Emeris Australia Independent practice Home The judgements The practice
Regulated financial services

The transition period is over, and most AI arrangements were never assessed against the standard in the first place.

CPS 230 has applied in full since 1 July 2026. The relief for pre-existing service provider contracts expired with it. If an AI capability sits inside a critical operation — a model scoring claims, triaging fraud, routing complaints, drafting advice — the questions APRA is now asking about it are the ones nobody was asked at procurement.

Thirty minutes to work out what your actual exposure is.

What actually changed

The regulator did not write a new AI standard. It applied the one you already have.

There is no separate AI instrument coming, and waiting for one is the mistake. AI risk arrives through operational risk, information security, supplier management and board oversight — all of which are already prudential obligations with an existing supervisory apparatus behind them.

What the April letter added was a finding. APRA looked across a set of large banks, insurers and trustees and reported that governance and assurance were not keeping pace with adoption. It named board reliance on vendor presentations without examination of the underlying risks. It noted identity and access management built for human users and not yet adjusted for non-human ones. It asked for recognised control frameworks and integrated assurance rather than a policy document.

ASIC wrote eight days later, on different ground: cyber resilience against an AI-accelerated threat environment, a twelve-point action list, and an instruction that the letter be tabled at the ultimate board and risk committees. Two regulators, ten days apart, arriving at the same place from opposite directions — the board, and what it can actually evidence.

Read alongside CPS 230, that is a specific and uncomfortable question about every AI capability in the business: is it inside a critical operation, and if it is, can you evidence what happens when it degrades, who intervenes, and how quickly you would know.

Where the exposure usually sits

Three positions, in roughly the order they get found

None of these are hypothetical failure modes. They are what turns up when someone goes looking.

The register was built before the capability was

An AI vendor inside a critical operation that nobody listed

Material service provider registers were assembled around infrastructure, outsourcing and core platforms. An AI capability procured through a business unit, or embedded inside a product you already buy, frequently is not on it — and a fourth-party model dependency behind that vendor almost never is. The register is the artefact APRA collects. A gap in it is not a documentation problem.

The tolerance was set for an outage, not a drift

An impact tolerance that assumes the system fails visibly

Business continuity thinking is built around things stopping. A model does not stop. It degrades quietly, keeps returning confident output, and the disruption is only detectable if someone is monitoring the distribution of decisions rather than the availability of the service. Tolerances written for downtime do not bind a capability that fails while still running.

The escalation path has never been walked

An accountable executive with no route to intervene

Accountability is assigned in the framework and the framework was signed. What has usually not been tested is whether the named person can actually stop the capability, on what evidence, on whose authority, and how long that takes on a Friday afternoon. I have been in the room when a production model degraded and the escalation path turned out to be theoretical. That is the discovery you want to make in an assessment rather than in an incident.

Why this reading

These failure modes are not new. The obligations are.

Emeris is built on sixteen years in signals intelligence followed by a decade delivering production AI inside Australian government operations — systems that make decisions about real people, under scrutiny, and still running on Monday. That work was governed under security and operational obligations rather than prudential ones, and arrived at the same questions from the other direction.

The branch I built and ran for a decade delivered the risk models supporting Australia's migration stream. Where an automated decision affects a person's circumstances, someone has to be able to intervene and answer for it. That was not a principle read somewhere. It was one that had to be designed for, and then defended when it was tested.

Emeris is not a law firm, an implementation shop or a vendor sales channel. The work is finding out what is actually true, then deciding what needs to change. Where the answer is legal advice, you need a lawyer, and I will say so.

Start here

Thirty minutes to find out whether this is worth continuing

No deck, no discovery process, no proposal arriving three days later unless you ask for one. Describe what you have deployed and where you think it sits. I will tell you what I think your exposure actually is, based on what you have told me, whether or not you engage Emeris.

Thirty minutes is usually the difference between a description and a diagnosis.

Line of Sight

Not ready for that conversation yet

A fortnightly brief for people who have to answer for AI rather than announce it. One argument at a time, worked through properly — what is going wrong at the production boundary, why, and what it means for whoever is accountable. Regulated financial services is a recurring subject. No news roundups, no vendor commentary, no predictions I would not put my name against.

Read Line of Sight Fortnightly · Unsubscribe any time · No list sharing

General information about prudential obligations, not legal advice. Verify against the prudential standard, APRA guidance and your own advisers. Sources: APRA, Prudential Standard CPS 230 Operational Risk Management and CPG 230, as amended 30 April 2026 and commenced 1 July 2026. APRA, Letter to industry on artificial intelligence, 30 April 2026. ASIC, Letter to industry on cyber resilience and frontier AI (26-092MR), 8 May 2026.