RBNZ AI Supervisory Expectations
RBNZ AI Supervisory Expectations: What Do Regulated Entities Need to Know?
- RBNZ has published no standalone AI supervisory guidance, policy, or regulatory standard as of March 2026, making it one of the most silent major central banks on AI-specific prudential expectations relative to its size and the sophistication of NZ's financial sector
- The May 2025 "Rise of the Machines" FSR article is RBNZ's first substantive AI publication and is explicitly a monitoring report, not rule-making: Kerry Watt (Director of Financial Stability Assessment and Strategy) confirmed RBNZ will "continue to closely monitor developments" rather than announcing new obligations
- RBNZ's four identified AI systemic risk concerns — system errors amplifying existing vulnerabilities, data privacy breaches, market distortions from correlated AI model behaviour, and concentration risk from reliance on a small number of third-party AI providers — mirror the FSB's November 2024 framework exactly, confirming RBNZ is tracking international standard-setter positions rather than developing independent analysis
- BS11/BPR frameworks implicitly regulate AI through technology-neutral operational risk, outsourcing, and critical operations requirements: AI systems in critical operations require local control and documented governance; material AI vendors are subject to concentration risk management and exit planning obligations under BS11 principles
- RBNZ mandatory cyber incident reporting (April 2024) extends to AI system failures: any cyber event adversely affecting an entity or its stakeholders — including AI system errors, data poisoning, or model manipulation attacks — must be reported within 72 hours for material incidents, with periodic reporting for all incidents
- APRA CPS 230 (effective 1 July 2025) is the highest-value comparator framework for NZ-regulated entities: it requires explicit operational risk scenario analysis, critical operation identification, and material service provider management that, applied to AI, produces specific governance obligations RBNZ has not yet articulated. RBNZ has explicitly modelled its cyber incident reporting regime on APRA's design, establishing a precedent for borrowing APRA standards when NZ-specific guidance is absent
- FCA/PRA's principles-based response to DP5/22 (confirmed in FS23/6, November 2023) is the closest rhetorical match to RBNZ's position, but the FCA has gone further by explicitly engaging industry, publishing feedback, and articulating how existing principles (SMCR, consumer duty, operational resilience) apply to AI — something RBNZ has not done
- EBA's 2023 ML for IRB Models report is the most technically demanding AI guidance from any comparator, requiring ML credit models to be interpretable, explainable, fully documented, independently validated, and aligned with CRR. ML credit models are likely "high-risk AI" under the EU AI Act, requiring formal conformity assessment. NZ entities with EU personal data exposure in ML credit scoring systems may face EU AI Act obligations regardless of RBNZ guidance
Research Question
What are the Reserve Bank of New Zealand's specific supervisory expectations for AI use by regulated entities, and how do these align with or diverge from the expectations of comparator regulators (APRA, FCA, ECB/EBA)?
Findings
Executive Summary
RBNZ has no standalone AI supervisory framework; its first substantive AI-focused publication is the May 2025 "Rise of the Machines" article in the Financial Stability Report, which maps systemic risks but announces no new regulatory requirements. AI risk for RBNZ-regulated entities is currently governed through existing principles-based frameworks: BS11/BPR operational risk and outsourcing requirements, Banking Prudential Requirements on board governance, and mandatory cyber incident reporting (effective April 2024). APRA is the highest-value comparator: CPS 230 (effective July 2025) and CPS 234 together constitute a de facto AI risk framework for operational and information security risk, and RBNZ has explicitly modelled its own cyber regime on APRA's design. For the majority of large NZ banks — subsidiaries of APRA-regulated Australian parents — APRA CPS 230 compliance will propagate AI governance into NZ operations regardless of RBNZ's gap, but NZ-only entities (non-bank deposit takers, NZ-owned insurers, fintechs) face genuine governance vacuum.
Key Findings
-
RBNZ has published no standalone AI supervisory guidance, policy, or regulatory standard as of March 2026, making it one of the most silent major central banks on AI-specific prudential expectations relative to its size and the sophistication of NZ's financial sector.
-
The May 2025 "Rise of the Machines" FSR article is RBNZ's first substantive AI publication and is explicitly a monitoring report, not rule-making: Kerry Watt (Director of Financial Stability Assessment and Strategy) confirmed RBNZ will "continue to closely monitor developments" rather than announcing new obligations.
-
RBNZ's four identified AI systemic risk concerns — system errors amplifying existing vulnerabilities, data privacy breaches, market distortions from correlated AI model behaviour, and concentration risk from reliance on a small number of third-party AI providers — mirror the FSB's November 2024 framework exactly, confirming RBNZ is tracking international standard-setter positions rather than developing independent analysis.
-
BS11/BPR frameworks implicitly regulate AI through technology-neutral operational risk, outsourcing, and critical operations requirements: AI systems in critical operations require local control and documented governance; material AI vendors are subject to concentration risk management and exit planning obligations under BS11 principles.
-
RBNZ mandatory cyber incident reporting (April 2024) extends to AI system failures: any cyber event adversely affecting an entity or its stakeholders — including AI system errors, data poisoning, or model manipulation attacks — must be reported within 72 hours for material incidents, with periodic reporting for all incidents.
-
APRA CPS 230 (effective 1 July 2025) is the highest-value comparator framework for NZ-regulated entities: it requires explicit operational risk scenario analysis, critical operation identification, and material service provider management that, applied to AI, produces specific governance obligations RBNZ has not yet articulated. RBNZ has explicitly modelled its cyber incident reporting regime on APRA's design, establishing a precedent for borrowing APRA standards when NZ-specific guidance is absent.
-
FCA/PRA's principles-based response to DP5/22 (confirmed in FS23/6, November 2023) is the closest rhetorical match to RBNZ's position, but the FCA has gone further by explicitly engaging industry, publishing feedback, and articulating how existing principles (SMCR, consumer duty, operational resilience) apply to AI — something RBNZ has not done.
-
EBA's 2023 ML for IRB Models report is the most technically demanding AI guidance from any comparator, requiring ML credit models to be interpretable, explainable, fully documented, independently validated, and aligned with CRR. ML credit models are likely "high-risk AI" under the EU AI Act, requiring formal conformity assessment. NZ entities with EU personal data exposure in ML credit scoring systems may face EU AI Act obligations regardless of RBNZ guidance.
-
NZ-only entities face the sharpest governance gap: APRA-group NZ banks will implement CPS 230 AI governance via parent compliance; NZ-owned non-bank deposit takers, domestic insurers, and fintechs have no analogous pressure point and must rely on voluntary adoption of best practice.
-
An OIA request to RBNZ is warranted and feasible to surface any non-public internal supervisory frameworks, thematic review results, or international coordination correspondence on AI risk.
Assumptions
-
Assumption: RBNZ's silence on AI-specific guidance reflects a deliberate policy choice to await maturation of the technology and international standard-setting, consistent with NZ's broader "Investing with Confidence" AI strategy. Justification: This is supported by the pattern across NZ government (light-touch, principles-based, rely on existing law) confirmed in the AI strategy item, and by the monitoring rather than prescriptive tone of the "Rise of the Machines" article. An alternative explanation — that RBNZ has internal non-public AI guidelines — is possible but unconfirmable without an OIA request.
-
Assumption: The APRA CPS 230 framework will propagate into NZ subsidiaries of APRA-regulated Australian banks through group-level compliance. Justification: ANZ, ASB (CBA subsidiary), BNZ (NAB subsidiary), and Westpac NZ are all subsidiaries of APRA-regulated entities implementing CPS 230 by 1 July 2025. Group operational risk frameworks typically apply across jurisdictions. No source directly confirms NZ subsidiary application, but this is standard group risk management practice.
Analysis
The evidence supports a clear analytical conclusion: RBNZ is behind its comparators in AI supervisory specificity, and this gap is structural rather than accidental. NZ's prudential regulatory philosophy prioritises principles over prescription. RBNZ has historically issued narrower, lighter guidance than APRA for equivalent risk categories, and AI is following that pattern.
The gap matters most for NZ-only entities. The four major banks face minimal effective gap because APRA group compliance fills it. NZ-only fintechs, non-bank deposit takers, and NZ-owned insurers deploying AI in credit decisioning, underwriting, or fraud detection have no external pressure to adopt the equivalent of APRA CPS 230 AI governance. The risk is not a compliance risk in NZ (no rules to breach) but a governance risk: poorly governed AI models in these entities could produce biased credit outcomes, unexplained adverse decisions, or operational failures without triggering any supervisory consequence until a material incident occurs.
The FCA comparison is instructive for RBNZ's likely next step. FCA's response to DP5/22 was to articulate how existing principles apply to AI (SMCR accountability for AI systems, consumer duty outcomes from AI), not to create new rules. RBNZ's equivalent would be a speech or guidance note explaining how BPR governance requirements, BS11 outsourcing standards, and cyber resilience expectations apply to AI specifically. This is the minimum gap-closure action available to RBNZ without new regulation.
The EBA comparison is relevant for entities with EU exposure and is the benchmark for model risk sophistication. NZ's IRB credit model banks (the major four) should be applying EBA-equivalent documentation and validation standards to ML models as a matter of sound practice, regardless of RBNZ's silence.
Risks, Gaps, and Uncertainties
-
Primary source access: RBNZ's "Rise of the Machines" PDF was inaccessible during research (403 error). The characterisation relies on secondary press coverage from four independent sources. There may be specific supervisory language or guidance in the full FSR that secondary sources did not capture.
-
Non-public internal guidance: RBNZ may have internal supervisory guidance, thematic review results, or correspondence with regulated entities that is not in the public domain. An OIA request is the only mechanism to surface this.
-
Insurer-specific gap: The research focused primarily on the bank sector. RBNZ-supervised insurers under the Insurance (Prudential Supervision) Act 2010 have specific model risk exposures (actuarial models, underwriting algorithms) that were not investigated in detail. APRA's insurer-specific operational risk standards (CPS 230 applies to general and life insurers) provide the most relevant comparator.
-
Timeline uncertainty: RBNZ's posture may change rapidly. The May 2025 "Rise of the Machines" article could be a precursor to a thematic review or consultation in late 2025 or 2026. The FSB's call for national authorities to "assess framework adequacy" creates international pressure for RBNZ to respond.
Open Questions
- Does RBNZ have non-public AI supervisory guidance? An OIA request seeking any internal frameworks, thematic review results, or correspondence on AI risk would determine whether the public gap reflects a genuine absence or a transparency gap.
- How are NZ-only non-bank deposit takers and fintechs managing AI model risk without any regulatory signal? A practitioner survey or interview-based study of NZ's fintech and challenger bank sector would surface the practical governance vacuum.
- What is the regulatory status of AI-generated actuarial models for NZ insurers? The RBNZ/IPSA regime and its intersection with AI-driven underwriting and reserving is an under-investigated area.
- When will RBNZ issue its first prescriptive AI guidance? The trajectory of comparator regulators suggests 2026–2027 is plausible. Monitoring RBNZ's response to FSB pressure and any signals in the full May 2025 FSR or November 2025 FSR would provide early indicators.
sources
- [x] RBNZ: rbnz.govt.nz — publications, speeches, supervisory letters
- [x] RBNZ Financial Stability Reports 2022–2025
- [x] APRA CPS 230: Operational Risk Management
- [x] APRA CPG 234: Information Security
- [x] FCA DP5/22: AI and Machine Learning
- [x] EBA/GL/2023/17: Guidelines on internal governance (proxied via EBA ML for IRB report Aug 2023)
- [x] BIS FSB: "Artificial Intelligence and Machine Learning in Financial Services" (2017, updated 2024)