Superannuation · AI
Guide

What a modern data platform needs before AI can serve super fund members

Most funds are early in AI adoption, and that is worth something. The estate is harder than most sectors because consolidation means a large fund's member records carry the administration history of every predecessor fund it absorbed, and a significant share of those records sit with an administrator rather than the trustee. This guide works backwards from three real member determinations to name what your serving layer, governance and data estate must guarantee before AI reaches a member, and sets out the six-step sequence to take to your board.

SuperannuationAIData platformPrudential obligationsMember dataSuccessor fund transfer
Inside the guide
  1. 01Why does your member data look the way it does?
  2. 02What happens when someone asks your data a question?
  3. 03What is a modern data platform, actually?
  4. 04Three determinations, traced backwards
  5. 05What does the prudential framework demand of the serving layer?
  6. 06How do you sequence this before the pilots land?

Full guide delivered to your inbox

What the guide covers

A sequence for what the fund is doing about AI, backed by named member determinations rather than a general commitment.

Covers why superannuation's data estate is harder than most sectors (a fourth consolidation clock on top of the usual three), what ASIC's 2026 platform trustee review already proved about the serving layer, three member determinations traced backwards through the six data platform capabilities, and how CPS 234, CPS 230, SPS 515 and the incoming Privacy Act transparency obligation already attach to different parts of the same problem.

What's inside

A reference architecture diagram, three worked determinations (servicing, transfer, fee accuracy) traced back to source, a prudential obligation map showing what attaches where, and a six-step sequencing checklist to take to the board.

Get the full guide
Delivered to your inbox. Name and email only.

No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.

55+
Funds have exited the industry through successor fund transfers in the last five years, each one adding an inherited estate to the receiving trustee.
Source: APRA, Delivering member outcomes into the future, 2025.
$300bn
In platform trustee member benefits across more than 977,000 member accounts, reviewed by ASIC's 2026 data monitoring assessment.
Source: ASIC, Report 833, Safeguarding super: How well are platform trustees monitoring risks to retirement savings?, 29 June 2026.
10 Dec 2026
Commencement date for Australian Privacy Principle 1.7 to 1.9, requiring disclosure of personal information used in automated decisions that significantly affect a person's rights or interests.
Source: Privacy Act 1988 (Cth), inserted by the Privacy and Other Legislation Amendment Act 2024.

Martin Barnier

Principal Consultant · Lumaris Consulting

Martin Barnier is Principal Consultant at Lumaris, an Australian-owned, vendor-neutral advisory firm specialising in AI, data, cyber security, cloud, and critical infrastructure. He is a security architect and technologist who works across all five domains, where most risk sits in the connections between them, not inside any one. Martin has over a decade of experience architecting security and technology across government, defence, national security, and health. Before Lumaris, he directed a large multidisciplinary practice at a Defence Prime delivering architecture, identity, cloud, and engineering capability for clients bound by APRA, Essential Eight, PSPF, and SOCI Act obligations. At Accenture, he was Lead Enterprise Security Architect for the Department of Health and Aged Care's Aged Care Transformation Program and Vaccines Response, and Lead Enterprise Architect for the National Security Portfolio and Department of Defence. Bachelor of Engineering (Robotics and Mechatronics), Swinburne University of Technology. TOGAF Practitioner, SABSA. Certified across AWS, Azure, and GCP. PRINCE2, Agile Scrum Master, SANS Cyber Incident Response Management.

View LinkedIn profile
Todd Noller
Principal Consultant · Lumaris Consulting

Todd Noller is Principal Consultant at Lumaris, an Australian-owned, vendor-neutral advisory firm specialising in AI, data, cyber security, cloud, and critical infrastructure. Todd is a delivery and operations leader who builds technology functions, governance frameworks, AI platforms, and the teams that run them. With over sixteen years across data, AI, and cyber delivery in regulated environments, Todd led the Complex Programs portfolio at a Defence Prime: a ~$40M book of cyber transformation spanning federal digital identity, enterprise integration, and security uplift. Prior to Thales, he stood up an investment management firm's entire technology function from scratch across New York and Australia, launching multiple SaaS products to SEC, FINRA, APRA CPS 234, and GDPR compliance within two years. At the Department of Defence, he coordinated national-scale cyber incident responses and served as Business Product Owner for a real-time threat intelligence platform. Todd spent three years as a Palantir specialist, including as a Country Manager for Palantir's Australian deployments. Bachelor of Information Technology (Web and Mobile Technologies), Deakin University. Diploma in Project Management. CISM (ISACA, in progress). Microsoft Sentinel, Microsoft Azure Fundamentals, SANS Incident Handling, Palantir Foundry.

View LinkedIn profile
Before you download

Questions about this guide

A fund needs to resolve each member across every predecessor administration they arrived through, know which insurance and product terms actually apply to them, and be able to serve a current answer rather than an overnight extract. Most funds cannot yet do this for members who arrived through a successor fund transfer, because the data was inherited rather than designed.

ASIC's June 2026 Report 833 reviewed six platform trustees covering roughly $300 billion in member benefits and found trustees are not making adequate use of the data they hold to identify risks to members. Several relied on manual processes and staff discretion rather than defined thresholds, and the regulator described itself as overwhelmingly disappointed with what it found.

Yes. CPS 230 requires an RSE licensee to classify fund administration as a critical operation and the administrator as a material service provider, and it requires a formal agreement setting out ownership and control of data. If a member-facing assistant cannot get a current answer because the record sits with the administrator, that is a service provider management question under a standard already in force.

From 10 December 2026, Australian Privacy Principle 1.7 to 1.9 requires an entity to disclose in its privacy policy the kinds of personal information used, and the kinds of decisions made, wherever a computer program makes or substantially supports a decision that could significantly affect a person's rights or interests. A fund cannot describe this if its serving layer cannot report what feeds each determination.

Let us talk

If the guide surfaces something you want to work through, that is a good place to start.

Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.