Australia's insurance regulator has set out a four-year plan that puts artificial intelligence-enabled cyber threats, climate-linked affordability pressures and superannuation valuation governance at the centre of its supervisory agenda for the next 18 months.
The Australian Prudential Regulation Authority (APRA) released its 2026-27 Corporate Plan on 20 August, outlining priorities for the banks, insurers and superannuation trustees it regulates through to 2029-30. APRA chair John Lonsdale said the plan responds to a volatile risk environment in which geopolitical tensions and emerging technology are reshaping threats across the financial system.
“Responding to these challenges, our latest Corporate Plan is focused on strengthening industry's resilience to geopolitical tensions, cyber-attacks and frontier AI, growing interconnections across the financial sector and an increased reliance on service providers,” Lonsdale said.
For general insurers, APRA said the sector remains well capitalised and profitable overall but continues to face a widening protection gap as claims costs, natural hazards and climate-related risk drive up premiums. That finding follows APRA's own Insurance Climate Vulnerability Assessment, released in March, which projected the share of uninsured freestanding households could rise from roughly one in seven today to one in four by 2050.
That earlier assessment prompted public reaction from industry bodies in April. The National Insurance Brokers Association (NIBA) called for expanded federal disaster mitigation funding, while the Insurance Council of Australia echoed calls for greater investment in physical mitigation and changes to policy settings affecting affordability and access to cover. Neither body has yet to issue a specific comment on this week's Corporate Plan.
Life insurers, APRA noted, continue to contend with legacy products, elevated lapse rates and claims experience, while private health insurers face pressure from an ageing membership base and rising claims costs.
The regulator plans targeted operational and technology risk reviews of general insurers and specialist payment providers during 2026-27, alongside continued reviews of how entities are implementing CPS 230, the operational risk management standard. Insurers using AI systems will be expected to demonstrate stronger governance, risk management and board oversight, with APRA also flagging quantum computing as a longer-term threat to existing encryption methods.
APRA said it intends for its policy changes to have a broadly net-neutral impact on regulatory burden, offsetting new requirements with simplification elsewhere. Planned work includes finalising governance requirements for insurers and superannuation funds – expected to take effect from early 2028 – and a joint consultation with the Australian Securities and Investments Commission (ASIC) on changes to the Financial Accountability Regime intended to cut administrative burden without weakening accountability.
“Over the past year, APRA progressed a range of initiatives that are delivering meaningful cost savings for industry,” Lonsdale said. “This year, we will go further by streamlining prudential requirements, removing duplicative reporting and providing greater flexibility for entities in meeting regulatory obligations.”
The regulator will commence work on a new system-wide stress test to examine risk linkages across the banking, insurance and superannuation sectors, and will require selected large superannuation trustees to commission independent reviews of their valuation governance practices.
Internally, APRA has budgeted $278 million for 2026-27, $2 million less than the prior year, with headcount projected to fall from 907 to 900 as the regulator moves data collection to its APRA Connect platform – a shift it estimates could save industry about $6 million annually in the long run.