Scenario

Document and manage AI risk.

Per-system risk assessments your organisation can stand behind, kept current as the portfolio evolves.

Why structured risk records matter

For APRA-regulated entities, AI risk sits inside CPS 230 operational risk obligations and, where information is involved, CPS 234 information security obligations. For other organisations, the trigger is often a board-level AI governance directive, peer-group benchmarking, internal audit scope or a material AI deployment that has just gone live.

A spreadsheet someone updates once a year is not a risk record. A solid record captures classification, structured risk items, controls, residual position and the trail of how the assessment was reached. It updates when the system changes, and it surfaces missing controls rather than papering over them.

Catalogue the systems requiring assessment

The system list comes straight from your AI Register. When a new system enters the register, a notification surfaces suggesting it for assessment. Existing systems can be assessed in the order that matches your priorities, typically starting with the most material.


Once the first portfolio pass is complete, risk assessment is a continuous activity. New systems surface for assessment when they enter the register. Material changes prompt re-assessment notifications. You decide what to run. Periodic review keeps the residual position current. When the General Manager Risk, the internal auditor, the board or APRA wants detail on a system, the assessment is there, structured and signed off, with the trail of how the position was reached.


Frequently asked questions

What should an AI risk assessment record capture?

A solid record captures the system's classification, structured risk items, the controls in place and the residual position, along with the trail of how the assessment was reached. It updates when the system changes and surfaces missing controls rather than papering over them. A spreadsheet someone updates once a year is not a risk record.

Do APRA-regulated entities have specific AI risk obligations?

For APRA-regulated entities, AI risk sits inside CPS 230 operational risk obligations and, where information is involved, CPS 234 information security obligations. For other organisations the trigger is more often a board-level AI governance directive, internal audit scope or a material AI deployment going live. In both cases the record needs to stand up when the General Manager Risk, the internal auditor or the regulator asks for detail on a system.

How do risk assessments stay current as systems change?

New systems surface for assessment when they enter the AI Register, and material changes prompt re-assessment notifications. You decide what to run. Periodic review keeps the residual position current rather than frozen at the first portfolio pass.

Start the work in Aicura

Aicura supports this work from the register that anchors it through to the documents and records it produces, with your people reviewing and approving everything along the way. It is guidance, not certification, audit or legal advice.