Skip to the main content.

Cyber Advisory Services

Your board approved AI. Can you evidence that you govern it?

An independent AI Readiness Assessment for organisations across Australia and New Zealand, measured against APRA, ASIC, and Five Eyes expectations. You receive a documented position, a prioritised roadmap, and a board ready briefing. Two to four weeks from scoping.

APRA AI Letter, 30 April 2026 ASIC 26-092MR, 8 May 2026 Five Eyes Statement, 22 June 2026 ISO/IEC 42001
Request Your Assessment See what is included

Why now

Three regulatory signals in eight weeks.

Between 30 April and 22 June 2026, Australia's prudential regulator, Australia's corporate regulator, and the cyber security agencies of Australia, New Zealand, the United Kingdom, Canada, and the United States each addressed AI risk directly to boards and executives. The expectations are now documented. The question for most organisations is whether they can evidence they meet them.

APRA expects a step change

APRA's letter to industry of 30 April 2026 found that assurance practices are not keeping pace with the scale, speed and complexity of AI. It sets minimum expectations across cyber and information security, governance and risk management, supplier risk, and change management and assurance. Where entities fail to manage AI risk proportionately, APRA has stated it will take stronger supervisory action and, where appropriate, pursue enforcement.

apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai

ASIC requires this at your board table

ASIC's open letter to AFS licensees and market participants, 26-092MR of 8 May 2026, states that frontier AI is not a distant or hypothetical risk. It expects boards and senior executives to understand their position, ask the right questions, and evidence the basis for their assurance. ASIC requires the letter to be tabled and discussed at the ultimate board and risk governance committees of every recipient.

asic.gov.au 26-092MR open letter

Five Eyes says months, not years

The joint statement of 22 June 2026 from the heads of the ASD, New Zealand's NCSC, the UK NCSC, CISA, and CSE warns that frontier AI models are anticipated to exceed current industry expectations, and that the timeline is measured in months rather than years. Leaders are asked to understand and assess risk, readiness and accountability, prioritise foundational controls, empower cyber leaders, and keep adapting.

cyber.gov.au five eyes cyber security agencies statement

Is this you

Adoption has outrun governance in most organisations.

Staff are already using AI tools, and nobody can produce a current inventory of which ones or for what.

Your board has asked what your AI exposure is, and the honest answer is that nobody has measured it.

You are APRA regulated and need to demonstrate the governance arrangements the April 2026 letter sets out.

You hold an AFS licence and the ASIC letter has been tabled, with an action item attached to it.

Developers are shipping AI generated code faster than your change and release controls were designed for.

A customer, insurer, or tender has asked how you govern AI, and you do not have a documented answer.

You are considering ISO/IEC 42001 and want to know the distance before committing to the programme.

You depend heavily on a single AI provider and have never tested substitution or exit.

What we assess

Five domains, mapped to published expectations.

This is not a generic maturity model. Each domain is assessed against what APRA, ASIC, the Five Eyes agencies, and ISO/IEC 42001 actually ask for, so that your findings map directly to the obligation you are answering to.

DOMAIN 01

AI governance and accountability

Policy, standards and reporting lines. Ownership across the AI lifecycle from design through to decommissioning. Human involvement in high risk decisions. Board literacy sufficient to set direction and provide effective challenge. Staff training on AI use, misuse and limitations.

DOMAIN 02

Inventory and use case visibility

A current inventory of AI tooling and AI use cases, including tools adopted outside formal procurement. Without this, no other control can be evidenced, and it is the most common gap we find.

DOMAIN 03

Cyber and information security

Threat models updated for AI specific attack pathways including prompt injection, data leakage, insecure integrations, exploit injection, and manipulation of autonomous agents. Identity and access management adjusted for non human actors. Security testing extended to AI implementations and to AI generated code.

DOMAIN 04

Supplier and concentration risk

Visibility over the AI supply chain including third and fourth party dependencies. Contractual provisions covering audit rights, model updates, incident notification and data handling. Substitution, portability and exit arrangements. Credible fall back where AI supports critical operations.

DOMAIN 05

Assurance and change management

Whether point in time assurance has been replaced by continuous validation suited to models that learn, adapt and degrade. Monitoring for drift, bias and failure modes. Integrated assurance across cyber, data governance, model performance, resilience, privacy and conduct. Second line and internal audit capability to assess AI systems independently.

OPTIONAL EXTENSION

ISO/IEC 42001 readiness mapping

Where certification is the destination, we extend the assessment to map your current position against the ISO/IEC 42001 AI management system standard, with an indicative pathway and timeframe to certification readiness. Insicon Cyber prepares organisations for certification. An accredited certification body issues the certificate.

What you receive

Six deliverables. Decision ready.

01

Current state assessment

A structured review of your existing AI governance, controls and practices across all five domains, scored with supporting evidence.

02

AI tooling and use case inventory

A documented register of AI systems in use, their owners, the data they touch, and their criticality. The artefact APRA expects, and the one most organisations do not have.

03

Regulatory alignment matrix

Your position mapped line by line against APRA, ASIC, and Five Eyes expectations, with ISO/IEC 42001 where in scope. Each finding traceable to the requirement it relates to.

04

Prioritised remediation roadmap

A sequenced action plan setting out what to address first, why, and the effort involved. Implementable with or without further Insicon Cyber support.

05

Board briefing pack

A briefing written for directors, not for engineers. Designed to satisfy the evidence expectation that both APRA and ASIC place on boards, in language a board can act on.

06

Fractional CISO debrief session

A facilitated session with your Insicon Cyber fractional CISO to walk through findings, answer challenge, and agree the next steps that make sense for your organisation.

How it works

Four steps. Two to four weeks.

Low friction on your side. Most of the effort sits with us.

01

Scoping and obligation mapping

We confirm which obligations actually bind you, whether that is APRA, ASIC, ISO/IEC 42001, a contractual requirement, or a combination, and scope the assessment to those.

02

Discovery and evidence gathering

Stakeholder interviews across technology, risk, legal and the business. Policy and contract review. Technical validation of AI integrations where applicable.

03

Analysis and reporting

Findings scored, prioritised by risk, likelihood and effort, and compiled into the full deliverable set. The board briefing pack is prepared in parallel.

04

Debrief and next steps

We present to your leadership team, work through the roadmap, and set out your options for closing the priority items.

Your assessment team

Founder reviewed. Every time.

CO-FOUNDER, CEO, AND FRACTIONAL CISO

Matt Miller

Matt works directly with boards and executive teams across Australia and New Zealand, translating cyber and AI risk into decisions leadership can actually make. He is a 2026 Australian Cyber Awards finalist for CISO of the Year.

CO-FOUNDER, DIRECTOR, AND FRACTIONAL CISO

Greg Bunt

Greg brings technical and governance depth to Insicon Cyber's assessment work. His hands on approach keeps findings grounded in operational reality, so the roadmap you receive is one your team can actually implement.

Why Insicon Cyber

We can act on our own findings.

Independent by construction

Our fractional CISOs carry no product quota. We do not onsell platforms. The assessment tells you what we found, not what we need you to buy.

The team that finds it can fix it

Most firms assess and exit. We can carry the findings through to implementation, governance, and ongoing operation. Nothing is lost re briefing a second supplier.

Australia and New Zealand depth

APRA, ASIC, ASD, the Privacy Act, NZISM, the NZ Privacy Act 2020 and NCSC New Zealand guidance. We work to what regulators on both sides of the Tasman actually expect.

ISO 27001 certified ourselves

We hold ISO 27001 certification. When we assess your management system readiness, we are speaking from having been through it, not from theory.

Testing capability behind the advice

Where the assessment finds untested AI implementations, we have the assurance capability to test them. Advice and evidence in the same relationship.

Written for the board table

Both APRA and ASIC place the expectation on directors. Our outputs are built to be tabled, not translated by someone else first.

After the assessment

Test it. Govern it. Maintain it.

The assessment gives you a position and a plan. Where you want support closing the priority items, the same team can carry it through. There is no obligation to continue, and the roadmap is written so that you can act on it independently if you choose to.

Test it

AI assurance and red teaming against your live implementations, closing the security testing coverage gap APRA identified.

AI Security and Governance

Govern it

ISO/IEC 42001 implementation, AI policy and framework build, and board advisory to lift the AI literacy APRA expects at director level.

AI Compliance, ISO 42001

Maintain it

Managed compliance and the Adaptive SOC, giving you the continuous validation that point in time assurance cannot provide for models that learn and drift.

Managed Compliance Services

Get started

Find out where you actually stand.

Tell us about your organisation and a member of our team will be in touch within one business day to discuss scope and pricing.

Delivered by a fractional CISO, not an automated questionnaire. Every assessment is human led.

Two to four weeks from scoping. Fast enough to be timely, thorough enough to be trusted.

Mapped to real obligations, so findings are traceable to APRA, ASIC, Five Eyes, and ISO/IEC 42001 requirements.

Australia and New Zealand. We deliver across both markets.

Request your assessment

Or email info@insiconcyber.com

Sources and references

APRA Letter to Industry on Artificial Intelligence, 30 April 2026 https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai
APRA media release, APRA calls for a step change in AI related risk management and governance https://www.apra.gov.au/news-and-publications/apra-calls-for-a-step-change-ai-related-risk-management-and-governance
ASIC Open Letter to AFS Licensees and Market Participants, 26-092MR, 8 May 2026 https://download.asic.gov.au/media/xhrf1w0e/26-092mr-open-letter-to-afs-licensees-and-market-participants.pdf
Five Eyes Cyber Security Agencies Statement, 22 June 2026 https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement
ASD, Frontier models and their impact on cyber security https://www.cyber.gov.au/about-us/view-all-content/news/frontier-models-and-their-impact-on-cyber-security
National Cyber Security Centre New Zealand https://www.ncsc.govt.nz
ISO/IEC 42001 Artificial Intelligence Management System https://www.iso.org/standard/42001