The Assurance You Could Not See
[Cyber Sunday Series: Cyber Guide for NZ Boards and Cyber News Cycle] | [Part 10: The Accountability Reckoning] | [CN#6: The Assurance You Didn't Verify]
The Privacy Commissioner just handed New Zealand boards a structural verdict. Not a technical incident report. Not a compliance checklist. A structural verdict: the assurance architecture that most organisations rely on for third-party data handling does not produce the governance outcome it promises.
In December 2025, 99,416 individuals had their health information compromised in the ManageMyHealth breach. The Office of the Privacy Commissioner completed Phase 1 of its inquiry in May 2026. What the report found was not a story about a vendor failing. It was a story about a governance model that had no mechanism to detect the failure.
Both ManageMyHealth and its third-party processor breached Rule 5 of the Health Information Privacy Code. The processor had no direct regulatory relationship with the Privacy Commissioner. Enforcement had to route through the primary controller. The commissioner's recommended remedy is direct OPC jurisdiction over third-party processors, a structural reform that requires legislative action.
Read that again. A processor handling health records for nearly one hundred thousand New Zealanders was not regulated by the body responsible for protecting those records. The primary controller had contractual obligations. The processor had none it could be held directly to account for. The assurance architecture was contractual, and the contract produced no real-time visibility into whether the code was being met.
At the same time, Kordia's 2026 Cyber Security Report landed a companion finding: 24% of New Zealand organisations now rank staff AI-misuse as a top-three security risk, up from 16% in 2025. Nearly half of surveyed organisations have experienced a cyber attack.
These two findings describe the same governance failure from opposite directions. The OPC describes it from outside the organisation: what happens when processing moves to a vendor your board cannot see. Kordia describes it from inside the organisation: what happens when processing moves to AI tools your board has not authorised. Both are assurance blind spots. Both trace to the same architectural gap. Both land on the board.
The Governance Architecture Finding
The MMH breach has been this series' primary case study since Part 1. Earlier articles covered the scale, the Northland concentration, the disproportionate impact on Māori communities, and the fiduciary risk exposure that follows when sensitive health data leaves organisational control. This article is not a retelling.
The Phase 1 report closes something open. It converts the incident from a data point about a breach into a formal regulatory finding about a governance architecture. Rule 5 of the Health Information Privacy Code governs how health information must be managed: agencies must ensure information is protected by security safeguards that are reasonable in the circumstances. The finding is that both MMH and its processor failed this standard.
The architectural implication is specific. The processor operated outside direct regulatory reach. No direct Privacy Commissioner jurisdiction existed over a party that handled health records for nearly one hundred thousand New Zealanders. The accountability chain required routing through the primary controller, who was itself in breach and who had no real-time visibility into processor compliance. A contract existed. Assurance did not.
Directors reading this need to translate it into their own environments. Your organisation processes data. Some of that processing is done by third parties under contract. For each of those contracts, ask: does that processor have a direct relationship with the relevant regulator? If the processor breaches its obligations, what is the enforcement path? Is there a mechanism in the contract that produces real-time compliance visibility, or does the contract simply state obligations that you have no way to verify are being met?
For health data, the OPC Phase 1 finding is explicit: contractual control without regulatory jurisdiction produced a governance gap. For personal data more broadly, the structural logic is identical. A data processing agreement is not the same as a governance architecture.
The Internal Mirror: Shadow AI as a Second Blind Spot
The Kordia finding on shadow AI is the internal equivalent of the third-party processor gap.
When a staff member uses an AI tool the organisation has not assessed or authorised, data moves to a processing environment the board cannot see. The organisation may have contractual relationships with approved AI vendors. It has no contractual or governance relationship with the AI tools staff are using independently. The assurance blind spot is structurally identical to the processor gap: processing is occurring, data is moving, and the governance layer has no line of sight.
The eight-percentage-point increase in AI-misuse concern from 2025 to 2026 reflects a real operational shift. As frontier AI tools become accessible without enterprise procurement, the gap between what a board believes its data environment looks like and what it actually looks like expands. Staff are not acting maliciously. They are acting practically, reaching for tools that work. The governance consequence is the same as malicious action: data is outside the controlled environment, and the board has no assurance architecture to detect or respond to it.
The compound risk is in the intersection. An organisation with a third-party processor gap on one side and a shadow AI gap on the other has two categories of processing it cannot see. The OPC finding and the Kordia finding arrive in the same week and describe the perimeter of a governance problem that most boards have not yet bounded.
The Agentic AI Amplification
There is a further layer. The Five Country Council, with the National Cyber Security Centre NZ as co-author, published guidance on 1 May 2026 titled "Careful Adoption of Agentic AI Services." The guidance identifies indirect data access chains in agentic AI deployments as a Tier 1 governance concern.
This is the OPC finding translated into the AI context. An agentic AI system does not merely process data you provide it. It operates with delegated authority, accesses systems on behalf of users, and may invoke further tools and services in the course of completing a task. Each of those invocations creates a data processing relationship the organisation may not have mapped.
The processor gap the OPC identified in the MMH context was visible in principle: MMH knew it had engaged a processor. What it lacked was real-time compliance visibility and a direct regulatory mechanism. The agentic AI equivalent can be structurally invisible: an AI agent that invokes external tools or services may create data processing relationships the organisation is not aware of and cannot audit.
The Five Country Council framing is precise: the concern is not that agentic AI is inherently unsafe. The concern is that indirect data access chains create governance blind spots that outpace the assurance architecture most organisations have in place. For boards already managing the processor accountability gap the OPC has identified, the agentic context is the next instantiation of the same problem.
What the Assurance Architecture Question Requires
The OPC Phase 1 recommendation for direct Privacy Commissioner jurisdiction over processors is a legislative reform. It requires Parliamentary action. Boards cannot act on it directly. But the governance question the recommendation highlights can be addressed now, at board level, without waiting for legislative reform.
Three questions follow from the OPC finding and the Kordia data together:
First: What processes sensitive data on your behalf? This is an existence question, not an adequacy question. Before a board can assess whether its third-party governance is adequate, it needs a complete map of what third parties hold or process personal, health, financial, or other sensitive information. Most organisations have incomplete maps.
Second: What is the real-time compliance mechanism for each of those processors? A data processing agreement states obligations. It is not, by itself, an assurance mechanism. Assurance requires a mechanism by which non-compliance produces a signal before a breach occurs. For most processor relationships, no such mechanism exists. The OPC finding is that this is not adequate.
Third: Where does AI processing occur that is not covered by the first two questions? This is the Kordia question. Staff using unauthorised AI tools are not captured by vendor contracts. The data processing is occurring outside the governance perimeter. The assurance architecture does not reach it.
The Audit of Intent framework from the Cyber Guide series applies here. An audit confirms that a control exists. An Audit of Intent confirms that the control is producing the intended governance output. The MMH Phase 1 finding is an Audit of Intent failure at scale: controls existed (the data processing agreement), but they produced no real-time visibility into whether the code was being met.
The Cultural Mana Raraunga Dimension
The 99,416 individuals affected include a disproportionate concentration of Māori health records. Earlier articles in this series documented that the breach was concentrated in Northland, a region with significantly higher Māori population proportions than the national average. Breaches affecting Māori health data carry a specific governance dimension that goes beyond Privacy Act compliance.
Te Mana Raraunga, the Māori Data Sovereignty Network, frames health data as taonga: it carries whakapapa, cultural identity, and community meaning that is not adequately captured in frameworks built around individual privacy rights alone. When a processor handling Māori health data has no direct regulatory relationship with the Privacy Commissioner, the accountability gap is not merely procedural. It is a gap in the governance architecture for taonga.
For boards governing organisations that hold or process Māori health data, the OPC Phase 1 finding is not just a risk management signal. It is a governance obligation under the Kaitiakitanga framework: to actively protect what is held in trust, not merely to contract its protection to a third party and assume the contract is sufficient.
The direct-liability reform the OPC has recommended would extend regulatory reach to processors. Until that reform is enacted, the board is the governance mechanism.
The National Cyber Security Strategy Context
The NZ Cyber Security Strategy 2026-2030 includes Action 8, the proposed civil pecuniary penalty instrument. As the strategy progresses, the regulatory context for data governance failures is moving in one direction: increasing liability for organisations that cannot demonstrate proactive governance.
The framing here is compliance context, not policy evaluation. The trajectory of regulatory consequence is a material fact for boards assessing their governance posture. Action 8 is not yet enacted. The direction is established.
For boards, the practical implication is timing. The governance gap the OPC Phase 1 finding describes is a liability exposure that exists now, under the current Privacy Act 2020 regime, not only under a future penalty framework. Section 123 of the Privacy Act 2020 allows the Human Rights Review Tribunal to award damages for interference with privacy, including distress and loss of dignity. Compliance notices are already in train from the OPC. The regulatory ratchet is moving.
The boards that address the third-party governance gap proactively, before a breach and before a compliance notice, are in a materially different position than those that wait for the enforcement instrument to clarify expectations.
The assurance architecture question is not a question about future regulation. It is a question about current fiduciary duty.
The same week that the Five Country Council warned that agentic AI creates indirect data access chains your governance architecture may not reach, the Privacy Commissioner confirmed that a processor handling health records for nearly one hundred thousand New Zealanders had no direct regulatory relationship with the body responsible for protecting those records. These are not separate signals. They are the same signal, arriving from two directions, describing the outer boundary of a governance problem that contracts alone have never been sufficient to address.
The processor gap is a supply chain integrity question. Organisations within the Five Eyes grouping handle data processed through partner networks every day. The accountability architecture for those chains is not contractual: it is structural, built on mandatory supply chain transparency requirements, security accreditation regimes, and direct regulatory oversight of processors regardless of affiliation. The Five Country Council guidance on agentic AI, co-authored by the National Cyber Security Centre New Zealand, applies the same architectural logic to the commercial context. Organisations that handle defence-adjacent data, including veterans' health records, personnel administration systems, or information subject to security classification by association, should read the OPC Phase 1 finding as structural confirmation of what allied supply chain governance has always required: accountability follows the data, not the contract.
What is your organisation's real-time compliance mechanism for the processors that hold your sensitive data, and when did a board director last verify it was working?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a Wellington-based enterprise architect, security specialist, and technology strategist with more than 30 years of experience across New Zealand government, banking, transport, and aviation. He is the founder of Te Pono Limited and an Associate Member of the Institute of Directors New Zealand. He holds TOGAF, IAPP, and AMInstD credentials. The Hamberger Report: Cyber Guide for New Zealand Boards is the definitive board-level cybersecurity governance guide.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
[1] Office of the Privacy Commissioner. "Phase 1 Inquiry Report: ManageMyHealth." May 2026. https://www.privacy.org.nz [verify URL at publication]
[2] Kordia. "Cyber Security Report 2026." Kordia Research, 2026. https://www.kordia.co.nz [verify URL at publication]
[3] National Cyber Security Centre New Zealand. "Careful Adoption of Agentic AI Services." Five Country Council, 1 May 2026. https://www.ncsc.govt.nz [verify URL at publication]
[4] New Zealand Government. "New Zealand Cyber Security Strategy 2026-2030." Department of the Prime Minister and Cabinet, 2026. https://www.dpmc.govt.nz [verify URL at publication]
[5] Office of the Privacy Commissioner. "Health Information Privacy Code 2020." https://www.privacy.org.nz/privacy-act-2020/codes-of-practice/hipc2020/
[6] Te Mana Raraunga. "Maori Data Sovereignty Network: Principles." https://www.temanararaunga.maori.nz
[7] New Zealand Parliament. "Privacy Act 2020." https://www.legislation.govt.nz/act/public/2020/0031/latest/LMS23223.html

