Field notes
AI Governance · 28 September 2026 · 5 min read

What APRA's April 2026 Letter on AI Asks of Regulated Entities

APRA's 30 April 2026 letter found AI assurance lagging and set out what it expects: an inventory, human involvement, and a supply chain you can see.

Krish Singh
Krish Singh
Chief Executive Officer, BackPro AI

On 30 April 2026, APRA wrote to every entity it regulates about artificial intelligence. The letter, signed by APRA Member Therese McCarthy Hockey, drew on what APRA observed at large entities in late 2025. It is guidance rather than a new standard, and it is worth reading closely for that reason: it tells you how APRA intends to apply the standards you already have.

Its central finding is one sentence. APRA found that "assurance practices are not keeping pace with the scale, speed and complexity of AI."

No new rule, and no preferred technology

The letter does not introduce an AI standard. It says "APRA's principle-based prudential framework is technology and vendor agnostic." Existing requirements, chiefly CPS 230 on operational risk and CPS 234 on information security, already apply to AI, and the letter describes what APRA expects to see when it checks them.

It also does not require AI to be hosted in Australia or inside your own environment. Anyone quoting the letter as a hosting mandate has misread it. What it asks is that you can see and govern whatever you choose.

What APRA expects

Guidance. On governance, APRA expects "an inventory of AI tooling and AI use cases; human involvement for high-risk decisions and accountability". An inventory sounds administrative until you try to build one. It has to include the tools staff use informally, not only the ones procurement bought.

Guidance. On suppliers, APRA expects entities to be "mapping and maintain visibility over the full AI supply chain, including material, third-party and fourth-party dependencies". A fourth party is your provider's own provider: the company that trains the model your vendor uses, or the cloud its service runs on. APRA's finding here was blunt: "upstream dependencies such as foundation models, training data sources and fourth party service providers are opaque".

Finding. APRA also observed that "contractual arrangements often lagged practice, with limited evidence of specific provisions addressing audit rights, model updates and deviations, incident notification or changes to data handling." Model updates is the item most contracts miss. A vendor can change the model behind a service without changing anything the contract names.

Finding. On staff use of AI tools, APRA flagged "entities relying primarily on policy direction or detective, after-the-fact measures, rather than enforceable technical restrictions or robust preventative controls." A policy that says "do not paste client data into public tools" is what APRA found insufficient on its own.

And it said what happens next: "we will take stronger supervisory action and, where appropriate, pursue enforcement."

How the letter connects to the standards

The expectations map onto obligations that are already binding.

Law. CPS 234 requires an entity to "assess the information security capability" of any party managing its information assets (para 16) and to "evaluate the design of that party's information security controls" (para 22). Material information security incidents must be notified to APRA no later than 72 hours after the entity becomes aware (para 35). An AI provider holding or processing your information is within these paragraphs.

Law. CPS 230 makes the Board "ultimately accountable for oversight of an entity's operational risk management", including "the management of service provider arrangements" (para 19). It requires agreements for material arrangements to address "ownership and control of data" and "audit access" (para 53(b)), which is where the letter's contract findings land. Where an AI service puts data or personnel offshore, paragraph 60(b) requires notice to APRA before a material offshoring arrangement is entered, which we cover in our note on notifying before, not after.

APRA made the underlying point well before this letter. In 2024 Therese McCarthy Hockey said: "Companies cannot delegate full responsibility to an AI program."

A checklist from the letter

For each AI tool in use, formal or informal, a regulated entity should be able to show:

  1. It is on the inventory, with its use cases and an owner.
  2. The decisions it touches are classified, and the high-risk ones have a named person involved.
  3. The supply chain is mapped to the fourth party: which model, whose cloud, which region processes each request.
  4. The contract covers audit rights, notice of model updates, incident notification and changes to data handling.
  5. Staff use is limited by technical controls, not only by policy.
  6. The CPS 234 assessment of the provider's controls is on file and current.

The same list applies to suppliers who want to serve these entities, us included. BackPro deploys into the customer's own cloud account, which makes items 3 and 5 easier to evidence because the environment and its access controls belong to the customer. It does not complete the list on the customer's behalf, and BackPro does not hold SOC 2 or ISO 27001 certification.

Our whitepaper, Where the data sits, puts the letter beside CPS 230, CPS 234, the Privacy Act and the licensee obligations, with each marked as law, guidance or a regulator's finding.

The letter's practical effect is on evidence rather than on rules. Every item in the checklist above was already implied by CPS 230 and CPS 234. What changed on 30 April 2026 is that APRA said it has looked, found assurance lagging, and intends to act.

Written by
Krish Singh
Krish Singh
Chief Executive Officer, BackPro AI
APRAAI governancesupplier riskCPS 230CPS 234fourth parties

Take this with you · eBook · PDF, 11 pages

The AI-Native Compliance Advantage

The questions advisers and licensees ask about AI in advice documents, from "will it make things up?" to "who is responsible?", answered with the evidence.

Sent to your inbox. No call, and nothing else unless you ask.