APRA’s quarterly download email is the start of an access check
The APRA Connect update sits between a familiar IT log and a security review of reporting access.

APRA will provide entities with a quarterly email extract of APRA Connect download activity, including download dates and times and the IP addresses of the machines used to initiate them. Those details may look like an answer to who accessed what. But APRA says a follow-up process can provide usernames and file names for transactions the entity identifies as outside its internal security policies. APRA’s support material
Suppose an entity sees an unfamiliar IP address in the extract. Before reading on, ask what the email alone would let a reviewer identify: the person, the file, or the download event? APRA lists dates, times and machine IP addresses. It describes usernames and file names as further information available through follow-up for transactions identified as outside internal security policies.
That distinction matters because APRA Connect is a data collection tool used to submit financial, statistical and prudential information to APRA. The access extract is intended to help entities validate and monitor access, and maintain compliance with their internal security policies. It is a prompt to check activity, rather than a complete account of every transaction. APRA’s support material
Give the review a route
An entity can decide in advance who receives or reviews the extract, who can explain the systems expected to generate downloads, and who can assess an entry against internal security policies. Those responsibilities may involve different people. The important point is to make clear who checks an unfamiliar entry and who can use APRA’s follow-up process if more detail is needed.
A practical review could compare the recorded activity with the access the entity expects, then identify entries that need investigation. An unfamiliar IP address is a reason to check, not by itself an answer about who accessed a file. Where a transaction is identified as outside internal security policies, APRA says its follow-up process can provide further information, such as usernames and file names. APRA’s support material
APRA’s quarterly email extracts will give entities download dates and times and the IP addresses of machines used to initiate downloads, with a follow-up process for further transaction information, including usernames and file names.1
References
- APRA Connect support material: https://www.apra.gov.au/apra-connect/apra-connect-support-material
