Australia’s prudential regulator has delivered a clear warning: artificial intelligence is being adopted faster than the governance, assurance and resilience practices needed to control it.
In a letter to banks, insurers and superannuation trustees, the Australian Prudential Regulation Authority (APRA) called for a step-change in the management of AI-related risk. Its review of selected large financial institutions found a gap between boards’ enthusiasm for AI’s benefits and their ability to challenge how it is being implemented.
APRA does not regulate New Zealand directors. Its findings are still relevant wherever AI is moving from informal experimentation into business processes, customer interactions and important decisions.
Board literacy must go beyond the vendor presentation
APRA found that many boards were still developing the technical literacy needed to oversee AI effectively. It also saw overreliance on vendor presentations and management summaries, without enough scrutiny of unpredictable model behaviour or the possible effect of failure on critical operations.
Directors do not need to become data scientists. They do need enough understanding to ask informed questions and recognise an incomplete answer. That includes knowing where AI is used, what information it receives, what decisions or actions it influences, how its performance is checked and what happens when it is unavailable or wrong.
AI may also arrive as a feature inside software the organisation already uses, rather than as a clearly labelled project. A board cannot oversee risks the organisation has not identified.
Risk appetite needs to become operational
APRA expects an organisation’s AI strategy to be consistent with its risk appetite and tolerance settings. That requires more than a broad statement that AI will be used “responsibly”.
Management needs practical boundaries. Which uses are permitted, restricted or prohibited? When is a formal assessment required? What level of human review is expected for customer-facing outputs, professional advice or automated decisions? What information must never be entered into an external service?
Board reporting should show whether those boundaries are working. It may cover higher-risk uses, exceptions, incidents, material vendor changes, unresolved control gaps and testing results. Clear escalation triggers allow unexpected behaviour to prompt action before it becomes a larger operational, privacy or conduct issue.
Vendor assurance is not board assurance
APRA paid particular attention to third-party and concentration risk. Some institutions depended heavily on one provider for several AI uses, while contingency planning and exit arrangements remained weak. Contracts did not always deal adequately with audit rights, model changes, incident notification or changes to data handling.
The same concern applies to New Zealand professional services, where AI is increasingly built into document platforms, productivity suites and specialist software. Boards should expect management to know which providers support material uses, what confidential or personal information is involved, how important changes will be detected and whether a credible alternative exists. A provider’s security statement is not independent assurance that the organisation’s particular use is safe and appropriate.
AI also introduces cyber vulnerabilities, including sensitive data leakage and prompt injection, that traditional IT security testing may not detect.
One-off approval is no longer enough
Traditional project approval and annual assurance can miss the way AI systems change. Performance may shift when a provider updates a model, data changes, users adopt new practices or the system connects to additional tools. APRA found that continuous validation and monitoring were uncommon, while risk and internal audit teams often lacked the capability to assess AI independently.
The answer is not to apply the same level of control to every use. Monitoring should be proportionate to the potential effect of failure. A drafting assistant used with public information does not require the same oversight as a system influencing lending, insurance, employment, client advice or access to sensitive data.
For material uses, the board should know who owns performance, how failures are identified, whether controls are independently tested and when a system will be paused or withdrawn.
What New Zealand directors should ask now
The Financial Markets Authority has said that good governance is fundamental to safe AI adoption and that boards and senior management remain accountable for their organisations’ activities. The Reserve Bank has highlighted the possibility that AI could amplify risks in the financial system. New Zealand’s Institute of Directors makes the same central point: AI may support judgement, but it does not replace directors’ accountability.
A useful board discussion can begin with six questions:
- Where is AI being used across the organisation, including through features embedded in existing software and unapproved staff use?
- Which uses affect clients, important decisions, critical operations, confidential information or personal information?
- What risk appetite, approval thresholds and human oversight requirements apply?
- Which third- and fourth-party providers are involved, and where are we exposed to concentration risk?
- How are performance, model changes, incidents and control failures monitored after deployment?
- What tested fallback exists if a material AI service becomes unavailable, unsafe or unreliable?
Our take
APRA’s letter is not a new rule for New Zealand companies, but it is a useful signal of the oversight boards can increasingly expect to demonstrate. AI can no longer sit only with technology teams or enthusiastic business users.
For New Zealand professional firms, the immediate task is to make AI use visible, set practical boundaries and give directors reporting that supports informed challenge. This does not require a large bureaucracy. It requires clear ownership, proportionate controls and evidence that the organisation understands both the opportunities and the consequences of failure.
How We Can Help
KiwiGen AI helps professional firms establish practical governance before AI use outpaces oversight. We can help develop an AI inventory, policy and risk framework; define approval and reporting requirements; assess privacy, security and supplier risks; and provide board and staff training.
The aim is not to slow useful adoption. It is to give boards confidence that AI is being used deliberately, within the organisation’s risk appetite and with controls that can be explained and tested.
Sources
- APRA, Letter to Industry on Artificial Intelligence
- Financial Markets Authority, Good governance key to adopting AI while managing risks
- Reserve Bank of New Zealand, Financial Stability Report May 2026
- Institute of Directors New Zealand, AI in the boardroom: A guide for directors

