The Vendor Concentration Blind Spot: What APRA's AI Letter Means for Every BFSI Technology Contract in Australia
source[code] | BFSI Technology Insight | 4 September 2026
Key Takeaways
- On 30 April 2026, APRA wrote to every regulated bank, insurer and superannuation trustee in Australia and named third-party and supply-chain risk as the area where AI governance practice has fallen furthest behind expectation - flagging entities "heavily dependent on a single provider for multiple AI use cases" with no tested exit or substitution strategy (APRA, 2026).
- This is not a theoretical exposure. Independent analysis of financial institutions' cloud relationships found the top three named providers account for roughly 73% of reported cloud-provider relationships, and UK regulators have already designated AWS, Microsoft and Google Cloud as Critical Third Parties in their own right (Pal Sinha, 2026; FCA, 2026).
- CPS 230, in force since 1 July 2026, already requires a material service provider register, a documented concentration risk assessment and a workable exit and substitution plan - obligations most AI vendor contracts signed before 2026 were never written to satisfy.
- APRA's expectation goes beyond paperwork: the regulator wants entities "to actively monitor supplier performance against those provisions, not just hold the paper" (MinterEllison, 2026).
- The practical question for 2026 is not whether an AI vendor's product is good. It is whether the contract, the concentration assessment and the exit plan behind it would survive a supervisory review this quarter.

A Letter That Reads Like A Findings Report, Not Guidance
APRA's 30 April 2026 letter to industry on artificial intelligence is unusual for a prudential communication. It does not set out a new principle-based framework. It reports what APRA's supervisors actually found when they looked, organised into four observation areas: governance, cyber and information security, supplier risk, and change management (Clayton Utz, 2026). Boards, the letter notes, are "still developing the technical literacy required" to challenge AI strategy, and APRA found widespread "overreliance on vendor presentations" in place of independent assurance (Clayton Utz, 2026).
Of the four areas, supplier risk is the one worth an Australian technology, risk or procurement leader's full attention, because MinterEllison's reading of the letter puts it plainly: third-party and supply-chain risk is "the widest gap between current practice and regulatory expectations" APRA identified (MinterEllison, 2026). That is a specific, testable finding, not a general warning. APRA described entities "heavily dependent on a single provider for multiple AI use cases," arrangements that lacked "contingency planning or tested exit and substitution strategies for critical AI providers," and contracts missing basic provisions on "audit rights, model updates and deviations, incident notification or changes to data handling" (APRA, 2026). It also flagged that foundation-model dependencies and fourth-party providers remain largely invisible to the entities relying on them, limiting any real ability to "independently assess model performance, bias, resilience and security" (APRA, 2026).
Put together, APRA's expectation is that regulated entities maintain "visibility over the full AI supply chain" and that contractual arrangements provide "sufficient transparency, auditability and assurance" (APRA, 2026) - not as a one-off legal review, but as an ongoing discipline.
Why Concentration Is A Real Number, Not A Hypothetical

It is tempting to treat vendor concentration as an abstract risk-management category: something every technology contract should nominally address, in the same way every contract nominally addresses force majeure. The market data says otherwise. Analysis of financial institutions' reported cloud relationships found that the top three named cloud providers account for roughly 73% of those relationships - a concentration the UK's Competition and Markets Authority separately found gives two of those providers positions of significant market power, with technical and commercial barriers that constrain how easily a bank or insurer can actually switch (Pal Sinha, 2026). The same analysis makes an important point that a purely contractual view of risk can miss: geographic distribution within a single provider's infrastructure does not equal genuine diversification, because banks spreading workloads across a provider's data centres are often still relying on the same identity systems, the same databases and the same recovery tooling as every other institution on that platform (Pal Sinha, 2026).
Regulators outside Australia have already acted on this logic. The UK's Critical Third Parties regime went live in July 2026, with AWS, Google Cloud and Microsoft among the first providers designated for direct regulatory oversight - a recognition that concentration in shared technology infrastructure has become a system-wide exposure that individual bank-by-bank contract review cannot fully address (FCA, 2026). Australia has not (yet) built an equivalent direct-oversight regime for critical technology providers. APRA's approach, for now, is to push the obligation back onto each regulated entity's own contracts, registers and exit planning - which is precisely why the AI letter's supplier-risk findings matter as much to a CTO or Head of Procurement as to a Chief Risk Officer.
What CPS 230 Already Requires That Most Contracts Don't Meet

APRA's AI letter did not invent these obligations. CPS 230 Operational Risk Management, in force since 1 July 2026, already requires every APRA-regulated entity - ADIs, general insurers, life companies, private health insurers and superannuation trustees - to maintain a comprehensive service provider management policy covering identification, monitoring, substitution and exit. Before entering an arrangement, entities must "undertake appropriate due diligence, including an appropriate selection process and an assessment of the ability of the service provider to provide the service on an ongoing basis" (APRA, 2026). Entities must identify and maintain a register of material service providers, submitted annually to APRA, and material providers explicitly include those supporting core technology and risk management functions (APRA, 2026). Critically for the AI concentration question, CPS 230 requires entities to assess "risks associated with geographic location or concentration of the service provider(s) or parties the service provider relies on," and to manage the risks of any fourth parties those material providers themselves depend on (APRA, 2026). Service agreements must also include termination provisions covering "the right to terminate both the arrangement in its entirety or parts of the arrangement," structured so the entity "can conduct an orderly exit from the arrangement if needed" (APRA, 2026).
Read the AI letter and CPS 230 together and the pattern is clear: APRA is not asking regulated entities to build a new compliance function specifically for AI vendors. It is asking them to apply an operational-resilience obligation they are already subject to, to a category of vendor relationship - foundation-model and AI-platform providers - that most procurement and legal teams had not yet treated with the same rigour as a core banking or claims-management provider. Clayton Utz's analysis makes the same point from the other direction: the AI letter's expectations "go materially beyond what CPS 220, CPS 230 or CPS 234 say in their own terms" (Clayton Utz, 2026) - meaning AI relationships now attract scrutiny above and beyond the operational-resilience baseline, not below it.
The Three Tests A Current AI Vendor Contract Needs To Pass
For a technology, risk or procurement leader trying to work out whether a specific AI vendor relationship is exposed, three tests - drawn directly from APRA's letter and CPS 230 - are more useful than a general compliance review.

The transparency test. Does the contract actually give the entity audit rights, a defined process for model updates and deviations, incident notification obligations, and visibility into changes to data handling - the specific gaps APRA named (APRA, 2026)? A contract that predates 2026 and has not been reviewed against this list almost certainly fails this test, because these were not standard clauses in most AI vendor agreements written before the letter.
The concentration test. Has the entity actually assessed how many AI use cases - not just how many contracts - depend on a single provider or a single foundation model underneath multiple nominally different products, and does that assessment extend to the fourth parties that provider itself depends on, as CPS 230 requires (APRA, 2026)? Multiple internal AI initiatives quietly built on the same underlying model API can look diversified in a vendor register and be highly concentrated in practice.
The exit test. Is there a substitution or exit plan for the arrangement, and - this is the distinction APRA's letter draws explicitly - has it actually been tested, rather than simply written and filed (APRA, 2026; MinterEllison, 2026)? A plan that has never been rehearsed against a realistic scenario (a provider outage, a pricing change, a model deprecation, a security incident) is not evidence of resilience; it is evidence that a document exists.
An arrangement can pass the transparency test and still fail the concentration test, if the contract is well-drafted but nobody has mapped how many other initiatives sit on the same provider. It can pass both and still fail the exit test, if the substitution plan has never left the page. APRA's monitoring expectation - that entities "actively monitor supplier performance against those provisions, not just hold the paper" (MinterEllison, 2026) - applies to all three, on an ongoing basis, not as a one-time contract review before signature.
The Counterpoint: Concentration Also Buys Capability
None of this is an argument for artificial diversification as a goal in itself. There are real reasons a bank, insurer or insurtech concentrates AI workloads on a small number of providers: deeper platform expertise inside a smaller vendor footprint, better negotiated pricing and support at scale, and - often decisively - the practical reality that only a handful of providers currently offer foundation models and AI infrastructure at the reliability and compliance maturity a regulated entity needs. Multiplying vendors to satisfy a concentration metric, without the internal capability to manage additional integration points, monitoring surfaces and security postures, can create more operational risk than it removes. CPS 230 itself does not mandate a minimum number of providers; it mandates that the concentration that exists be identified, assessed and planned for, which is a materially different bar than "avoid concentration at any cost."
The more accurate reading of APRA's letter is that concentration is not the violation. The absence of a tested plan for what happens if that concentrated dependency fails, is repriced, or is withdrawn - that is the finding. An entity that has consciously chosen to concentrate on one or two AI providers, documented why, assessed the fourth-party risk beneath them, and rehearsed a credible substitution path is in a materially stronger position than one running five nominally diversified vendors with no register, no concentration assessment and no exit plan for any of them.
The source[code] Perspective
In the BFSI technology engagements we support across the region, the vendor conversations that go well are rarely the ones where a provider claims to have no concentration exposure at all - in a market where a small number of foundation-model and cloud providers underpin most of the industry, that claim is rarely credible.
The conversations that go well are the ones where a delivery partner can walk through, clause by clause, exactly what the contract says about audit rights, model change notification and incident disclosure; can show a concentration assessment that includes the fourth parties sitting beneath the primary provider; and can demonstrate - not merely describe - a substitution path that has actually been exercised.
For an Australian bank, insurer or Insurtech evaluating a new AI initiative, or reviewing an existing one against CPS 230's 1 July 2026 requirements, that is a more useful evaluation question than "which vendor has the best model": can this partner show its own arrangements have already been tested against the three-test standard APRA's letter now implies for every AI relationship in the chain.
Conclusion
APRA's 30 April 2026 letter did not create a new obligation out of nothing - it made explicit that CPS 230's existing service-provider, concentration and exit-planning requirements now apply, with particular scrutiny, to AI vendor relationships that most procurement and legal teams had not yet reviewed against that standard.
The gap APRA found was not that entities use a small number of AI providers; concentration in a market this new, with this few credible providers, is close to unavoidable. The gap was contractual transparency that does not reflect operational reality, concentration that has never been formally assessed, and exit plans that exist on paper but have never been tested. For every BFSI technology and risk leader in Australia, the practical task this year is not choosing a different vendor. It is being able to answer, with evidence rather than assurance, whether the contract, the concentration assessment and the exit plan behind the current one would survive a supervisory review today.
If you're reviewing an AI vendor contract against CPS 230's concentration and exit-planning requirements, we're happy to walk through the three-test framework against your specific arrangement - transparency, concentration and exit, in that order. Talk to us!
Frequently Asked Questions
What did APRA's April 2026 AI letter say about vendor risk? APRA identified supplier and third-party risk as the area with the widest gap between current industry practice and regulatory expectations, citing entities heavily dependent on a single AI provider across multiple use cases, contracts missing basic provisions like audit rights and incident notification, and exit or substitution strategies that had never been tested (APRA, 2026; MinterEllison, 2026).
Does CPS 230 already cover AI vendor concentration risk? Yes. CPS 230 Operational Risk Management, in force since 1 July 2026, requires APRA-regulated entities to maintain a material service provider register, assess concentration risk including fourth-party dependencies, and hold tested exit and substitution plans - obligations that apply to AI vendors as much as to any other material service provider (APRA, 2026).
How concentrated is the AI and cloud vendor market for financial institutions? Independent analysis of reported cloud-provider relationships among financial institutions found the top three named providers account for roughly 73% of those relationships, a concentration regulators in the UK have already responded to by designating AWS, Google Cloud and Microsoft as Critical Third Parties (Pal Sinha, 2026; FCA, 2026).
Is having multiple AI vendors the solution to concentration risk? Not necessarily. CPS 230 does not require a minimum number of providers; it requires that whatever concentration exists is identified, assessed and planned for. Diversifying vendors without the internal capability to manage the additional integration and monitoring burden can introduce more operational risk than it removes.
What should a technology or risk leader do first in response to the AI letter? Review current AI vendor contracts against three tests: whether they contain the specific transparency provisions APRA named (audit rights, model change notification, incident disclosure), whether a formal concentration risk assessment has been completed including fourth-party dependencies, and whether the exit or substitution plan has actually been tested rather than only documented (APRA, 2026; MinterEllison, 2026).
Reference List
Australian Prudential Regulation Authority [APRA] (2026) APRA Letter to Industry on Artificial Intelligence (AI). Available at: https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai (Accessed: 4 September 2026).
Australian Prudential Regulation Authority [APRA] (2026) CPS 230 Operational Risk Management. Available at: https://www.apra.gov.au/standards/cps-230 (Accessed: 4 September 2026).
Clayton Utz (2026) APRA's AI letter: a shift from framework to targeted expectations. Available at: https://www.claytonutz.com/insights/2026/may/apras-ai-letter-a-shift-from-framework-to-targeted-expectations (Accessed: 4 September 2026).
Financial Conduct Authority [FCA] (2026) UK financial regulators to begin overseeing Critical Third Parties announced by Treasury. Available at: https://www.fca.org.uk/news/statements/uk-financial-regulators-overseeing-critical-third-parties-announced-treasury (Accessed: 4 September 2026).
MinterEllison (2026) APRA's AI Letter: A Wake-up Call for Managing Your Third-Party Suppliers - What Banks and Insurers Must Fix Before Enforcement. Available at: https://www.minterellison.com/articles/apra-ai-letter-third-party-suppliers (Accessed: 4 September 2026).
Pal Sinha, B. (2026) The Hidden Concentration Risk in Banking's Dependence on Microsoft, Amazon and Google. Global Banking & Finance Review. Available at: https://www.globalbankingandfinance.com/the-hidden-concentration-risk-in-banking-s-dependence-on-microsoft-amazon-and-google/ (Accessed: 4 September 2026).