Guide

AI governance under APRA's expectations

APRA wrote to regulated entities setting out its expectations for AI risk. What the letter asks for, what each expectation means in practice and how the work gets done.

What are APRA's expectations for AI governance?

In April 2026 APRA wrote to regulated entities setting out its expectations for managing AI-related risk. The letter is short and its expectations are concrete: an inventory of AI tooling and scenarios in use, ownership across the AI lifecycle through to decommissioning, human involvement in high-risk decisions, visibility over the AI supply chain and assessment through the whole lifecycle. None of it is a new prudential standard. All of it is work a regulated entity is expected to be able to show.

This guide walks through what each expectation means in practice for a bank, insurer or superannuation trustee, and how the work gets done without standing up a program office to do it.

The inventory expectation

APRA’s letter asks for an inventory of AI tooling and scenarios with ownership across the lifecycle, and it observes that systems are being deployed without one. The observation is the tell: supervisors are finding AI in use that risk functions cannot account for, from vendor decisioning platforms to models embedded in software the organisation already runs.

In practice the inventory is a register: every AI system and agent, each with a named owner, tracked through its lifecycle including decommissioning, with version history as systems change. The register is also the foundation the rest of the letter’s expectations build on, because ownership, assessment and supply-chain visibility all attach to register entries. An inventory assembled once for the letter and left to age fails the expectation the second a new system arrives, so the register has to be the working record, not a snapshot.

Aicura is that register. It registers every AI system and agent with an owner, tracks each through its lifecycle including decommissioning and keeps the version history, so the inventory expectation is met by the same record the rest of the governance work builds on.

Ownership across the lifecycle

The letter’s ownership expectation runs from adoption through operation to decommissioning. The practical test a supervisor applies is simple: for any system, who is accountable for it right now, and did that accountability survive the project team disbanding? Ownership recorded in a business case and never updated fails that test. Ownership carried on the register entry, updated as people move and prompted when a review falls due, passes it.

Human involvement in high-risk decisions

APRA expects humans involved in decisions that carry high risk. The governance work here is twofold: knowing which of your systems make or contribute to such decisions, and being able to show where the human sits in each. That is a property of the register and the assessments, not a policy statement. A register that records each system’s decision role, with assessments that describe the human oversight as it actually operates, gives the organisation something to point at when asked. In Aicura, the assessment carries that description, the accountable owner refines and locks it, and attestations capture the people standing behind each record cryptographically.

Visibility over the AI supply chain

Most AI risk in a regulated entity arrives through vendors: decisioning platforms, fraud models, features switched on inside software already deployed. The letter’s supply-chain expectation asks the entity to know what it depends on. In practice that is a model card per system: the single document describing what the system is, who provides it and what depends on it, kept current as versions change. Aicura generates a model card for each registered system and agent from the register data, supply chain included, so the answer to “what do you depend on” is a document that already exists.

Assessment through the whole lifecycle

The letter expects assessment before deployment and again as systems change, not a one-time gate. Every system in Aicura gets a risk and impact assessment before it goes live and again as it changes, generated from the register data and refined by the accountable owner, so the risks are understood while there is still time to act on them. The risks and suggested controls feed the risk processes the organisation already operates, and the work is done where it lands rather than in a parallel structure.

Where this meets your prudential processes

A regulated entity already runs a risk platform, a service provider register, critical operations mapping, incident management and board reporting. The AI-specific work does not replace any of it. The register, the assessments, the model cards and the evidence come from Aicura, and what they produce feeds the processes already in place, with risks and controls going into the risk platform, vendors into the provider register, incidents into incident management and evidence into board reporting. Your teams keep working where they always have.

Evidence for the supervisory conversation

The letter’s expectations all end in the same place, which is being able to show the work when a board, an auditor or a supervisor asks. Aicura’s Evidence Vault seals what the platform produces, so each record can be proven unchanged from the moment it was created, and attestations capture who stood behind it. When the question comes, an evidence pack assembles the relevant records, drawn from work done as it happened rather than pieced together for the occasion, and it can be verified without taking anyone’s word for it, Aicura’s included.

A note on this page

APRA’s letter is the primary source and this page is a practitioner’s reading of it, not legal or prudential advice. Aicura supports the governance work the letter describes, and it does not certify, audit or issue a compliance verdict, so APRA’s prudential standards remain matters between your organisation, its advisers and its supervisor. Read the letter itself on APRA’s website, and treat this page as a map of the work rather than an opinion on your obligations.


Related guides

When you need to show your work

Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.