Answer index
Governance, risk and compliance
154 questions answered. APRA, ASIC, AML/CTF and the prudential standards.
- Are ASIC's proposed kill-switch rules in force?
No. ASIC released CP 386, proposing amendments to the market integrity rules for trading systems and automated trading, on 27 August 2025, with comments closing on 22 October 2025. Among the proposals are a requirement for kill switches enabling immediate suspension of aberrant trading algorithm activity, and an extension of the principles-based trading system rules to participants' development, testing, use and monitoring of their algorithms. As at the time of writing, the amended rules had not been made. Treat the items as proposals with a clear direction of travel, not obligations. From Agentic Trading and the Purpose Problem
- Are these forecasts hiring advice?
No. They are editorial projections based on regulator, labour-market and salary-guide signals available to 10 July 2026. Employers and candidates should refresh the evidence and obtain professional advice for their circumstances. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
- Can a superannuation trustee let an AI make a decision?
A trustee can use AI to inform or support a decision, but the core discretions the SIS Act reserves to the trustee cannot be handed to a model. Section 52(2)(h) requires the trustee not to enter into any contract, or do anything else, that would prevent or hinder it from properly performing its functions, and section 52(2)(c) requires the trustee to exercise its powers in the best financial interests of beneficiaries. A decision made or effectively dictated by an AI, where the trustee cannot explain or stand behind the reasoning, is difficult to reconcile with those covenants. The safe pattern is AI supports, the trustee decides, and the reasoning is recorded. From Super Trustees, AI and the Discretion You Cannot Delegate
- Can AI decide the outcome of a customer complaint?
No. Deciding whether to uphold or reject a complaint, and explaining the reasons, is a regulated decision that a person accountable under RG 271 must own. AI can draft a response for a human to check and approve, but it cannot be the decision-maker, and letting it decide would put an unexplained, potentially unfair outcome in front of an aggrieved customer. From AI in Complaints Handling: What RG 271 Reserves for a Person
- Can AI-generated output stand as audit evidence under Standard 14.1?
Not on its own. Standard 14.1 requires information to be relevant, reliable and sufficient. AI output is not obtained directly by the auditor, is not an independent source, and a non-deterministic system cannot guarantee a competent person re-running the work reaches the same result. Corroboration against source records, not generation, earns it a place in the file. From AI in Internal Audit: What Still Counts as Evidence
- Can an AI agent initiate CDR payments today?
No. The Act is in force but no action type has been designated, so no provider, human or AI, is initiating payments or switches through the CDR yet. That gap is the opportunity. Compliance teams can design the authorisation, consent and audit controls for agent-initiated actions before any money can move, rather than retrofitting them onto a live rail under time pressure. From Governing AI Agents Before the Consumer Data Right Lets Them Act
- Can an LLM make the decision to file a suspicious matter report?
No. The decision to file or not file a suspicious matter report is a judgement the regulated entity makes, with consequences sitting with the entity. LLM-driven triage can support the analyst's decision, but the decision itself should sit with a human. Final certification of customer due diligence is likewise a regulated act requiring human authority. From AML/CTF and Large Language Models: A Compliance View
- Can competitors use the same pricing software?
Common software use is not automatically unlawful. Risk rises when the provider combines competitively sensitive data from multiple competitors or delivers recommendations that reduce uncertainty about rivals' future conduct, the hub-and-spoke pattern regulators keep flagging. Obtain competition advice on the actual design, data flows and contractual restrictions rather than relying on a generic confidentiality clause. From Your Pricing Agent Is Still Your Competition Risk
- Can disclaimers keep an AI interaction inside DDO and general advice?
No. ASIC's communication emphasises that the substance of a communication matters more than the formal classification an institution applies. Disclaimers cannot, on their own, change how the law characterises a communication. If an interaction has substantively crossed into personal advice, a general information disclaimer will not recharacterise it. From DDO and AI-Driven Personalisation: Where the Boundary Sits
- Can I use an AI model to help build the ADM register and disclosure?
Yes, for structuring, classification logic and first-draft drafting, but only inside a dedicated project space using de-identified inputs with placeholder tokens. Never paste real personal, claim or health data. The model produces a register skeleton and disclosure language. It does not decide what is in scope. A named human checks every scope call against the primary source. From Automated Decisions Now Belong in Your Privacy Policy
- Can I use an AI model to help review these contracts?
Yes, for drafting a gap checklist, summarising a long agreement against the requirements and producing a first-pass register. It is a drafting aid, not the decision-maker. A named accountable person, with legal advice, decides whether a contract complies and whether an exit or fallback is genuinely feasible. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
- Do the IIA Global Internal Audit Standards mention artificial intelligence?
No. A full-text search of the 2024 Global Internal Audit Standards returns no mention of artificial intelligence, and there is no AI Topical Requirement. The Standards are technology-neutral by design, so AI-assisted work answers to the same evidence, documentation, objectivity and due-care requirements as any other audit work. From AI in Internal Audit: What Still Counts as Evidence
- Do we need a human to review AI-generated marketing content?
In practice, yes. Because AI-generated advertising is held to the same standard as human-written advertising, and because generative tools can produce inaccurate, outdated or biased claims, a defensible process puts AI-generated marketing through the same substantiation and sign-off you already apply to human content. The person who approves it, not the model, is accountable for whether the final claim is true and not misleading. From AI Wrote the Ad. ASIC Still Holds You to It.
- Does a human approval step take an automated system out of scope?
No. APP 1.8 expressly covers decisions where a machine does something substantially and directly related to making the decision and a person finishes it. If a model ranks, scores or recommends and a human clicks approve, the system still shapes the outcome and belongs in the privacy policy. From Automated Decisions Now Belong in Your Privacy Policy
- Does an AI complaints tool create privacy obligations?
Yes. A complaint file routinely contains sensitive information such as health, financial hardship and family and domestic violence. An AI tool that reads and drafts on that file is processing sensitive personal information, often through a third-party service, so it carries Privacy Act obligations and needs the same governance as any high-consequence system. From AI in Complaints Handling: What RG 271 Reserves for a Person
- Does an offline controls console satisfy APRA CPS 230 on its own?
No. CPS 230 requires identifying and managing operational risks, maintaining and testing controls, and remediating gaps on a timely basis. A console does not satisfy it alone. It only makes the working layer of control monitoring and testing more consistent before results enter the official platform. From Build an Offline GRC Controls Console Without Creating Shadow IT
- Does APRA CPS 230 apply to enterprise AI tools like Copilot, Gemini, Claude and ChatGPT Enterprise?
Yes. Most enterprise AI tools sit inside the third-party arrangements CPS 230 governs. Where AI outputs feed material decisions or critical operations, the standard reaches the model lifecycle as well as the contract, so the question is no longer whether AI is in scope but how to evidence it. From CPS 230 and AI: A Practical Operational Resilience Playbook
- Does APRA's AI letter apply to superannuation trustees?
Yes. APRA's 30 April 2026 letter to industry states that APRA conducted a targeted engagement on a group of selected large banks, insurers and superannuation trustees in late 2025, and the expectations it sets out apply across regulated entities including RSE licensees. Among the minimums APRA names are ownership and accountability across the AI lifecycle, an inventory of AI tooling and use cases, human involvement for high-risk decisions and accountability, and staff training on AI use, misuse and limitations. From Super Trustees, AI and the Discretion You Cannot Delegate
- Does ASIC's RG 234 apply to AI-generated advertising?
Yes. ASIC's updated RG 234, published on 9 June 2026, makes clear that the law and ASIC's guidance apply to AI-generated advertising in the same way they apply to human-written advertising. Using an AI tool to generate a claim does not lower the standard or shift responsibility. The financial services misleading-conduct prohibitions in the ASIC Act and Corporations Act apply regardless of who or what produced the words. From AI Wrote the Ad. ASIC Still Holds You to It.
- Does AUSTRAC have AI-specific guidance for AML/CTF programs?
AUSTRAC has not published AI-specific guidance. The AUSTRAC Compliance Guide makes clear the obligation is on the reporting entity to design a program proportionate to its risk profile and operate it consistently with the AML/CTF Rules. LLM use sits inside that obligation, not outside it, and supervisory engagement on AI is increasingly likely. From AML/CTF and Large Language Models: A Compliance View
- Does Australia have an AI Act?
No. The National AI Plan, launched on 2 December 2025, confirmed the government will not introduce a standalone AI Act or the mandatory guardrails for high-risk AI proposed in 2024. Australia has chosen to regulate AI through existing technology-neutral laws, sector regulators, voluntary guidance and an advisory AI Safety Institute, rather than a single dedicated statute. From Australia Will Not Pass an AI Act. You Are Still Regulated.
- Does CPS 230 apply to AI vendors even if the contract is not labelled an AI contract?
Yes. CPS 230 reaches any material service provider, meaning one an entity relies on to perform a critical operation or that exposes it to material operational risk. If a model helps run claims processing, fraud detection or credit decisioning, the provider behind it is captured, whatever the contract calls it. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
- Does CPS 234 apply to AI vendors my organisation uses?
Yes. CPS 234 covers information assets managed by third parties, not just the entity itself. AI vendors introduce new asset categories such as prompts, fine-tuning data, embeddings, and inference logs, all of which the standard treats as in-scope and which must be identified, classified, and protected commensurate with their sensitivity. From CPS 234 and AI Vendors: A Due Diligence Framework
- Does FAR apply to AI tooling decisions in financial services?
Yes. AI tooling decisions sit inside FAR-prescribed responsibilities even when not framed as AI decisions. Deploying AI in compliance monitoring is a compliance system design decision; deploying it in customer-facing operations is a customer outcomes decision. The accountable person owns the consequence regardless of how procurement framed the tooling choice. From FAR and AI: How Accountability Maps to Tooling Decisions
- Does FAR apply to insurers and superannuation trustees for AI governance?
FAR replaced BEAR for ADIs in March 2024 and is being extended to insurers and trustees in stages through 2026. The architecture is the same, though prescribed responsibilities are weighted differently. AI tooling governance should be part of FAR readiness and inside the responsibility map from day one, not a separate workstream. From FAR and AI: How Accountability Maps to Tooling Decisions
- Does human approval remove the competition risk?
No. A human click is a weak control if the reviewer does not understand the inputs, the objective or the market pattern the agent is producing. Human oversight needs authority, information, materiality thresholds and the time to challenge a recommendation before it takes effect. From Your Pricing Agent Is Still Your Competition Risk
- Does market manipulation in Australia require proof of intent?
No. Australia's core prohibitions are drafted on effect. In DPP (Cth) v JM [2013] HCA 30; (2013) 94 ACSR 1; 298 ALR 615, the High Court took a broad view and held that a sole or dominant purpose of creating or maintaining an artificial price is not necessary to a contravention, though it can provide evidence that a transaction is likely to have the prohibited effect. Purpose is evidence rather than an element to prove. It still matters, because a legitimate trader purpose is what saves a price-moving trade. From Agentic Trading and the Purpose Problem
- Does the AUSTRAC AI update affect my firm if we already run a mature AML program?
Yes, but differently. The starter kits are not your tool, yet the national risk assessment you must consider now names AI as an enabling capability. Revisit how your enterprise risk assessment, onboarding controls and monitoring scenarios treat AI-enabled identity fraud, document forgery and high-volume, machine-paced structuring. From AUSTRAC Just Put AI Risk Into Your AML Program Documents
- Does the best financial interests duty apply to AI spending?
It applies to the money the fund spends. Section 52(3A) of the SIS Act states that the best financial interests obligation applies in respect of payments to a third party by, or on behalf of, the entity. So the cost of buying or building an AI system, like any other expenditure, has to be justifiable as being in members' best financial interests, and APRA's SPS 515 reinforces the expectation that controls prevent expenditure that would be unjustifiable against that duty. From Super Trustees, AI and the Discretion You Cannot Delegate
- Does the FAR relief reduce accountability for AI decisions?
No. ASIC and APRA framed the package as reducing regulatory burden without lowering accountability standards. A named accountable person still owns the consequences of an AI tool deployed inside a regulated function, and the reasonable-steps duty is unchanged. What has moved is the volume of routine reporting, not the underlying obligation to be able to evidence it. From FAR Eased Up. Your AI Map Still Holds
- Does the government mandate apply to private companies?
No. The policy binds non-corporate Commonwealth entities, with some exceptions, not private companies. Its value to a private-sector GRC team is as a template. The field set, the accountable-owner requirement and the reporting cadence show what a government thinks a minimum viable AI register looks like, which is useful reference material for a register built under CPS 230 or the Voluntary AI Safety Standard. From Canberra's AI Register Mandate Is a Preview
- Does the Office of AI regulate how an organisation uses AI?
No. The joint media release of 15 July 2026 says the Office of AI is established within the Department of the Prime Minister and Cabinet to accelerate implementation of the Australian Standards for AI at a national level. It is a coordinating body inside a central agency. The release gives it no enforcement powers, and no standard, draft or bill has been published. It changes who coordinates AI standards work, not what binds a deployer of AI. From A New AI Office Is Not a New AI Obligation
- Does the Privacy Act say anything specific about public-facing chatbots?
Yes. The OAIC's guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025, says businesses should update privacy policies and notifications with clear information about their use of AI, including ensuring that any public facing AI tools such as chatbots are clearly identified as such to external users. It also states that where AI systems generate or infer personal information, that is a collection. From Your Website AI Assistant Is Someone Else's Code
- Does using the business's AI platform impair audit independence?
Not automatically, much like sharing the corporate ERP or email. But Standards 2.1 and 2.2 require objectivity threats to be recognised and managed. The real risk is the dependency never gets written down. Use a dedicated audit workspace, independent validation data, and state the shared-platform dependence in engagement workpapers. From AI in Internal Audit: What Still Counts as Evidence
- Has ASIC created new AI-specific rules or licensing conditions?
No. ASIC has not imposed a new licensing condition, prohibited specific AI use cases, provided a safe harbour, or signalled immediate legislative change. The existing licensing framework continues to apply. Compliance is judged against existing obligations applied to the specific facts of each AI use case. From ASIC's AI Supervisory Posture, Decoded
- How are large language models being used in AML/CTF compliance programs?
They draft suspicious matter report narratives from structured alert data, summarise complex KYC source-of-wealth documentation, triage high-volume transaction monitoring alerts with recommended dispositions, and generate internal training and policy content. Each use case sits inside the regulated AML/CTF program and remains subject to AUSTRAC oversight and the reporting entity's responsibility. From AML/CTF and Large Language Models: A Compliance View
- How can an organisation start an AI incident process without overbuilding?
Create a minimum viable extension to existing incident management: an AI incident intake checklist, an evidence pack template, escalation criteria and post-incident review questions. Link these artefacts to the AI use-case register, privacy assessment, cyber incident playbook and vendor management framework, then have internal audit test consistency. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook
- How do APRA's CPS 234 and CPS 230 standards apply to AI cyber risk?
CPS 234 requires boards to approve information security strategies, define cyber risk roles, test and monitor controls, and manage incident reporting. CPS 230 requires operational risk frameworks to cover emerging risks, including AI. Both embed AI cyber risk into enterprise risk management as a strategic, not niche technical, issue. From AI Cyber Risk Is Now a Board Governance Issue
- How do GRC teams triage suspected AI incidents?
Build an AI triage layer into existing incident intake. Ask whether AI influenced a decision or communication, whether personal, confidential or regulated data was involved, whether a third party was involved, whether an automated action was performed, and whether a human reviewed the output. The triage outcome should determine escalation. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook
- How do I prove the console is genuinely offline?
Open the browser developer tools, switch to the Network tab, reload the file, then import, validate, filter and export. If request count stays at zero, the offline promise holds. Repeat with the machine disconnected entirely. A tool that still works with the network out is genuinely offline. From Build an Offline GRC Controls Console Without Creating Shadow IT
- How do I set CPS 230 tolerance levels for an AI-supported operation?
AI disruption can be partial rather than binary, so tolerance levels must express both availability and output quality. Put four answers in writing: maximum tolerable availability disruption, maximum tolerable quality degradation, the manual fallback and its throughput, and the named owner accountable for setting the level and triggering escalation when breached. From CPS 230 and AI: A Practical Operational Resilience Playbook
- How do I start building an AI use case register?
Start with high-risk or high-impact use cases affecting customers, employees or critical operations. Use a standard template for consistency, integrate with existing risk and compliance systems, train owners and reviewers, automate tracking and reporting, document human oversight clearly, record incidents and complaints, and review and update the register regularly. From Build an AI Use Case Register That Boards Can Actually Use
- How do I stop an AI-built controls console from becoming shadow IT?
Treat it as governed end-user computing. Give it a named owner, keep it offline, validate inputs, separate preparer from reviewer, ship a short governance pack, and write a retirement date before use. The code can be identical to shadow IT; only that governance keeps it on the right side. From Build an Offline GRC Controls Console Without Creating Shadow IT
- How do I turn voluntary AI guardrails into audit evidence?
Convert each guardrail into a control objective stating what must be true, then define controls that make it true and evidence that proves the control operated. Human oversight, for example, becomes a control objective requiring competent human review of material outputs, supported by workflow gating, reviewer training, approval records, exception logs and audit samples. From From Voluntary AI Guardrails to Audit Evidence
- How does AI incident response connect to accountability?
A mature process connects events to accountability by identifying whether governance allocated responsibility before the incident occurred. The practical question is who was accountable for approving, monitoring and accepting residual risk for the AI use case. If that is unclear during an incident, the governance model is probably unclear during normal operations. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook
- How does ASIC's AI posture intersect with APRA, AUSTRAC, and OAIC?
ASIC does not operate alone. A single AI use case can attract supervisory questions from multiple regulators: ASIC on conduct, APRA on operational risk, AUSTRAC on AML and CTF, and OAIC on privacy. Mature institutions design AI governance to map to all relevant regimes from inception rather than retrofitting compliance later. From ASIC's AI Supervisory Posture, Decoded
- How does the six-monthly DTA cadence compare with APRA's expectations?
The DTA sets a fixed six-monthly reporting rhythm to a central agency. CPS 230 requires APRA-regulated entities to maintain registers and manage operational risk, and to notify APRA of material operational risk incidents, but it does not prescribe a fixed six-monthly submission of an AI register. The lesson is the discipline of a set cadence, not the specific interval. From Canberra's AI Register Mandate Is a Preview
- How does this connect to APRA's April 2026 AI letter?
The April letter named weak board AI literacy, overreliance on vendor summaries and gaps in AI lifecycle management as live findings. CPS 510 hands boards back time by cutting process paperwork. The practical move is to spend that time closing the gaps the April letter named. From Freed Board Bandwidth Is for AI Oversight
- How does using an LLM in an AML/CTF program intersect with the Privacy Act?
Customer data flowing through prompts is in scope of the Australian Privacy Principles, inference logs containing customer data raise use and disclosure questions, and cross-border transfer to an overseas-hosted LLM engages APP 8. The OAIC position is that the Privacy Act applies to AI processing, so deployments must satisfy both AUSTRAC and OAIC frameworks. From AML/CTF and Large Language Models: A Compliance View
- How often does the government register have to be reported?
Agencies must share their register with the Digital Transformation Agency every six months, counting from when the register is first created, by emailing it to the DTA or using a method agreed with the DTA in advance. Accountable officials must also notify the DTA whenever a new high-risk use case is identified. From Canberra's AI Register Mandate Is a Preview
- How often should AI controls be monitored?
AI assurance cannot be a once-a-year policy check, because models, data, user behaviour and processes all change. Organisations should define what is monitored, how often, by whom and with what escalation triggers. Useful signals include newly detected AI tools, high-risk use cases without review, unresolved red-team findings, human review exceptions, incidents and vendor model changes, fed into ordinary risk reporting. From From Voluntary AI Guardrails to Audit Evidence
- How often should AI use cases in the register be reviewed?
Use cases in production should be reviewed at least quarterly, while pilots should be reviewed monthly. Reviews must verify risk controls, human oversight effectiveness, incident reports, and any changes in scope or technology. Significant issues or emerging risks must be escalated promptly to the board or risk committee with clear recommendations. From Build an AI Use Case Register That Boards Can Actually Use
- How often should I test controls for material AI vendor relationships?
Match the testing cadence to the change cadence. Because the underlying model can change without notice, annual-only assurance is unlikely to be sufficient. Quarterly assurance with continuous output monitoring is a reasonable starting point for material vendors, with documented trigger conditions for ad hoc reassessment. From CPS 234 and AI Vendors: A Due Diligence Framework
- How should an AI personalisation engine interact with target market determinations?
The target market determination is the source of truth. The engine's distribution rules should derive from it as a hard filter, not run in parallel. Where an engine optimised for conversion drifts from the TMD, the entity has a control failure supervisors can pursue. Review TMDs for material products against the engine's actual operation. From DDO and AI-Driven Personalisation: Where the Boundary Sits
- How should board AI literacy training be designed?
Literacy should be role-specific and built around decisions the board actually makes, covering AI strategy, materiality thresholds, high-risk use cases, assurance expectations, regulatory reporting, third-party concentration, cyber exposures and incident escalation. The best programmes use scenarios, revealing whether directors understand materiality, affected stakeholders, failure modes and assurance needs rather than vocabulary recall. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
- How should I govern AI used in transaction monitoring or screening?
Mirror AUSTRAC's own model from its AI transparency statement: AI surfaces and prioritises while a person forms the suspicion and makes the report, sensitive data never enters public generative tools through protective-security controls, and someone is named accountable for the AI. Keep a record of why the tool is calibrated as it is. From AUSTRAC Just Put AI Risk Into Your AML Program Documents
- How should internal audit provide assurance over AI controls under CPS 230?
CPS 230 paragraph 56 expects independent assurance. Three approaches are emerging: upskilling internal audit, co-sourcing with external specialists, or establishing a second line AI risk function that audit can review. None is wrong; the test is whether the assurance model produces credible findings. Silence on AI controls is what is unacceptable. From CPS 230 and AI: A Practical Operational Resilience Playbook
- How should the change affect an AI use-case register?
Treat it as a prompt to restructure, not to shrink. Split the register into a maintained core that a named owner keeps current and reports on, and an on-request evidence library that stays available but is not routinely filed. The lighter map means fewer scheduled updates, so the register becomes the more important record of where AI actually sits. From FAR Eased Up. Your AI Map Still Holds
- If there is no AI Act, is AI unregulated in Australia?
No, and that is the point most teams miss. AI is regulated by every law that already applies to what the AI does. Misleading AI marketing is caught by the ASIC Act, an AI decision affecting a person engages the Privacy Act, an AI vendor supporting a bank engages APRA's prudential standards. The absence of an AI Act does not mean an absence of obligations. It spreads them across the frameworks you already answer to. From Australia Will Not Pass an AI Act. You Are Still Regulated.
- Is dynamic pricing illegal in Australia?
No. The ACCC states that surge or dynamic pricing is not illegal, but businesses must be clear about the price consumers will pay and must not make false or misleading claims about prices or the reasons for price changes. The risk depends on conduct, including misleading price representations, anti-competitive agreements, cartel provisions and misuse of market power. Independent pricing and clear customer information remain the baseline. From Your Pricing Agent Is Still Your Competition Risk
- Is full-population testing the same as generative AI in audit?
No, and conflating them is a common error. Full-population testing is deterministic analytics, returning the same answer every run, and predates the generative wave. Generative AI helps around the analytics by drafting query logic and threshold rationale, but the deterministic test remains the evidence engine, supported by Standard 14.1 data-reliability work. From AI in Internal Audit: What Still Counts as Evidence
- Is there a standard salary for an AI governance manager in Australia?
No reliable standard series exists. Use adjacent risk, compliance, audit, privacy, cyber or model-risk benchmarks, then adjust for actual scope, technical depth, accountability, city and observed candidate scarcity. Robert Half's 2026 guide puts adjacent senior risk and compliance roles at a national median of $170,000 excluding superannuation. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
- Should internal auditors learn to code?
Not every auditor needs to code. Internal audit does need enough technical literacy to scope the system, challenge specialists, obtain appropriate evidence and understand test limitations. Some teams will also need dedicated technical-assurance capability. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
- What AI typologies should my AML/CTF risk assessment now address?
The article names three shifts: identity fabrication, where convincing fakes and synthetic identities have become cheap; scale, where AI automates manual laundering and runs many machine-paced transactions; and communications, where plausible emails and supporting stories are generated cleanly, removing the sloppiness analysts once relied on to spot launderers. From AUSTRAC Just Put AI Risk Into Your AML Program Documents
- What are ASIC's five supervisory themes on AI?
The five themes are: personalisation crossing into personal advice; disclosure and explainability; consumer remediation and dispute resolution; market integrity for AI in trading activity; and operational risk and resilience. Together they shape how ASIC expects licensees to apply existing obligations to AI components of their operations. From ASIC's AI Supervisory Posture, Decoded
- What are the five components of the AI cyber risk governance operating model?
The article sets out five components: critical asset mapping, decision cadence and reporting, control validation and assurance, incident response exercises, and third-party concentration review. Together they translate ASIC and APRA expectations into actionable board and risk committee practices for managing AI-accelerated cyber risk effectively. From AI Cyber Risk Is Now a Board Governance Issue
- What are the key Tranche 2 deadlines I need to meet?
Reforms for existing reporting entities commenced on 31 March 2026. The new Tranche 2 designated services switch on from 1 July 2026, and newly regulated businesses must enrol with AUSTRAC by 29 July 2026. AUSTRAC has been explicit that enrolment is the start of the obligation, not the end of it. From AML Tranche 2: What AI Can and Cannot Do for Your New Program
- What artefacts should GRC teams build to turn AI literacy into a control?
GRC teams should build an AI use-case register covering owner, purpose, users, affected stakeholders, data categories, vendor dependencies, risk rating and assurance status; a board reporting pack summarising material uses, exceptions, incidents and assurance outcomes; and a literacy and attestation process for executives accountable for material AI systems. These should be tested through internal audit. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
- What controls should compliance teams build before actions are designated?
Five. An inventory of every CDR touchpoint marked read-only or action-capable. A policy separating propose from authorise so an agent never holds the trigger. Consent captured at the action, not just the connection. An immutable audit trail recording whether a human or an agent instructed each action. And a named accountable owner for every agent, with documented authority limits. From Governing AI Agents Before the Consumer Data Right Lets Them Act
- What counts as reasonable steps for an accountable person managing AI under FAR?
Section 28 requires accountable persons to take reasonable steps to discharge their accountability. For AI, four categories are likely to be tested: awareness of the AI tools in their portfolio, adequate governance design, monitoring and escalation through existing risk channels, and a response capability covering AI-specific failure modes. From FAR and AI: How Accountability Maps to Tooling Decisions
- What CPS 230 documentation gaps surface most often with AI tooling?
Three recur. First, no documented threshold at which an AI tool becomes a material service provider. Second, a change cadence mismatch, since AI tools update frequently while review frequency is often annual. Third, human-in-the-loop claims that are nominal, lacking evidence of review time, information available, and how often outputs are modified or rejected. From CPS 230 and AI: A Practical Operational Resilience Playbook
- What did APRA announce on 16 June 2026?
APRA released an updated draft of CPS 510 Governance for a further round of consultation. It consolidates five existing governance, fit-and-proper and conflicts standards into a single cross-industry standard, sets consistent governance minimums, and removes routine fit-and-proper reporting that had become duplicative under the Financial Accountability Regime, covering around 6,000 individuals. From Freed Board Bandwidth Is for AI Oversight
- What did ASIC and APRA change about FAR on 16 June 2026?
They proposed trimming three reporting obligations under the Financial Accountability Regime: removing the prescribed list of key functions from the FAR register, no longer requiring information about accountable persons' direct reports in accountability maps, and raising the materiality threshold at which entities must notify the regulators of changes to accountability arrangements. The regulators will consult on the changes and aim to implement them by the end of 2026. From FAR Eased Up. Your AI Map Still Holds
- What did ASIC's May 2026 cyber uplift warning say?
On 8 May 2026, ASIC urged organisations to urgently enhance cyber resilience, linking the warning to frontier AI intensifying the threat landscape. It emphasised that cyber resilience is not merely an IT issue but a core licensing obligation that boards and risk committees must actively oversee and integrate into existing governance. From AI Cyber Risk Is Now a Board Governance Issue
- What did AUSTRAC change in the AML program starter kits on 19 June 2026?
AUSTRAC made targeted updates to the program starter kit documents, refreshing the risk assessment with new information on artificial intelligence, decentralised finance and offshore virtual asset providers. It also clarified that indicators of unusual or criminal behaviour apply during initial customer onboarding, where synthetic identities most often slip through. From AUSTRAC Just Put AI Risk Into Your AML Program Documents
- What did the 15 July 2026 announcement actually contain?
An office effective that day, a commitment to introduce a set of Australian Standards for AI building on the Data Centre Expectations, a first set of concrete rules aimed at large data centres covering power supply, connection costs, grid support and water efficiency, a sequence of National Cabinet consideration in August with legislation expected early next year, a commitment on Australian creative works, and a promise to outline whole-of-government AI consumer safety priorities in coming weeks. From A New AI Office Is Not a New AI Obligation
- What did the Australian Government make mandatory for AI use?
Under version 2.0 of the DTA's Policy for the responsible use of AI in government, effective 15 December 2025, the first new mandatory requirement took effect on 15 June 2026: a strategic position on AI adoption, communicated to staff. Mandatory staff training and AI use-case impact assessments phase in by 15 December 2026. Every in-scope AI use case must also have a named accountable owner recorded in an internal register, with the register in place within 12 months of the policy taking effect. From Canberra's AI Register Mandate Is a Preview
- What did the Privacy Commissioner actually decide in June 2026?
In two determinations dated 11 June 2026 and published on 24 June 2026, the Privacy Commissioner found that Medmate Australia and Monash IVF interfered with the privacy of individuals whose sensitive information was collected through third-party tracking pixels on their websites. The Commissioner's register records the Monash IVF findings against Australian Privacy Principles 3.3, 5.1, 5.2 and 7.1. The media release states the decision establishes that tracking website visitors on health-related sites and then targeting them with social media advertising amounts to a collection of sensitive information for which consent must be obtained. From Your Website AI Assistant Is Someone Else's Code
- What does 'reasonable steps' mean when scams are AI-generated?
Reasonable steps is a moving standard, judged against the risk, the available technology and the cost. As AI-assisted detection becomes standard and affordable, the floor of what counts as reasonable rises. Reactive moderation after a customer reports a scam will increasingly read as below the standard. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
- What does a CPS 234 AI vendor due diligence framework cover?
Eight areas: information asset identification and classification, vendor architecture and chain mapping, control commitments, data handling commitments, update and change management, incident notification and response, testing and assurance, and exit planning. Each area produces a documented artefact that becomes part of the vendor file. From CPS 234 and AI Vendors: A Due Diligence Framework
- What does an AI governance professional do?
The work varies, but usually covers AI inventory, risk classification, control design, regulatory mapping, third-party oversight, monitoring, incident governance and evidence for executive or audit review. Some roles own the framework. Others provide independent challenge or technical assurance. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
- What does APRA's April 2026 AI letter mean for board AI literacy?
APRA's 30 April 2026 letter signals that AI literacy is now connected to risk appetite, control assurance, third-party oversight, resilience and accountability. It expects boards to hold enough literacy to understand AI opportunities, limitations and risks, including risks arising through third-party services and cyber pathways, and to interrogate management's control story. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
- What does ASIC RG 271 require for handling complaints?
RG 271 is ASIC's internal dispute resolution standard for financial firms. It sets an enforceable maximum of 30 calendar days to give a standard complaint an IDR response, defines a complaint broadly using the AS/NZS 10002:2014 wording, requires IDR responses to explain the reasons for the outcome, and requires firms to identify, escalate and act on systemic issues. Firms also report IDR data to ASIC. From AI in Complaints Handling: What RG 271 Reserves for a Person
- What does ASIC's REP 835 actually say about AI in trading?
REP 835 is a landscape review ASIC commissioned from the Digital Finance Cooperative Research Centre, published on 30 June 2026. Its fourth stream deals with AI in trading. It states that agentic AI, increasingly autonomous trading systems and trading systems with limited explainability are hard to assess through traditional notions of trader intent or fixed algorithm design, that this places pressure on ASIC's surveillance capability, and that such systems raise legal and enforcement questions about how to define and prove misconduct distinguished by intent, such as market manipulation. From Agentic Trading and the Purpose Problem
- What does the CPS 230 1 July 2026 deadline actually require?
For contracts that already existed when CPS 230 commenced, APRA gave entities until the earlier of the next renewal date or 1 July 2026 to bring the agreement into line with the standard's service provider requirements. Those cover service levels, orderly exit, sub-contracting and fourth-party arrangements, APRA access and inspection, change notification and ongoing monitoring. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
- What does the new APP 1.7 and 1.8 automated decision-making obligation actually require?
It is a transparency rule, not an explainability mandate. From 10 December 2026, an entity must describe in its privacy policy the kinds of personal information its automated systems use and the kinds of decisions made or substantially shaped by those systems. You do not have to explain individual model logic or why one person was declined. From Automated Decisions Now Belong in Your Privacy Policy
- What fields should an AI use case register include?
Each entry should capture use case name, business unit or owner, AI type, purpose, status, risk category, human oversight, controls or mitigations, impact assessment, privacy considerations, vendor details, review frequency, last review date, and notes or issues. This detail lets boards assess risk, controls and outcomes and supports meaningful oversight. From Build an AI Use Case Register That Boards Can Actually Use
- What governance controls should AML/CTF teams apply to LLM use?
Map every LLM workflow to a specific AML/CTF Rules obligation, default to prompt-level de-identification, keep humans accountable for each regulated act, back-test triage decisions monthly, verify every regulatory citation in generated content, capture which model version made each decision, and cover LLM use cases in the independent program review. From AML/CTF and Large Language Models: A Compliance View
- What immediate actions should compliance teams take under ASIC's AI posture?
Three actions: review AI-driven customer interactions against the personal advice test, refreshing structure where the line is blurred; refresh customer disclosure documents for AI-relevant content against the substance test; and build an internal capability to explain AI-influenced decisions within RG 271 dispute resolution timeframes. From ASIC's AI Supervisory Posture, Decoded
- What is action initiation under the Consumer Data Right?
Action initiation, sometimes called write access, lets a consumer authorise an accredited provider to initiate actions on their behalf, such as making payments, switching providers, opening or closing accounts and submitting product applications. It became law through the Treasury Laws Amendment (Consumer Data Right) Act 2024, but individual action types must still be designated by the government before anyone can use them. From Governing AI Agents Before the Consumer Data Right Lets Them Act
- What is AI-washing?
AI-washing is overstating the role, sophistication or benefit of artificial intelligence in a product or service. In financial services it looks like marketing that calls a tool AI-powered when it applies simple rules, or that promises tailored AI advice when the tool considers only a couple of data points. It is a species of misleading conduct, and RG 234's update flags disclosing the real capability and limitations of AI-enabled customer tools as part of advertising them accurately. From AI Wrote the Ad. ASIC Still Holds You to It.
- What is an offline GRC controls console and what should it be used for?
It is a single-file HTML tool that runs locally to structure evidence, log exceptions, capture reviewer sign-off and produce a clean review pack without sending data anywhere. Use it for one narrow control test as a working layer, never to replace Archer, ServiceNow or any approved system of record. From Build an Offline GRC Controls Console Without Creating Shadow IT
- What is APRA's model risk thematic review?
A thematic review is APRA's deep-dive supervisory tool. It is not enforcement or consultation, but a structured study of how a sector manages a specific risk. Findings typically feed into supervisory letters, updated guidance, or new prudential standards. APRA ran similar reviews on cyber maturity and operational resilience. From APRA's Model Risk Thematic Review: What to Expect
- What is ASIC's supervisory posture on AI in financial services?
ASIC's posture is that AI is a use case to which existing law applies. The presence of AI does not change a licensee's conduct, disclosure, design and distribution, or dispute resolution obligations. It changes where the licensee needs to look to evidence compliance, not what the obligations are. From ASIC's AI Supervisory Posture, Decoded
- What is the Australian AI Safety Institute?
The Australian AI Safety Institute is an advisory body launched in early 2026 with about 29.9 million dollars in funding under the National AI Plan. It monitors, tests and shares information on emerging AI capabilities, risks and harms. It has no enforcement powers. For GRC its value is as an early-warning signal for where targeted regulation may eventually land. From Australia Will Not Pass an AI Act. You Are Still Regulated.
- What is the correct order of work for a newly regulated firm?
Build the ML/TF risk assessment first, with a person doing the thinking and AI structuring and drafting. Let that assessment drive the program. Use AI to scaffold policies, then edit to what is true. Record why calibration settings landed where they did, and keep that reasoning as a defensible governance record. From AML Tranche 2: What AI Can and Cannot Do for Your New Program
- What is the difference between an AI guardrail and a control?
A guardrail describes what good practice looks like, while a control describes how an organisation makes that true and produces evidence that can be tested. A principle such as humans remaining in the loop is not assurance evidence. A workflow plus sampled records showing a reviewer checked output before a decision is finalised is evidence. From From Voluntary AI Guardrails to Audit Evidence
- What is the difference between DDO and personal advice for AI personalisation?
DDO is conceptually about classes of consumer. The issuer defines a target market and the distribution chain operates within it. Personal advice concerns a specific person, triggered when a recommendation considers individual circumstances in a way a reasonable person expects to be taken into account, attracting Chapter 7 licensing and best-interest obligations. From DDO and AI-Driven Personalisation: Where the Boundary Sits
- What is the first thing a compliance function should do about this?
Build an inventory of every third-party component running on customer-facing pages, including analytics, advertising, session recording, support widgets and AI assistants. For each one, record who supplies it, what it receives, where that goes, whether the categories can include sensitive information, and which notice or consent covers it. Most organisations discover components nobody currently owns. From Your Website AI Assistant Is Someone Else's Code
- What is the minimum an in-scope AI use-case register must record?
The DTA's Standard for accountability sets a thirteen-field minimum, including a description of what the AI does, its business objective and, where relevant, the underpinning product name; the AI technology type, being generative AI, machine learning, natural language processing or computer vision; the lifecycle stage; the accountable use case owner's details; and inherent and residual risk ratings from the impact assessment. High-risk use cases also record review dates. From Canberra's AI Register Mandate Is a Preview
- What is the new triennial board performance review?
Draft CPS 510 strengthens annual board, committee and director performance assessments and requires significant financial institutions to commission an independent external assessment of board performance at least every three years. That assessment is a natural place to test whether the board can genuinely challenge AI risk. From Freed Board Bandwidth Is for AI Oversight
- What is the practical control for AI in a super fund?
An AI-decision register. List every current and proposed AI use case, and classify each one as either supporting a trustee discretion or making or dictating it. Put a hard human-involvement gate on anything in the second group, require a documented best financial interests business case for the spend, and keep an accountable owner for each use case under the accountability regime. That register is the evidence APRA and your board will ask for. From Super Trustees, AI and the Discretion You Cannot Delegate
- What is the practical task list for compliance teams after this update?
Check which starter kit version your documents were built from and whether it predates 19 June 2026. Update the risk assessment for AI typologies, revisit onboarding controls, document any AI used in monitoring against AUSTRAC's model, and keep the reasoning and version history as a defensible record. From AUSTRAC Just Put AI Risk Into Your AML Program Documents
- What is the risk of reading this relief as less AI documentation?
Under-documentation exactly where supervisors look. Lighter filing does not reduce the need to explain an adverse automated decision or show who owns an AI tool in a regulated process. If a register decays because the map now needs fewer updates, the entity loses the evidence that made an accountable person's position defensible in the first place. From FAR Eased Up. Your AI Map Still Holds
- What is the Scams Prevention Framework and when does it bite?
The SPF is the Commonwealth regime created by the Scams Prevention Framework Act 2025, which amended the Competition and Consumer Act 2010 to make banks, telcos and digital platforms responsible for preventing, detecting and disrupting scams. Treasury released the exposure-draft codes and rules on 28 May 2026, consultation closed on 25 June 2026, and substantive sector obligations are proposed from 31 March 2027. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
- What law sits behind RG 234?
RG 234 is guidance on how to comply with the misleading-conduct prohibitions, principally section 12DB of the ASIC Act, which prohibits false or misleading representations about financial services, and section 1041H of the Corporations Act, which prohibits misleading or deceptive conduct in relation to financial products. RG 234 does not create new law. It sets ASIC's expectations for how advertising, now including AI-generated advertising, meets that existing law. From AI Wrote the Ad. ASIC Still Holds You to It.
- What makes a register entry useful rather than poor?
A useful entry provides clear accountability, detailed controls, documented human oversight, evidence of impact assessment and privacy considerations, and an appropriate review rhythm with an escalation process. A poor entry lacks control detail, has no impact assessment, reviews too infrequently for the risk level, and cannot support meaningful board oversight. From Build an AI Use Case Register That Boards Can Actually Use
- What parts of AML compliance must a person keep, not AI?
Three lines stay with people: the formation of suspicion and decision to report, the calibration of risk appetite, and accountability, which rests on the reporting entity, its governing body and AML compliance officer. There is also a confidentiality duty: do not feed privileged client detail into a general consumer AI tool. From AML Tranche 2: What AI Can and Cannot Do for Your New Program
- What practical actions should GRC teams take for AI personalisation under DDO?
Map every AI-driven customer touchpoint against the DDO and personal advice framework, tagging each as general information, general advice, or personal advice. Test that operational behaviour matches the tag through monthly sampling. Govern recommendation logic, not just outputs. Set a clear policy on generative AI customer interactions and apply CPS 234-style vendor due diligence. From DDO and AI-Driven Personalisation: Where the Boundary Sits
- What readiness work should a GRC team do before December 2026?
Four moves. Inventory every system that makes or substantially shapes a decision about a person, including older and vendor systems. Classify each by whether it significantly affects rights. Draft the disclosure under the three APP 1.8 categories. Evidence it with the inventory, impact assessments and policy version history. The inventory is the long pole, not the drafting. From Automated Decisions Now Belong in Your Privacy Policy
- What reporting cadence should boards use for AI cyber risk?
The article recommends the board review cyber risk posture, incident summaries and strategic decisions quarterly; the risk committee review control effectiveness, risk trends and third-party risks monthly or bi-monthly; and IT security and AI ops review operational incidents, patching status and threat intelligence weekly or fortnightly to ensure timely escalation. From AI Cyber Risk Is Now a Board Governance Issue
- What should a GRC team do before 1 July 2026?
Four passes over your AI estate. Find the AI inside your material arrangements, starting from the service provider register. Test each contract against the CPS 230 service provider requirements. Build and actually exercise a fallback where AI supports a critical operation. Then manage and document the concentration risk. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
- What should a GRC team do before deploying AI in IDR?
Map every RG 271 obligation to what AI may touch and what stays human, keep a person accountable for the outcome and the reasons, log what the AI drafted versus what the person decided, govern the tool as a system that handles sensitive data, and confirm the deployment against the current RG 271 and Instrument 2020/98 before go-live. From AI in Complaints Handling: What RG 271 Reserves for a Person
- What should a GRC team do before the framework applies in 2027?
Confirm scope, build a principle-to-control map across the six principles with named owners and evidence, inventory every AI model in the detection stack, stand up the dispute and reporting pipelines, govern the detection AI as a high-consequence system, and keep the board across the govern principle. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
- What should AI vendor due diligence cover beyond security questionnaires?
Due diligence should cover data use, model changes, logging, incident notification, subcontractors, service availability, exit arrangements and the ability to explain or test outputs. For critical operations, resilience testing should consider what happens if the provider changes the model, the service fails, logs are unavailable or data must be removed quickly, with fallback processes and exit plans documented. From From Voluntary AI Guardrails to Audit Evidence
- What should an AI incident evidence pack contain?
It should capture the incident timeline, AI system involved, business process, stakeholders affected, data categories, prompts and outputs, model or vendor details, access permissions, human review steps, containment, root cause, control failures, customer or employee impact, regulatory assessment and remediation. It should also record confirmed facts, working assumptions and unresolved questions. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook
- What should an audit workpaper record when AI is used?
Standard 14.6 documentation must let another auditor reach the same conclusions. Record five things: the tool and version, the prompt given, the raw output before editing, the corroboration performed against source records and by whom, and the corrections made. Keep it proportionate: log only where output influenced an audit judgement. From AI in Internal Audit: What Still Counts as Evidence
- What should go on the regulatory watch list after a machinery announcement?
Four entries, each with a named owner, an observable trigger and a review date: National Cabinet consideration in August 2026, the Australian Standards for AI text itself, the legislation flagged for early next year, and the whole-of-government AI consumer safety priorities promised in coming weeks. Record against each that there is no current obligation, no control change and no spend, so the assessment is visible rather than assumed. From A New AI Office Is Not a New AI Obligation
- What should GRC teams do about CPS 230 and AI in the next ninety days?
Four actions. Re-run critical operations mapping with AI treated as a first-class component. Inventory the AI stack against material service provider criteria. Define quality tolerance levels alongside availability ones. Map each material tool's model and infrastructure chain, documenting the contracting party, model provider, inference infrastructure, and data residency. From CPS 230 and AI: A Practical Operational Resilience Playbook
- What should GRC teams do given there is no AI Act?
Build a map from each AI use case to the existing obligations it touches, adopt the Voluntary AI Safety Standard as a practical framework, watch the AI Safety Institute and the coming Privacy Act reforms as the direction of travel, and name an accountable owner for each material AI system. The work is compliance mapping and governance, not waiting for a law that is not coming. From Australia Will Not Pass an AI Act. You Are Still Regulated.
- What should GRC teams do now to prepare?
Four actions are sensible regardless of timing: run a model risk inventory completeness check covering AI tools with a documented threshold, map validation methodology by model type, document human-in-the-loop adequacy for material AI outputs, and build third-party AI transparency into procurement and ongoing oversight. From APRA's Model Risk Thematic Review: What to Expect
- What should trigger an automatic pause of a pricing agent?
Examples include unexplained convergence with competitors, abnormal retaliation against discounting, use of unapproved data sources, missing logs, a material vendor change or prices outside approved bounds. Triggers should be tailored to the market and reviewed by competition specialists, and the pause owner must be named, including outside business hours. From Your Pricing Agent Is Still Your Competition Risk
- When does an AI customer service assistant cross into personal advice?
If a generative AI assistant considers a customer's circumstances, such as account holdings, balance, or transaction patterns, and is presented in a way the customer reasonably expects to take those circumstances into account, it can be personal advice regardless of any disclaimer. Knowing the customer's holdings creates a strong expectation of personalisation. From DDO and AI-Driven Personalisation: Where the Boundary Sits
- When does CPS 510 commence?
Consultation on the draft is open until 28 August 2026. APRA expects to finalise CPS 510 and a unified practice guide, CPG 510, by the end of 2026, with the new requirements expected to take effect from early 2028. From Freed Board Bandwidth Is for AI Oversight
- When does the CDR expand beyond banking?
The read side is widening now. Under the CDR rules, product data sharing obligations apply to non-bank lenders from 13 July 2026, with consumer data sharing from 9 November 2026 for initial providers and 10 May 2027 for large providers. Every new accredited connection is a potential future action surface, which makes the expansion a useful dress rehearsal for the action layer. From Governing AI Agents Before the Consumer Data Right Lets Them Act
- When is the APRA model risk review expected to land?
Multiple signals across 2025 and early 2026 indicate it is likely in the second half of 2026. APRA has not published a terms of reference, so this is a planning input rather than a forecast. The work practitioners should do does not depend on the exact timing. From APRA's Model Risk Thematic Review: What to Expect
- Where can AI genuinely help a newly regulated firm build its AML program?
AI fits four jobs: drafting the program scaffolding, structuring the ML/TF risk assessment by interviewing the practitioner toward an answer, tuning customer due diligence and monitoring for firms with existing data, and drafting suspicious matter reports once a suspicion is formed. Point it at administrative load, not judgement. From AML Tranche 2: What AI Can and Cannot Do for Your New Program
- Where can AI genuinely help in complaints handling?
AI can acknowledge and triage incoming complaints, summarise a long file, draft a first-pass plain-English response for review, keep the language consistent and readable, and analyse complaint data sets to surface possible systemic issues for a human to investigate. Each of these is admin or pattern-spotting that a person still signs off. From AI in Complaints Handling: What RG 271 Reserves for a Person
- Where will supervisory pressure focus in the review?
Six areas are likely to see sharp questions: model inventory completeness, validation methodology fit for AI, human-in-the-loop design quality, third-party AI provider oversight, bias and consumer outcome testing, and documentation of model purpose to detect scope creep beyond a model's validated use. From APRA's Model Risk Thematic Review: What to Expect
- Which AI assurance skills are hardest to hire?
The difficult combination is regulatory interpretation, technical-system literacy, test design, evidence judgement and executive communication. Organisations often find pieces of this profile in different people rather than one complete candidate. From The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
- Which AI obligations actually bind an Australian business right now?
The ones that already did. The Privacy Act, including the automated decision-making transparency obligation in APP 1.7 commencing 10 December 2026, the misleading and deceptive conduct prohibitions in the ASIC Act, the Australian Consumer Law, APRA prudential standards such as CPS 230 and CPS 234 for regulated entities, and the AML/CTF regime. The 15 July announcement does not add to or subtract from that list. From A New AI Office Is Not a New AI Obligation
- Which AI systems will the review likely examine?
Three categories: traditional models augmented with AI components, AI-native decision support systems such as generative tools drafting credit memos or compliance assessments, and autonomous or near-autonomous systems like automated AML triage and underwriting. Many of these are operationally embedded but sit outside the formal model inventory. From APRA's Model Risk Thematic Review: What to Expect
- Which AI-specific failure modes should I assess in vendor due diligence?
Three the article highlights: prompt injection, where inputs cause unintended behaviour or data exposure; data leakage between customers in multi-tenant inference infrastructure; and training data contamination, where customer data used for training may surface in responses to others. Standard questionnaires omit these, so add them deliberately. From CPS 234 and AI Vendors: A Due Diligence Framework
- Which five standards does draft CPS 510 consolidate?
The reforms bring together CPS 510 and SPS 510 Governance, CPS 520 and SPS 520 Fit and Proper, and SPS 521 Conflicts of Interest into one cross-industry CPS 510, applying consistent governance minimums across banks, insurers and superannuation trustees. From Freed Board Bandwidth Is for AI Oversight
- Which prescribed responsibilities can AI tooling decisions fall under?
AI tooling can sit inside operational risk management, regulatory compliance management, customer outcomes management, and information system integrity. For example, AI in claims or underwriting touches operational risk, AI in AML monitoring touches compliance, and AI in personalisation or automated decisioning touches customer outcomes. From FAR and AI: How Accountability Maps to Tooling Decisions
- Which provision catches an AI that learns to place and cancel orders?
Orders that never become transactions sit awkwardly with a prohibition framed around creating an artificial price for entering a transaction. In his paper published by the Supreme Court of NSW, Justice Ashley Black records that DPP (Cth) v JM confirms a significant degree of overlap between sections 1041A and 1041B, and that other conduct with a price effect, including the placing of orders that did not give rise to transactions, would typically fall within the scope of section 1041B. That is the provision an AI-learned order-and-cancel pattern most naturally engages. From Agentic Trading and the Purpose Problem
- Who becomes AML regulated under Tranche 2 from 1 July 2026?
From 1 July 2026, around 80,000 to 90,000 businesses move inside the perimeter: lawyers, accountants, conveyancers, real estate agents and developers, and dealers in precious metals, stones and products. These professions handle the transactions launderers favour and had no prior reporting obligation, pushing the total regulated count toward 100,000. From AML Tranche 2: What AI Can and Cannot Do for Your New Program
- Who is accountable when an AI tool is procured centrally but used across multiple business units?
Each AI tool should have a clearly designated accountable person, even with multiple users. The emerging pattern designates the person responsible for the most material use as lead, with secondary business units holding supporting accountability for their specific use cases. This only satisfies FAR if it is documented. From FAR and AI: How Accountability Maps to Tooling Decisions
- Who is affected by the FAR reporting changes?
ASIC and APRA estimated the reforms would reduce reporting for all accountable entities and around 4,500 accountable persons. A separate change streamlines responsible manager competence-evidence requirements for roughly 2,000 current AFS licensees from October 2026. The proposals sit inside the Government's Better Regulation reforms announced in the 2026-27 Budget. From FAR Eased Up. Your AI Map Still Holds
- Who owns the pricing-agent risk?
The commercial owner owns the outcome, supported by pricing, legal, competition, data, technology and risk specialists. A vendor may carry contractual obligations, but outsourcing the software does not outsource the organisation's accountability under the Competition and Consumer Act. From Your Pricing Agent Is Still Your Competition Risk
- Who regulates AI agents acting under the Consumer Data Right?
Two regulators share the field. The ACCC accredits CDR data recipients and monitors compliance with the CDR rules and standards, while ASIC governs the conduct and licensing of the financial services activity wrapped around them. An AI agent initiating a regulated action touches both, so control evidence needs to satisfy both lenses. ASIC has also flagged agentic AI as a key 2026 supervisory concern. From Governing AI Agents Before the Consumer Data Right Lets Them Act
- Who regulates the SPF and what are the penalties?
Three regulators share the work: the ACCC is the general regulator and covers digital platforms, ASIC regulates the banking code, and ACMA regulates the telco code, with AFCA as the external dispute resolution scheme. The most serious breaches attract civil penalties up to around 50 million dollars per contravention for a body corporate, alongside a path to consumer compensation. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
- Who should own an AI use case register?
Each use case needs a named senior manager accountable for its performance, risk management and compliance, with access to risk, compliance, IT and privacy teams. The AI governance or risk committee owns the overall register, ensuring completeness and quality and providing regular reports on key risks, changes and incidents. From Build an AI Use Case Register That Boards Can Actually Use
- Why do AI incidents need a different incident response approach?
AI failure modes do not always look like traditional outages. A model can produce a harmful recommendation while the platform stays available, a chatbot can expose sensitive data without a breach, or an agent can act on a malicious prompt. Standard time, owner and remediation fields cannot cleanly capture these AI-specific failures. From AI Incident Response Needs an Evidence Pack, Not Just a Playbook
- Why does a tracking pixel determination matter to an AI assistant?
Because the architecture is identical. Both are code supplied by another party, embedded in a page you control, which receives what your users do there and sends it somewhere you do not operate. The AI assistant is the higher risk of the two, because a pixel observes clicks while an assistant receives whatever a person chooses to type, including health, financial hardship and identity details you never asked for. From Your Website AI Assistant Is Someone Else's Code
- Why does third-party AI most test board literacy?
Many organisations buy software, embed vendor copilots and connect enterprise data to external platforms rather than building models. APRA's letter points to third-party dependencies for board attention. AI due diligence needs questions on model behaviour, data retention, explainability, subcontractors, monitoring, incident notification and exit, beyond traditional security and contractual checks. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
- Why does this obligation hit Australian financial services hardest?
Three reasons. Credit, insurance and banking decisions affect rights and interests by nature, so the significant-effect threshold is cleared routinely. The systems are layered and old, mixing rules engines, scorecards, vendor services and machine learning across teams. The OAIC has new infringement and compliance notice powers and has flagged privacy policies in high-risk sectors as a focus. From Automated Decisions Now Belong in Your Privacy Policy
- Why does using AI to detect scams create a second obligation?
The moment an entity deploys AI to meet the prevent, detect and disrupt principles, it puts an AI system into a consumer-facing, high-consequence decision. Too aggressive and it freezes legitimate customers out of their money; too permissive and it misses the scam. That model needs validation, monitoring, false-positive handling, human review and privacy and explainability sign-off. From The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
- Why is AI cyber risk a board responsibility and not just an IT issue?
ASIC and APRA make clear that cyber resilience is a core licensing obligation boards must actively oversee. AI accelerates attack speed and complexity beyond traditional IT controls, incidents threaten business continuity and reputation, and boards are ultimately accountable for licensing obligations and setting the organisation's risk appetite. From AI Cyber Risk Is Now a Board Governance Issue
- Why is AI the part of CPS 230 most likely to be tested first?
On 30 April 2026 APRA published a letter to industry on AI that found entities heavily dependent on single AI providers, few tested exit or substitution strategies, and opaque upstream dependencies. Those are the exact things CPS 230 contracts must address, so the deadline and the supervisory focus have converged on the same clauses. From CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
- Why is board AI literacy treated as a control rather than awareness training?
Because boards approve strategy, set risk appetite and oversee material risk, they need enough literacy to ask whether AI systems are governed with the same discipline as other material technology, data, outsourcing and operational risks. That is a higher standard than watching a chatbot demonstration or attending a one-hour awareness session. From Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
- Why is the AI use-case register the foundation for AI assurance?
The register defines the population of AI activity, so an incomplete register weakens every downstream test. It should capture business purpose, owner, system, users, affected stakeholders, data categories, decision influence, automation level, criticality, risk rating, approval status and review date. The risk rating then determines assurance depth and board visibility for each use case. From From Voluntary AI Guardrails to Audit Evidence
- Why is the standard SaaS security questionnaire not enough for AI vendors?
Standard questionnaires do not ask about prompt retention, training data use, multi-tenant inference isolation, or model-version notice, because the technology was not in scope when they were designed. Build an AI-specific addendum so vendor responses on these points are captured in writing, dated, and signed. From CPS 234 and AI Vendors: A Due Diligence Framework
- Why must JavaScript libraries be vendored into the file rather than loaded from a CDN?
A CDN reference is a live network call, and a live network call breaks the offline promise. Charting and table libraries such as Chart.js, Tabulator, PapaParse and SheetJS are useful, but each must be vendored inline or shipped locally alongside the file, with a dependency note, never pulled from a content delivery network. From Build an Offline GRC Controls Console Without Creating Shadow IT