Four frameworks already require regulated entities to evidence how material decisions are made, governed, and overseen. None of them were written for AI, but every one of them applies to it. This page summarises each, in plain language.
APRA's Prudential Practice Guide 234 sets out information security expectations for banks, insurers, and superannuation trustees. It's the framework regulators use to assess whether a regulated entity can identify, protect, detect, respond to, and recover from information security incidents.
Every AI model that influences a consumer outcome is an information asset. The inputs, outputs, and the decisions that follow are sensitive data. CPG 234 already expects you to log, monitor, and evidence integrity over assets like that, regardless of whether they came from a deterministic system or a probabilistic one.
Effective 1 July 2025, CPS 230 is APRA's modernised operational risk standard. It consolidates and replaces several earlier standards and explicitly raises the bar on how regulated entities manage critical operations, third parties, and business continuity.
CPS 230 doesn't mention models, but it absolutely covers them. Customer lending, claims triage, fraud holds, and AML decisioning are typically critical operations. The model is a material service provider in many implementations. Without an audit trail, the board cannot evidence that the risk is being managed within tolerance.
RG 271 sets ASIC's expectations for how financial services and credit providers handle complaints. It requires firms to acknowledge complaints quickly, investigate fairly, and provide written reasons for the decisions made.
When a consumer complains about an automated outcome (a declined loan, a held claim, a fraud flag), the regulated entity has to explain how the decision was made. "The model decided" is not an answer that meets RG 271's written reasons standard. Firms need to evidence what the system saw, what it produced, and what the human reviewer did with it.
RG 274 governs the Design and Distribution Obligations (DDO) regime. Issuers and distributors must define a target market for each product, distribute only to consumers in that market, and monitor outcomes to ensure the product remains likely to be consistent with consumer objectives.
AI-driven recommendation systems, eligibility models, and risk-segmentation engines are part of how products are distributed. Under RG 274, you have to evidence not just that distribution stayed within the target market, but how the system made each decision and what monitoring detected any drift.
Book a 45-minute working session. We'll walk you through how Proofmarc maps to your current AI footprint and where the auditability gaps are.
Request a working session →