Compliance

Why AI Risk Management Must Address Vendor Change Controls to Prevent Operational Disruption

Microsoft Azure AI Foundry and Amazon Bedrock show how model retirement can shorten notice periods, stop requests and require code changes. The EU's DORA framework shows why notification, objection and exit rights must connect to a tested operational response.

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance shortcomings. But the more valuable question is not simply what...

When the Price of Milk is about Governance

The ACCC fined Lactalis $59,400 over misleading 'fresh' milk labelling, while the Federal Court's $11.3 million penalty against Mercer Super shows the same claims-outrun-evidence governance failure at a very different scale.

AI Vendor Assurances Alone Don’t Cut It: A Risk Management Wake-Up Call

APRA's April 2026 letter to industry and ASIC's Report 798 both warn that boards are leaning on AI vendor assurances instead of independently verifying them. Here is what Australian organisations should be checking before they trust the compliance pack.

OAIC determination puts insider privacy risk back in the spotlight

The OAIC found an organisation breached APP 11.1 after an employee accessed customer personal information without authorisation. With the Medibank civil penalty case before the Federal Court, OAIC enforcement on internal access controls is active and escalating.

Regulatory pressure often starts as an audit response before it becomes a broader operating expectation

The OAIC has published a formal response to the ANAO’s performance audit on administration of the Freedom of Information Act, signalling a review of FOI regulation, guidance, priorities and capabilities.

Recent posts