What did APRA's 30 April 2026 letter actually say?
APRA's letter to industry of 30 April 2026 set out the findings of a targeted supervisory review conducted in late 2025, concluding that governance, risk management, assurance and operational resilience practices are not keeping pace with the scale, speed and complexity of AI adoption.
APRA's core obligations under CPS 230 sit across three areas: identifying and managing operational risk, maintaining business continuity, and managing the risk of material service providers. For most regulated entities, the third area, material service providers, has been the most operationally demanding. The standard requires entities to identify the providers that materially support their critical operations, maintain a register, set tolerance levels, test continuity arrangements, and ensure exit and substitution strategies exist for each material provider.
The review was conducted across large banks, insurers and superannuation trustees. APRA's warning was direct: "Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, the regulator will take stronger supervisory action and, where appropriate, pursue enforcement."
APRA did not introduce a new AI-specific prudential standard. It did the opposite, it pointed to the existing standards, including CPS 230 and CPS 234, and made clear that they apply to AI just as firmly as they apply to any other technology supporting critical operations. The supervisory review surfaced specific gaps that map directly to CPS 230 obligations: concentration risk in single AI providers without tested exit and substitution strategies; contractual arrangements lacking provisions for audit rights, model update notifications and incident reporting; limited visibility into how AI components embedded in broader software platforms are trained, updated, or constrained; and identity and access management capabilities that have not adapted to non-human actors such as AI agents. Each of those is, in CPS 230 terms, either a material service provider failure or an operational resilience failure. Often both.
What does "material service provider" actually mean for AI?
CPS 230 defines a material service provider as one on which the entity relies to undertake a critical operation, or to perform a service that, if disrupted, would have a material impact on the entity's business operations or its ability to meet its prudential obligations. In an AI context, that is broader than a single vendor relationship.
The same critical operation may rely on a foundation model provider (such as the developer of the underlying large language model), a platform vendor (the cloud or AI platform that hosts the model and exposes it via API), a vendor providing the AI-enabled application (which sits on top of the platform and is what the business actually integrates with), and a fourth party that one of the above relies on, often invisibly.
Each of these can independently meet the threshold for material service provider designation, depending on what the AI capability is doing and how reliant the critical operation is on it. CPS 230 does not give entities the option to focus on one tier and ignore the others.
Practical implication: the CPS 230 register of material service providers needs to reflect the AI supply chain, not just the named vendor on the contract. Where the foundation model and the platform are different parties, both warrant assessment. Where the named vendor is opaque about its sub-providers, that opacity is itself a CPS 230 finding.
Where are most programs exposed?
Three patterns recur across the conversations we are having with risk and compliance leaders this quarter: an AI footprint wider than the procurement record, exit and substitution strategies that remain theoretical, and contractual rights that do not match the operational risk.
1. The AI footprint is wider than the procurement record. CPS 230 obliges entities to identify their material service providers, which requires knowing what AI is in use. Most programs we see are still building that inventory, particularly for AI capabilities embedded in productivity tools, customer-facing platforms, and existing software-as-a-service contracts where AI features have been switched on after the original procurement. APRA's letter explicitly named shadow AI as a governance failure, and was direct about why: entities are relying on policy direction or after-the-fact detective measures rather than enforceable technical restrictions or robust preventative controls.
2. Exit and substitution strategies are theoretical. CPS 230 paragraph 53 requires entities to have credible, tested exit strategies for material service providers. For traditional technology, this is well-understood. For AI providers, it is harder: the model-specific tuning, prompt libraries, evaluation harnesses, and integration patterns built up around a particular vendor are often non-trivial to port to an alternative, and the alternative may not behave the same way under the same prompts. APRA's observation that few entities had demonstrated robust contingency planning or tested exit and substitution strategies for critical AI providers is a direct CPS 230 finding waiting to happen.
3. Contractual rights do not match the operational risk. Under CPS 230, contracts with material service providers must enable the entity to comply with its obligations. In practice, that includes audit rights, incident notification provisions, change control, and information sufficient to monitor the provider's performance. AI vendor contracts, particularly the click-through commercial terms that came with AI features bolted onto existing platforms, frequently fall short. APRA called this out specifically: contractual arrangements often lack provisions for audit rights, model update notifications and incident reporting.
What is the bigger picture?
APRA's position on AI is now operational, not aspirational. The standards have not changed; what has changed is that APRA has been explicit about how the existing standards apply to AI, and that supervisory action and enforcement are on the table where they do not.
For entities still treating AI risk as a parallel program, the practical move is to fold it back into the operational risk and material service provider regimes that CPS 230 already established. The frameworks exist. The work is making the AI footprint visible inside them.
What we would do this quarter
- Map the AI inventory to CPS 230For each AI capability, identify the foundation model provider, platform, and integrating vendor. Determine which (if any) sit inside the material service provider perimeter. Update the register.
- Stress-test exit and substitutionFor each material AI provider, document what substitution would actually require, including prompt libraries, evaluations, integrations, and the time and cost involved. CPS 230 does not require seamless substitution; it requires credible substitution.
- Audit the contracts against CPS 230 paragraph 50Where audit rights, incident notification, change control, or information rights are missing, prioritise renegotiation. Several AI providers have updated their commercial terms in response to APRA's letter; the renegotiation window is open.
