Trustees, platforms, cyber risk under APRA spotlightBY KARREN VERGARA | FRIDAY, 21 AUG 2026 12:28PMSuperannuation trustees, platforms and cyber resilience will be under more scrutiny in the 2027 financial year from the prudential regulator. APRA laid out its priorities in its newly published 2026-27 Corporate Plan, firing warning shots at trustees and platforms, in particular, which have been in the hot seat since the collapse of the Shield and First Guardian master funds. "Trustees offering platforms should expect intensive and risk-based supervisory oversight. This will include ensuring entities currently subject to enforcement action take timely and appropriate remedial action," APRA said. "APRA will take further supervisory and enforcement action should trustees fall short of meeting their prudential obligations." Platform trustees and providers can expect more scrutiny. This comes ahead of APRA undertaking work to consult on a proposed package of reforms that takes into account findings from its review of platform providers and lessons learned from the collapse of Shield and First Guardian. "The impact of the reforms will be most significant for platform trustees, given that investment menus are typically broader, products are more complex, and advisers can play a larger role in selecting and recommending investment options," APRA said. As previously reported, a key theme for APRA this financial year is investment governance with respect to valuation practices and platforms. This is part of assistant treasurer Daniel Mulino's newly announced reforms, by which APRA will be given greater oversight to ensure trustees have the financial capacity to meet their obligations under the proposed compensation scheme. APRA did not provide any details on any changes to the superannuation Performance Test and Comprehensive Product Performance, other than saying the package remains "an important transparency and accountability mechanism." "We continue to work with government on potential future revisions to the Performance Test," APRA said. Meanwhile, APRA said cyber security, artificial intelligence and operational resilience would remain in focus following the introduction of Prudential Standard CPS 230 Operational Risk Management. The standard, which took effect on 1 July 2025, strengthened requirements around operational risk management, business continuity and oversight of material service providers. APRA said entities should expect more frequent and deeper engagement on cyber and AI risks and must be able to demonstrate how those risks are being managed. The regulator will also continue reviewing implementation of CPS 230 through prudential and thematic reviews across several industries. Related News |
Editor's Choice
Trustees, platforms, cyber risk under APRA spotlight
|ASIC draws parallels between ASX and super trustee failures
|Perpetual hit with double whammy redemption, impairment
|GQG hit by $21bn outflows, FUM falls
|Products
Featured Profile

Andrew Gregory
UNISUPER






