Governance That Makes You Faster
Organisations without AI governance move slowly, because every initiative renegotiates the same questions from scratch. Settling these decisions once removes friction rather than adding it. This is the practical list, not a compliance framework.
General guidance to structure your own approach, not legal advice. Most organisations can work through this in a couple of sessions.
AI Governance Checklist
Decisions, not documents. Most of this is a couple of sessions.
Your ticks are saved in this browser, so you can work through the list over several sessions.
01Acceptable use
0/5This is already happening. Decide the position.
02Approval and ownership
0/5Tiered by consequence, so low-risk work is not obstructed.
03Data handling
0/5What may be processed by what, and where it may go.
04Human oversight
0/5Decide by consequence, not by capability.
05Transparency
0/5What you tell staff, customers and regulators.
06Incidents and review
0/6Decide these calmly, before you need them.
General guidance only, not legal advice and not exhaustive. Australian AI regulation is developing, and existing privacy, consumer and anti-discrimination law already applies. Obtain professional advice for your specific circumstances.
What Good Governance Looks Like
The aim is a small number of decisions everyone knows, not a large document nobody reads. Three principles keep it useful.
Proportionate to consequence
A tool drafting internal meeting notes and a system influencing customer outcomes should not face the same approval burden. Tiering by consequence is what stops governance becoming an obstacle people route around.
Decisions, not documents
What matters is that people know who approves things, what data may be used where, and when a human must review. A one-page set of answered questions beats a forty-page framework nobody has read.
Written before you need it
Incident response, stop conditions and escalation paths are quick to decide calmly and painful to decide during an actual incident. These are the items most worth doing in advance.
The Six Areas
Six areas covering the decisions that actually come up. Each can be assigned to whoever is best placed to settle it.
Acceptable use
What staff may and may not do with AI tools, including the ones they are already using.
Approval and ownership
Who approves an initiative, on what basis, and who owns it once it is running.
Data handling
What data may be processed by what, and where it may go.
Human oversight
Where a person must review, and what the system may never do unattended.
Transparency
What you tell staff, customers and regulators about how AI is used.
Incidents and review
What happens when something goes wrong, and how systems are reviewed over time.
The Four Decisions That Matter Most
If you only settle four things, settle these. They cover the majority of situations that actually arise.
What staff may put into public AI tools
This is happening right now in your organisation whether or not it is sanctioned. The useful position is specific rather than prohibitive: name the categories that must never be pasted into a public tool, and provide an approved alternative for the work people are genuinely trying to do.
- Name the specific categories that must never go into public tools
- Provide a sanctioned alternative: a ban with no alternative is ignored
- Cover customer data, personal information, credentials and unreleased material
- Communicate it in plain language, not as a policy document nobody opens
A tiered approval process
One approval path for everything guarantees either that low-risk work is obstructed or that high-risk work is waved through. Three tiers based on consequence handles nearly every case and keeps the process credible.
- Tier 1: internal, low consequence: team-level approval
- Tier 2: affects customers or uses personal information: formal review
- Tier 3: consequential decisions or regulated activity: executive approval
- Publish the tier definitions so people can self-assess before asking
Where a human must stay in the loop
Decide by consequence rather than by capability. The question is not whether the system could act unattended, but what it would cost if it acted wrongly and nobody noticed until later.
- Require human review for anything irreversible or externally visible
- Require it for decisions affecting a person’s rights, money or access
- Start new systems in recommend-only mode regardless of tier
- Ensure the reviewer has genuine capacity to review, not just accountability
Keeping pace with a moving landscape
Australian AI regulation is developing, with proposals around mandatory guardrails for high-risk settings under active discussion, alongside existing obligations under privacy, consumer and anti-discrimination law that already apply today.
- Existing law already applies: privacy, consumer protection, discrimination
- Assign someone to track developments rather than assuming stability
- Maintain an inventory of AI systems so scope questions can be answered
- Sector regulators may move ahead of general legislation
Next Steps
AI Maturity Scorecard
See where governance sits relative to your other capability dimensions.
Score maturity →AI Vendor Due Diligence Checklist
The questions to put to any supplier before they touch your data.
Open the checklist →AI Governance Consulting
How we help organisations put proportionate governance in place.
See the service →Frequently Asked Questions
You need settled decisions; whether they live in a formal policy depends on your size and sector. For a small organisation, a one-page document covering acceptable use, approval and data handling is genuinely sufficient and considerably more likely to be read. Larger and regulated organisations generally need something more formal, integrated with existing risk and procurement frameworks. The failure mode to avoid is producing a comprehensive policy that nobody reads while staff continue pasting customer data into public tools, which is the situation in a great many organisations right now.
There is no single comprehensive AI act at present, but that does not mean AI is unregulated. Existing law applies fully: the Privacy Act 1988 governs personal information, Australian Consumer Law prohibits misleading and deceptive conduct, anti-discrimination law applies to automated decisions, and sector regulators have their own obligations. The Australian Government has been consulting on mandatory guardrails for AI in high-risk settings, and the position continues to develop. Organisations should assume existing obligations apply today and that specific AI requirements may follow. This is general information, not legal advice.
Largely by removing the reason they are doing it. Shadow usage happens because people have work to do and an approved path does not exist or is too slow. A prohibition without an alternative moves the behaviour out of sight rather than stopping it. The approach that works is to provide a sanctioned tool that handles the common cases, be specific about what must never be entered anywhere, and make the approval path for new tools genuinely fast for low-risk cases. Finding out what people are already using, without blame, is usually the most informative first step.
It needs a named accountable owner, and where that sits depends on your structure. Risk, legal or the CIO are all common and workable. What matters more than the reporting line is that the owner has authority to make decisions, visibility of what is actually happening, and enough understanding of the technology to be proportionate. Governance owned by someone with no visibility of usage becomes theatre, and governance owned by someone with no authority becomes advice that gets ignored.
Every six months at minimum in the current environment, and immediately on any material change. A new high-risk use case, a regulatory development, a significant incident, or a change in your major AI supplier. The technology and the regulatory position are both moving faster than typical annual policy cycles accommodate. Assign the review to a named person with a calendar date rather than leaving it to be triggered by events, since the events that trigger it are usually the ones you wanted to have prepared for.
No. It is a practical prompt list to help an organisation settle the decisions that commonly arise, drawn from general Australian principles. It is not legal advice, it is not exhaustive, and it cannot account for your sector, size, contractual obligations or the specific systems you operate. The regulatory position is also developing. For decisions with real consequence, obtain advice from a qualified professional and check the current position with the relevant regulator.
Want Governance That Does Not Slow You Down?
We help Australian organisations put proportionate AI governance in place, enough to manage the risk, not so much that teams route around it.