From accountable to in control
Knowing you're accountable is not the same as knowing what to do.
In our advisory work on the APRA and ASIC letters, the question directors actually ask is this. In practice, what does this mean we have to do? Four moves, in the order we take boards through them.
The same expectations are now surfacing in New York, California and the EU. This is not only an Australian question.
Map your AI, and get control of shadow AI
One inventory of every place AI touches a decision, including inside your vendors' tools. Then remove the reason people use their own. A governed AI your staff are allowed to use. A policy is not a control.
Bring vendors inside the tent, and move from assertion to evidence
Where AI supports a critical operation, the vendor falls within CPS 230's material service provider regime, and the transition period has ended. And ASIC's word was evidence. For any AI-assisted decision, what the system did, who reviewed it, who signed off.
Test every AI use with four questions
- Can you explain how it reaches a decision?
- Can you evidence that it works, rather than assert it?
- Is there a named human accountable for the outcome?
- Are you governing the vendor's system as if it were your own?
These four are where the regulators are converging.
Commission a board-owned AI strategy
Not a policy the AI team drafts and the board signs off. A strategy grounded in the regulators' principles, owned by the board, with enough technical fluency at the table to challenge it. The piece that cannot be delegated.
This is the shape of the work we do with boards. A governance review grounded in what the regulators actually require, that turns "we know we're accountable" into a plan the board can stand behind and evidence.