Business continuity & AI technology risk

 

You already depend on AI. You just haven't assessed it.

 

Most organisations didn't set out to become dependent on AI. It arrived embedded in tools they already used — customer service platforms, document processing, coding tools, decision support — and now sits quietly inside processes that matter.

That's the risk. Not AI itself, but the fact that it's often adopted faster than it's assessed. We help organisations understand where AI creates operational dependency and build that exposure into their resilience planning, without slowing down the adoption that's already happening.

 

Four types of AI risk


Dependency risk

When an AI tool becomes part of how a time-critical activity gets done, its availability becomes your availability. If the vendor has an outage, changes the model, or deprecates a feature you rely on, can your team still do the work? Most organisations haven't mapped which of their Prioritised Activities now depend on an AI tool.

 

Data and security risk

Sensitive or confidential data entered into third-party AI tools may leave your control in ways your existing data governance doesn't account for. This includes staff using consumer AI tools without oversight ("shadow AI"), and the security posture of AI vendors your critical systems now sit behind.

 

Decision and output risk

Where AI outputs feed into real decisions (approvals, communications, analysis, code), errors or fabricated content ("hallucinations") can cause operational or reputational harm if there's no human check in the loop. This is a process design question as much as a technology one: where does human oversight sit, and is it actually happening?

 

Third-party concentration risk

AI capability is often delivered several layers deep in your supply chain; your CRM, your helpdesk, your document platform may all rely on the same handful of underlying AI providers. A disruption to one upstream provider can affect multiple systems you thought were independent. This is precisely the kind of subcontractor visibility CPS 230 requires for Critical Operations.

 

What we do


AI dependency mapping

We work with your team to identify where AI tools sit inside your Prioritised Activities, and what would happen if they became unavailable or unreliable.

 

Gap analysis

We review your current AI use (formal and informal) against the National AI Centre's Guidance for AI Adoption, and identify where governance, oversight or data handling gaps exist.

 

Third-party and vendor risk review

We help you trace AI dependency through your existing service provider chain, including subcontracted AI capability your primary vendors may not disclose upfront.

 

Integration with business continuity planning

AI risk needs to be reflected in your BIA and third-party risk assessment, not treated as a separate workstream. We fold AI dependency findings into your broader resilience program alongside the other risks you already manage.

See our Business Continuity Plan service

 

Regulatory context

 

Australia doesn't have a dedicated AI Act, and the mandatory guardrails proposed in 2024 were shelved in the government's December 2025 National AI Plan. Instead, AI is currently governed through existing, technology-neutral law — the Privacy Act, Australian Consumer Law, and directors' general duties — supported by voluntary guidance rather than AI-specific rules.

  • Guidance for AI Adoption (National AI Centre, October 2025) — the current reference standard for responsible AI governance, covering accountability, impact assessment, risk management, transparency, testing and human oversight

  • Australian AI Safety Institute (AISI) — launched in early 2026 to test systems and monitor risk; advisory only, with no enforcement powers

  • Existing sector regulators — including APRA and ASIC — continue to apply their existing frameworks to AI-related risk within the entities they regulate, rather than a separate AI regime

This is a fast-moving area. The government has flagged further legislative developments for large-scale AI infrastructure, so this space is worth revisiting periodically rather than treating current settings as fixed.

 

Regulated by APRA?

 

APRA hasn't issued an AI-specific prudential standard — but CPS 230's existing requirements around Critical Operations and service provider risk already apply to AI tools your organisation depends on, including AI capability delivered by your vendors' subcontractors.

See what CPS 230 requires

 
 

Ready to talk?

Not sure where AI sits in your risk profile? Get in touch and we'll talk through where to start.

Get in touch