top of page
Nuj_Super_Logo_600px.jpg

Regulatory Reporting and Why AI at Nuj Will Always Nudge, Never Steer

Writer: Team Nuj
Team Nuj
1 day ago
6 min read

Superannuation regulatory reporting has become heavier over the past several years. The Superannuation Data Transformation programme has widened in scope and gone deeper in granularity, the stakeholders watching the output have multiplied, and the tolerance for error has, if anything, tightened. What hasn’t grown in step is the size of the teams doing the work, even as scrutiny and consequence have increased. Given that, AI's appeal to a stretched reporting function isn't a fad. It’s a rational response to the cost pressures specific to this industry, compounded by real pressure to keep pace.


However, regulatory reporting is not an ordinary place to apply “move fast and see what happens.” The space comes with significant consequences if things are missed or incorrectly done. A fund’s reporting team exists to protect members and satisfy a regulator, not to experiment on either. That tension, the pull towards AI’s obvious efficiency on one side and the cost of getting it wrong on the other, is the tightrope we’re all now walking. We’ve been weighing it in three ways, namely what APRA keeps telling the industry, what we hear directly from funds, and what our own experience and judgement tells us.






What APRA keeps telling us


Over the past several months, APRA has approached the same message from three different directions. These include a letter to industry on AI in April, insights from its joint roundtables with ASIC on frontier AI and operational resilience published in August, and its own 2026-27 corporate plan, which sets out plans for APRA itself to become a more AI-enabled regulator. Read together, the position is consistent enough to state plainly: adopt AI, but govern it rigorously.


The April letter highlighted three key points that are worth calling out directly. First, boards often rely on vendor presentations instead of independently examining what a model actually does, and few have real visibility into what's underneath their AI vendors themselves. Second, assurance and audit practices designed for stable, rule-based systems don’t translate well to adaptive models. For us, that’s a design constraint: anything AI touches must be checkable after the fact, not just seem reasonable in the moment. Third, AI is too often governed like any other IT project, rather than as something with its own lifecycle risks. We believe the answer is to build governance into the platform from the start, not add it later.


The corporate plan adds another important consideration. APRA is developing its own AI-enabled supervision tools to identify risks earlier and analyse submissions more thoroughly. Reports that look right on the surface may not stand up to a regulator that is becoming more skilled at spotting what doesn’t add up.


Naming these points doesn’t mean we have all the answers. It’s simply the most transparent way to show how we’re measuring our own approach against standards set by others, not just by ourselves.



What the industry keeps telling us


The second input is less formal but just as useful: what we hear directly from super funds. Across the conversations we’ve hosted with super executives and teams, one theme comes up consistently: a clear line between AI helping someone understand their data and AI touching the data itself. Interrogating figures for anomalies, benchmarking, and year-on-year or quarter-on-quarter trends is a properly useful role for AI, because the person asking the question can immediately see and judge the answer. Preparing or reviewing what actually gets submitted is a different category of risk entirely. A hallucinated figure quietly introduced at that stage might not be obvious to anyone, and one wrong number in a regulatory submission can have severe consequences. The funds we talk to draw that line deliberately, and so do we.


We’re also hearing a shift in how teams interact with AI: moving from simply instructing a system to actively engaging with its output. AI results are something to question and test, not just accept, because these tools behave differently from the deterministic systems reporting teams have relied on. There’s also a clear need for a quality assurance process with multiple checks, rather than relying on a single model’s answer.


What we see from the inside


The third perspective comes from our own judgement and experience, with specialists across data, security, engineering, regulatory practice, and AI. They know first-hand where this technology actually stands today, not just how it’s marketed. Bringing these disciplines together enables us to build, and it keeps our expectations grounded and realistic.






Our answer: AI joins the team, it doesn’t take the wheel


Nuj is pronounced 'nudge.' Our logo captures that idea, as a tugboat nudges much larger vessels safely into harbour or out to sea. It doesn’t take the wheel or claim credit for the journey. That principle has guided us from the start, and it fits perfectly with the role we see for AI in regulatory reporting: present, helpful, and never in control. It’s our answer to the challenges above. AI should be transparent about its limits, easy to check after the fact, and never where accountability sits.


In practice, AI at Nuj is designed to support the person or team doing the work, whether that's here at Nuj or at the super funds we work with, not to replace their judgement or take credit for their results. As we build out our own AI capability, we treat people's expertise, ours and our clients', as just as important as the technology itself. We're trying to enable teams, ours and yours, with more insight and less day-to-day friction, so they can be more proactive than reactive.



What that looks like today


A good example is Nujie, our natural language tool for querying reported data. It lets you ask questions in plain language and get fast, clear answers. Nujie doesn’t submit, decide, or act on your behalf. It’s more like a well-informed colleague than an autopilot.


To take this further, we recently held our first internal hackathon asking, “Could an AI tool help a client interrogate their own data and gain real insight into member assets and fee structures, faster and more intuitively?” Our SMEs from data, security, engineering, and regulatory practice spent the day together tackling the challenge. By the end, we had a working prototype and a much clearer sense of what comes next. So, stay tuned.




The bigger picture


We don't have this all solved, and we don’t believe anyone does. Questions about accuracy, oversight and exactly where the line sits between “AI assists” and “AI decides” are ones we are working through carefully.


KPMG’s latest global AI in finance survey, covering over a thousand senior finance leaders across 20 countries in 2026, found that while more than three-quarters of organisations now use AI in financial planning, reporting, and analysis, only about 23% say it exceeds expectations. The main driver of that gap is governance and audit readiness. Organisations with clear AI audit evidence saw three to six times the rate of significant improvement compared to those without it. For example, 33% versus 6% on error reduction, and 42% versus 14% on confidence to scale further. In short, being ready for assurance predicts performance better than how quickly you adopt AI.


A separate, slightly earlier KPMG study of Australian and global finance leaders found that concerns rise sharply when generative AI is involved. Worries about data sovereignty nearly doubled, and issues like bias, hallucination, and cyber-security were flagged consistently. A parallel KPMG and University of Melbourne trust study showed that while half of Australians use AI regularly, only about 36% say they trust it, and 78% are concerned it could produce a bad outcome.


This gap between AI adoption and actual trust mirrors the tension we started with. There’s real appeal, real caution, and both are entirely justified.


Superannuation is a particularly clear test case, given the high level of regulatory scrutiny and the stakes involved. It's why we built here first. The challenge of applying AI in a domain where mistakes have real consequences isn't unique to this industry, and we don't expect the solution to be either.


What we can say with confidence is the principle that guides us. AI at Nuj nudges; it doesn't steer. That keeps accountability with people, not models, as APRA expects. 




Sources:





Comments


bottom of page