Skip to main content

    Framework

    Build governance around the lifecycle of the work.

    An AI governance framework explains how the organisation identifies a use, decides whether it is appropriate, controls deployment and responds when conditions change. People should know what they may do, what evidence is needed and who has authority to decide.

    Define the scope

    Identify the technologies and uses covered. Include relevant vendor features, models, agents and automated workflows, while recognising that different obligations use different definitions.

    An AI inventory and automated-decision disclosure map may overlap. They are not interchangeable: a rules-based decision can matter for privacy disclosure without being described as AI.

    Identify the use and owner

    Record purpose, workflow, affected people, information, systems and accountable business owner. Distinguish confirmed facts from initial declarations.

    The owner should understand the operating consequence, not only the procurement history.

    Assess the consequence

    Examine plausible benefits, failures and harms in context. Consider quality, privacy, security, fairness, resilience, vendor dependence and autonomy.

    Bring in specialists where needed. A single aggregate score should not conceal a legal issue or an unacceptable failure mode.

    Decide what may proceed

    Define the approval route, evidence, restrictions and deployment conditions. Experimentation and consequential production use should not rely on the same standard.

    Record the limits. Approval for one dataset or action is not permission for every future use of the product.

    Put controls into the workflow

    Implement boundaries in access, interfaces, operating procedures and review. Make the human role specific and test whether it works.

    Policy describes what should happen. Technical and operational evidence helps establish what can and does happen.

    Monitor, respond and change

    Track performance, incidents, complaints, exceptions and material changes. Identify who receives alerts, who can interrupt the system and how work continues if it becomes unavailable.

    Reassess changes to model, data, tools, permissions, purpose or affected population. Retire access and information appropriately when a use ends.

    Integrate with existing governance

    Finance, procurement, privacy, security, risk and internal audit already make decisions AI touches. Connect to those processes rather than creating an isolated committee for everything.

    NIST's AI Risk Management Framework is a useful voluntary reference. It does not certify an organisation or replace Australian law. The operating practices here are our synthesis, not a mandatory statutory checklist.

    Test the framework on one actual use

    Follow it from purpose to approval, controls, monitoring and response. Where evidence is missing, assign an action rather than filling the gap with generic policy language.

    Bring the AI systems already in use and the governance question the board needs answered.

    Discuss your AI problem

    Related Topics

    Explore This Pillar

    Go deeper with the matching master pillar and the most relevant supporting topics for this page.