AI governance consulting · A Cipher Projects practice

The system around the AI you already run.

Inventory, owners, risk register, evidence. Built with your people, aligned to ISO/IEC 42001:2023 and the NIST AI RMF, and ready for the APP 1 disclosure rules that commence 10 December 2026.

Australia-wide. In the room or remote.

Book 30 minutes
A person in a dark suit walking along a walkway in front of a wide grey panel wall

Governance is unglamorous: an inventory, an owner and a record. It is also the part an auditor, a customer or a regulator will ask for first.

Purpose

Australia has no AI Act. You still have duties.

Most organisations are not missing a policy. They are missing the record — what AI they run, which decisions it makes or materially contributes to, and who answers for it.

The duties already exist: the Privacy Act 1988 and the Australian Privacy Principles, Australian Consumer Law, employment and anti-discrimination law, work health and safety, APRA's standards for regulated entities — plus what your customers, insurers and tender processes now ask for in writing.

We build the record with your people. The register lives in your tools. The owners sit in your org chart. The evidence trail keeps working after we leave.

Clear Direction AI is the AI governance practice of Cipher Projects. The engineering sits next door: architecture, platforms and delivery, when the fix is technical rather than procedural.

Deliverables

What you get

Every engagement produces artefacts you keep. Here is what they are.

  1. 01

    AI inventory

    Every AI system and feature in use, bought or built — including the ones that arrived inside another tool. Each row gets an owner, a business purpose and the data it touches.

  2. 02

    Classification and materiality

    Which uses touch personal information, which decide things about people, and which the law actually reaches today. The point is a list short enough to run.

  3. 03

    Decision map

    For each in-scope automated decision: the inputs, the logic, the human hand in it, and the outcome. This is the raw material for the APP 1 disclosure and for any conversation with a regulator.

  4. 04

    Risk register

    Risks recorded against the NIST AI RMF functions — govern, map, measure, manage — each with a treatment, an owner and a review date. Reviewed on a cadence, not filed.

  5. 05

    AI management system

    Scope, policy, objectives, documented procedures, internal audit and management review, shaped to ISO/IEC 42001:2023 — so certification becomes a decision rather than a rebuild.

  6. 06

    Controls and evidence pack

    Logging, human oversight, vendor and model review, change control, and the export a lawyer, auditor, insurer or customer can read without you in the room.

  7. 07

    Board summary

    One page: what you run, what the law requires, what is missing, who owns it, and what it takes to close the gaps.

Key terms

The vocabulary you will need

Governance work dies in ambiguity. These are the terms we use, and what they mean here.

Describing what you run

The inventory is the foundation. If a system is not on the list, no control, risk assessment or disclosure covers it. We start wide — spend, logins, vendor lists, the tools HR and marketing bought themselves — then cut back to what matters.

Showing how decisions get made

APP 1 subclauses 1.7 to 1.9 commence on 10 December 2026. From that date an APP entity must describe, in its privacy policy, the kinds of personal information used by in-scope computer programs and the kinds of decisions those programs make or materially contribute to.

Proving it after the fact

A control nobody can evidence is a claim. The management system, the log, the review minutes and the export are what turn a claim into a record — the difference between saying you govern AI and showing it.

AI inventory
A register of every AI system and feature in use, with an owner, a purpose and the data it touches.
Automated decision-making (ADM)
A computer program that makes, or materially contributes to, a decision about an individual.
APP 1 disclosure
The privacy-policy statement required from 10 December 2026 for in-scope automated decision-making.
AI management system (AIMS)
The documented system — scope, policy, objectives, procedures, internal audit, management review — that ISO/IEC 42001:2023 certifies.
Risk register
Risks with a score, a treatment, an owner and a review date, recorded against the NIST AI RMF functions.
Human oversight
The named person who can review, override or stop what a system produces — and who knows they can.
System card
A one-page record of what a system does, what data it uses, where its limits are and who owns it.
Evidence pack
The export your lawyer, auditor, insurer or customer can read without you in the room.
Guardrails
The ten practices in the Voluntary AI Safety Standard, published September 2024. Useful for boards and tenders; it creates no new legal duty.
Materiality
Whether a system's output actually changes a decision about a person — the test that decides what has to be disclosed.

How it runs

Four stages, then a cadence.

The work is staged so each one stands on its own. You can stop after any of them and keep what was built.

Baseline

What you run

We inventory the systems, map the decisions and score the gaps against the law you are actually exposed to — not the whole statute book.

Build

The system

The inventory, the register, the management system documents, the controls and the evidence trail, written where your team already works.

Assure

The test

Internal audit and management review with your people running the meeting, against ISO/IEC 42001:2023. That is the rehearsal for a real one.

Operate

The cadence

Review dates, new systems, vendor changes and the next disclosure cycle — on a rhythm your team owns and we can sit in on.

Engagements are advisory, project-based, or a standing retainer. Scope and fee are agreed before work starts. Nothing here is legal advice, and we are not a certification body.

Who it is for

This is for

Boards and executives

The person who answers for the system when a customer, a regulator or a journalist asks what it does. You get a one-page position and a review cadence.

Risk, compliance and privacy

The people who own the register, the assessments and the wording of the disclosure — and who currently hold it together in a spreadsheet.

Technology, data and security

The people who know where the model runs, what it touches and what could go wrong at 2am. They get controls that match how the system is actually built.

Legal and procurement

The people who have to sign, and who keep getting the AI questionnaire attached to a tender. They get an export they can read.

Getting started

Three ways to start

Frameworks

The standards we work to

Primary sources, not summaries. Regulatory mapping last verified against these sources on 3 September 2026.

Related insights

Start with the writing

7 November 2025

AI Governance Framework Australia: How to Implement the 10 Guardrails

What the voluntary standard asks for, and how to turn ten principles into owned work.

Read the guide

26 November 2025

ISO 42001 Implementation Guide: Certification Steps That Actually Work

The management system in order — scope, policy, risk, controls, internal audit, review.

Read the guide

26 November 2025

AI Risk Assessment Template: Low / Medium / High Framework for Enterprise Teams

Scoring that survives contact with a real register, with rows you can copy today.

Read the guide

The fine print, up front

Clear Direction AI is a Cipher Projects practice. Not a law firm. Not a compliance assessor. Not a certification body. Nothing on this page is legal advice. Sign-off on your privacy policy stays with your lawyer.

We do not claim Australia has an AI Act. It does not. We do not claim an engagement makes you compliant or certified. No engagement does.

Regulatory mapping on this page was last verified against primary sources on 3 September 2026. Dates move; check the sources linked above before you act.

Tell us what you already run.

We will tell you what the law already asks for, what we would put in place first, and whether governance work is the right next step. If it is not, we will say so.

Book 30 minutes