On 30 April 2026, APRA wrote to all regulated entities setting out its observations and minimum expectations on AI risk, signed by APRA Member Therese McCarthy Hockey. The letter covers four areas: information security, governance, supplier risk, and change management and assurance. It introduces no new prudential standard. It states what APRA expects entities to do, at a minimum.
01 · What the letter says
The letter reports the findings of a targeted supervisory engagement APRA conducted in late 2025 with selected large banks, insurers and superannuation trustees, published for the benefit of all regulated entities. APRA's summary finding is that governance, risk management, assurance and operational resilience practices are "not keeping pace with the scale, speed and complexity" of AI adoption. The full letter is published at APRA Letter to Industry on Artificial Intelligence.
| Area | What APRA observed | What APRA expects, at a minimum |
|---|---|---|
| Information security | AI adoption is expanding cyber attack pathways, including prompt injection, data leakage, insecure integrations and misuse of autonomous agents. Identity and access management has not adjusted to non-human actors, and patching timelines lag the accelerated threat environment. | Security controls addressing AI-specific threats, strong privileged access management, timely patching, security testing of AI-generated code, and credible fallback processes where AI supports critical operations. |
| Governance | AI adoption is outpacing governance maturity. Entities tend to treat AI as just another technology, leaving gaps in post-deployment monitoring, change management and decommissioning. Boards are still developing the literacy needed for effective challenge, with overreliance on vendor presentations. | Frameworks and reporting lines for safe adoption, ownership and accountability across the AI lifecycle, an inventory of AI tooling and use cases, human involvement for high-risk decisions, and staff training on AI use and limitations. |
| Supplier risk | Some entities depend heavily on a single provider across multiple AI use cases, with limited contingency planning or tested exit strategies. Upstream dependencies such as foundation models and fourth-party providers are often opaque. | Visibility over the full AI supply chain including fourth-party dependencies, contractual arrangements providing transparency and auditability, and active management of concentration risk including credible substitution and exit arrangements. |
| Change management and assurance | Entities rely on point-in-time and sample-based assurance methods that are poorly suited to probabilistic models that learn, adapt and degrade over time. Few run continuous validation for model drift or bias. Internal audit functions often lack the specialist capability to examine AI. | Recognised control frameworks for AI implementations, integrated assurance across security, data, model performance, resilience, privacy and conduct risks, second-line and internal audit functions able to independently examine AI systems, and continuous monitoring proportionate to the criticality of the use case. |
02 · Board expectations
The letter sets two board-level minimums. Boards are expected to maintain sufficient understanding and literacy of AI to set strategic direction and provide effective challenge and oversight. Boards are also expected to oversee an AI strategy consistent with the entity's risk appetite and tolerance settings, supported by monitoring and reporting that covers third-party dependencies, with defined triggers for action when systems are not operating as expected.
The attachment to the letter sets out APRA's observations and expectations for accountable executives, directed at CROs, CTOs and CISOs. APRA invites entities to engage early with its Non-Financial Risk Team on heightened AI risk concerns, and states that where entities fail to manage AI risks proportionate to their size and complexity, stronger supervisory action and, where appropriate, enforcement will follow.
03 · The assurance finding
The letter's fourth observation area carries its sharpest finding. APRA observed entities relying on point-in-time and sample-based assurance methods, and stated plainly that these methods are ill-suited to probabilistic models that learn, adapt and degrade over time. It found few entities running continuous validation capable of detecting model drift, bias or control breakdowns in a timely way.
APRA separately observed that internal audit and risk functions often lack the specialist skills and tools to examine AI systems, particularly where agentic behaviour or automated decision-making is involved, and that assurance activities lagged AI deployment as a result. Its stated expectation is that second-line and internal audit functions be capable of independently examining AI systems, including probabilistic models and agentic workflows.
Read together, the two findings describe a structural gap: the entity's own review functions are behind the systems they review, and the methods available to them expire the day they are run.
04 · The evidence layer
The letter tells entities what APRA expects. It does not tell them what the evidence of meeting those expectations looks like. That layer is the entity's to build, and it is what a supervisor will ask to see.
An AI Accountability Audit produces part of that evidence independently. The inventory APRA expects maps to what the audit records under tool deployment: the AI systems and automation tools running in production in each function, named and categorised. The ownership and accountability APRA expects maps to what the audit records under governance and oversight: the policies, approval structures and accountability assignments controlling how AI is evaluated and deployed. These mappings are kn0w's reading of the letter, not APRA's.
The audit's cadence answers the letter's assurance finding directly. A Statement is issued at a point in time, and standing is then maintained through three Quarterly Reviews across the twelve-month cycle and confirmed by the Annual Statement, reissued under the same methodology. The evidence does not expire the day it is produced.
05 · Where a Statement sits
A Statement issued for a company records what AI is running, who is accountable for it, what is spent on it and what oversight applies, benchmarked against a peer cohort. It is the artefact a company holds before a supervisory review asks what evidence exists, rather than the document assembled after.
The full methodology is published at kn0w.co/methodology. A sample of the issued Statement is available at kn0w.co/sample-statement. The category is defined at kn0w.co/ai-accountability-audit.
06 · Frequently asked questions
No. The letter is guidance based on APRA's observations under its existing principle-based prudential framework, which APRA describes as technology and vendor agnostic. APRA states it is finalising its supervisory forward plan and will consider whether further policy action is needed.
The letter is addressed to all APRA-regulated entities. Its observations are drawn from targeted engagement with selected large banks, insurers and superannuation trustees in late 2025, published so entities earlier in AI adoption can draw on the lessons.
No. It sets expectations, including that internal review functions be capable of independently examining AI systems. An independent audit is one way an entity produces evidence against those expectations before being asked for it.
Yes. APRA states it is engaging across the sector on the potential for increased cyber threats from high-capability frontier AI models, and directs entities to current Australian Signals Directorate advice on frontier models.
The full letter and its attachment are published on APRA's website at APRA Letter to Industry on Artificial Intelligence.
Published 24 August 2026. Verified against the APRA letter of 30 April 2026 on 24 August 2026.