Business continuity & AI technology risk

 

You already depend on AI. You just haven't assessed it.

 

Most organisations didn't set out to become dependent on AI. It arrived embedded in tools they already used — customer service platforms, document processing, coding tools, decision support — and now sits quietly inside processes that matter.

That's the risk. Not AI itself, but the fact that it's often adopted faster than it's assessed. We help organisations understand where AI creates operational dependency and build that exposure into their resilience planning, without slowing down the adoption that's already happening.

 

Four types of AI risk


Dependency risk

When an AI tool becomes an essential part of a time-critical activity, its availability becomes your availability. If the AI vendor suffers an outage, changes the model, or deprecates a feature you rely on, can your team still complete their work? Most organisations haven't mapped which of their Prioritised Activities now depend on an AI tool.

 

Data and security risk

Sensitive or confidential data entered into Third Party AI tools may be stored or accessible that your existing data governance doesn't account for. In particular, are you fully aware of which consumer AI tools your staff are using? Shadow AI is creating major concerns for risk management and those responsible for the security posture of organisations.

 

Decision and output risk

Where AI outputs feed into real decisions (approvals, communications, analysis, code), errors or fabricated content ("hallucinations") can cause operational or reputational harm if there's no human check in the loop. If critical decisions need to be made that impact your clients, at what point do humans assure that the decisions are correct? If material damage is done to a client, who is responsible, does your insurance policy cover it?

 

Third-party concentration risk

AI capability is often delivered several layers deep in your supply chain; your CRM, your helpdesk, your document platform may all rely on the same handful of underlying AI providers. A disruption to one upstream provider can affect multiple systems you thought were independent. This is precisely the kind of subcontractor visibility APRA’s CPS 230 requires for Critical Operations, where fourth and fifth party risks need to be considered.

 

What we do


Governance and Policy Development

If the use of AI is not tightly governed and guided by an effective Policy, it will be very difficult to manage the risks and ensure that the benefits of AI are realised and are consistent with your organisation’s strategic direction. 

We will assist you to develop a Use of AI Policy that addresses the governance, operational risk, service resilience and the management of Third Party AI service providers.

 

Gap analysis

We review your current AI use (formal and informal) against the National AI Centre's Guidance for AI Adoption and identify where governance, oversight or data handling gaps exist.

AI dependency mapping

We work with your team to identify where AI tools are used in the workflow to deliver your Prioritised Activities and what would happen if they became unavailable or unreliable.

 

Third-party and vendor risk review

We help you trace AI dependency through your existing service provider chain, including subcontracted AI capability your primary vendors may not disclose upfront.

 

Integration with business continuity planning

AI risk needs to be reflected in your Business Impact Analysis and Business Continuity Risks Reports, not treated as a separate workstream. We fold AI dependency findings into your broader resilience program alongside the other risks you already manage.

See our Business Continuity Plan service

 

Regulatory context

 

In July 2026, the Australian Government announced intentions to set standards for the construction of AI data centres, the copyright protection for artists and the use of AI by the Government. AI is currently governed through existing, technology-neutral law - the Privacy Act, Australian Consumer Law and directors' general duties - supported by voluntary guidance rather than AI-specific rules.

  • Guidance for AI Adoption (National AI Centre, October 2025) - the current reference standard for responsible AI governance, covering accountability, impact assessment, risk management, transparency, testing and human oversight 

  • Australian AI Safety Institute (AISI) - launched in early 2026 to test systems and monitor risk; advisory only, with no enforcement powers 

  • Existing sector regulators - including APRA and ASIC continue to apply their existing frameworks to AI-related risk within the entities they regulate, rather than a separate AI regime. 

In April 2025 APRA published a letter to banks, insurers, and superannuation trustees warning that their risk management and governance practices are lagging behind rapid AI adoption. 

This is a fast-moving area. The government has flagged further legislative developments for large-scale AI infrastructure, so this space is worth revisiting periodically rather than treating current settings as fixed.

 

Regulated by APRA?

 

To-date (August 2026) APRA has only issued the letter mentioned above and has not issued an AI-specific prudential standard.

CPS 230's existing requirements around Critical Operations and service provider risk can already apply to AI tools your organisation depends on, including AI capability delivered by your vendors' subcontractors.

See what CPS 230 requires

 
 

Ready to talk?

Not sure where AI sits in your risk profile? Get in touch and we'll talk through where to start.

Get in touch