AI is becoming embedded in core processes and decisions, and competitive advantage increasingly depends on how safely and effectively you scale it. APRA's letter to industry makes clear that governance, risk management, resilience and assurance practices are not keeping pace with adoption. For everyone else, it is a useful reference point that reinforces good-practice expectations already echoed in the Australian Government's Voluntary AI Safety Standard (VAISS).
Whether you are APRA-regulated or not, the expectation is the same: scale AI with clearer accountability, continuous assurance and stronger control of third-party and agentic risks. Our two points of view set out what that looks like in practice.
Jon Benson
Cybersecurity & Privacy, Partner, PwC Australia
Nicola Costello
Partner, Digital and AI Trust Leader, PwC Australia
Pia Chakravarti
Cybersecurity & Privacy, Partner, PwC Australia
Bevan Lim
Partner, Assurance, PwC Australia
© 2017 - 2026 PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Please see www.pwc.com/structure for further details. Liability limited by a scheme approved under Professional Standards Legislation.