APRA calls for a major step-change in artificial intelligence governance

Introduction

‍The Australian Prudential Regulation Authority ('APRA') has now made it clear that Artificial Intelligence ('AI') governance is now a strategic priority for Australia's banks, insurers and superannuation trustees. As AI technologies become increasingly embedded within financial services, APRA expects regulated entities to significantly strengthen their governance, risk management and operational oversight.‍ ‍

For Australian Financial Services Licence ('AFSL') holders and prudentially regulated entities, AI should no longer be viewed simply as an information technology productivity initiative. It is now a serious governance issue requiring active Board oversight, executive accountability and robust risk management.‍ ‍

I’ve summarised below a practical summary on what Company Boards, Risk Committees and senior management may wish to consider when reviewing updated AI governance arrangements.‍‍ ‍

1. Establish clear Board accountability for AI

Boards remain ultimately responsible for ensuring their organisation appropriately identifies, manages and monitors material risks arising from AI.‍ ‍

Directors should understand where AI is currently being used across the business, the associated risks, and whether existing governance arrangements remain appropriate.‍ ‍

Suggested Action:‍ ‍

Ensure Board reporting specifically addresses understanding where AI is being used in the business, broad AI risks, emerging AI productivity initiatives and identifying material AI incidents.‍ ‍

Consider whether AI governance should become a standing agenda item for the Board, Risk Committee or Technology Committee or whether a Board bub committee should be formed.‍ ‍

Questions Boards may wish to ask include:‍ ‍

  • Where is AI currently deployed across the organisation?

  • Are there any critical business decisions that rely on using AI and if so, how are these decisions challenged by human executives?

  • Who is accountable for approving AI implementations?

  • How are AI risks actually monitored and reported?

‍ ‍‍ ‍

2. Strengthen governance and executive accountability

‍APRA expects AI governance to be embedded within existing governance frameworks rather than managed solely by technology teams.‍ ‍

Senior management should have clearly defined responsibilities for overseeing AI implementation, risk management and ongoing monitoring.‍ ‍

Suggested Action:‍ ‍

Clearly allocate executive accountability for AI governance.‍ ‍

Ensure AI risks are incorporated into existing governance frameworks, including:‍ ‍

  • Enterprise risk management;

  • Operational risk;

  • Compliance;

  • Information security;

  • Internal audit; and

  • Technology governance.

‍Consider whether existing governance committees or Board sub-committees possess sufficient AI capability and expertise.

‍ ‍

3. Integrate AI into enterprise risk management‍ ‍

AI introduces new categories of operational, legal, compliance and prudential risk that should be incorporated into existing enterprise risk management frameworks.‍ ‍

Risk assessments should consider:‍ ‍

  • Overall data quality;

  • Model assumptions, accuracy and reliability on AI inputs;

  • Assessment on algorithmic bias generated by AI;

  • Customer outcomes influenced by AI;

  • Customer privacy obligations consistent with Australian privacy laws;

  • Any cybersecurity vulnerabilities;

  • Third-party dependencies; and

  • Overall regulatory compliance.

‍Suggested Action:

Update enterprise risk assessments to specifically identify AI-related risks and establish appropriate controls, monitoring and reporting.‍

AI risk assessments should become governance documents that evolve alongside the technology with suggested minimum 12 monthly Board reviews.

‍‍ ‍

4. Strengthen model governance and oversight

Many AI systems operate as sophisticated predictive models that require ongoing validation and monitoring.

‍Boards should ensure management has appropriate governance over the full AI lifecycle, including design, testing, implementation, monitoring and retirement.‍ ‍

Suggested Action:‍ ‍

Implement formal model governance processes that include:‍ ‍

  • Independent validation;

  • Performance monitoring;

  • Periodic review;

  • Change management;

  • Human oversight; and

  • Documented approval processes.

‍Organisations should also maintain an inventory of AI systems being used and clearly identify those systems that support critical business functions.

‍ ‍‍ ‍

5. Review third-party AI providers

‍Many organisations are adopting AI through external vendors, cloud providers and software platforms rather than developing systems internally.

This method of procurement does not reduce governance obligations.‍

Boards remain responsible for ensuring outsourced AI services are appropriately governed.

‍Suggested Action:

Review third-party governance arrangements to ensure appropriate:‍ ‍

  • Initial due diligence and ongoing diligence;

  • Contractual protections;

  • Data security;

  • Ongoing monitoring;

  • Performance reporting; and

  • Exit planning.

‍Existing outsourcing and operational risk frameworks should be reviewed to ensure they adequately address assessment of AI providers and then product suite.

‍ ‍

6. Strengthen data governance and cybersecurity‍ ‍

AI systems are only as reliable as the data used to train and operate them.‍ Poor quality data may result in inaccurate decisions, customer harm and increased regulatory risk.‍ Similarly, AI technologies may introduce new cybersecurity threats requiring additional controls.‍ ‍

Suggested Action:‍ ‍

Review existing data governance frameworks to ensure they support:‍ ‍

  • Data quality;

  • Data integrity;

  • Secure information management;

  • Access controls; and

  • Cyber resilience.

‍Existing cybersecurity controls should also be assessed to determine whether they adequately address AI-specific threats.

‍ ‍‍ ‍

7. Maintain appropriate human oversight‍ ‍

One of the key governance principles emerging globally is that AI should not operate without appropriate human oversight, particularly where significant customer or financial decisions are involved.‍ ‍

Boards should understand where human review remains necessary and ensure AI outputs are not accepted uncritically, and to reacquaint themselves with the GIGO principle - ‘Garbage in, Garbage Out’, i.e. the quality of an output is strictly determined by the quality of the input.‍ ‍

Suggested Action:‍ ‍

Develop policies that clearly define:‍

  • Which decisions require human approval;

  • Escalation processes;

  • Exception management;

  • Incident reporting; and

  • Accountability for AI-generated decisions.

‍ Maintaining appropriate human judgement remains a critical governance control.

‍ ‍ ‍

8. Invest in Board capability and organisational culture

‍Effective AI governance requires informed decision-making at every level of the organisation.

Boards should ensure directors and senior executives have sufficient understanding of AI technologies to discharge their governance and oversight responsibilities. ‍

Suggested Action:

‍Consider:‍ ‍

  • Board training and education programs;

  • Executive level AI training;

  • Governance workshops to enhance executive understanding of AI risks;

  • Broad organisational risk awareness initiatives; and

  • Ongoing review of emerging financial services, banking and superannuation regulatory developments.

Building internal capability sooner will better position organisations to manage emerging risks as AI technology and subsequent regulation continues to evolve quickly.

‍ ‍ ‍

Conclusion

‍Artificial intelligence is expected to reshape Australia's financial services sector over the coming decade.‍ ‍

While AI presents significant opportunities to improve productivity, customer service and operational efficiency, APRA has made it clear that these benefits must be supported by strong governance, effective risk management and Board accountability.‍ ‍

Boards should take this opportunity to assess whether existing governance frameworks adequately address AI risks, or whether additional policies, reporting and oversight are required.‍ ‍

Organisations that proactively strengthen their AI governance today will be better positioned to meet APRA's prudential expectations, protect customers, improve operational resilience and maintain stakeholder confidence.‍ ‍

If your Board does not yet have a governance professional with experience in AI governance, operational risk or prudential compliance, I would welcome the opportunity to assist your organisation by reviewing your existing governance framework, advising your Risk or Compliance Committee, or supporting your Board in implementing institutional-grade AI governance practices. If your Board requires assistance reviewing your AI governance framework or understanding APRA's evolving expectations, please don't hesitate to contact me.

‍‍ ‍

Can we help your business?

‍If you are a private company board or a company holding an AFSL and would like to discuss how I can assist your company with enhancing your governance so that you can better manage your compliance risks and protect your investors, please contact me for an obligation-free discussion. I can assist your company with:‍ ‍‍ ‍

  • Responsible manager;

  • Compliance committee;

  • Company director;

  • Advisory board services;

  • International company resident director services;

  • Compliance reviews; and

  • Governance committee services.

I’d be excited to assist your company meet its ongoing governance and compliance obligations relating to your company, or your AFSL, and to give your customers and investors/shareholders comfort that you can manage your business with institutional grade corporate governance.

‍ ‍‍ ‍

Governance + Strategy = High Performance

https://www.andrewsmcneil.com/

‍ ‍

‍ ‍

Next
Next

Accountants now need to comply with AML/CTF laws