Cannot Do for Your New Program

  • Who is accountable when an AI tool is procured centrally but used across multiple business units?

    Under section 21(2) of the FAR Act, where two or more accountable persons hold the same responsibility, each of them is accountable to the same extent as if it were solely their own, so shared use of an AI tool does not dilute anyone's accountability. The practical pattern designates the person responsible for the most material use as lead, with secondary business units holding supporting accountability for their specific use cases. This only helps if it is documented. From FAR and AI: How Accountability Maps to Tooling Decisions

  • Who is affected by the FAR reporting changes?

    ASIC and APRA estimated the reforms would reduce reporting for all accountable entities and around 4,500 accountable persons. A separate change streamlines responsible manager competence-evidence requirements for roughly 2,000 current AFS licensees from October 2026. The proposals sit inside the Government's Better Regulation reforms announced in the 2026-27 Budget. From FAR Eased Up. Your AI Map Still Holds

  • Who must sign or assure prudential returns?

    It depends on the sector framework. APS 310, GPS 310, LPS 310, SPS 310 and HPS 310 each set their own appointed-auditor assurance and declaration arrangements, from GPS 310's CEO and CFO Financial Information Declaration to SPS 310's limited assurance over systems, procedures and internal controls. A model cannot hold any of those roles. From AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

  • Who notifies when both we and the AI provider hold the same information?

    Section 26WM means only one of the entities that jointly holds the information needs to comply with the assessment and notification requirements on behalf of the group. The OAIC guidance suggests the entity with the most direct relationship with the individuals at risk of serious harm may be best placed to notify them. That is usually you. The point is to decide it in the contract rather than in the first hour of an incident. From Your AI Vendor's Breach Starts Your Clock

  • Who owns the pricing-agent risk?

    The commercial owner owns the outcome, supported by pricing, legal, competition, data, technology and risk specialists. A vendor may carry contractual obligations, but outsourcing the software does not outsource the organisation's accountability under the Competition and Consumer Act. From Your Pricing Agent Is Still Your Competition Risk

  • Who regulates AI agents acting under the Consumer Data Right?

    Two regulators share the field. The ACCC accredits CDR data recipients and monitors compliance with the CDR rules and standards, while ASIC governs the conduct and licensing of the financial services activity wrapped around them. An AI agent initiating a regulated action touches both, so control evidence needs to satisfy both lenses. ASIC has also flagged agentic AI as a key 2026 supervisory concern. From Governing AI Agents Before the Consumer Data Right Lets Them Act

  • Who regulates the SPF and what are the penalties?

    Three regulators share the work: the ACCC is the general regulator and covers digital platforms, ASIC regulates the banking code, and ACMA regulates the telco code, with AFCA as the external dispute resolution scheme. The most serious breaches attract civil penalties up to around 50 million dollars per contravention for a body corporate, alongside a path to consumer compensation. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

  • Who should own an AI use case register?

    Each use case needs a named senior manager accountable for its performance, risk management and compliance, with access to risk, compliance, IT and privacy teams. The AI governance or risk committee owns the overall register, ensuring completeness and quality and providing regular reports on key risks, changes and incidents. From Build an AI Use Case Register That Boards Can Actually Use

  • Who signs a risk management declaration?

    That depends on the standard. CPS 220 specifies the Board chair and Board Risk Committee chair, with the senior officer outside Australia or two Compliance Committee members signing instead for a Category C insurer, foreign ADI or EFLIC. SPS 220 requires two directors. Confirm the signatories against the applicable standard before building an evidence pack around them. From The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

  • Why can a passed synthetic test not clear a product?

    Because generated profiles cannot supply outcome evidence. ASIC Report 795 says pre-launch questionnaire testing can identify flaws but cannot guarantee intended performance, and that you cannot know whether a questionnaire works until it is live and viewed alongside cancellations, complaints and consumer outcomes. Keep synthetic and live evidence in separate lanes. From Your TMD Needs Customers Who Do Not Exist.

  • Why do AI incidents need a different incident response approach?

    AI failure modes do not always look like traditional outages. A model can produce a harmful recommendation while the platform stays available, a chatbot can expose sensitive data without a breach, or an agent can act on a malicious prompt. Standard time, owner and remediation fields cannot cleanly capture these AI-specific failures. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook

  • Why does a tracking pixel determination matter to an AI assistant?

    Because the architecture is identical. Both are code supplied by another party, embedded in a page you control, which receives what your users do there and sends it somewhere you do not operate. The AI assistant is the higher risk of the two, because a pixel observes clicks while an assistant receives whatever a person chooses to type, including health, financial hardship and identity details you never asked for. From Your Website AI Assistant Is Someone Else's Code

  • Why does AI concentrate exposure to the tort?

    Clause 7(5) expressly makes the means, including the use of any device or technology, relevant to the reasonable-expectation test. AI systems collect and join data at a scale people do not expect and produce confident inferences about individuals that may be wrong, and clause 7(7) makes it immaterial whether the information was true. Remedies can also reach derived material through destruction or delivery-up orders. From Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

  • Why does offboarding matter more than onboarding?

    Onboarding decisions are made once, with attention, and are usually well documented because someone was arguing for the option. Offboarding is the decision nobody is advocating for, so it drifts. It is also the point at which member harm either stops or continues, which makes the exit criterion, its owner and the dated record that it was tested the most testable control in the lifecycle. From Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

  • Why does the current RG 78 PDF still show 30 days in places?

    The February 2026 PDF retains old 30-day investigation references in Figure 1, the Example 11 heading and Table 8. For the current position, use section 6A of ASIC instrument 2024/620 and RG 78.26, RG 78.48 to RG 78.49 and RG 78.102 to RG 78.106, which apply the 60-day threshold. From AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

  • Why does third-party AI most test board literacy?

    Many organisations buy software, embed vendor copilots and connect enterprise data to external platforms rather than building models. APRA's letter points to third-party dependencies for board attention. AI due diligence needs questions on model behaviour, data retention, explainability, subcontractors, monitoring, incident notification and exit, beyond traditional security and contractual checks. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

  • Why does this obligation hit Australian financial services hardest?

    Three reasons. Credit, insurance and banking decisions affect rights and interests by nature, so the significant-effect threshold is cleared routinely. The systems are layered and old, mixing rules engines, scorecards, vendor services and machine learning across teams. The OAIC has new infringement and compliance notice powers and has flagged privacy policies in high-risk sectors as a focus. From Automated Decisions Now Belong in Your Privacy Policy

  • Why does using AI to detect scams create a second obligation?

    The moment an entity deploys AI to meet the prevent, detect and disrupt principles, it puts an AI system into a consumer-facing, high-consequence decision. Too aggressive and it freezes legitimate customers out of their money; too permissive and it misses the scam. That model needs validation, monitoring, false-positive handling, human review and privacy and explainability sign-off. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

  • Why is a saved prompt and final answer not enough?

    Because they cover only two points in the chain. The link in a citation may now point to a revised policy, the retrieval layer may have selected different passages, and a filter may have excluded the record that changed the answer. A defensible packet also captures the source snapshot, transformations, retrieved context, available configuration, raw output, human edits and final use. From Defensible AI Lineage Starts Before the Prompt.

  • Why is AI cyber risk a board responsibility and not just an IT issue?

    ASIC and APRA make clear that cyber resilience is a core licensing obligation boards must actively oversee. AI accelerates attack speed and complexity beyond traditional IT controls, incidents threaten business continuity and reputation, and boards are ultimately accountable for licensing obligations and setting the organisation's risk appetite. From AI Cyber Risk Is Now a Board Governance Issue

  • Why is AI the part of CPS 230 most likely to be tested first?

    On 30 April 2026 APRA published a letter to industry on AI that found entities heavily dependent on single AI providers, few tested exit or substitution strategies, and opaque upstream dependencies. Those are the exact things CPS 230 contracts must address, so the deadline and the supervisory focus have converged on the same clauses. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

  • Why is an AI summary not the evidence ASIC asked for?

    ASIC uses the statutory term books broadly, and INFO 242 and its production guidelines cover documents and other recorded information in electronic or hard-copy form. ASIC generally prefers electronic books in original native file format with associated metadata. A native email retains sender, recipient, timestamp and attachments. An AI paragraph about what the email means is a new object generated after collection, so it cannot prove which version existed at the relevant time. From ASIC Asked for the File. Your AI Summary Is Not the Production.

  • Why is board AI literacy treated as a control rather than awareness training?

    Because boards approve strategy, set risk appetite and oversee material risk, they need enough literacy to ask whether AI systems are governed with the same discipline as other material technology, data, outsourcing and operational risks. That is a higher standard than watching a chatbot demonstration or attending a one-hour awareness session. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

  • Why is the AI use-case register the foundation for AI assurance?

    The register defines the population of AI activity, so an incomplete register weakens every downstream test. It should capture business purpose, owner, system, users, affected stakeholders, data categories, decision influence, automation level, criticality, risk rating, approval status and review date. The risk rating then determines assurance depth and board visibility for each use case. From From Voluntary AI Guardrails to Audit Evidence

  • Why is the standard SaaS security questionnaire not enough for AI vendors?

    Standard questionnaires do not ask about prompt retention, training data use, multi-tenant inference isolation, or model-version notice, because the technology was not in scope when they were designed. Build an AI-specific addendum so vendor responses on these points are captured in writing, dated, and signed. From CPS 234 and AI Vendors: A Due Diligence Framework

  • Why must JavaScript libraries be vendored into the file rather than loaded from a CDN?

    A CDN reference is a live network call, and a live network call breaks the offline promise. Charting and table libraries such as Chart.js, Tabulator, PapaParse and SheetJS are useful, but each must be vendored inline or shipped locally alongside the file, with a dependency note, never pulled from a content delivery network. From Build an Offline GRC Controls Console Without Creating Shadow IT

  • Why preserve the exact list snapshot?

    Because the Consolidated List changes. DFAT's page showed the spreadsheet last updated on 23 July 2026 when this article was verified. A defensible negative disposition must show what the analyst screened against at the time, so store the source URL, displayed update date, retrieval timestamp, file and internal hash with the case rather than relying on today's live link. From A Sanctions Alert Is Not Cleared Because the Model Says So.

← All practice areasAsk your own question