
Australian superannuation trustees, retirement platforms and cybersecurity will face additional scrutiny in the 2027 financial year from the Australian Prudential Regulation Authority, according to its newly published plan.
The APRA laid out its priorities in the 2026-27 Corporate Plan, warning trustees and retirement platforms, in particular, which have been in the hot seat since the 2024 collapses of the Shield and First Guardian master funds, which saw investors lose more than A$1.1 billion ($788.5 million).
“Trustees offering platforms should expect intensive and risk-based supervisory oversight,” the APRA stated among its strategic objectives. “This will include ensuring entities currently subject to enforcement action take timely and appropriate remedial action. APRA will take further supervisory and enforcement action should trustees fall short of meeting their prudential obligations.”
The additional scrutiny comes ahead of the APRA consulting on a proposed package of reforms that takes into account findings from its review of platform providers and lessons learned from the collapse of Shield and First Guardian.
“The impact of the reforms will be most significant for platform trustees, given that investment menus are typically broader, products are more complex, and advisers can play a larger role in selecting and recommending investment options,” the APRA stated.
A key theme for the APRA this financial year is expected to be investment governance with respect to valuation practices and platforms. This is part of new reforms announced by Daniel Mulino, Australia’s assistant treasurer and minister for financial services, through which the APRA will be given greater oversight to ensure trustees have the financial capacity to meet their obligations under the proposed compensation scheme.
The APRA did not provide any details on any changes to the superannuation Performance Test and Comprehensive Product Performance, other than stating that the package remains “an important transparency and accountability mechanism.”
Meanwhile, the APRA stated that cybersecurity, artificial intelligence and operational resilience would remain in focus following the introduction last year of Prudential Standard CPS 230 Operational Risk Management.
The standard, which took effect on July 1, 2025, strengthened requirements for operational risk management, business continuity and oversight of material service providers. The APRA stated that entities should expect more frequent and deeper engagement on digital and AI risks and must be able to demonstrate how those risks are being managed.
The regulator stated that it would also continue reviewing implementation of CPS 230 through prudential and thematic reviews across several industries.
A version of this article originally appeared in our sister publication, Financial Standard, which like CIO is owned by ISS STOXX.
Tags: Australian Prudential Regulation Authority, Superannuation Funds

