Skip to content

Governance That Makes You Faster

Organisations without AI governance move slowly, because every initiative renegotiates the same questions from scratch. Settling these decisions once removes friction rather than adding it. This is the practical list, not a compliance framework.

General guidance to structure your own approach, not legal advice. Most organisations can work through this in a couple of sessions.

AI Governance Checklist

Decisions, not documents. Most of this is a couple of sessions.

0 of 31 complete0%

Your ticks are saved in this browser, so you can work through the list over several sessions.

01Acceptable use

0/5

This is already happening. Decide the position.

02Approval and ownership

0/5

Tiered by consequence, so low-risk work is not obstructed.

03Data handling

0/5

What may be processed by what, and where it may go.

04Human oversight

0/5

Decide by consequence, not by capability.

05Transparency

0/5

What you tell staff, customers and regulators.

06Incidents and review

0/6

Decide these calmly, before you need them.

General guidance only, not legal advice and not exhaustive. Australian AI regulation is developing, and existing privacy, consumer and anti-discrimination law already applies. Obtain professional advice for your specific circumstances.

What Good Governance Looks Like

The aim is a small number of decisions everyone knows, not a large document nobody reads. Three principles keep it useful.

Proportionate to consequence

A tool drafting internal meeting notes and a system influencing customer outcomes should not face the same approval burden. Tiering by consequence is what stops governance becoming an obstacle people route around.

Decisions, not documents

What matters is that people know who approves things, what data may be used where, and when a human must review. A one-page set of answered questions beats a forty-page framework nobody has read.

Written before you need it

Incident response, stop conditions and escalation paths are quick to decide calmly and painful to decide during an actual incident. These are the items most worth doing in advance.

The Six Areas

Six areas covering the decisions that actually come up. Each can be assigned to whoever is best placed to settle it.

1

Acceptable use

What staff may and may not do with AI tools, including the ones they are already using.

2

Approval and ownership

Who approves an initiative, on what basis, and who owns it once it is running.

3

Data handling

What data may be processed by what, and where it may go.

4

Human oversight

Where a person must review, and what the system may never do unattended.

5

Transparency

What you tell staff, customers and regulators about how AI is used.

6

Incidents and review

What happens when something goes wrong, and how systems are reviewed over time.

The Four Decisions That Matter Most

If you only settle four things, settle these. They cover the majority of situations that actually arise.

What staff may put into public AI tools

This is happening right now in your organisation whether or not it is sanctioned. The useful position is specific rather than prohibitive: name the categories that must never be pasted into a public tool, and provide an approved alternative for the work people are genuinely trying to do.

  • Name the specific categories that must never go into public tools
  • Provide a sanctioned alternative: a ban with no alternative is ignored
  • Cover customer data, personal information, credentials and unreleased material
  • Communicate it in plain language, not as a policy document nobody opens

A tiered approval process

One approval path for everything guarantees either that low-risk work is obstructed or that high-risk work is waved through. Three tiers based on consequence handles nearly every case and keeps the process credible.

  • Tier 1: internal, low consequence: team-level approval
  • Tier 2: affects customers or uses personal information: formal review
  • Tier 3: consequential decisions or regulated activity: executive approval
  • Publish the tier definitions so people can self-assess before asking

Where a human must stay in the loop

Decide by consequence rather than by capability. The question is not whether the system could act unattended, but what it would cost if it acted wrongly and nobody noticed until later.

  • Require human review for anything irreversible or externally visible
  • Require it for decisions affecting a person’s rights, money or access
  • Start new systems in recommend-only mode regardless of tier
  • Ensure the reviewer has genuine capacity to review, not just accountability

Keeping pace with a moving landscape

Australian AI regulation is developing, with proposals around mandatory guardrails for high-risk settings under active discussion, alongside existing obligations under privacy, consumer and anti-discrimination law that already apply today.

  • Existing law already applies: privacy, consumer protection, discrimination
  • Assign someone to track developments rather than assuming stability
  • Maintain an inventory of AI systems so scope questions can be answered
  • Sector regulators may move ahead of general legislation

Next Steps

AI Maturity Scorecard

See where governance sits relative to your other capability dimensions.

Score maturity

AI Vendor Due Diligence Checklist

The questions to put to any supplier before they touch your data.

Open the checklist

AI Governance Consulting

How we help organisations put proportionate governance in place.

See the service

Frequently Asked Questions

Want Governance That Does Not Slow You Down?

We help Australian organisations put proportionate AI governance in place, enough to manage the risk, not so much that teams route around it.