How to Use This Checklist
Work through each section in order. Mark items complete only when you have documented evidence, not just verbal confirmation. The evidence trail is the entire point. If ASIC, OAIC, or APRA investigates, they'll ask for documentation, not assurances.
Each item includes a compliance requirement, the relevant regulation, a suggested evidence format, and a recommended deadline. Items marked "Critical" must be completed before 10 December 2026. Items marked "Priority" should be completed within 90 days. Items marked "Standard" should be completed within 6 months.
Section 1: AI System Inventory (Priority)
- Complete inventory of all AI and automated decision-making systems
- Classification of each system by risk level (affects customers, affects employees, internal only)
- Documentation of data inputs and outputs for each system
- Identification of which systems fall under ADM transparency requirements
- Mapping of AI vendor relationships and data processing agreements
Regulation: Privacy Act 1988, ASIC REP 798 Evidence: Spreadsheet or register listing all AI systems with risk classifications Deadline: Within 30 days of starting compliance programme
Most organisations undercount their AI systems. Credit scoring, fraud detection, customer service routing, HR screening, automated email responses, recommendation engines, pricing algorithms. I've audited firms that listed two systems initially and documented eleven by the end of the inventory.
Section 2: OAIC Privacy Compliance (Critical)
- Privacy policy reviewed for accuracy and currency
- APP 1.4 compliance verified (privacy policy covers all actual data practices)
- Consumer data collection practices audited against OAIC guidance
- Data breach response plan updated to include AI-specific scenarios
- Staff trained on privacy obligations when using AI tools
Regulation: Privacy Act 1988, APP 1.4, APP 11 Evidence: Updated privacy policy, training records, breach response plan Deadline: Immediately (OAIC Privacy Sweep is active)
The OAIC Privacy Sweep (January 2026) targeted 60 entities with penalties up to $66,000 per non-compliant policy. If your privacy policy hasn't been reviewed in the past 12 months, it almost certainly doesn't cover your current AI usage.
Section 3: ADM Transparency (Critical)
- Automated decision-making systems identified (all systems that "significantly affect rights or interests")
- Plain-English descriptions written for each ADM system
- Privacy policy updated to disclose ADM systems, their purpose, and their impact on individuals
- Consumer notification process established for automated decisions
- Review and appeal mechanisms documented for ADM decisions
Regulation: Privacy and Other Legislation Amendment Act 2024 Evidence: Updated privacy policy with ADM disclosures, consumer notification procedures Deadline: 10 December 2026 (no extensions)
The scope is broader than most organisations expect. Any system that makes automated decisions affecting credit, insurance, employment, service access, or pricing likely qualifies. Start the inventory early. The firms I've worked with typically take 2 to 4 weeks for a thorough ADM mapping.
Section 4: ASIC Governance (Priority for Financial Services, Recommended for All)
- AI governance framework approved by the board
- Fairness and bias policies documented for each customer-facing AI system
- Transparency policies documented (how AI decisions are explained to customers)
- Accountability framework in place (named human accountable for each AI system)
- Bias testing conducted or scheduled for customer-facing AI
- Board minutes reflect AI governance discussions at least quarterly
Regulation: Corporations Act s180, ASIC REP 798 Evidence: Board-approved governance framework, fairness policies, bias testing reports, board minutes Deadline: Within 90 days for financial services. Within 6 months for other sectors.
ASIC's enforcement focus is financial services, but the principles apply broadly. Any organisation deploying AI that affects customers should assume these standards will eventually apply to them. Building governance now is cheaper than retrofitting later.
Section 5: APRA Compliance (Financial Services Only)
- CPS 230 operational risk assessment includes AI systems
- Human accountability documented for each AI system (not per-transaction review)
- AI vendor management aligned to CPS 231 outsourcing requirements
- Information security for AI systems aligned to CPS 234
- Incident response procedures cover AI system failures
Regulation: APRA CPS 230, CPS 231, CPS 234 Evidence: Updated operational risk framework, accountability documentation, vendor assessments Deadline: Immediately (CPS 230 live since July 2025)
Key nuance: APRA requires human accountability for AI systems, not human review of every AI decision. A human must be responsible for the algorithm, its operations, and the outcomes it produces. Don't over-engineer per-transaction review when APRA's actual requirement is system-level accountability.
Section 6: Data Security for AI (Standard)
- Enterprise-grade AI tools with data processing agreements replace consumer accounts
- Data sovereignty confirmed (know where AI processes your data geographically)
- Access controls implemented (only authorised personnel use AI on sensitive data)
- Data retention policies cover AI-processed information
- Logging and audit trails enabled for AI system decisions
Regulation: Privacy Act APP 11, APRA CPS 234 Evidence: Vendor agreements, data flow documentation, access control records Deadline: Within 6 months
If your team uses personal ChatGPT or Claude accounts to process customer data, that's an APP 11 risk. Enterprise accounts with data processing agreements aren't optional. They're a regulatory requirement when AI handles personal information.
Section 7: Ongoing Monitoring (Standard)
- Quarterly AI risk register review scheduled
- Annual AI governance framework review scheduled
- Regulatory monitoring process in place (ASIC, OAIC, APRA updates)
- AI system performance monitoring established (accuracy, fairness metrics)
- Staff AI usage policies reviewed and updated annually
Evidence: Review schedules, monitoring dashboards, policy update records Deadline: Establish within 6 months, then ongoing
Related Resources
- AI Governance Framework: Full governance framework
- AI Risk Register Template: Risk tracking template
- ASIC AI Director Duties: Director obligations
- Privacy Act AI Compliance: ADM transparency guide
Download the checklist, assign an owner for each section, and set your deadlines. If you need help completing it, the ADM Transparency Sprint (6 weeks) covers Sections 1 through 3 with guaranteed compliance by 10 December 2026.
Related Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.