Free tool for one AI system
AI Prudential
Risk Scan.
Examine how one AI system or agent is governed, tested, constrained and recoverable. The questions adapt to what it does and the consequences of failure.
Assessment
- 01 System context
- 02 Control questions
- 03 Results
Allow about 10 to 15 minutes. Answer for the current implementation, not a future plan.
Before you begin
How to use this scan.
This is a self-assessment of one AI use case. It applies fixed questions and rules informed by published APRA direction and relevant industry practice, using the sources identified in the report.
The result relies on your answers. Avowal does not inspect documents, test controls or verify outcomes through this tool. A selected control may still be ineffective in practice. The scan does not determine compliance or residual risk and is not legal advice or certification.
Your answers are processed in this browser, not uploaded or stored by this site. A PDF you choose to save stays where you save it. Continue if you understand these limits.
01 / System context
Describe the system.
Choose one real use case. “Your organisation” means the APRA-regulated organisation accountable for it; “provider” means an external supplier. Your answers determine which control questions apply.
Outside this scan
This scan is for APRA-regulated organisations.
It would be misleading to assess another organisation against this APRA-focused question set. No result has been generated.
02 / Control questions
What is operating today?
Answer the groups that apply to this system. “Yes, with evidence” means you can point to a current document or test, not just an intention.
03 / Your self-assessment
AI Prudential Risk Scan
This is based on the use case and possible consequences. It does not change when a control is reported as present.
Why this impact level applies
Impact and reported controls
These are separate dimensions. Reported controls may reduce risk, but this scan has not tested whether they work. This grid is not a residual-risk rating.
| Potential impact | Gaps reported | Mixed or uncertain | All reported in place |
|---|---|---|---|
| High | |||
| Medium | |||
| Low |
Control areas to examine
These areas reflect your answers, not verified control effectiveness. The examples are possible responses, not prescribed APRA requirements.
All self-reported control answers
These include controls that did not trigger findings. Avowal has not tested them.
Method and limitations
The scan applies fixed rules to one system described by the respondent. “Direct” means a question maps to stated APRA or prudential text. “Derived” means Avowal has turned a regulatory concern into a system-level check. CPG 230 is guidance, not a prudential standard. ASD material is a separate technical reference.
No documents or operating controls were independently examined. A selected “Yes” does not establish that a control works. This scan is not a compliance opinion, certification or substitute for an evidence-based review.
Regulatory sources: APRA AI letter, APRA/ASIC frontier-AI paper, and CPS 230. Non-regulatory practice context: AICD director guide and Actuaries Institute paper. Sources reviewed on .
Want these answers tested against evidence?
Avowal can review one system's documents, control operation and priority actions. The scan does not send us your answers or findings.
Method and privacy
Fixed rules.
Clear limits.
Context answers open relevant groups. No, partial and unknown responses lead to fixed, source-mapped findings. Neither AI nor a person rewrites the result behind the scenes.
Answers are not uploaded or stored by this site. Reloading starts a new assessment. The report uses your browser's print-to-PDF feature. There is no analytics, contact form or answer submission. See our privacy notice.