Adopt AI with Confidence
Jun 2026
This paper is a practical guide for APRA-regulated entities navigating AI governance requirements. Download the full paper for worked examples, a self-assessment framework, and implementation guidance.
Australia's prudential regulator has sent a clear signal: AI governance is no longer a technology concern — it is a governance, risk, and assurance priority.
APRA's 2024 letter to regulated entities elevated AI from an innovation discussion to a prudential one. For boards and executives across banking, insurance, and superannuation, the question is no longer whether their organisation can use AI. The question is whether they can prove that AI use is known, owned, risk-assessed, aligned to appetite, monitored, independently checked, and supported by reliable evidence.
Most cannot — yet.

What APRA Found
In reviewing AI practices across regulated entities, APRA identified consistent patterns of weakness. These are not niche edge cases. They represent the gaps that exist when AI adoption races ahead of governance:
- Board understanding and engagement — boards are approving AI use without adequate visibility into how it operates, what it decides, or where accountability sits
- AI strategy — organisations lack a clear, risk-informed position on where AI is appropriate, at what scale, and under what conditions
- Inventories — many entities cannot produce a complete, current list of AI systems in production; shadow AI is common
- Human oversight and accountability — automated decisions are made without clear records of who reviewed them, approved them, or owns the outcome
- Staff experimentation — uncontrolled use of consumer AI tools by employees creates data, IP, and model risk that is not captured in any formal governance framework
- Cyber controls — AI introduces new attack surfaces and model manipulation risks that existing cyber frameworks do not adequately address
- Supplier dependencies — third-party AI providers create concentration risk and opacity that is difficult to assess under current vendor management practices
- Assurance — independent review of AI systems is either absent or conducted by teams without the technical depth to assess what they are reviewing
- Continuous validation — AI models drift; what was validated at deployment may not reflect current behaviour
- Operational resilience — AI failures can be fast, systemic, and difficult to reverse; recovery planning does not reflect this
The Real Test
For regulated entities, these are not abstract governance themes. They are the risks that emerge when AI agents become embedded in lending decisions, claims processing, financial advice, complaints handling, fraud detection, and internal operations.
APRA's position is that each of these areas represents a credible pathway to a prudential event — not a theoretical one.
The question is not whether you are using AI. It is whether you can show that its use is controlled, accountable, and within your risk appetite.
Moving from Confidence to Control
The gap most organisations need to close is not a technology gap. It is an evidence gap.
Many institutions can say they believe their AI systems are performing appropriately. Far fewer can show a regulator — or their own board — a coherent record of what AI is being used, by whom, for what decisions, under whose authority, with what oversight, and with what outcomes.
Closing this gap requires an operating layer for AI governance:
- A single, maintained inventory of all AI systems, agents, and use cases across the business
- Accountability records that trace each AI use case to a named owner, an approved risk assessment, and an obligation register
- Monitoring outputs that are reviewed on a defined cadence and escalated when thresholds are breached
- Human oversight workflows for decisions that are material, irreversible, or affect customers
- Independent assurance supported by structured audit trails — not just attestations
What This Means for Your Organisation
Institutions best placed to benefit from AI will not be those that slow adoption to avoid risk. They will be those that adopt AI at pace while demonstrating disciplined control: clear accountability, effective human oversight, transparent reporting, and credible independent assurance.
The goal is to move from we think we know where AI is being used to we can show where it is used, who is accountable, how it is governed, what evidence exists, and where attention is required.
That shift — from informal confidence to demonstrable control — is what APRA is asking for. It is also what your board, your auditors, and your customers increasingly expect.

