Regulatory and standards preconditions for deployment of Artificial…
Regulatory and standards preconditions for deployment of Artificial Intelligence (AI) systems that can take multi-step actions: does incomplete access control and data governance constitute a control failure?
- APRA CPS 230 and DORA both require documented controls, mapped assets and dependencies, resilience tolerances, and explicit governance ownership before regulated digital operations can be considered adequately controlled, so those conditions are best read as organisational preconditions for write-capable agent deploymentAPRA (n.d.)DORA (2022)
- Access controls that still grant more permissions than needed for each task are likely to become a direct control failure once multi-step agents are introduced because autonomous or semi-autonomous agents increase the number, speed, and potential blast radius of resource access decisions across the estateAPRA (n.d.)DORA (2022)NIST (n.d.)
- A partially classified or unclassified data estate is likely to be incompatible with defensible deployment of AI systems that can take multi-step actions on behalf of users in a regulated bank because the institution cannot demonstrate which data and systems are critical, how access should be bounded, or how severe disruptions would propagateDORA (2022)APRA (n.d.)ISO (2018)
- Unresolved systems capability debt becomes a control problem, not just an efficiency problem, once agents are introduced because execution power is being increased before the bank proves that its underlying technology capability and resilience arrangements can absorb failureAPRA (n.d.)Basel (n.d.)ISO (2018)
- The United Kingdom comparator material shows that firms cannot wait for bespoke AI regulation before treating these weaknesses as failures, because the supervisory posture is to apply existing governance, accountability, and model-risk tools to AI and then clarify gaps from that baseBankofengland (n.d.)FCA (n.d.)PRA (n.d.)
- NIST SP 800-207 shows that Zero Trust Architecture rejects broad inherited permissions and requires per-resource authorization, so delegating multi-step agent actions into an estate that still relies on broad standing access is reasonably treated as a failed architectural precondition rather than a safe starting pointNIST (n.d.)
- Within payment-data and AI-management-system contexts, the same weaknesses should still be treated as control failures or precondition failures rather than governance preferences, but the clause-level precision of that conclusion is constrained here by source-access limitsPCI (n.d.)PCI (n.d.)Iso (n.d.)
- The shared cross-framework precondition set is bounded identity, classified information, governed builders, explicit ownership, third-party oversight, and tested resilience, so the board-level decision is whether those foundations are demonstrably in place now rather than whether an agent platform promises productivityNIST (n.d.)NIST (n.d.)Github (n.d.)
Research Question
Under applicable regulatory and standards frameworks, including Australian Prudential Regulation Authority (APRA) CPS 230, the European Union (EU) Digital Operational Resilience Act (DORA), Payment Card Industry Data Security Standard (PCI DSS) v4, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001, National Institute of Standards and Technology (NIST) Special Publication (SP) 800-207, NIST SP 800-53, Basel Committee operational resilience principles, United Kingdom (UK) Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) Artificial Intelligence (AI) guidance, and ISO 31000, what organisational preconditions are required before deploying AI systems that can take multi-step actions on behalf of users, and does deploying those systems into an environment where access control does not yet limit identities to the minimum permissions needed for each task, the data estate is not fully classified, citizen development is ungoverned, and systems capability debt remains unresolved constitute a current or foreseeable control failure?
Findings
(Populated from §6 Synthesis above.)
Executive Summary
- Deploying AI systems that can take multi-step actions on behalf of users into an environment with incomplete access control, an unclassified data estate, ungoverned citizen development, and unresolved systems capability debt is already a current or clearly foreseeable control failure under the cited prudential, resilience, security, and risk-management frameworks, not merely a governance gap.
- The clearest direct support comes from APRA CPS 230 and DORA, which require effective internal controls, documented assets and dependencies, sound technology capability, and tested resilience before digital operations can be treated as adequately controlled.
- NIST Zero Trust Architecture, PRA SS1/23, and the United Kingdom supervisory AI material reinforce the same conclusion by showing that AI does not suspend existing expectations for per-resource access discipline, model-risk governance, accountability, or independent challenge.
- That conclusion is strongest for broad, write-capable deployments that inherit existing estate-level weaknesses; narrowly scoped agents with separate identities, bounded workflows, and proven compensating controls could change the characterisation for particular use cases.
- PCI DSS, ISO/IEC 42001, and NIST AI RMF 1.0 corroborate the direction of travel, although the PCI and ISO portions carry lower confidence here because the full PCI text was not retrievable in this runtime and the ISO text is paywalled.
Key Findings
- High confidence. APRA CPS 230 and DORA both require documented controls, mapped assets and dependencies, resilience tolerances, and explicit governance ownership before regulated digital operations can be considered adequately controlled, so those conditions are best read as organisational preconditions for write-capable agent deployment.
- Medium confidence. Access controls that still grant more permissions than needed for each task are likely to become a direct control failure once multi-step agents are introduced because autonomous or semi-autonomous agents increase the number, speed, and potential blast radius of resource access decisions across the estate.
- Medium confidence. A partially classified or unclassified data estate is likely to be incompatible with defensible deployment of AI systems that can take multi-step actions on behalf of users in a regulated bank because the institution cannot demonstrate which data and systems are critical, how access should be bounded, or how severe disruptions would propagate.
- High confidence. Unresolved systems capability debt becomes a control problem, not just an efficiency problem, once agents are introduced because execution power is being increased before the bank proves that its underlying technology capability and resilience arrangements can absorb failure.
- Medium confidence. The United Kingdom comparator material shows that firms cannot wait for bespoke AI regulation before treating these weaknesses as failures, because the supervisory posture is to apply existing governance, accountability, and model-risk tools to AI and then clarify gaps from that base.
- Medium confidence. NIST SP 800-207 shows that Zero Trust Architecture rejects broad inherited permissions and requires per-resource authorization, so delegating multi-step agent actions into an estate that still relies on broad standing access is reasonably treated as a failed architectural precondition rather than a safe starting point.
- Medium confidence. Within payment-data and AI-management-system contexts, the same weaknesses should still be treated as control failures or precondition failures rather than governance preferences, but the clause-level precision of that conclusion is constrained here by source-access limits.
- High confidence. The shared cross-framework precondition set is bounded identity, classified information, governed builders, explicit ownership, third-party oversight, and tested resilience, so the board-level decision is whether those foundations are demonstrably in place now rather than whether an agent platform promises productivity.
Assumptions
- Assumption: The detailed PCI DSS v4.0.1 structure for access control and stored-data protection remains materially aligned with the standard's public framing. Justification: The direct standard PDF was not retrievable in this runtime, so the PCI analysis relies on official PCI site material rather than a clause-by-clause read.
- Assumption: ISO's public summary is sufficient to characterise ISO/IEC 42001 as requiring formal AI governance, policy, and continual-improvement preconditions. Justification: The full standard text is paywalled.
- Assumption: PRA SS1/23 is partly a direct source and partly a comparator for broader agentic AI use cases outside its formal model-capital scope. Justification: The statement still expresses a prudential supervisor's minimum expectations for governing model-led decision support.
Analysis
- The analysis weights APRA CPS 230 and DORA most heavily because they are current, accessible, and explicit about internal controls, mapped assets, governance ownership, resilience tolerances, and third-party oversight.
- NIST SP 800-207, ISO 31000, and NIST AI RMF 1.0 were used as independent architectural and risk-management checks to test whether the prudential conclusion survives outside banking-specific rulebooks, and it does.
- The United Kingdom sources were used to assess regulator logic rather than clause prescription, and they consistently support the position that existing governance and accountability tools apply to AI now.
- PCI DSS and ISO/IEC 42001 were kept at medium confidence because the accessible evidence supports directional conclusions but not the same clause-level precision available for APRA, DORA, and NIST.
- The main competing interpretation is that narrowly scoped agents with separate identities, bounded workflows, and proven compensating controls could avoid the control-failure characterisation for specific use cases; this item does not reject that possibility, but treats it as a boundary condition outside the scenario studied here, which assumes unresolved estate-level weaknesses rather than already-proven compensating controls.
Risks, Gaps, and Uncertainties
- The PCI DSS portion should be treated as directionally reliable but not citation-complete until the full v4.0.1 text is reviewed outside this runtime.
- The ISO/IEC 42001 portion is limited to the public summary and therefore cannot support the same clause-specific board wording as accessible full-text frameworks.
- New Zealand primary prudential guidance remains less explicit than the comparator jurisdictions, and the main RBNZ handbook page was inaccessible here, so APRA and DORA remain the strongest regulatory anchors.
Open Questions
- What public clarifications, if any, will RBNZ or the Financial Markets Authority (FMA) issue as agentic AI moves from experimentation into operational banking use cases in New Zealand?
- What minimum technical baseline for agent identity, credential delegation, approval paths, monitoring, and kill-switch control is sufficient to move a bank from foreseeable control failure to defensible deployment readiness?
- Which exact PCI DSS v4.0.1 and ISO/IEC 42001 clauses provide the strongest board-committee wording once the full standards are reviewed outside this runtime?
sources
- [x] APRA CPS 230 - Operational Risk Management — - Official APRA prudential handbook page and current operative text; primary Trans-Tasman operational-risk comparator.
- [x] DORA - Regulation (EU) 2022/2554 — - Official European Union Digital Operational Resilience Act text.
- [x] PCI Data Security Standard (PCI DSS) — - Official PCI Security Standards Council standard page describing the scope and purpose of PCI DSS.
- [x] PCI Security Standards Council Document Library - PCI DSS v4.0.1 — - Official document library page identifying the current PCI DSS v4.0.1 standard and document location; the direct PDF itself returned access restrictions in this runtime.
- [x] ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system — - Official public summary for the Artificial Intelligence Management System (AIMS) standard.
- [x] NIST SP 800-207 - Zero Trust Architecture — - Official National Institute of Standards and Technology (NIST) publication page for Zero Trust Architecture.
- [x] NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations — - Official NIST security and privacy control catalog publication page.
- [x] Basel Committee on Banking Supervision - Principles for operational resilience — - Official Bank for International Settlements (BIS) / Basel Committee page for the operational resilience principles.
- [x] FCA Discussion Paper DP22/4 - Artificial Intelligence and Machine Learning — - Official United Kingdom (UK) Financial Conduct Authority (FCA) landing page for the joint discussion paper.
- [x] Bank of England / PRA Discussion Paper 5/22 - Artificial Intelligence and Machine Learning — - Official Bank of England / Prudential Regulation Authority (PRA) page containing the discussion paper text.
- [x] FCA Feedback Statement FS23/6 - Artificial Intelligence and Machine Learning — - Official FCA feedback statement on the joint AI discussion paper.
- [x] PRA Supervisory Statement SS1/23 - Model risk management principles for banks — - Official PRA supervisory statement page.
- [x] ISO 31000:2018 - Risk management - Guidelines — - Official public summary of ISO 31000.
- [x] RBNZ banking supervision handbook — - Primary New Zealand prudential-context page; it returned 403 in this runtime and was not used for downstream factual support.
- [x] NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) publication page — - Official NIST publication page for AI RMF 1.0.
- [x] NIST AI Risk Management Framework hub — - Official NIST framework hub and supporting materials.