ABN 21636682141  ·  Sydney, NSW

AI assurance · Australian regulated sectors

The obligations already have dates.

Australia has no AI Act. What it has instead is a set of dated instruments, a prudential regulator that has told boards their AI assurance is behind, and a stated intention to start asking suppliers directly. Infigency helps you answer that in writing, before someone asks.

Instrument Commences Status
APRA CPS 230 Operational risk management, extended to all contracted service providers 1 Jul 2026 In force
APRA letter to industry on AI Board literacy, lifecycle accountability, third-party management, assurance 30 Apr 2026 Issued
Privacy Act, APP 1.7 Automated decision-making transparency in privacy policies 10 Dec 2026
EU AI Act, Article 50 Transparency duties reaching Australian exporters and their AI-enabled products 2 Aug 2026 In force
AS ISO/IEC 42001:2023 Certifiable AI management system, now appearing in enterprise procurement Voluntary Procurement-led

Register maintained by Infigency. Dates reflect published commencement and issue dates as at the last review. Confirm current status against the source instrument before relying on it.

Engagements

Four pieces of work, each with a fixed scope.

Every engagement produces one artefact you can hand to a regulator, an assessor, or the customer holding up your deal. Scoped before it starts, priced before it starts, and delivered by the person who sold it.

01 · For vendors

AI supplier assurance

Your customer is an APRA-regulated entity. Their CPS 230 obligations now reach you, and the assessment questions arriving in your inbox were written by someone who assumes you already have answers.

  • Assessment readiness against what the assessor is actually looking for
  • Model, agent and data-flow description your customer's risk team can accept
  • Standing evidence pack, so the next questionnaire takes hours instead of weeks
  • Gap list ranked by what stalls deals first

2–3 weeks · Fixed fee, quoted on scope

02 · Commences 10 Dec 2026

Automated decision-making inventory and APP 1.7 readiness

The disclosure paragraph takes an afternoon. Finding out what your systems truly decide, and getting engineering, product and privacy to agree on the wording, is the part that takes the remaining time.

  • Inventory of automated decisions across your own and vendor-supplied systems
  • Assessment of which decisions significantly affect people
  • Drafted privacy policy disclosure your legal team can sign off
  • Evidence trail behind every line of it

3–4 weeks · Fixed fee, quoted on scope

03 · For regulated entities

APRA AI assurance review

APRA's April 2026 letter set out AI-specific expectations without changing a single prudential standard. The gap sits between what the standards say and what evidencing them now looks like with AI in scope.

  • Current state mapped to CPS 230, CPS 234, CPG 235 and CPS 510
  • AI dependencies traced into critical operations and continuity planning
  • Third-party and concentration exposure across your AI supply chain
  • Findings written for a board risk committee, not a control spreadsheet

4–6 weeks · Fixed fee, quoted on scope

04 · Readiness only

ISO 42001 readiness and independent internal audit

Accredited audit capacity in Australia is still building out, and booking is the bottleneck. Arriving at Stage 2 with an AI management system that holds up is the part you control.

  • Gap assessment against AS ISO/IEC 42001:2023
  • AI system inventory covering in-house, embedded and vendor-supplied
  • Management system build support, sized to what you already run
  • Independent internal audit ahead of your certification body

6–10 weeks · Fixed fee, quoted on scope

How we work

01

We don't build what we assess

No implementation work, no reselling, no referral fees from platform vendors. Assurance is only worth something if the person giving it has nothing riding on the answer.

02

The person you meet does the work

No pyramid. You are not introduced to a partner and then handed to a delivery team you have never spoken to.

03

Fixed scope, fixed fee

Scope agreed in writing before the engagement opens. If the work changes, we re-scope it rather than letting the invoice drift.

Background from the Founder

I have spent most of my career on the assessing side of these questions.

My work has been cloud security, technology risk and enterprise architecture for Australian financial services, insurance, energy and government organisations, in environments where a control has to survive a regulator reading it rather than an internal review.

That means I have sat on the buyer's side of supplier assessments: writing the questions, reading the responses, and deciding which vendors made it through. Most people advising vendors on those assessments have never seen one from that angle. It changes what you tell them to fix first.

Infigency is the practice I run that work through. It is deliberately small, which is why the scope is fixed and the diary is finite.

Focus
APRA-regulated entities, critical infrastructure operators, and the technology vendors selling into both.
Instruments
CPS 230 · CPS 234 · CPG 235 · CPS 510 · Privacy Act APP 1.7 · SOCI Act · AS ISO/IEC 42001 · EU AI Act
Based
Sydney. Engagements run remotely across Australia, on site where the work needs it.

Start here

Send us the question you're stuck on.

If a customer assessment is holding up a deal, or you have a December date and no inventory, a short call will tell you whether this is worth scoping. No charge for that conversation.

Response

Within one business day