Australian banks, insurers, super funds, and credit providers face overlapping AI obligations from at least four regulators. This is the complete map.
Nine frameworks. All active. Map your AI systems against each.
Banks, insurers and superannuation trustees must identify, assess and manage operational risks, including those arising from AI systems, with effective internal controls, monitoring and remediation, maintain critical operations through severe disruptions, and manage the risks of AI and technology service providers through a service provider management policy, formal agreements and robust monitoring.
Source: APRA Prudential Standard CPS 230In its 30 April 2026 letter, APRA calls for a step-change in AI risk management, expecting boards and executives of regulated banks, insurers and super funds to lift maturity across governance, operational risk, information security and data risk, with clear ownership across the AI lifecycle and assurance proportionate to AI criticality. APRA has begun an active supervisory program on AI.
Source: APRA media release, AI letter to industry (30 April 2026)From 10 December 2026, an APP entity that arranges for a computer program to use personal information to make, or substantially assist in making, a decision that could reasonably be expected to significantly affect an individual must disclose in its privacy policy the kinds of personal information used and the kinds of decisions made. This is highly relevant to AI-driven credit, pricing, fraud and claims decisions in financial services.
Source: OAIC APP 1 guidelines, automated decisionsRegulated financial entities must maintain information security capability commensurate with vulnerabilities and threats, implement controls to protect information assets including those managed by third parties and AI vendors, and notify APRA of material information security incidents. APRA has stressed that AI accelerates the threat and that identification and patching of vulnerabilities must operate faster.
Source: APRA CPS 234 Information SecurityRegulated institutions must maintain a board-approved risk management framework, risk appetite statement and risk management strategy that identify, measure, monitor and control all material risks, including emerging risks from AI adoption, with the board ultimately responsible and the framework reviewed comprehensively at least every three years. CPS 220 applies to ADIs and insurers and expressly does not apply to RSE licensees; superannuation trustees are covered by the equivalent standard SPS 220.
Source: APRA CPS 220 Risk ManagementThe Voluntary AI Safety Standard sets ten guardrails for organisations that develop or deploy AI, covering accountability and governance, risk management, data governance, testing, human oversight, user transparency, contestability, supply chain transparency and record keeping. Financial firms are encouraged to apply it now, ahead of the proposed mandatory guardrails for high-risk settings.
Source: Voluntary AI Safety Standard, the 10 guardrailsCredit licensees must make reasonable inquiries and verification about a consumer requirements, objectives and financial situation, and must not enter, suggest or assist with a credit contract that is unsuitable. Where AI or automated credit scoring drives these assessments, licensees remain accountable for meeting the not-unsuitable test set out in ASIC RG 209 under Chapter 3 of the National Consumer Credit Protection Act.
Source: ASIC RG 209 Responsible lending conductA provider of personal financial product advice to a retail client must act in the best interests of the client and give appropriate advice. Where AI or digital advice tools generate or shape recommendations, the licensee and adviser remain responsible for satisfying the best interests duty and related obligations in Part 7.7A of the Corporations Act.
Source: ASIC, giving financial product advice (best interests duty)Financial firms must operate an internal dispute resolution system that meets ASIC enforceable standards, including recording complaints and responding within maximum timeframes. Complaints about AI-driven or automated outcomes must be handled under RG 271, and consumers must be able to access a human review where a decision is contested.
Source: ASIC RG 271 Internal dispute resolutionEach obligation links to its primary or official source. Verified against APRA, ASIC, the OAIC and the Department of Industry, Science and Resources, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of every regulatory framework that applies.
Conduct a full AI system inventory, map every AI system to the applicable APRA, ASIC, OAIC, and ACCC obligations
Assess your model risk management framework, does it adequately cover ML models including explainability, drift monitoring, and distributional assumptions?
Review credit decisioning AI for responsible lending compliance, independent legal assessment of AI methodology is required
Audit your privacy policy, does it accurately describe AI use of customer data? APP 1 requires it
Establish customer explanation mechanisms for AI-driven adverse decisions (credit refusals, insurance denials, claim rejections)
For super funds: obtain legal advice on sole purpose test compliance for any AI that uses member data for purposes beyond direct member benefit
Brief your board on AI risk, APRA and ASIC both expect board-level awareness and oversight of material AI risk
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check