Share this article

How APRA’s AI guidance impacts banks and insurers in Australia
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Vanta’s 2025 Australia State of Trust Report highlights the fast pace of AI adoption in the region: nearly 80% of organisations are using or planning to use agentic AI in operations. Australia's financial services industry, covering banks, insurers, and superannuation trustees regulated by the Australian Prudential Regulation Authority (APRA), is also integrating AI into everyday processes such as customer engagement, claims processing, fraud detection, and risk analysis.
APRA plays a central role in helping regulated organisations strengthen their overall resilience and risk management practices, primarily through guidance and prudential frameworks. In April 2026, it released an industry letter outlining its observations on AI adoption and reinforcing how existing prudential standards apply to AI use cases. This guide will break down APRA’s AI guidance letter, outline key expectations, and explain what you can do to meet them.
What does APRA’s AI guidance letter say?
On 30 April 2026, APRA released the Letter to Industry on Artificial Intelligence (AI) outlining its observations on AI adoption and governance across regulated organisations. It reinforces that APRA's principle-based prudential framework is technology and vendor agnostic and applies regardless of whether organisations rely on traditional technologies or use AI. Rather than introducing new AI-specific prudential requirements, this letter serves as a supervisory debrief, highlighting:
- How current organisational practices fall short
- How existing APRA prudential standards apply to AI
The letter’s central observation is that governance, risk management, assurance, and operational resilience practices are not keeping pace with AI adoption. APRA also notes significant variance in AI governance maturity between organisations, suggesting different levels of preparedness for AI risks.
The letter identifies significant gaps across all four observation areas, including supplier concentration and opacity in the AI supply chain. Many organisations lack sufficient visibility into their AI-enabled service providers and their upstream and downstream dependencies, which leads to blind spots in risk management and operational resilience.
Finally, the letter also warns that organisations failing to address these concerns may face stronger supervisory scrutiny and, where appropriate, enforcement action.
Key takeaway: APRA’s AI guidance letter upholds that AI risk management is part of the existing prudential obligations of Australian banks and insurers, not a separate compliance exercise. So, if a bank deploys an AI model for lending decisions or fraud detection, APRA expects it to comply with existing prudential standards such as CPS 220 (Risk Management), CPS 230 (Operational Risk Management), and CPS 234 (Information Security).
{{cta_withimage28="/cta-blocks"}} | AI security assessment
How APRA's AI guidance relates to existing prudential standards
APRA's AI guidance letter doesn’t introduce any new AI-specific prudential requirements but clarifies that AI risks should be managed through existing prudential standards. In practice, this means organisations should review and update their existing governance, operational risk, information security, and third-party risk management processes to account for risks introduced by AI-driven systems and processes. For example:
- To comply with CPS 220, you include AI risks in your risk registers, governance processes, and reporting
- To comply with CPS 230, you assess AI-enabled providers under your material service provider arrangements and extend operational resilience and business continuity planning to AI-supported critical operations.
- To comply with CPS 234, you implement appropriate security controls across the AI lifecycle
The guidance letter doesn’t just point out the gaps in existing implementation. It also signals where regulatory expectations are headed as AI adoption accelerates.
How APRA reinforces its security expectations for AI
APRA’s AI guidance letter explains how existing obligations should be applied to support AI risk management. It presents four observations:
- AI threats increasing but information security struggling to keep pace
- AI adoption moving fast but governance maturity lagging
- Supplier risk management in place but supplier concentration and opacity present challenges
- Traditional change management and assurance in place but not sufficient for dynamic AI solutions
The letter sets the minimum baseline expectation by outlining sample practices banks, insurers, and other APRA-regulated entities should implement. Let’s explore the practical areas of implementation below:
1. Visibility in the AI supply chain is weak
APRA’s letter emphasises that organisations often lack visibility into the AI risks embedded in software, platforms, and development tools and how AI-dependent their processes are. This can lead to a concentration risk, where organisations rely on a single AI platform or AI-enabled vendor for multiple use cases, increasing the potential impact of disruptions.
APRA also points out gaps in resilience planning, including limited disaster and contingency plans for potential outages and insufficient contractual protections with service providers.
A key concern is the lack of upstream visibility. There’s limited oversight of foundation models, training data sources, and fourth-party service providers, making it difficult to evaluate and respond to AI risks effectively.
To address these, APRA emphasises the importance of TPRM through practices such as:
- Expanding visibility to the complete AI supply chain, as well as mapping fourth-party dependencies
- Implementing contractual and governance arrangements that provide transparency, auditability, and assurance over AI services
- Actively managing concentration risk by including scenario analyses of possible systemic failures and credible options for substitution, portability, and exit from AI vendors
2. AI adoption outpaces governance maturity
APRA observed that AI adoption is accelerating, especially for use cases such as claims triage, loan application processing, fraud and scam disruption, customer interaction, and insight generation. While many organisations recognise that prudential standards apply to AI, APRA found that governance practices aren’t keeping up with adoption.
This gap stems from organisations failing to operationalise AI governance or account for the unique risks introduced by AI systems, such as adaptive model behaviour, inherent bias, privacy and data risks, and unpredictable outputs. As a result, AI risks aren’t consistently incorporated into GRC processes.
To strengthen governance maturity, APRA expects organisations to:
- Implement governance frameworks and reporting lines to support safe, responsible, and sustainable AI adoption
- Create an inventory of AI systems and use cases
- Maintain human-in-the-loop processes for high-risk decisions
- Establish clear accountability and ownership across the entire AI lifecycle
3. Information security doesn’t address AI threats
The letter emphasises that AI significantly increases an organisation’s attack surface by introducing new risks that existing controls may not adequately address. While some teams are using AI to strengthen their cybersecurity capabilities and cover AI risks, APRA found that many organisations are yet to adapt their security controls and remediation efforts.
Some of the gaps that APRA warns against include identity and access management practices that don't account for AI agents, incomplete coverage and scope for security testing during implementation and risk response, and inconsistent control implementation timelines.
Another concern is the growing shadow AI, where staff use tools outside risk and approval loops, thus often relying on policy or after-the-fact detective measures rather than preventative technical controls, creating unmapped governance and security risks.
To strengthen your AI security posture, the guidance suggests organisations should:
- Assess reliance on AI for critical operations and business continuity
- Implement appropriate fallback measures
- Conduct security testing across AI-generated code, software components, and libraries
- Continuously evaluate third-party and concentration implications on common platforms, services, and providers
{{cta_withimage7="/cta-blocks"}}| ISO 42001 checklist
4. Traditional processes can’t keep up with AI
APRA’s letter emphasises that AI risk cuts across multiple domains and governance functions, including:
- Operational risk
- Data governance
- Model risk
- Change control and release management
- Legal and regulatory compliance
- Procurement
- TPRM
The letter notes that governance, change management, and assurance activities are typically fragmented across these domains and don’t offer sufficient oversight. In practice, APRA notes reliance on point-in-time and sample-based assurance methods, which are ill-suited to probabilistic models that learn, adapt, and degrade over time. Assurance using simplistic spreadsheets is inadequate for managing risk in dynamic AI systems.
Another bottleneck the letter warns against is the lack of stakeholder understanding and tooling to manage and validate AI models continuously, as this can cause AI risks to escalate until they become harder to address.
To improve and modernise risk management, APRA recommends:
- Implementing globally recognised frameworks with control libraries and change management for AI tools
- Conducting comprehensive risk and information security assessments both before deployment and throughout the AI lifecycle
- Coordinating assurance activities across data governance, model performance risk, operational resilience, privacy, and regulatory compliance
How to build an AI governance program aligned with APRA
To operationalise APRA’s expectations into your existing GRC programs, focus on implementing practices that support responsible AI use. Key priorities include:
- Build an AI inventory: Document AI-related systems, models, and third-party services
- Strengthen third-party and supply chain visibility: Identify AI dependencies within material service provider arrangements and establish appropriate oversight for all upstream relationships
- Embed AI risk into existing risk management: Introduce AI-specific risks into your existing risk registers and risk taxonomy and strengthen CPS 230- and CPS 234-aligned practices to account for AI
- Enhance board and management oversight: Ensure that board and senior management have the necessary AI literacy to oversee AI risks and make informed decisions
- Enable continuous oversight and testing: Move away from periodic reviews by continuously monitoring AI systems, validating model performance, and reassessing risks throughout the AI lifecycle
AI governance frameworks can provide additional structure as you align with APRA’s expectations
Top compliance and risk management solutions like Vanta can help you build the foundation necessary to meet APRA’s AI expectations.
Strengthen AI governance and compliance with Vanta
Vanta is the leading agentic trust platform that helps organisations transition from manual governance approaches to automation and AI-supported security posture. It achieves this through a combination of agentic workflows, centralised visibility through dashboards, and continuous oversight, which make it easier to detect and respond to AI and vendor risks.
Vanta helps you maintain an integrated risk register with controls supporting vendor discovery and AI sub-processor mapping. You will have a framework to meet the requirements to identify and assess operational risks, including those introduced by material service providers and embedded AI functionality.
Vanta’s ISO 42001 solution comes with features that operationalise many of APRA’s expectations and build a strong AI security foundation going forward, such as:
- 1,400+ automated tests supported by 400+ integrations
- Document and policy templates
- Control mappings and AI-specific risk scenarios
- Adaptive scoping
Vanta can also help you comply with other AI frameworks and regulations, such as the NIST AI RMF and the EU AI Act.
Schedule a custom demo to see how Vanta can support your AI compliance program.
{{cta_simple21="/cta-blocks"}} | ISO 42001 demo
Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.












.png)
.png)


.png)





