How we help · Financial Services
For APRA-regulated entities

Five risk domains. One regulatory environment. None of them simple.

Australia's banks, insurers, and super funds are dealing with five things at once: AI adoption, data rules, cyber threats, cloud migration, and critical infrastructure rules. APRA's April 2026 letter on AI raised the bar. Lumaris partners with banks and insurers to lift capability across all five domains at once, as one programme rather than five.

Why financial services is on the agenda now

Three forces converging on every CRO and CISO.

— 01

APRA is moving from observation to enforcement on AI

The April 2026 letter to industry signals stronger oversight where AI use outpaces the controls. The prudential rules already apply. AI-specific guidance is next.

— 02

Cyber is a board-level risk, not a technology risk

The March 2025 attacks on five major super funds compromised 20,000+ accounts in days. They exposed gaps in multi-factor login, identity, and the joint controls between funds and their administrators.

— 03

Critical infrastructure rules are now in force

The resilience rule from 1 July 2025 added stricter requirements. Critical-infrastructure rules apply to listed banks, payment systems, and super funds. Board-approved risk-management plans are required.

How we work in financial services

Capabilities tuned to the prudential perimeter.

AI oversight for regulated decisions

Model risk frameworks, explainability, and human-in-the-loop design for credit, claims, underwriting, and member-facing AI.

Data platforms with privacy by design

Privacy-respecting analytics on customer, claims, contributions, and beneficiary data with consent and traceability built in.

Cloud, resilience, and critical-infrastructure alignment

Multi-region cloud foundations, resilience evidence, and risk-management plan controls for trustee, administrator, and custodian touch points.

CPS 234 cyber assurance

Capability assessment, controls testing programme, incident playbooks, and joint controls with administrators, custodians, and major providers.

Identity, fraud, and account takeover

Identity verification, multi-factor login enforcement, and account-takeover defence tuned to outsourced administration and embedded distribution.

CPS 230 operational resilience

Critical operations registers, tolerance levels, scenario testing, and oversight of major service providers. Aligned to the rules and board reporting.

The landscape we read

Five domains. One regulatory environment. None of them simple.

APRA-regulated entities are managing security and oversight challenges across AI, data, cyber, cloud, and critical infrastructure simultaneously. Each domain is evolving rapidly. Each carries its own compliance obligations. Each intersects with the others in ways that fragmented, domain-by-domain approaches cannot address.

$9.8T

In assets supervised by APRA across banks, insurers and superannuation funds, the prudential perimeter the AI letter applies to

APRA, 2026

20,000+

Superannuation accounts compromised in the March 2025 coordinated credential stuffing attacks across five major funds

Reuters / BleepingComputer, 2025

55M

AI-driven decisions made daily by CommBank across more than 2,000 models, illustrating the scale APRA is now supervising

CommBank / Computer Weekly, 2025

1 July 2025

CPS 230 effective date, raising the operational resilience bar for all regulated entities

APRA

AI oversight

Shadow AI use without enforceable technical controls

APRA's 30 April 2026 letter found entities relying primarily on policy direction or after-the-fact detective measures rather than preventative technical restrictions. Identity and access management capabilities have not yet adapted to non-human actors such as AI agents.

  • Shadow AI tools ingesting client data, pre-earnings information, and board materials
  • Model drift, bias, and lifecycle oversight gaps undiscovered in most entities
  • Concentration risk in single AI providers without tested exit and substitution strategies
Cyber and identity

Credential stuffing, account takeover, and AI-augmented threats

Cyber risk was rated the top concern by regulated entities in recent stakeholder reporting. The March 2025 super fund attacks demonstrated the scale at which credential stuffing can be coordinated. Many funds had MFA available but not enforced at login.

  • MFA and authentication controls not consistently enforced
  • AI-augmented threats outpacing traditional detection and response
  • CPS 234 compliance gaps in authentication, testing, and third-party assurance
Cloud and operational resilience

Multi-cloud and fourth-party dependencies creating CPS 230 exposure

Cloud landing zones deployed without security architecture review. Hybrid environments creating IT/OT convergence risks. Vendor concentration creating CPS 230 operational resilience exposure.

  • Cloud landing zones deployed without data sovereignty controls
  • Hybrid cloud creating segmentation gaps and IT/OT convergence risks
  • Concentration in technology vendors creating systemic exposure points
Critical infrastructure

CIRMP obligations not yet fully operationalised

Designated critical infrastructure assets carry mandatory board-approved CIRMPs, 12-hour critical cyber security incident notification, and exposure to government assistance powers. CPS 230 effective 1 July 2025 adds further operational resilience requirements.

  • Board-approved CIRMPs required but not yet fully operationalised across the sector
  • Geopolitical tensions increasing the likelihood and severity of targeted attacks
  • Operational resilience tolerance levels and tested scenarios still maturing
Proof points

Artefacts a board and supervisor will accept.

  • AI model risk framework with explainability and human-oversight controls.
  • Customer data platform with consent, traceability, and Privacy Act alignment.
  • Multi-region cloud foundation with resilience evidence for board reporting.
  • CPS 234 capability assessment, controls testing plan, and joint-controls pack.
  • Account-takeover and fraud defence programme spanning institution and administrator.
  • CPS 230 critical-operations register, tolerance levels, and tested scenarios.
The rules we work to

The rules we work to.

We work to the major Australian rules for financial services. APRA's prudential standards set the bar. Critical-infrastructure rules cover listed banks, payment systems, and super funds. Privacy and consumer-data rules apply on top. See the glossary for what each one covers and when it bites.
Latest insights

Recent articles for financial services.

All insights →
Where this sector usually starts

Service offerings most relevant to financial services.

Other sectors we work with

8 other sectors. Same converged practice.

Talk to us about your financial services programme.

Tell us about your environment and we will be in touch within one business day.

Rise with confidence.