ASIC Report 798, 'Beware the gap: Governance arrangements in the face of AI innovation', released on 29 October 2024, is the Australian Securities and Investments Commission's first examination of how financial services and credit licensees use AI where it affects consumers. ASIC analysed 624 AI use cases at 23 licensees and found that some licensees were adopting AI faster than they updated risk and governance arrangements, creating a 'governance gap' and risk of consumer harm. It sets out eight findings and eleven questions for licensees, and reminds them that the regulatory framework is technology neutral, so existing general licensee obligations, consumer protection provisions and directors' duties apply to AI. It is a review report, not a rule: no new obligations or penalties are created.
OFFICIAL TEXT: asic.gov.au ↗ · FINAL · APRA / ASIC
| Document | ASIC REP 798 — REP 798 Beware the gap: Governance arrangements in the face of AI innovation |
| Issued by | Australian Prudential Regulation Authority and Australian Securities and Investments Commission |
| Type | Report |
| Status | Final |
| Published | Oct 29, 2024 |
| Applies to | Australian financial services (AFS) licensees and credit licensees. The review sample was 23 licensees drawn from the banking, credit, general and life insurance, and financial advice sectors, looked at as of December 2023. The report is not legal advice and creates no new obligations: it describes how existing technology-neutral obligations apply to AI |
| Official source | asic.gov.au ↗ |
| Use cases | AI governance (general) · Third-party & vendor AI · Credit scoring & underwriting · Generative & agentic AI · Customer-facing chatbots · Fair lending & discrimination |
What are the key points of ASIC REP 798?
- ASIC analysed 624 AI use cases from 23 licensees in banking, credit, insurance and financial advice, current or in development as at December 2023, and met 12 of the licensees in June 2024.
- Finding 1 and 2: AI use varied significantly and is accelerating; 57% of all use cases were less than two years old or in development, and there is a shift to more complex and opaque techniques, particularly generative AI (92% of generative AI use cases were less than a year old or not yet deployed).
- Finding 3: deployment strategies were mostly cautious; AI generally augmented human decisions or increased efficiency rather than making autonomous decisions, and most use cases did not directly interact with consumers.
- Findings 4 to 6: not all licensees had adequate arrangements for AI risks; some assessed risk through the lens of the business rather than the consumer (for example algorithmic bias); governance varied widely. Only 12 licensees had AI policies referencing fairness and only 10 referenced disclosure of AI use to consumers.
- Finding 7: the maturity of governance and risk management did not always align with the nature and scale of AI use; in two cases governance lagged AI use, creating the greatest risk of consumer harm.
- Finding 8: licensees relied heavily on third parties for AI models; 30% of use cases used third-party models, for four licensees all of their models were third-party, and for 13 licensees at least half were; not all had appropriate governance to manage the risks.
- ASIC reminds licensees that existing obligations are technology neutral: general licensee obligations, consumer protection provisions including prohibitions on unconscionable conduct and on false or misleading representations, directors' duties of care and diligence, and responsibility for outsourced functions.
- ASIC sets 11 governance questions: taking stock, strategy, fairness, accountability, risks, alignment, policies, resources, oversight, third parties and regulatory reform.
What did ASIC REP 798 change for banks?
REP 798 is the benchmark for how ASIC will look at AI governance at financial services and credit licensees, including banks' consumer-facing businesses. It did not change any legal requirement, but ASIC's message that licensees should not take a 'wait-and-see approach' to reform and that governance arrangements should lead AI use signals what it will look for. It was followed in 2026 by APRA's AI letter to industry (30 April 2026) and the joint APRA-ASIC frontier AI statement (27 August 2026), which cover the prudential and cyber side.
What does ASIC Report 798 expect of financial services licensees using AI?
ASIC Report 798 expects licensees to make sure governance leads AI use rather than trailing it. ASIC reviewed 624 AI use cases at 23 licensees (as at December 2023) and found a rapid acceleration in use, a shift towards complex and opaque techniques such as generative AI, gaps in how some licensees assessed consumer risks like algorithmic bias, and heavy reliance on third-party models. It says licensees should consider the existing technology-neutral framework (general licensee obligations, consumer protection provisions including false or misleading representations and unconscionable conduct, and directors' duties), treat third-party models with the same expectations as internal ones, and work through eleven questions on strategy, fairness, accountability, risk, policies, resources, oversight and third parties. The report creates no new obligations.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Finding 4 — Risk management arrangements | APRA / ASIC | Have adequate arrangements for identifying and managing AI risks; ASIC found not all licensees did. | Published 29 October 2024 |
| Finding 5 — Consumer-lens risk assessment | APRA / ASIC | Assess risks from the consumer's perspective, including AI-specific risks such as algorithmic bias, not only business risk. | Published 29 October 2024 |
| Finding 6 — Governance varied widely | APRA / ASIC | Close the governance weaknesses ASIC saw (its case study licensee had no overarching AI strategy, no AI policies and no risk rating of its use cases) before gaps widen as AI use accelerates. | Published 29 October 2024 |
| Finding 7 — Governance must keep pace | APRA / ASIC | Align governance and risk management maturity with the nature and scale of AI use; governance arrangements should lead AI use as it increases and evolves. | Published 29 October 2024 |
| Finding 8 — Third-party models | APRA / ASIC | Manage third-party AI models with the same expectations as internally developed models, including validation, monitoring and review; licensees remain responsible for outsourced functions. | Published 29 October 2024 |
| Existing obligations — Where to from here | APRA / ASIC | Consider general licensee obligations, consumer protection provisions (false or misleading representations, unconscionable conduct) and directors' duties when deploying AI. | Published 29 October 2024 |
| Questions 1 to 6 — Stock, strategy, fairness, accountability, risks, alignment | APRA / ASIC | Know where AI is used, set a strategy tied to risk appetite, provide services efficiently, honestly and fairly, name who is accountable, identify consumer and regulatory risks across the AI lifecycle, and test whether governance leads or lags use. | Published 29 October 2024 |
| Questions 7 to 11 — Policies, resources, oversight, third parties, reform | APRA / ASIC | Translate strategy into staff expectations, resource AI properly, define human oversight and an action plan for unexpected outputs, validate third-party models, and engage with AI regulatory reform proposals. | Published 29 October 2024 |
REP 798 is the conduct-side counterpart to APRA's prudential standards. ASIC's foreword says current licensee obligations, consumer protection laws and director duties are technology neutral and that licensees 'should not take a wait-and-see approach' to legislative and regulatory reform. ASIC says it will continue to monitor how regulated entities use AI, contribute to the Australian Government's development of AI-specific regulation, collaborate with domestic and international counterparts and, where necessary and appropriate, take enforcement action.
The report's case study is a licensee whose AI credit-default model was a 'black box' with limited monitoring and incomplete documentation yet stayed in use for several months, illustrating the gap between adoption and governance. The sample is not representative of AI use generally, which is why the report is a pointer to supervisory focus rather than a market measure.
For banks, REP 798 is best read alongside APRA's CPS 230 (service providers and operational resilience), CPS 234 (information security) and April 2026 letter on AI; ASIC covers conduct and consumer outcomes, APRA covers prudential resilience.
WHAT THIS MEANS IN PRACTICE
- Run the eleven questions as a self-assessment and record who answered each and what evidence supports it.
- Keep an inventory of AI use cases with a risk rating that considers consumer impact, not only business risk, and assess bias and explainability for models that affect credit or product decisions.
- Apply the same validation and monitoring expectations to third-party AI models as to internal ones, and keep a documented third-party supplier process.
- Make sure representations about AI use, model performance and outputs are accurate, and decide how to disclose AI use to affected consumers.
- Brief directors and officers: ASIC says their duty of care and diligence extends to the adoption, deployment and use of AI.
Is ASIC Report 798 binding?
No. REP 798 reports ASIC's review findings and states that its examples are illustrative and not intended to impose or imply particular rules or requirements. It reminds licensees that existing obligations, which are technology neutral, apply to their use of AI, and ASIC says it will take enforcement action where necessary and appropriate if AI use results in breaches of those obligations.
Does ASIC Report 798 apply to banks?
It applies to AFS licensees and credit licensees, and the 23 licensees reviewed included banking and credit firms. Banks that hold such licences are within ASIC's conduct regime in addition to APRA's prudential standards such as CPS 230 and CPS 234.
What is the 'governance gap' in ASIC Report 798?
It is ASIC's term for licensees adopting AI more rapidly than they update their risk and governance arrangements. ASIC found governance lagged AI use in two cases and warned that gaps may widen as adoption accelerates, because governance arrangements are by nature slow to change.
How does REP 798 compare with APRA's 2026 AI letter?
Both say existing technology-neutral frameworks apply to AI and that governance is lagging adoption. REP 798 (October 2024) is ASIC's conduct-focused review of consumer impact; APRA's April 2026 letter is prudential, directed at boards and executives on cyber, supplier concentration and assurance, and says APRA will take stronger supervisory action where AI risks are not managed.
| Date | Document | Status |
|---|---|---|
| Apr 30, 2026 | APRA AI Letter to Industry (April 2026) — APRA Letter to Industry on Artificial Intelligence (AI) | Final |
| Jul 17, 2023 | APRA CPS 230 — Prudential Standard CPS 230 Operational Risk Management | In force |
| Nov 30, 2018 | APRA CPS 234 — Prudential Standard CPS 234 Information Security | In force |
| Sep 30, 2026 | SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act) | Final |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 28, 2026 | AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act) | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning