Quite possibly, and if it is, the contractual requirements in CPS 230 are not optional. CPS 230 commenced on 1 July 2025, the updated standard and CPG 230 commenced on 1 July 2026, and pre-existing arrangements had to be brought into line by the earlier of their next renewal date or 1 July 2026. That date has passed. On 30 April 2026 APRA wrote to every regulated entity to say AI governance is lagging AI adoption, and named third party and supply chain risk as the biggest gap it found.
What CPS 230 actually requires
CPS 230 applies to all APRA regulated entities, across banking, superannuation, general insurance, life insurance and private health insurance. The parts that matter for AI are the service provider parts.
You have to maintain a register of all material service provider arrangements, and completed registers were due to APRA by 1 October 2025. You have to notify APRA of new or modified material arrangements. And material arrangements have to carry specific contractual provisions, covering things like the ability to monitor performance, audit and access rights, incident notification and how the arrangement ends.
The transition was generous by design. APRA delayed commencement to 1 July 2025, then allowed a further year so entities could work through existing contracts, with the requirements biting from the earlier of the next renewal or 1 July 2026.
If you are reading this in September 2026 and your AI tooling is not on the register, you are not preparing for a deadline. You have missed one.
The 30 April letter
On the same day it finalised the CPS 230 amendments, APRA published a letter to industry on artificial intelligence setting out what a targeted supervisory review of large banks, insurers and superannuation trustees had found.
The finding, in short: adoption is moving faster than governance, and conventional risk frameworks were not built for the way AI behaves. The letter organises the problem into four areas, cyber and information security, AI governance, assurance, and third party and supply chain risk.
The third party piece is the one that should worry a mid-sized regulated entity most, and it is worth understanding why.
Why AI vendors are the hard case
Classic outsourcing was legible. You knew who ran the service, where it ran, and who to ring.
AI is different in three ways that break the usual approach.
It arrives embedded. Nobody signs a contract called "AI vendor". You buy a CRM, a claims platform, a document tool, a service desk, and AI capability appears inside it through a product update. The material arrangement you assessed two years ago now does something materially different, and no procurement process was triggered.
The dependencies are opaque. Your vendor's AI feature sits on a foundation model from someone else, which was trained on data from someone else again. Your fourth parties are real, and you usually cannot name them.
It changes underneath you. A model gets swapped, retuned or upgraded, and behaviour shifts without a release note you would notice. There is no equivalent of this in a payroll outsourcing arrangement.
Put those together and the standard question, is this provider material, gets harder. APRA's position is straightforward enough: many AI providers will meet the threshold, either already or as use deepens. Materiality is about whether a disruption would have a significant impact on your operations or your ability to meet obligations, not about the size of the invoice. A cheap tool sitting in the middle of your claims assessment can be material. An expensive one nobody depends on may not be.
The four provisions your contracts probably do not have
This is where the letter turns into work. Older contracts, even well drafted ones, tend to be silent on the things AI makes important. The data handling row in particular is worth reading beside where your data actually goes when you use AI.
| Provision | Why it matters for AI | What to ask for |
|---|---|---|
| Audit and assurance rights | You cannot assure a system you are not allowed to examine | Rights that reach the AI capability, not just the hosting, and are usable in practice |
| Notification of model change | Behaviour can shift without any change you would notice | Advance notice of model swaps, retuning and material capability changes |
| Incident notification | AI failures are often quality failures, not outages, so they miss the usual triggers | A definition of incident that includes degraded or incorrect output, with a notification window |
| Changes to data handling | Where your data goes, and whether it trains anything, can change with a product update | Notice of any change to processing location, retention or training use, with a right to object |
None of these are exotic asks in 2026. Most large vendors have answers. The problem is that the contract you signed in 2023 did not ask, and the renewal that would have caught it may already have passed.
The carve out, and what it does not do
The 30 April amendments introduced limited exemptions from specific contractual requirements for material arrangements with certain categories of service providers, where contractual compliance is not practicable. This was aimed at non-traditional service providers, the ones where you have no realistic negotiating position, and the designated categories sit in an attachment to the standard.
Read that narrowly. It is relief from particular contractual clauses for particular categories of provider. It is not a general exemption for anything with AI in it, and it does not remove the obligation to identify the arrangement, assess materiality, register it, or manage the risk. If your plan is to classify your AI stack as non-negotiable and move on, that is not what the amendment does.
If you sell AI into a regulated entity
This cuts the other way too, and it is a commercial opportunity rather than a burden.
Your customer now has to be able to evidence audit rights, change notification, incident definitions and data handling commitments. A vendor who can hand that over in a pack, without a three month legal negotiation, is materially easier to buy. We have watched this decide deals.
If you sell into banks, insurers or super funds, having your CPS 230 answers ready is now part of the product.
What we do on client builds
- We ask what the AI touches, not what it costs. Materiality follows dependency. The register entry gets written from the process it sits in.
- Model change notification goes in every AI contract we help scope. It is the clause most often missing and the one most likely to matter, because it is the one that changes system behaviour without anyone deciding anything.
- Assurance means evidence, not assertion. Our pre-launch agent testing exists so there is something to show a supervisor beyond "the vendor says it works".
- We treat wrong output as an incident. Logging and alerting is built so degraded quality is detectable, not just downtime. A system that confidently returns nonsense while reporting 100% uptime is the failure mode nobody's runbook covers.
- The register is generated, not maintained by hand. Where we can, it is derived from the systems inventory so it does not quietly go stale between reviews.
The short version
If you are APRA regulated, go and look at your material service provider register and ask which entries have gained AI capability since you assessed them. That list is the work. Then check the four provisions above in each of those contracts, because the 1 July 2026 date for pre-existing arrangements has been and gone, and APRA has already told the industry in writing that it thinks governance is behind adoption.
If you sell AI to regulated entities, build the answer pack now. Your buyers are being asked these questions by their own supervisors.
Frequently asked questions
Does CPS 230 mention AI specifically? The standard is technology neutral and speaks about material service providers and operational risk generally. APRA's April 2026 letter to industry is where it set out its AI specific expectations and its review findings. The obligations come from the standard, the expectations from the letter.
Our AI is inside a platform we already assessed. Is that covered? Not automatically. If the arrangement now does something materially different, the assessment behind it is out of date. New AI capability inside an existing platform is one of the specific situations APRA's letter is pointing at.
Is a small AI tool ever material? Yes. Materiality turns on the impact of disruption on your operations and your ability to meet obligations, not on contract value. A low cost tool embedded in a critical process can be material.
We are not APRA regulated. Does any of this apply to us? Not directly. It is still the clearest published statement of what good AI third party risk management looks like in Australia, and if you sell into financial services you will be asked to meet it by contract regardless.
Sources
- APRA, Prudential Standard CPS 230 Operational Risk Management and CPG 230. Commencement, the service provider register, and the April 2026 targeted amendments.
- APRA, Letter to Industry on Artificial Intelligence, 30 April 2026. Findings of the targeted supervisory review of large banks, insurers and superannuation trustees.
The pattern we see most is an AI capability that arrived in a product update and never went near procurement. If you are not sure what is on your register, give us a shout and tell us what's broken.