Supervision
Quantum
Resilience

More frequent and deeper cyber and AI engagement

Transition plan expected by the end of 2026

Evidence, testing and service-provider concentration

APRA's 2026-27 Corporate Plan (the 2026–27 Plan) is notable not because it creates a new cyber or AI standard, but because it signals a change in supervisory posture. Cyber threats, frontier AI, quantum computing, common technology platforms and material service providers are presented as interconnected threats to operational resilience and, ultimately, financial stability.

The practical message is that implementation is no longer enough. APRA says entities should expect more frequent and deeper engagement on cyber and AI risks and should be readily able to demonstrate how those risks are being managed. Policies will matter, but so will evidence: board reporting, inventories, control testing, scenario exercises, remediation records, supplier maps, contracts and credible contingency arrangements.

The 2026–27 Plan also sits alongside a clear enforcement signal. APRA says it is prepared to increase supervisory intensity and take formal action where material risks are not addressed or an entity is not cooperative. Resilience should therefore be treated as a board and executive accountability issue, with a defensible record of decisions and follow-through.

APRA’s amendments to the prudential framework will be accompanied by changes to simplify certain requirements, reduce duplication and free up capacity for lending and investment. Boards should assess whether current processes can be simplified in anticipation of the reforms, while continuing to meet existing obligations until the changes take effect.

Cyber and AI are now one prudential resilience agenda

APRA identifies cyber and AI risks as intensifying, with frontier AI increasing the sophistication, speed and scale of threats. It also highlights the financial-system consequences of common dependencies: an outage or control failure at a widely used platform or service provider may affect multiple regulated entities and critical services at the same time.

For regulated entities, this brings CPS 234 information security, CPS 230 operational risk, board oversight, crisis management and supplier governance into a single supervisory conversation. A technically sound control environment that is not connected to critical operations, tolerance levels, business continuity and board accountability is unlikely to be enough.

AI governance must keep pace with adoption

The 2026–27 Plan builds on APRA's April 2026 industry letter, which called for a step-change in AI risk management. APRA's review found that AI adoption was moving faster than governance, assurance and operational resilience. It highlighted gaps in board literacy, AI inventories, lifecycle ownership, post-deployment monitoring, security testing, controls over AI agents and AI-generated code, and supplier transparency.

APRA is applying its existing principles-based prudential framework rather than waiting for a standalone AI rule. Its minimum expectations include an AI strategy aligned to risk appetite and resilience objectives; clear accountability; an inventory of tools and use cases; human involvement in high-risk decisions; continuous and proportionate monitoring; credible fallback where AI supports critical operations; and visibility over third- and fourth-party dependencies.

What boards should be asking

  • Which AI use cases support or could disrupt a critical operation?
  • Do we have enforceable controls over staff use, non-human identities, autonomous agents and AI-generated code?
  • Can management explain material model changes, performance issues, data handling and supplier dependencies?
  • Are second-line and internal audit capabilities sufficient to challenge probabilistic and agentic systems?
  • What is the fallback if a model, platform or provider becomes unavailable, unsafe or unacceptable?

Quantum readiness is a 2026 governance issue

APRA will increase its focus on quantum computing risks and expects entities to make timely progress on post-quantum cryptography, prioritising their most critical information assets and operations. The  ASD milestones are concrete: a refined transition plan by the end of 2026, commencement of transition for critical systems and data by the end of 2028, and completion by the end of 2030.

A credible plan will require more than a cyber policy. Organisations need governance, a cryptographic dependency inventory, data-sensitivity and retention analysis, prioritisation, vendor engagement, procurement requirements, budget and change sequencing. Long-lived sensitive data also raises the risk of ‘harvest now, decrypt later’ attacks, which means deferring action until quantum computing is commercially available would be too late.

CPS 230 is moving from implementation to demonstration

With CPS 230 operating since July 2025 and an updated version in force from July 2026, APRA is now focusing on implementation quality. The 2026–27 Plan foreshadows prudential and thematic reviews across industries and specifically identifies operational and technology risk management at general insurers and specialist payment providers as a 2026-27 focus.

APRA is also increasing its focus on business continuity planning. Entities are expected to test whether they can maintain critical operations through a range of severe but plausible disruptions, including cyber and frontier-AI scenarios. Exercises should test decision-making and dependencies, not merely confirm that a written plan exists.

Material service providers and concentration risk

The 2026–27 Plan elevates common technology platforms and material service providers from entity-level outsourcing issues to system-level concentration risks. APRA intends to formalise data collection on material service providers and strengthen oversight of common dependencies. It is also continuing work with other regulators and industry on contingency arrangements for significant disruptions to payments availability.

This increases the importance of end-to-end dependency mapping, fourth-party visibility, tested substitution and exit strategies, and contracts that deal with auditability, incident notification, material changes, data handling, resilience, cooperation and transition. Contract compliance is only one part of the task: the entity must be able to show that the operating model is credible in practice.

APRA is becoming a more data-driven supervisor

APRA itself plans to use AI, supervisory dashboards and advanced analytics to identify risks earlier and intervene more quickly. In practice, entities should expect sharper questions about the consistency of their data, the ageing of issues, the speed of remediation and the evidence supporting management and board assurances.

Regulatory burden will be reduced to offset strengthened prudential requirements

APRA aims to simplify certain requirements and reduce regulatory burden to offset the impact of new requirements to strengthen governance practices of regulated entities. APRA is currently consulting on major reforms proposed to Prudential Standard CPS 510 Governance to reinforce expectations of boards and senior leaders while reducing duplication and providing greater flexibility. In parallel, the Australian Securities and Investments Commission (ASIC) and APRA are jointly consulting on proposed changes to the FAR to reduce administrative burden while continuing to maintain strong accountability standards. APRA expects both of the planned changes to commence early 2028. See our article [INSERT APRA’s 2026–27 Corporate Plan: sharper execution, with FAR and governance reforms in view LINK] for more detail on these reforms.

Where the emphasis falls

Sector-specific implications


SECTOR

APRA SIGNAL

PRACTICAL PRIORITIES




Banking

Digital banking, payments availability, common platforms, AI-enabled threats and system interconnections.

Test digital-channel and payment disruption; map cloud, identity and other common dependencies; govern AI in lending, fraud, customer service and software engineering; approve a quantum transition plan.

Insurance

General insurers are a stated thematic focus; claims processing is a critical operation. APRA is building on work with private health insurers.

Validate claims continuity, outsourced claims and core-platform resilience; govern AI used in underwriting and claims; test catastrophe-plus-cyber scenarios; remediate supplier contracts and concentration.

Superannuation

APRA is building on recent operational and technology risk work with trustees; fund administration and investment management are critical operations. Valuation governance practices and outcomes for members in the retirement phase are in focus.

Map administrator, custodian, platform and cloud dependencies; test member-service and transaction continuity; govern AI and member data; document trustee oversight and remediation.

Payments

Specialist payment providers are a thematic focus; APRA is supporting payment-availability contingency planning and preparing for a large stored-value facility regime.

Build prudential-grade resilience into payment, wallet, ledger and key-management services; map technology concentration; run outage and cyber exercises; prepare for an evolving APRA/ASIC perimeter.

Actions for regulated entities

A practical 90-day response

  1. Board and accountability. Provide a targeted board briefing; confirm accountabilities for cyber, AI, operational resilience, suppliers and quantum; agree what evidence the board expects to see.
  2. Supervisory evidence pack. Assemble the current-state evidence APRA is likely to request: risk appetite, inventories, dashboards, control testing, scenario results, remediation decisions, material-service-provider records and contracts.
  3. AI inventory and risk tiering. Identify approved and embedded AI, including AI within software and developer tools; classify use cases by criticality and customer impact; close gaps in lifecycle governance, security and assurance.
  4. Concentration and contract review. Map third- and fourth-party dependencies across critical operations; test substitution and exit assumptions; prioritise contractual remediation and management controls.
  5. Quantum transition plan. Establish governance, scope cryptographic dependencies, prioritise long-lived sensitive data and critical systems, engage vendors and obtain board approval before the end of 2026.
  6. Severe-but-plausible exercise. Run a cross-functional exercise covering a cyber or AI-enabled disruption, a material-provider failure and overlapping regulatory notifications, customer impacts and recovery decisions.
  7. Incident readiness. Refresh notification matrices, decision protocols, forensic and communications arrangements, and legal engagement terms; consider a standing cyber and operational incident response retainer.
  8. FAR consultation. Engage with the forthcoming FAR consultation and provide feedback on the proposed changes.
  9. Start planning. Assess the new requirements and opportunities introduced by the proposed reforms; commence implementation planning now.

How our team can help

  • APRA cyber, AI and operational resilience readiness reviews, including board papers, evidence packs and prioritised remediation plans.
  • AI governance and assurance frameworks covering inventory, lifecycle controls, risk appetite, privacy, security, supplier risk and accountable-person oversight.
  • Post-quantum governance and transition planning, delivered with client security teams or specialist technical advisers where cryptographic discovery is required.
  • CPS 230 material-service-provider mapping, contracting, fourth-party risk, substitution and exit arrangements.
  • Severe-but-plausible scenario exercises and board or executive tabletops, including regulator, notification, communications and customer-response decisions.
  • 24/7 cyber and operational incident response retainers, with legal-led coordination of technical advisers and support for regulatory engagement and post-incident remediation.
  • Governance and FAR framework uplifts and regulatory change implementation for governance and FAR reforms.
  • Large-scale regulatory change implementation programs across banking, insurance and superannuation.