Define the scope
Identify the technologies and uses covered. Include relevant vendor features, models, agents and automated workflows, while recognising that different obligations use different definitions.
An AI inventory and automated-decision disclosure map may overlap. They are not interchangeable: a rules-based decision can matter for privacy disclosure without being described as AI.
Identify the use and owner
Record purpose, workflow, affected people, information, systems and accountable business owner. Distinguish confirmed facts from initial declarations.
The owner should understand the operating consequence, not only the procurement history.
Assess the consequence
Examine plausible benefits, failures and harms in context. Consider quality, privacy, security, fairness, resilience, vendor dependence and autonomy.
Bring in specialists where needed. A single aggregate score should not conceal a legal issue or an unacceptable failure mode.
Decide what may proceed
Define the approval route, evidence, restrictions and deployment conditions. Experimentation and consequential production use should not rely on the same standard.
Record the limits. Approval for one dataset or action is not permission for every future use of the product.
Put controls into the workflow
Implement boundaries in access, interfaces, operating procedures and review. Make the human role specific and test whether it works.
Policy describes what should happen. Technical and operational evidence helps establish what can and does happen.
Monitor, respond and change
Track performance, incidents, complaints, exceptions and material changes. Identify who receives alerts, who can interrupt the system and how work continues if it becomes unavailable.
Reassess changes to model, data, tools, permissions, purpose or affected population. Retire access and information appropriately when a use ends.
Integrate with existing governance
Finance, procurement, privacy, security, risk and internal audit already make decisions AI touches. Connect to those processes rather than creating an isolated committee for everything.
NIST's AI Risk Management Framework is a useful voluntary reference. It does not certify an organisation or replace Australian law. The operating practices here are our synthesis, not a mandatory statutory checklist.
Test the framework on one actual use
Follow it from purpose to approval, controls, monitoring and response. Where evidence is missing, assign an action rather than filling the gap with generic policy language.
Bring the AI systems already in use and the governance question the board needs answered.
Discuss your AI problemRelated Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.