7 November 2025
AI Governance Framework Australia: How to Implement the 10 Guardrails
What the voluntary standard asks for, and how to turn ten principles into owned work.
Read the guideAI governance consulting · A Cipher Projects practice
Inventory, owners, risk register, evidence. Built with your people, aligned to ISO/IEC 42001:2023 and the NIST AI RMF, and ready for the APP 1 disclosure rules that commence 10 December 2026.
Australia-wide. In the room or remote.
Governance is unglamorous: an inventory, an owner and a record. It is also the part an auditor, a customer or a regulator will ask for first.
Purpose
Most organisations are not missing a policy. They are missing the record — what AI they run, which decisions it makes or materially contributes to, and who answers for it.
The duties already exist: the Privacy Act 1988 and the Australian Privacy Principles, Australian Consumer Law, employment and anti-discrimination law, work health and safety, APRA's standards for regulated entities — plus what your customers, insurers and tender processes now ask for in writing.
We build the record with your people. The register lives in your tools. The owners sit in your org chart. The evidence trail keeps working after we leave.
Clear Direction AI is the AI governance practice of Cipher Projects. The engineering sits next door: architecture, platforms and delivery, when the fix is technical rather than procedural.
Deliverables
Every engagement produces artefacts you keep. Here is what they are.
Every AI system and feature in use, bought or built — including the ones that arrived inside another tool. Each row gets an owner, a business purpose and the data it touches.
Which uses touch personal information, which decide things about people, and which the law actually reaches today. The point is a list short enough to run.
For each in-scope automated decision: the inputs, the logic, the human hand in it, and the outcome. This is the raw material for the APP 1 disclosure and for any conversation with a regulator.
Risks recorded against the NIST AI RMF functions — govern, map, measure, manage — each with a treatment, an owner and a review date. Reviewed on a cadence, not filed.
Scope, policy, objectives, documented procedures, internal audit and management review, shaped to ISO/IEC 42001:2023 — so certification becomes a decision rather than a rebuild.
Logging, human oversight, vendor and model review, change control, and the export a lawyer, auditor, insurer or customer can read without you in the room.
One page: what you run, what the law requires, what is missing, who owns it, and what it takes to close the gaps.
Key terms
Governance work dies in ambiguity. These are the terms we use, and what they mean here.
The inventory is the foundation. If a system is not on the list, no control, risk assessment or disclosure covers it. We start wide — spend, logins, vendor lists, the tools HR and marketing bought themselves — then cut back to what matters.
APP 1 subclauses 1.7 to 1.9 commence on 10 December 2026. From that date an APP entity must describe, in its privacy policy, the kinds of personal information used by in-scope computer programs and the kinds of decisions those programs make or materially contribute to.
A control nobody can evidence is a claim. The management system, the log, the review minutes and the export are what turn a claim into a record — the difference between saying you govern AI and showing it.
How it runs
The work is staged so each one stands on its own. You can stop after any of them and keep what was built.
We inventory the systems, map the decisions and score the gaps against the law you are actually exposed to — not the whole statute book.
The inventory, the register, the management system documents, the controls and the evidence trail, written where your team already works.
Internal audit and management review with your people running the meeting, against ISO/IEC 42001:2023. That is the rehearsal for a real one.
Review dates, new systems, vendor changes and the next disclosure cycle — on a rhythm your team owns and we can sit in on.
Engagements are advisory, project-based, or a standing retainer. Scope and fee are agreed before work starts. Nothing here is legal advice, and we are not a certification body.
Who it is for
The person who answers for the system when a customer, a regulator or a journalist asks what it does. You get a one-page position and a review cadence.
The people who own the register, the assessments and the wording of the disclosure — and who currently hold it together in a spreadsheet.
The people who know where the model runs, what it touches and what could go wrong at 2am. They get controls that match how the system is actually built.
The people who have to sign, and who keep getting the AI questionnaire attached to a tender. They get an export they can read.
Getting started
Frameworks
Primary sources, not summaries. Regulatory mapping last verified against these sources on 3 September 2026.
Related insights
7 November 2025
What the voluntary standard asks for, and how to turn ten principles into owned work.
Read the guide26 November 2025
The management system in order — scope, policy, risk, controls, internal audit, review.
Read the guide26 November 2025
Scoring that survives contact with a real register, with rows you can copy today.
Read the guideClear Direction AI is a Cipher Projects practice. Not a law firm. Not a compliance assessor. Not a certification body. Nothing on this page is legal advice. Sign-off on your privacy policy stays with your lawyer.
We do not claim Australia has an AI Act. It does not. We do not claim an engagement makes you compliant or certified. No engagement does.
Regulatory mapping on this page was last verified against primary sources on 3 September 2026. Dates move; check the sources linked above before you act.
We will tell you what the law already asks for, what we would put in place first, and whether governance work is the right next step. If it is not, we will say so.
Tell us what you already run. We will tell you what the law already asks for, and whether this is the right next step.