Prudential requirement
APRA standards
Direct obligations are treated as requirements only where the cited standard applies. CPS 230 informs questions about critical operations, service providers, resilience and continuity.
Open the tool
Our AI governance method
AI governance becomes useful when it changes a decision, a control or an operating practice. We start with the use case and its consequences, open only the questions that matter, and separate what has been reported from what has been proven.
Rules first. AI where justified. Controls outside the model. Evidence over assurances.
Deterministic by design
The scan does not ask an AI model to interpret, score or rewrite a response. Its question routing, findings, combined patterns and priorities are fixed in the published rule pack used by the browser.
Describe one implementation: who it affects, what it can access or change, where people intervene and whether it supports a critical operation.
Context determines which groups apply, including accuracy, fairness, model change, security, authority, oversight, fallback and third parties.
Fixed patterns identify when separate answers create a more consequential problem together and state the first practical move.
The report lists evidence prompts for every applicable answer. A deeper review examines whether documents, tests and operating records support the claim.
How sources are used
The scan maps questions and findings to their basis. It does not present contextual guidance as an APRA requirement.
Prudential requirement
Direct obligations are treated as requirements only where the cited standard applies. CPS 230 informs questions about critical operations, service providers, resilience and continuity.
Regulatory direction
Letters and roundtable material indicate supervisory focus and emerging expectations. They are not converted into new legal obligations.
Governance context
Director and actuarial publications broaden the practical control set, especially around accountability, fairness, model risk and the questions boards should ask.
Technical context
Agentic-AI guidance informs practical controls for privileges, identities, tools, untrusted inputs, monitoring, stop mechanisms and unintended objectives.
What the scan does not do
Potential impact is separated from the self-reported control position. Control effectiveness cannot be established without evidence and testing.
Applicability depends on the organisation, system and facts. The scan is not legal advice, audit, certification or a substitute for current source material.
Avowal does not receive answers through the tool. No documents, logs, model behaviour, fallback arrangements or supplier claims are independently verified.
What an evidence review adds
A focused review can trace the most consequential claims to current evidence: decision rights, test results, exception records, change approvals, access controls, logs, incident playbooks, fallback exercises and supplier commitments.
The objective is not a longer governance document. It is a short list of material weaknesses, evidence that supports or contradicts the reported position, and practical actions with owners.
Discuss a deeper reviewCurrent source links
The scan is maintained against published direction, but source material can change.