How we help · Superannuation
For APRA-regulated trustees

Members trust you with a lifetime. The systems should match.

Superannuation trustees sit on a generation of member savings. They run complex administration outsourced to a small set of providers. The prudential rules and the SIS Act apply. AI explainability has become a board topic. Operational risk is now a board-level discipline. Lumaris partners with trustees and their administrators to lift capability at trust pace.

Why super is on the agenda now

Three forces sharpening the trustee agenda.

— 01

CPS 230 has put operational resilience on the board agenda

Critical operations registers, tolerance levels, scenario testing, and oversight of major service providers. These now sit alongside investment risk in board reporting.

— 02

The cyber bar has risen

Cyber capability sized to the trustee's size and complexity. Tested controls. Incident reporting within 72 hours. The standard is operational, not paper.

— 03

Member-facing AI is arriving fast

Retirement guidance, member chat, fraud detection, and underwriting copilots. All need explainability, traceability, and human oversight. The standard is what survives trustee scrutiny.

How we work with trustees

Capabilities tuned to trustee governance.

AI oversight for member services

Model risk frameworks, explainability, and human-in-the-loop design for retirement and member-facing AI.

Member data platforms

Privacy-respecting analytics on member, contribution, and beneficiary data with consent and traceability built in.

Cloud & resilience engineering

Multi-region cloud foundations and resilience testing for trustee, administrator, and custodian touch points.

CPS 234 cyber assurance

Capability assessment, controls testing programme, incident playbooks, and joint controls with administrators and custodians.

Identity & fraud

Identity verification, account-takeover defence, and fraud analytics tuned to outsourced administration models.

CPS 230 operational resilience

Critical operations identification, tolerance setting, scenario testing, and service-provider uplift mapped to the rules.

The landscape we read

A $4 trillion industry under simultaneous regulatory, technological, and threat pressure.

Superannuation is a uniquely Australian construction: compulsory, long-dated, and uniquely concentrated in retirement savings. That makes it valuable to members, valuable to attackers, and increasingly central to APRA's prudential focus.

~$4T

Total assets under management in Australia's superannuation system, the fifth-largest retirement savings scheme in the world

the regulator / industry reporting

20,000+

Member accounts compromised in the March 2025 coordinated credential stuffing attacks across five major super funds

Reuters / BleepingComputer, 2025

AU$500K

Lost from four AustralianSuper member accounts in the same attacks; the lost-account count would have been higher without rapid containment

AustralianSuper / public reporting, 2025

1 July 2025

the resilience rule effective date, operational resilience now applies fully to trustees and their material service providers

the regulator

Member account security

multi-factor login available, but not enforced, and SMS-based factors still in use

The March 2025 attacks succeeded primarily because credential reuse from prior unrelated breaches was matched against super fund logins where multi-factor login was offered but not required. Several funds also relied on SMS-based multi-factor login, which is increasingly considered insufficient for high-value financial accounts. The Financial Services Council recommended mandatory multi-factor login for super funds by July 2026.

  • multi-factor login enforcement gaps at login on member-facing portals
  • SMS-based factors still in use for sensitive transactions
  • Limited adoption of phishing-resistant authentication (passkeys, hardware tokens)
Tripartite assurance

Assurance across trustee, administrator and custodian, coordinated in name, not always in practice

the resilience rule requires trustees to oversee material service providers. But the practical assurance regime, testing, incident response, change control, often runs as three parallel programmes rather than one. Incidents move faster than the coordination mechanisms.

  • Critical operations defined at the trustee but tested only at the administrator
  • Incident notification SLAs that don't survive contact with a real incident
  • Fourth-party dependencies inside the administrator that the trustee does not see
Member-facing AI

AI in regulated decisions without trustee-grade oversight

Retirement projections, hardship claims, fraud detection and underwriting copilots all touch regulated decision surfaces. The regulator has signalled clearly that the existing prudential standards apply. Few trustees have yet operationalised the AI oversight chain to a standard their board would defend in a member complaint. Explainability. Human oversight. Accountability or supervisory engagement.

  • AI used in hardship or retirement decisions without explainability surfaces
  • Identity and access frameworks not adapted to non-human actors (AI agents)
  • Shadow AI use among administrator staff handling member data
Operational resilience

The resilience rule evidence that holds up in a real incident, not just a tabletop

Tolerance levels, scenario testing, and exit and substitution strategies for material providers are the resilience rule baseline. The funds doing this well are testing them against scenarios that look like the next March 2025, not the last one.

  • Tolerance levels set on paper but not tested in operational conditions
  • Exit and substitution strategies for AI and core platform providers, theoretical
  • Member communications playbooks that have not been rehearsed under load
Proof points

Artefacts a trustee board will accept.

  • Member AI oversight framework with explainability and human-oversight controls.
  • Member data platform with consent, traceability, and OAIC alignment.
  • Multi-region cloud foundation with resilience evidence for trustee reporting.
  • Cyber capability assessment, controls testing plan, and joint-controls pack.
  • Account-takeover and fraud defence programme spanning trustee and administrator.
  • Critical-operations register, tolerance levels, and tested scenarios.
The rules we work to

The rules we work to.

We work to the major Australian rules for super. APRA's prudential standards set the bar for resilience and cyber. The SIS Act sits underneath. Critical-infrastructure rules apply to designated funds. Privacy rules cover member data. See the glossary for what each one covers and when it bites.
Latest insights

Recent articles for superannuation.

All insights →
Where this sector usually starts

Service offerings most relevant to superannuation.

Other sectors we work with

8 other sectors. Same converged practice.

Talk to us about your superannuation programme.

Tell us about your environment and we will be in touch within one business day.

Rise with confidence.