13 September 2026
What APRA's AI Letter Actually Means for the Executive Who Signs the Accountability Statement
TL;DR: APRA's 30 April 2026 letter moved AI governance inside the Financial Accountability Regime. The named executive on the accountability register now carries personal exposure, including disqualification and civil penalty, for AI systems they may not know are running. IOSCO, FCA, FSB, ASIC, and MAS reached the same position inside ten weeks. The informal phase is ending. * APRA's April letter places AI governance inside FAR, attaching personal liability to named executives, not to the comp

TL;DR: APRA's 30 April 2026 letter moved AI governance inside the Financial Accountability Regime. The named executive on the accountability register now carries personal exposure, including disqualification and civil penalty, for AI systems they may not know are running. IOSCO, FCA, FSB, ASIC, and MAS reached the same position inside ten weeks. The informal phase is ending.
- APRA's April letter places AI governance inside FAR, attaching personal liability to named executives, not to the compliance function.
- The supervisory finding is specific: boards lack technical literacy to challenge AI risk, and few institutions have operationalised governance in practice.
- A policy, committee, or framework is not evidence. A supervisor will ask what a specific AI system did on a specific day, on whose authority, subject to what controls.
- Vendor-supplied agentic capabilities, including those inside Microsoft Copilot, Salesforce Einstein, SimCorp, and Bloomberg, fall inside FAR scope. They are not excluded because they arrived as a product update.
- Six supervisors, APRA, ASIC, IOSCO, FCA, FSB, and MAS, reached the same governance position inside one quarter. Firms acting now are in the informal phase. Firms acting later may not be.
Four months ago, APRA sent a letter to every regulated financial institution in Australia. Most filed it. A small number read it carefully, understood what it said, and started to change how they operate. Those two groups will have different conversations with their regulator inside the next 12 months.
The letter, dated 30 April 2026, does something specific. It moves AI governance from an enterprise risk category into the Financial Accountability Regime. That is a structural shift, and the audience for that shift is not the compliance function. It is the accountable person whose name sits on the register next to the words "technology," "operations," "risk," or any prescribed responsibility that touches an AI system.
FAR is a personal accountability regime. It attaches to a named human. It follows that human after they leave the role. The consequences available under it include disqualification, remuneration adjustment, and civil penalty. When APRA writes that it will pursue enforcement where entities fail to identify, manage or control AI risks, that pursuit runs through the accountability statement, not around it.
Eight days after APRA's letter, ASIC issued its own to Australian Financial Services Licensees (AFS licensees). The message coordinated with APRA's: existing obligations already cover AI use. Boards and executives who assume AI is subject to a lighter standard because the technology is new have misread the environment. Regulators do not see a new risk category needing new rules. They see existing rules applying to a class of system that regulated firms have not yet learned to govern.

The specific finding that changes the exposure
Two sentences from APRA's April review deserve to be read out loud in every executive committee this quarter.
The first: many boards have "strong interest for AI's potential benefits but lack the technical literacy required to provide effective challenge to management on AI related risks."
The second: "few have operationalised governance in practice."
These are supervisory findings. They describe a state APRA has formally identified and, in effect, given the industry a window to correct. The window is not open indefinitely. The regulator has explicitly linked these findings to the accountability regime, which means the next supervisory visit does not need to find new evidence. It only needs to confirm the finding has not been closed.
If the board cannot effectively challenge AI risk, the accountability question is not resolved by board training alone. It is resolved by making the evidence base for AI risk visible and challengeable. That work sits with the executive whose accountability statement includes the systems doing it.
Key point: APRA's finding is precise. It is not about the absence of governance. It is about governance that exists on paper and does not operate in practice. Those are different problems with different fixes.
Why policy is not evidence
The instinct in most institutions is to respond to a supervisory finding with a policy revision. A new AI policy is drafted. A committee is stood up. A framework is bought or built. A training program is launched. A dashboard appears in the board pack.
None of that is evidence.
None of that is evidence.
A policy states an intention. A committee states a governance structure. A framework states a taxonomy. A dashboard states a summary. What none of them state is what a specific AI system did on a specific day, at a specific time, on whose authority, with what human involvement, subject to what checks that could have stopped it.
That record is what a supervisor will ask for. The accountability regime demands it. If a decision produced a harm, the question is whether the control operated, not whether a policy existed. That question has a factual answer, or it does not.
AI governance in many regulated firms cannot produce a factual answer, because the control was not built to produce one. It was built to satisfy an audit at the end of the month, not to record what happened at the moment the AI acted.
Key point: A policy is a statement of intent. Evidence is a record of what occurred. A supervisor will ask for the second and accept nothing else as a substitute for it.
Verifiable, not assertable
The direction that matters is the shift from assertion to verifiability. It runs through every serious governance paper published in the last twelve months, and it is the axis on which the coming enforcement environment will turn.
Verifiability means a control produces evidence at the point of action. The evidence is independent of the system that produced it. The evidence chain is tamper-evident. The evidence can be reconstructed months later, presented to a supervisor or a court, and stand up to challenge.

Verifiability is expensive to build and cheap to rely on. Assertion is the opposite: cheap to state, expensive to defend when it turns out to be untrue.
The firms that will hold up under FAR have already made the switch. Their control statements read: "we have a system that produced this record for every instance of Y in the period, and here it is."
Controls that cannot survive that translation point to an architecture problem, not a policy problem.
Key point: Verifiability is not a higher standard layered on top of existing governance. It is a different structure entirely, one built to produce evidence at the point of action rather than to reconstruct it afterward.
Three things worth doing before the next supervisory visit
Map the accountability chain against actual AI usage.
Take the accountability register. Take an inventory of every AI system in production, in pilot, and in vendor-supplied form (agentic capabilities buried inside a SaaS product often surface as features that do not appear on any inventory). For each system, name the accountable person and the specific accountability statement clauses that apply.
If a system exists that cannot be tied cleanly to an accountable person, that is the exposure. The executive whose statement covers it does not know they are on the hook.
Test the evidence, not the policy.
For each mapped system, ask a specific question. "If APRA asked us to produce a complete record of what this system did last Tuesday, on whose authority, with what human review, and what would have stopped it if it had done something wrong, could we produce that record in the room?"
The answer is yes or no. If the answer is no, the firm has an evidence architecture problem. That is the thing to fix.
Close the board challenge loop.
Boards can only challenge what they can see. If board packs contain summary dashboards, the board will ask summary questions. If they contain drill-down evidence of how specific controls operate on specific systems, the board will ask questions that actually test the control environment.
The change is not more content in the board pack. It is different content. The executive responsible for briefing the board carries the same FAR exposure as the board itself. Building the briefing that lets the board effectively challenge is a defence for the executive, not a favour to the board.
Key point: The accountability chain runs through the executive who briefs the board, not around them. If the board cannot challenge AI risk effectively, the accountability question lands one level down.
Where this is heading
APRA has been consistent about direction. ASIC has aligned. Overseas supervisors reached the same position inside a single quarter: IOSCO's Supervisory Toolkit for AI Use in Capital Markets (FR/02/2026) on 25 May, the FSB's consultation on responsible AI adoption in June, the FCA's Mills Review on 7 July, MAS publishing its Safeguards for Agentic Finance at Runtime (SAFR) framework also in July. This is a global posture shift being executed through local supervisory action, not a coordinated announcement.
The common position across all of it: governance is expected to operate at the point of the decision, not after it. Evidence is expected to be produced by the system, not reconstructed from it. Accountability is expected to be personal, verifiable, and defensible under adversarial conditions.
Firms that treat this as a compliance program will be surprised by their first enforcement action. Firms that treat it as an operating model shift will find that most of the work satisfying the regulator also improves the underlying operation. Better evidence produces better decisions, and better decisions produce outcomes the accountable person can defend on their own terms.
The argument for doing this is operational, not regulatory.
Key point: Six supervisors, working through separate processes, reached the same governance position inside one quarter. That is convergence, not coordination. The implication for timing is the same either way.
What "operationalised" actually means
APRA's finding that "few have operationalised governance in practice" is precise language. It does not say governance is absent. It says governance has not been made operational. The institutions that received this finding almost certainly have governance documents: policies, risk committees, control frameworks, board reporting structures. The finding is about the distance between their existence and their function.
Operationalised governance has three characteristics that paper governance does not.

The first is pre-action controls. A pre-action control runs before the AI system acts, not after. It confirms that the conditions for action are met: that the system is operating within its approved parameters, that human review has occurred where required, that the decision is within the authority of the account the system is operating under. If a control only fires when something goes wrong, it is a detection mechanism, not a control.
The second is contemporaneous recording. The record of what the system did is created at the moment it does it. Not reconstructed from logs afterward. Not summarised in a monthly report. Created and stored at the point of action, in a form that is independent of the system that produced it. This is the difference between a control that produces evidence and a system that can be asked to produce evidence later.
The third is independence. The evidence produced by the control is not held by the system being controlled. It does not sit in the same database. It cannot be altered by the same administrative access. Independence is what makes evidence supervisory-grade rather than internally useful. A supervisor is not interested in evidence that the regulated entity could have changed after the fact. An entity that cannot demonstrate independence has assertion, not evidence.
AI governance frameworks often do not produce all three. Many produce none. The instinct is to focus on the policy layer because that is where most governance expertise lives. The evidence layer requires architectural decisions that sit inside the technology function, and the technology function is often not fluent in what the regulatory framework actually demands.
Key point: Pre-action controls, contemporaneous recording, and independence are not features that can be added to an existing governance framework. They require architectural decisions made before a system goes into production.
The agentic problem is not theoretical
The AI systems that sit most clearly outside current governance structures are often not the large language models a firm deployed deliberately. They are the agentic capabilities inside platforms the firm already uses.
A SaaS vendor ships an update. The update includes an AI agent that can draft communications, summarise data, or initiate workflow steps on behalf of a user. The capability is described in release notes as a feature enhancement. It appears in the product as a button or a toggle. The firm's AI risk committee saw no paper on it. The AI system inventory did not review it. The accountable executive whose statement covers the relevant operational domain did not know it existed.
This is the current state in institutions using modern productivity suites, customer relationship management platforms, and portfolio management systems. Microsoft Copilot, Salesforce Einstein, SimCorp's AI capabilities, Bloomberg's AI-assisted functions: all of these have shipped or are shipping agentic capabilities that operate inside regulated environments, touching regulated data, producing regulated outputs. They appear as features. They function as AI systems subject to CPS 230 operational risk requirements.

The boundary problem this creates is not a technology problem. The firm's AI governance applies to systems the firm deployed. Vendor-originated capability arriving inside an existing contract sits in a classification grey area that most frameworks have not resolved. APRA's guidance does not distinguish between proprietary and vendor AI. The accountability statement does not distinguish. The regime attaches to the output and the decision, not to the source of the system that produced them.
The AI system inventory must extend to vendor capabilities, not just internal deployments. This requires a different review process: a clause-level review of vendor contracts and data processing agreements, a product update monitoring protocol, and a defined process for the AI risk function to assess and classify each new capability before it reaches production use. Without that, the inventory is systematically incomplete, and an incomplete inventory produces an accountability statement that cannot be defended.
Key point: FAR scope does not follow deployment origin. It follows the output and the decision. An AI capability that arrived as a vendor feature update is inside the regime from the moment it acts on regulated data.
What tamper-evident logging means in plain language
Evidence architecture makes more immediate sense to an engineer than to an executive. Here is the version that matters for the accountability statement.
A log is a record of what happened. AI systems produce logs. Those logs are held in the same environment as the AI system, managed by the same administrative access, retained under the same data lifecycle policies as operational data. That structure means the log is useful for internal review and almost useless for regulatory defence.
A tamper-evident log is different in three ways. The record is created and immediately replicated to a write-once location the AI system cannot modify. Each record is cryptographically linked to the previous record, so any alteration of a prior record is mathematically detectable. The integrity of the chain can be verified by a third party without access to the system that produced it.

The outcome is a record a supervisor or court can accept as an accurate account of what the system did, because any post-hoc alteration would be visible. That is what makes evidence supervisory-grade.
The executive does not need to build this. The executive needs to know whether it exists, because the accountability statement is a personal instrument. If the AI systems the executive is accountable for do not produce this class of evidence, the executive carries personal exposure that no policy document closes. The question to ask the technology function is not "do we log AI activity?" It is "is our AI logging tamper-evident and independently verifiable?" Those are different questions with different answers in almost every institution that has not specifically designed for this.
The threshold is not perfection. The threshold is whether the evidence produced would survive adversarial challenge. If it would not, the exposure is known and the executive has elected to carry it. That is a different category of risk from the exposure that is simply unknown.
Key point: The question is not whether the firm logs AI activity. It is whether that log would survive challenge from a supervisor, a court, or an opposing counsel. Those are different bars and require different architectures.
The international signal and what it says about timing
Six supervisors reached the same conclusion inside a single quarter. IOSCO published its Supervisory Toolkit for AI Use in Capital Markets (FR/02/2026) on 25 May. ASIC had written to AFS licensees eight days after APRA, in early May. By the time MAS published SAFR in July, the sequence had been running for ten weeks. Ten weeks is not a coordinated wave. It is six bodies, working through separate processes, arriving at the same position independently. The informal phase is ending. The formal phase, characterised by enforcement, licensing conditions, and public findings, is beginning.

The FCA's Mills Review, published on 7 July 2026, drew a direct line between AI governance failures and consumer harm. It used the same language APRA used: boards lack technical literacy, governance has not been operationalised, assertion is not evidence. The FSB's consultation on responsible AI adoption, published in June 2026, applied that framing to systemically important institutions. MAS published SAFR in July 2026, setting out runtime governance requirements for AI systems in financial services.
MAS is relevant here not because Australian firms are subject to Singaporean regulation, but because MAS specifications become the technical reference point that global standard-setters use. SAFR addresses what adequate runtime controls look like in practice: independence of evidence stores, contemporaneous recording at the point of action, and verifiability by a third party. That vocabulary is now in the global supervisory register. APRA supervisors reviewing Australian firms will have read it. They will use it, informally at first and formally later, as the benchmark against which they assess adequacy.
Firms that move in the next two quarters are moving during the informal phase, where the consequence of a control gap is a finding and a remediation requirement. Firms that move later may find themselves moving during the formal phase, where the same control gap carries enforcement weight. The difference in outcome is significant. The difference in effort required is not. The work is the same. The timing changes what the work costs.
The supervisory calendar is readable. The question is whether the institution has read it.
Key point: Ten weeks across six supervisors, each working independently, is convergence. The informal phase is ending. The cost of the same remediation work is rising.
The executive who should read this
FAR accountability statements vary by institution and by role. Several prescribed responsibility descriptions consistently appear next to the executives carrying the greatest exposure in the current AI governance environment.
"Responsible for the adoption and use of technology." If an AI system is technology, this clause applies to it. The executive holding this responsibility is accountable not just for the decision to deploy but for the adequacy of the governance structure around the deployment. If that governance structure cannot produce supervisory-grade evidence, the accountability statement cannot be defended.
"Responsible for the management of operational risk." AI systems are operational systems. They fail. They produce errors. They drift from approved parameters over time. The operational risk framework is supposed to identify, assess, and control those failures. If it has not been extended to cover AI systems, the executive responsible for operational risk has a formally identified control gap in their framework.
"Responsible for compliance with laws and regulations." This clause catches everything else. Every AI system operating in a regulated environment is subject to existing regulatory obligations. The AFS licensee obligations ASIC described in May 2026 apply to outputs produced by AI as clearly as they apply to outputs produced by humans. If an AI system produces a non-compliant output and the compliance framework had no mechanism to detect or prevent it, the accountable executive is in the position of having a compliance responsibility they cannot demonstrate they met.

The point is to name the exposure with precision, because the executive who does not know they carry it cannot take action to address it. The FAR register is the place to start. Read the statement next to the AI system inventory. Ask whether the statement can currently be defended for every system on the inventory.
Key point: Three FAR prescribed responsibility clauses, covering technology adoption, operational risk management, and compliance, collectively cover the AI governance exposure. Executives holding any of them should read the April and May letters next to their own accountability statement.
The next 90 days
Read the April letter and the May letter side by side. Read them next to your accountability statement.
Then walk into your next executive committee with three artefacts: an inventory of AI systems with named accountable persons, a short list of systems where the evidence chain does not currently support the accountability statement, and a single-page plan to close the highest-risk item within 90 days.
That is what running the risk looks like when the regime attaches to your name.
The letter has been sitting in a folder in most institutions since April. The firms where somebody read it in the first person, and understood that the "you" in it was them, are already ahead. The rest have a window that is closing.
Frequently asked questions
Does APRA's April 2026 letter create new obligations, or does it apply existing ones?
It applies existing obligations. APRA's position is that the Financial Accountability Regime and CPS 230 already cover AI systems. The letter puts the industry on formal notice that APRA has reviewed current practice, identified specific governance failures, and will pursue enforcement through the accountability regime, not through new AI-specific rules.
Which executives carry FAR exposure for AI governance?
Any executive whose accountability statement includes a prescribed responsibility touching technology adoption, operational risk management, or regulatory compliance carries direct exposure. FAR attaches to named individuals. It follows them after they leave the role. The relevant clauses are identified in the accountability register, not in an AI-specific document.
Do vendor-supplied AI capabilities, such as those inside Microsoft Copilot or SimCorp, fall inside FAR scope?
Yes. APRA's guidance does not distinguish between proprietary and vendor-supplied AI. The accountability regime attaches to the output and the decision, not to the origin of the system that produced them. A capability that arrived as a product update is inside the regime from the moment it acts on regulated data or produces a regulated output.
What does APRA mean by "operationalised governance"?
Governance that operates at the point of the AI system's action, not governance that is documented in a policy. Operationalised governance has three characteristics: pre-action controls that run before the system acts, contemporaneous recording of what the system did and on whose authority, and independence of the evidence store from the system being controlled.
What is a tamper-evident log and why does it matter under FAR?
A tamper-evident log is a record where each entry is cryptographically linked to the previous one, replicated to a write-once location the AI system cannot modify, and verifiable by a third party without access to the originating system. It matters under FAR because it produces evidence a supervisor or court can accept as an accurate account of what the system did. A standard log, held in the same environment as the AI system, does not meet that bar.
How is IOSCO's Supervisory Toolkit for AI Use in Capital Markets relevant to Australian firms?
IOSCO published FR/02/2026 on 25 May 2026. Australian firms are not directly subject to IOSCO standards, but IOSCO guidance shapes the positions of member regulators including ASIC. The toolkit's language on governance and evidence requirements tracks closely with APRA's and ASIC's domestic communications.
What is the practical difference between the informal and formal supervisory phases?
In the informal phase, a supervisory finding typically results in a remediation requirement and a follow-up visit. In the formal phase, the same finding carries enforcement weight: civil penalties, licensing conditions, or disqualification proceedings. The work required to close a control gap is the same in both phases. The cost of carrying the gap is not.
What should an executive do in the next 90 days?
Read APRA's April letter and ASIC's May letter next to the relevant accountability statement. Produce an AI system inventory that includes vendor-supplied capabilities. Identify systems where the evidence chain does not support the accountability statement. Bring those three artefacts to the next executive committee with a plan to close the highest-risk item within 90 days.
Key takeaways
- APRA's 30 April 2026 letter moves AI governance inside the Financial Accountability Regime. Personal liability, including disqualification and civil penalty, attaches to the named executive on the accountability register, not to the compliance function.
- APRA's supervisory finding is specific: boards lack technical literacy to challenge AI risk, and few institutions have operationalised governance in practice. The next supervisory visit only needs to confirm the finding has not been closed.
- A policy, committee, or framework is not evidence. A supervisor will ask what a specific AI system did on a specific day, on whose authority, subject to what controls. That question has a factual answer or it does not.
- Vendor-supplied agentic capabilities, including those inside Microsoft Copilot, Salesforce Einstein, SimCorp, and Bloomberg, fall inside FAR scope from the moment they act on regulated data. The accountability statement does not exclude them because they arrived as a product update.
- Operationalised governance requires three things that paper governance does not: pre-action controls, contemporaneous recording, and independence of the evidence store from the system being controlled.
- Six supervisors, APRA, ASIC, IOSCO, FCA, FSB, and MAS, reached the same governance position inside ten weeks, each through separate processes. The informal phase is ending. Firms acting now face a finding and a remediation requirement. Firms acting later may face enforcement.
- The question to ask the technology function is not "do we log AI activity?" It is "is our AI logging tamper-evident and independently verifiable?" Those questions have different answers in almost every institution that has not specifically designed for this.
Get these as they’re published.
Long-form on AI governance in regulated firms — what the control gap actually is, what regulators are asking for, and what the evidence has to look like. Roughly monthly. No pitches.