Five questions to ask an AI vendor
The questions a regulated buyer puts to an AI vendor before contract, and what a strong answer to each one requires.
Purpose
CPS 230 is the operational risk standard issued by the Australian Prudential Regulation Authority. The original standard commenced on 1 July 2025. Following targeted amendments, the current instrument commenced on 1 July 2026.
The standard requires a regulated firm to manage the operational risks associated with its service providers. A material service provider is one on which the firm relies to undertake a critical operation or which exposes it to material operational risk. This document refers to such a provider as a vendor.
APRA’s April 2026 letter to industry on artificial intelligence sets expectations for the management of AI-related risk, including supplier management and integrated assurance.
A buyer already asks whether a vendor’s product is secure. For an AI service, it also needs evidence of what the system did on an identified decision and what record would be available to an auditor, a board or a regulator.
SOC 2 and ISO 27001 can test aspects of the vendor’s security and control environment. They do not by themselves provide a reconstructable record of one AI decision. A buyer needs to ask for that evidence directly.
Regulatory basis
- CPS 230
- A Prudential Standard. The original standard commenced on 1 July 2025; the current instrument commenced on 1 July 2026.
- CPG 230
- The practice guide accompanying the standard. It assists implementation but does not create enforceable requirements of its own.
- AI letter, April 2026
- A statement of supervisory expectations. It is not a Prudential Standard and should not be described as one.
CPS 230 creates binding prudential obligations. CPG 230 explains APRA’s guidance, while the AI letter communicates supervisory expectations. Each has a different legal and practical role.
Application
A vendor review runs from first contact to signature. A security questionnaire sits within that sequence, followed by legal review and contract.
These five questions belong at the front of the sequence, before the questionnaire is issued. Their purpose is to establish whether the remainder of the process is warranted.
They should be issued in writing, with sufficient notice for the vendor to prepare a considered response.
The five questions
-
01
Do you keep a contemporaneous record of every decision your AI makes while serving us?
What it means. The record is written as the decision occurs, and is not assembled afterwards from memory or from other systems.
A strong answer. A stated scope of coverage, and the number of decisions recorded in a defined period.
-
02
Can any single decision be reconstructed after the fact, from inputs through to output and any human step?
What it means. The reconstruction of one identified decision after the event, from the inputs through to the output.
A strong answer. A worked replay of a single real decision, produced on request within days.
-
03
Is the record tamper-evident, and can our auditor verify its integrity without relying on your word?
What it means. Any subsequent alteration to the record is detectable, and the auditor can establish this without reliance on the vendor.
A strong answer. Records sealed at the point of capture, and a verification method the auditor can run without the vendor present.
-
04
What sits behind the AI, including models, versions, hosting regions and tools, and how are changes recorded?
What it means. The vendor’s own suppliers, including the model provider behind the product. CPS 230 requires the buyer to consider fourth-party risks that may affect a material service arrangement.
A strong answer. A dated inventory of models, versions, hosting regions and tools, with each change recorded in the same trail as the decisions.
-
05
How are boundary events evidenced, including blocked actions, escalations, overrides and incidents, and what is your retention position?
What it means. Boundary events are the points at which the AI is stopped, escalated, overridden or fails. Retention is the period for which evidence of those events is held.
A strong answer. A register of those events, tied to the sealed records, and a documented retention schedule.
Assessing the responses
A strong response identifies an artifact rather than offering an assurance. Each strong answer above names something capable of being handed over. A scope and a count, a replay, a verification method, an inventory, a register.
A vendor who responds that logs are kept has answered a different question. Logs record that a system ran. These questions concern what it decided, and whether that can be established independently.
Scope and limitations
These five questions do not constitute a due-diligence process and do not replace one. A vendor may answer all five satisfactorily and remain unsuitable, since evidence is distinct from fit, price and capability.
The questions reflect what regulated buyers were asking through 2025 and 2026. They will change as practice changes, and this document carries the date of its current edition.
General information only. This document summarises Arkna’s reading of the cited material and is not legal, compliance or professional advice. Obligations should be verified against the instruments themselves and with the reader’s own advisers.