In short
Executive Summary
- Start with outcomes about people, not with an AI inventory, or you will map the chatbot and miss the scorer
- Four columns are enough: workflow, person affected, software or vendor, personal information used
- Ninety minutes is a first map for legal and the board, not a complete audit of every system
- Mark Unsure as Unsure. A blank looks like a no, and a no you have not checked is the usual December surprise
Detail
Overview
Most organisations start this work in the wrong place. They ask IT for the AI register. They get a list of copilots, licences and experiments. None of that tells you whether software is already deciding who gets a shift, a refund, a shortlist or a hold on their account.
Sit down with the people who run the work. Hiring. Credit or collections. Claims. Customer service. Fraud. Rostering. Pricing for a named customer. Ask one question per area: where does a computer program recommend, rank, score, flag, route or complete an outcome about a person, using information about that person.
Write four columns. Workflow, in the language the team actually uses. Person affected: candidate, customer, claimant, staff member, account holder. Software or vendor, even if the name is embarrassing. Personal information used, in kinds: identity, financial, behavioural, employment, location. If nobody in the room can fill a cell, write Unsure. That cell is now a work item, not a comfort.
Then apply three filters. Does this affect a person in a way they would notice. Is personal information in the input. Is a computer program doing more than storing the file. If all three are yes or unsure, it stays on the map. If the first is no, it can wait.
Ninety minutes is enough for a first list across the obvious functions. It is not enough to inspect every configuration. Stop when you can brief privacy counsel with named workflows rather than with a feeling that “we probably have some AI”. The Rapid Review exists for the pass that tests likely exposure and turns the list into a decision map. This hour and a half exists so that pass is not a fishing trip.
Commercial impact
Why It Matters for Organisations
APP 1.7 drafting fails when legal is asked to write kinds of decisions into a policy and operations cannot name the decisions. The deadline does not create the workflows. It only creates a date by which the policy may have to mention them.
A 90-minute map also stops two expensive mistakes. The first is treating every generative tool as in scope and burning the autumn on the wrong systems. The second is assuming a human in the loop means there is nothing to disclose, while staff are accepting ranked lists they have not read.
Boards do not need a 40-page register from this sitting. They need to see whether the organisation can produce a list at all. If 90 minutes with the people who run the work cannot produce one, you do not have a documentation problem. You have an ownership problem, and December will not fix it.
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
In a 90-minute session with an operations director and a people-and-culture lead, the live list was recruitment ranking, rostering, and a performance dashboard that fed bonus conversations. The generative writing assistant never made the cut. That is the usual pattern: the tools with a demo are not the tools with a decision.
A claims manager said “the system suggests a settlement range and we can override it”. The useful follow-up was how often they override, and whether a reason is required. The map captured the workflow as substantially supported until someone could show independent review. Counsel then had a fact to test, not a slogan.
A finance team listed a collections scorer they had forgotten was still on. It used account history and contactability flags. Nobody had included it in the AI steering pack because it was “just the old bureau tool”. APP 1.7 does not care what you branded it.
When a cell stayed Unsure after 90 minutes, we left it Unsure and assigned an owner to confirm within a week. Pretending it was out of scope would have been the faster room and the worse policy.
What to do
Key Takeaways
- Map outcomes about people first, then name the software, or the AI register will hide the real decisions
- Use four columns and allow Unsure; do not convert ignorance into a no
- Treat human approval as a fact to test, not as an automatic exclusion
- Stop at a list that privacy counsel can use, then deepen the high-impact workflows
- A Rapid Review is the next pass when the first map shows likely exposure before 10 December 2026
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Check whether policy, accountability, and compliance are keeping pace with deployment. The assessment scores governance and decision control alongside four other dimensions.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Where this sits
Explore This Pillar
Next step