On 30 April 2026, APRA wrote to every entity it regulates (banks, insurers and superannuation trustees), calling for what it described as a step-change in how they manage and govern AI risk.1 The letter followed a targeted supervisory review of selected large entities conducted in late 2025.
The most important thing about that letter is what it did not do. APRA was explicit that it is not proposing to introduce additional prudential requirements at this stage.2 There is no new standard to implement, no new compliance program with its own budget line, no implementation date to plan around.
There is no new rule to comply with. There is a regulator that has told you your existing controls are not keeping pace, and existing standards it expects you to meet with them.
That is a harder problem to resource than a new standard, and it is why this hire tends to arrive unbudgeted. A new prudential standard creates a project. A supervisory expectation creates a capability gap, and capability gaps get filled by people.
What APRA actually found
APRA Member Therese McCarthy Hockey summarised the position as one where AI adoption is running ahead of the governance around it: “the systems and processes required to safely govern its use aren’t keeping up”.2 Four findings from the review are worth reading closely, because each maps to a different skill set.
1. Boards cannot challenge what they do not understand
APRA found that many boards “lack the technical literacy required to provide effective challenge to management on AI related risks”.2 Note the phrasing: the expectation is not that directors become engineers, but that they can meaningfully challenge. That requires someone whose job is to translate model behaviour into risk language a board can interrogate, and who is senior enough to be believed when the answer is unwelcome.
2. Internal audit does not have the tools
The letter states that internal audit functions “lack the specialist skills and tools required to engage in AI assessment”.1 This is the clearest hiring signal in the document. Point-in-time audit is a poor fit for probabilistic systems that change behaviour between reviews, and APRA is asking for integrated assurance across cyber security, data governance and model performance risk, with continuous monitoring proportionate to how critical the use case is.
3. Supplier concentration is untested
APRA observed that “few entities had demonstrated robust contingency planning or tested exit and substitution strategies for critical AI providers”, with some heavily dependent on a single provider across multiple use cases.1 It expects entities to map the full AI supply chain including fourth-party dependencies, and to secure contractual provisions covering audit rights, model updates and incident notification.
That is third-party risk work, but it requires someone who understands what a model update actually changes: a combination of vendor risk management and technical literacy that is rare in one person.
4. The cyber threat surface has changed shape
The letter identifies prompt injection, data leakage and autonomous agent misuse as material changes to the threat landscape, and notes that identity management and change controls struggle with “nonhuman actors such as AI agents”.1 APRA’s expectation is that “the speed at which entities can identify and patch vulnerabilities needs to operate much faster, commensurate with the AI-accelerated threat”.2
The context this lands in
CPS 230 Operational Risk Management came into force on 1 July 2025, with targeted amendments effective 1 July 2026.3 CPS 230 never mentions AI. APRA’s framework is deliberately technology and vendor agnostic. But a model that scores loan applications or triages claims is captured the moment it underpins a critical operation. The AI letter is best read as APRA telling the industry how it intends to supervise AI within that existing framework.
The role this implies is not one role
Read the four findings together and the temptation is to write one job description covering all of them. That role does not exist in the Australian market at any price. What the letter actually describes is a small function, and the sequencing matters more than the headcount.
In practice the first hire is the one that determines whether the second one says yes. Our view on the ordering:
- First: the translator. Someone senior enough to own the AI risk framework, the use-case inventory and board reporting. This person needs credibility in two rooms (the board and the engineering team), and the ability to hold both is the scarce attribute, not the risk qualification.
- Second: model validation and assurance. The person who can actually test a probabilistic system and say something defensible about it. Often found in model risk functions in banking, where the discipline has existed for credit and market risk models for years.
- Third: AI-aware third-party and cyber risk. Frequently an uplift to people you already have, rather than an external hire, provided someone in the first two roles can teach them what to ask.
Why the titles will mislead you
“Head of AI Governance” is a title barely three years old in this market, which means CVs carrying it range from genuine model risk practitioners to policy writers who have never inspected a model. Meanwhile, some of the strongest candidates for this work do not have the title at all: they sit in model validation, in quantitative risk, or in data governance, and have been doing a version of this against credit and market risk models for a decade.
Screening on the title narrows you to the people who moved fastest to claim it. Screening on the capability (can you challenge a model in front of a board, and can you evidence that challenge afterwards) opens a materially larger pool.
One caution worth stating plainly: nobody has a credible count of how many people in Australia can genuinely do this work. We do not publish one, and we would treat any firm that does with some suspicion. What is knowable is that the demand signal arrived in April 2026 for every APRA-regulated entity simultaneously, and that supply does not respond to a supervisory letter on the same timescale.