Skip to content

Topics · The files I read most often

A few files, read carefully, written about openly.

Each topic gathers every note, report and digest filed under it. New writing attaches to the topic as the file develops; older pieces remain dated and untouched so the reading record is honest.

No. 01

APRA and AI

No pieces yet

The 30 April 2026 letter, CPS 220, CPS 230, CPS 234, CPS 510, read carefully, mapped to AI deployments, written about as the prudential surface develops.

Read →

No. 02

Consumer Data Right

No pieces yet

The CDR rollout across banking, energy, and non-bank lending; accreditation tiers; action initiation; where AI sits in the data-recipient and action-initiator lifecycle.

Read →

No. 03

AI and work

1 piece

Where model risk, the CDR consent ledger, and the first-line build team actually sit when half that first line is software. How agentic workflows redistribute decision rights, evidence, and accountability, what that does to three-lines-of-defence and audit programme design, and what the org chart of a regulated AI team should actually look like.

Read →

No. 04

AI in internal audit

No pieces yet

Workpapers, evidence, the IIA standards as they apply to AI assurance, and the practical question of what an audit trail looks like for a model.

Read →

No. 05

Board oversight of AI

No pieces yet

What an audit-committee chair might reasonably ask. What documentary evidence the chair should expect in return. Director-level reading of the regulator file.

Read →

No. 06

AI third-party risk

1 piece

Material service providers under CPS 230, vendor contract review, exit planning, and the operational resilience layer beneath any production AI deployment.

Read →

No. 07

Australian AI regulation

No pieces yet

DISR Voluntary AI Safety Standard, the National AI Plan, OAIC privacy intersections, NSW AI Assurance Framework: the federal and state layers read together.

Read →

A note on what is and is not here

This is a writing site, not a services site.

The topics above are subjects I read closely. They are not services on offer. If a note prompts a question I can answer in writing, I will answer it in writing and the answer will become a future note. Reader correspondence is welcome at me@xiongzhitao.me.