Regulatory Landscape

The Australian rules that make
AI decision auditability non-negotiable.

Four frameworks already require regulated entities to evidence how material decisions are made, governed, and overseen. None of them were written for AI, but every one of them applies to it. This page summarises each, in plain language.

Information Security

APRA's Prudential Practice Guide 234 sets out information security expectations for banks, insurers, and superannuation trustees. It's the framework regulators use to assess whether a regulated entity can identify, protect, detect, respond to, and recover from information security incidents.

What it covers

Why it matters for AI

Every AI model that influences a consumer outcome is an information asset. The inputs, outputs, and the decisions that follow are sensitive data. CPG 234 already expects you to log, monitor, and evidence integrity over assets like that, regardless of whether they came from a deterministic system or a probabilistic one.

How Proofmarc helps
Proofmarc captures every consequential model interaction as a cryptographically immutable record, with full inputs, outputs, model version, confidence, and the human review status. That gives internal audit and APRA examiners the integrity evidence CPG 234 expects, without instrumenting it after the fact.

Operational Risk Management

Effective 1 July 2025, CPS 230 is APRA's modernised operational risk standard. It consolidates and replaces several earlier standards and explicitly raises the bar on how regulated entities manage critical operations, third parties, and business continuity.

Three obligations that bite for AI

Why this is the AI standard nobody calls the AI standard

CPS 230 doesn't mention models, but it absolutely covers them. Customer lending, claims triage, fraud holds, and AML decisioning are typically critical operations. The model is a material service provider in many implementations. Without an audit trail, the board cannot evidence that the risk is being managed within tolerance.

How Proofmarc helps
Proofmarc provides the operational evidence trail the standard expects: every material AI decision is recorded with the inputs, the model version (your tolerance metric), the confidence, the human review record, and the resolved outcome. Tolerance breaches surface in real time on the governance dashboard.

Internal Dispute Resolution

RG 271 sets ASIC's expectations for how financial services and credit providers handle complaints. It requires firms to acknowledge complaints quickly, investigate fairly, and provide written reasons for the decisions made.

The audit-trail problem

When a consumer complains about an automated outcome (a declined loan, a held claim, a fraud flag), the regulated entity has to explain how the decision was made. "The model decided" is not an answer that meets RG 271's written reasons standard. Firms need to evidence what the system saw, what it produced, and what the human reviewer did with it.

How Proofmarc helps
Every decision Proofmarc records is queryable by customer reference. Complaints teams can pull a single decision record showing model inputs, output, confidence, human review status, and the final outcome — ready to be summarised into a written-reasons letter within hours, not days.

Product Design and Distribution Obligations

RG 274 governs the Design and Distribution Obligations (DDO) regime. Issuers and distributors must define a target market for each product, distribute only to consumers in that market, and monitor outcomes to ensure the product remains likely to be consistent with consumer objectives.

Where AI sits in the DDO chain

AI-driven recommendation systems, eligibility models, and risk-segmentation engines are part of how products are distributed. Under RG 274, you have to evidence not just that distribution stayed within the target market, but how the system made each decision and what monitoring detected any drift.

How Proofmarc helps
Proofmarc's segmentation reports surface distribution drift in real time. If a credit decisioning model starts approving outside the defined target market, the board sees it the same week the data lands, not at the next quarterly review.

Map your stack against all four standards.

Book a 45-minute working session. We'll walk you through how Proofmarc maps to your current AI footprint and where the auditability gaps are.

Request a working session →