APRA Compliance in 2026: What You Need to Prove


Risk & Compliance

APRA Compliance in 2026: What CPS 220, 230 and 234 Now Expect You to Prove

Three standards. No new rules. A much harder question to answer on short notice.

6 min read
For CROs, CISOs, Compliance and Internal Audit at APRA-regulated entities

APRA’s April 2026 letter to industry didn’t rewrite CPS 220, 230 or 234. It raised the evidentiary bar on all three: from “we have a framework” to “show us, right now.” This piece breaks down what each standard now expects you to prove, why most programs fail that test, and what a continuous evidence layer actually looks like in practice.

The Evidentiary Bar Has Moved

APRA’s supervisory deep-dive across large banks, insurers and superannuation trustees in late 2025 landed on one central finding: governance, risk management, assurance and operational resilience practices aren’t keeping pace with AI adoption. The letter that followed in April 2026 didn’t introduce a new AI standard. It applied three existing ones, CPS 220, 230 and 234, more specifically to AI, and raised what counts as acceptable proof under each.

That distinction matters. Most institutions can describe their AI governance approach in a meeting. Far fewer can produce a current inventory, a mapped dependency chain, or evidence that risk monitoring actually happened, on short notice, without a multi-week reconstruction exercise. APRA’s letter is a bet that this gap is now worth closing before, not after, an incident forces the question.

CPS 220, 230 and 234: What’s Expected Now

Each standard already covered AI in principle. Here’s what “prove it” means for each one in practice.

CPS 220: Operational Risk Management

A risk framework that names AI as a category is no longer the finish line. What’s expected now is demonstrable resilience across every operation AI actually touches, with named ownership and monitoring evidence behind it, not a policy sitting in a shared drive.

CPS 230: Operational Resilience

A resilience plan on file used to be sufficient. Now, entities need tested fallback processes for AI supporting critical operations, and credible exit or substitution arrangements wherever a single supplier is carrying concentration risk.

CPS 234: Information Security

Standard cyber controls no longer cover the threat model. APRA expects controls that account for what AI specifically changes about the attack surface: prompt injection, agentic manipulation, identity management for non-human actors, and shadow AI running outside approved frameworks.

The pattern across all three is consistent. APRA isn’t finding that the frameworks don’t exist. It’s finding that institutions can’t produce current, connected proof that they’re working. That’s an evidence problem, not a policy problem.

Why Most Programs Fail the Proof Test

Ask a risk or compliance team to produce a current AI inventory, and the honest answer is usually “give us two weeks.” That gap tends to come from three places, repeated across CRO, CISO and data teams alike.

Registers stop at the vendor name

A vendor field says who to call. It doesn’t say what trained the model, what data fed it, or what breaks if the vendor changes something upstream.

Evidence lives in spreadsheets

Ownership, lineage and control status get tracked separately, by separate teams, and rarely stay in sync once anything changes.

Assurance is point-in-time

An annual sign-off answers whether something was compliant on the day it was checked, not whether a model that “learns, adapts and degrades over time” still behaves the same way today.

There’s a simple test for where you stand: if a supervisor asked today for your AI inventory, its dependencies and its controls, would the answer be assembled, or retrieved?

We’ve turned APRA’s five questions into a free one-page checklist that names what a supervisor or internal auditor would expect to see under each one: not what to buy, what to look for.

Get the Evidence Checklist

Building a Continuous Evidence Layer

Closing this gap isn’t a documentation project. It’s a metadata orchestration problem: connecting the data, model, ownership and supplier signals that already exist across your estate into one structure that stays current as things change, rather than one rebuilt every time someone asks a question.

An automated data lineage tool applied to AI does exactly this: it traces the chain from source data through to model, application, business process and supplier dependency, and flags what’s affected the moment any part of that chain changes. That’s the practical difference between a register someone updates once a year and evidence that’s accurate by construction. It’s also the foundation of what’s increasingly called agentic data operations: governance and evidence generation built into how the AI estate runs day to day, not a parallel process someone owns for the next audit.

Analysts including Gartner have pointed to exactly this shift: mature data lineage tooling and metadata orchestration are becoming the practical backbone of AI governance programs, not an optional add-on to them.

What This Looks Like in Practice

Alex Solutions builds this evidence layer from metadata that’s already sitting across an institution’s data platforms, applications, model tooling and supplier systems, attaching ownership, criticality and policy context to each AI use case, and detecting change across the chain as it happens rather than at the next scheduled review.

This is the same lineage and data risk foundation Alex Solutions has applied with two of Australia’s Top 4 banks on APRA-aligned data risk and BCBS 239 work, extended to the AI estate. The judgement calls (risk appetite, escalation thresholds, board challenge) stay with the people accountable for them. What changes is whether the evidence behind those calls exists the moment someone asks for it, instead of the week before an audit.

Frequently Asked Questions

Did APRA introduce a new AI regulation in 2026?

No. APRA’s April 2026 Letter to Industry applies existing standards (CPS 220, 230 and 234) more specifically to AI. It signals stronger supervisory attention, not a new prudential standard.

What is data lineage, and why does APRA’s letter make it relevant?

Data lineage is the traceable path from a data source through every transformation, model and output it feeds. For AI, that same tracing shows what data trained a model, what depends on it downstream, and what’s affected when something changes, which is exactly the visibility APRA’s letter says is currently missing.

How do I know if my organisation’s AI governance is ready for an APRA review?

A practical test: could you produce a current AI inventory, a mapped supplier and data dependency chain, and evidence that risk monitoring actually happened, today, without a multi-week reconstruction exercise? If the honest answer is no, that gap is the starting point. Our one-page evidence checklist breaks that test down by each of APRA’s five questions, so you can see exactly where the gap sits.

What does “continuous assurance” mean for AI risk management?

It means the signals that matter (model changes, data changes, supplier updates, policy status) are tracked and connected so a change is detected and routed when it happens, rather than discovered at the next scheduled audit.

See what a current evidentiary view of your AI estate could look like.

Alex Solutions supports APRA-aligned AI governance and evidence-readiness. It does not replace privileged access management, model validation, legal review or supplier contracting.

Book an Intro Call