Skip to content
INSIGHT · AUGUST 2026

The APRA AI letter, translated into artefacts

On 30 April 2026, APRA wrote to every bank, insurer and superannuation trustee calling for a "step-change" in AI risk management — warning that "the systems and processes required to safely govern [AI] aren't keeping up." No new prudential standard came with it. That's the point: the expectations apply now, under existing standards, and they arrive as supervisory questions.

Every expectation in the letter is answerable with an artefact — a record that exists, carries its evidence and survives a second question. Here is the translation.

Expectation 1

An inventory of all AI tooling and use cases

The artefact: A maintained register — every model, agent, vendor tool and embedded-AI feature, with owner, purpose, data touched, and last-verified date. Not a spreadsheet from a workshop; a register that stays true.

Why it's harder than it sounds: The inventory decays the day it's written. The artefact that survives supervision is the one with a refresh mechanism and a freshness stamp — staleness visible, not hidden.

Expectation 2

Board AI literacy and effective challenge

The artefact: Board reporting that a director can actually challenge: what AI is in use, what decisions it touches, what went wrong this period, and what the metrics mean — with the measurement basis attached to every figure.

Why it's harder than it sounds: Most board packs assert; few evidence. 'Effective challenge' requires reports that carry their own population and method, so a director can ask a second question.

Expectation 3

Formal governance frameworks and reporting lines

The artefact: A framework that executes — named accountable humans per AI system, escalation paths that have been exercised, and approval gates that exist in the workflow rather than in a policy PDF.

Why it's harder than it sounds: A framework written in prose cannot refuse a request. If the gate isn't in the system, the framework is a description of intentions.

Expectation 4

Lifecycle ownership, design through decommissioning

The artefact: Per-system lifecycle records: who approved deployment and on what evidence, monitoring in operation, and — the part everyone forgets — a decommissioning record proving the model, its data and its access were actually retired.

Why it's harder than it sounds: Decommissioning is the orphan stage. Access that outlives the system it belonged to is both a security finding and a governance finding.

Expectation 5

Human accountability for high-risk decisions

The artefact: A named human per high-risk decision class, and records showing the human gate actually operated — approvals, refusals and overrides logged as they happened, tamper-evident.

Why it's harder than it sounds: Accountability that can't be evidenced is indistinguishable from accountability that didn't happen. The log is the control.

Expectation 6

Supplier and concentration risk; transparency on embedded AI

The artefact: Vendor due-diligence records answering, in writing: where processing runs, whose law reaches it, whether your data trains their models, and what happens when their AI fails. Plus a concentration view — which obligations depend on which single vendor.

Why it's harder than it sounds: The sleeper issue is AI embedded in software you already licensed — it entered without an AI decision ever being made. The inventory has to catch what procurement didn't.

This is what our response pack produces

The six artefacts above, produced as records rather than slideware — agent-executed under human gates, on sovereign Australian infrastructure. Sources: the letter and quotes above are from APRA's own publication of 30 April 2026, read directly; this page states no figure we didn't verify.

The APRA response pack