List your product on Stack Search

Get in front of thousands of GRC decision-makers

APRA Maps Out a Tougher Test for Financial Resilience

APRA Maps Out a Tougher Test for Financial Resilience

By
Key Takeaways
  • Emerging Risks Move to the Foreground: APRA is putting AI-enabled cyber threats, quantum computing and geopolitical risk closer to the center of its supervisory work as the threat environment facing financial institutions changes.
  • Shared Technology Creates Shared Exposure: The regulator is paying closer attention to banks, insurers and superannuation trustees relying on the same technology platforms and material service providers, where a problem at one provider could reach well beyond a single institution.
  • APRA Is Looking Across the Financial System: A new system-risk stress test will examine the connections between sectors and help APRA understand how disruption could travel through the wider financial system.
  • Lending and Valuation Practices Face a Closer Look: Banks will undergo targeted reviews of lending practices, while selected large superannuation trustees will have independent parties examine their valuation governance.
  • More Scrutiny Does Not Necessarily Mean More Rules: APRA wants its policy agenda to have a net-neutral impact on regulatory burden, pairing new requirements with efforts to simplify standards, eliminate duplicative reporting and give institutions greater flexibility.
Deep Dive

APRA’s 2026-27 Corporate Plan puts cyberattacks, artificial intelligence, geopolitical tensions and dependence on common technology providers among the risks demanding closer attention from banks, insurers and superannuation trustees. The plan sets the regulator’s strategic direction for the next four years and, more immediately, its policy and supervisory agenda for the coming 12 to 18 months.

Capital and liquidity remain part of that work. So do lending standards and valuation governance. But much of the plan is concerned with risks that move differently through a financial system: across institutions, through shared providers and technological dependencies, and sometimes from events originating thousands of miles from Australia.

“As we look across the operating environment, it’s clear that the international and domestic economic environments remain challenging,” APRA Chair John Lonsdale said. Geopolitical tensions, he said, continue to affect inflation, trade relationships and cost-of-living pressures, while technological developments are creating new threats, amplifying old ones and putting competitive pressure on traditional business models.

The regulator intends to make those concerns tangible in its supervision.

APRA will examine whether regulated entities are strengthening their resilience to AI-enabled cyber threats and will increase its focus on risks associated with quantum computing. It will also assess how institutions identify and manage their exposure to common technology platforms and material service providers, an acknowledgment that a firm can be well defended on its own terms and still be vulnerable through something it shares with everybody else.

That dependence has become one of the more difficult facts of modern operational resilience. Outsourcing can distribute work without necessarily distributing risk. When enough institutions rely on the same platforms or providers, what appears on one firm’s risk register as a third-party exposure can become a problem for the system.

APRA plans to look more closely at those connections through a new system-risk stress test designed to deepen its understanding of linkages between sectors and their potential consequences for financial stability.

Geopolitical risk will receive similarly sharper treatment. The regulator plans to reinforce minimum expectations for its management and subject entities to more intensive supervision to ensure gaps are addressed in a timely manner.

There is a notable change of scale running through these priorities. APRA is not simply asking whether an institution can survive a cyberattack, a provider failure or geopolitical disruption. It is increasingly interested in what happens when the same event reaches several institutions at once.

The more traditional work of prudential supervision continues alongside it. APRA will conduct targeted thematic reviews of banks’ lending practices to determine whether they remain prudent given the possibility of less favorable economic conditions. Selected large superannuation trustees, meanwhile, will be required to appoint an independent party to conduct a deep review of their valuation governance practices.

More Rules, Without More Burden

For all the attention given to emerging and interconnected risks, APRA is also trying to constrain something much closer to home: the cost of regulation itself. One of the plan’s three strategic priorities is what the regulator calls “getting the balance right.” APRA wants to preserve financial safety and stability without imposing undue costs on the institutions it supervises. The other priorities are maintaining the safety and stability of the financial system and improving APRA’s own organizational effectiveness.

That balance will be tested by a policy agenda that still contains a substantial amount of new work.

APRA plans to consult on superannuation reforms that include development of a risk-sensitive capital framework to support the government’s proposed new member compensation scheme. It expects to finalize new governance requirements for banks, insurers and superannuation funds, with those requirements due to take effect at the beginning of 2028.

Changes are also coming to the banking framework. APRA will finalize targeted revisions to bank capital requirements while beginning consultation on changes to liquidity standards.

Together with the Australian Securities and Investments Commission, the regulator will consult on proposed changes to the Financial Accountability Regime intended to reduce administrative burden without weakening accountability standards. APRA also plans to develop a new prudential framework for large stored value facility providers and work with ASIC on joint implementation guidance, subject to the government finalizing the relevant reforms.

Lonsdale said APRA is aiming for the policy agenda to have a “net neutral impact” on regulatory burden, with new requirements broadly offset by simplification elsewhere.

“Over the past year, APRA progressed a range of initiatives that are delivering meaningful cost savings for industry,” he said. “This year, we will go further by streamlining prudential requirements, removing duplicative reporting and providing greater flexibility for entities in meeting regulatory obligations.”

It is an important qualification to an otherwise expansive plan. APRA is not proposing that every newly visible risk should produce another layer of regulatory machinery. Its stated ambition is to make the framework more demanding where the risk warrants it and less cumbersome where existing requirements can be simplified.

The regulator is applying some of the same logic to itself. APRA said it intends to improve its organizational effectiveness, including through greater use of AI, so its staff can respond more quickly and productively as the environment it supervises becomes more complex.

“We also need to ensure our own people have the skill and resources needed to act quickly and decisively in a more complex and uncertain world,” Lonsdale said.

The harder task in the plan lies beyond any single rule or supervisory review. Financial institutions have become bound together by technology, service providers and economic relationships that do not respect the old lines between operational, financial and geopolitical risk. A weakness can belong to one institution. A dependency can belong to hundreds.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong