APRA moves to tighten superannuation investment governance

Super trustees cannot treat investment governance as a product-selection exercise; APRA expects evidence that every option is controlled across its full lifecycle.

The 30-second take

APRA’s 2025 thematic review covered platforms representing about 95% of platform assets under management and identified weaknesses across eight investment lifecycle areas. Consultation on strengthened standards is due to begin, while enforcement action against five trustees shows the issue has already moved beyond guidance.

The control gap is end to end

APRA’s 19 August 2026 announcement points to reforms covering due diligence, conflicts, fees, liquidity, performance, valuation, monitoring and member outcomes. Those controls cannot sit with separate teams that only meet when something fails.

A trustee needs a traceable line from approval criteria to ongoing monitoring, escalation and exit. If an option changes structure, liquidity or risk profile, the governance response should occur before member harm becomes visible in complaints or losses.

What stronger governance looks like

Boards should require a current inventory of investment options, named owners, decision rights, key dependencies and objective triggers for review. Exceptions need time limits and explicit acceptance.

Member communications and operational readiness should be tested alongside investment analysis, not after it.

Questions for your organisation

  • Can we trace each investment option from approval through monitoring and exit?
  • Which options rely on stale due diligence or unresolved conflicts?
  • Are liquidity, valuation and member-outcome signals reviewed together?
  • Who can suspend inflows or remove an option when thresholds are breached?
  • Does the board receive evidence of control effectiveness rather than process completion?

Test the lifecycle, not the paperwork

Visit the Innovation of Risk to assess whether your governance controls operate as one accountable system.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.