What this covers
Most organisations already use AI in more places than they have recorded: staff using public tools, vendors switching on AI features inside existing platforms, and models that shape decisions without a named owner. Governance starts by making that visible, then deciding, system by system, what level of scrutiny each one needs.
- AI inventory and use-case register. Where AI is used, by whom, on what data, and who owns it.
- Risk and impact assessments. Structured assessments proportionate to each use case, including the AI impact assessments expected of Australian Government agencies.
- Compliance mapping. Your systems mapped against the obligations that apply to you, such as the Australian Government's Policy for the responsible use of AI in government, the National AI Centre's Guidance for AI Adoption, the Privacy Act 1988 and relevant state frameworks.
- Policies, roles and accountability. An AI policy people can follow, named accountable owners, approval pathways and reporting your executive or board can act on.
State government frameworks
NSW and Queensland agencies assess AI projects against their own state frameworks. We support agency teams in preparing those assessments and the evidence behind them. Decisions, approvals and any committee review remain with the agency.
How an engagement runs
Governance work usually begins with the AI Governance Readiness Assessment, a fixed-scope review of where you stand and what to fix first. From there, work can continue into implementing an AI management system and testing the systems that carry the most risk.