Inventory
Every AI system and feature in use, bought or built — including the ones that arrived inside another tool.
AI governance · A Cipher Projects practice
We prepare you for the disclosure rules that start 10 December 2026. Inventory, owners, a risk register and the evidence — built with your people.
Governance is unglamorous: an inventory, an owner and a record. It is also the part an auditor, a customer or a regulator will ask for first.
Every AI system and feature in use, bought or built — including the ones that arrived inside another tool.
A named person for every system. The register lives in your tools. The owners sit in your org chart.
Risks against the NIST AI RMF — govern, map, measure, manage — each with a treatment, an owner and a review date.
The export a lawyer, auditor, insurer or customer can read without you in the room.
Purpose
Most organisations are not missing a policy. They are missing the record — what AI they run, which decisions it makes or materially contributes to, and who answers for it.
The duties already exist: the Privacy Act 1988 and the Australian Privacy Principles, Australian Consumer Law, employment and anti-discrimination law, work health and safety, APRA's standards for regulated entities — plus what your customers, insurers and tender processes now ask for in writing.
We build the record with your people. The evidence trail keeps working after we leave.
Clear Direction AI is the AI governance practice of Cipher Projects. AI strategy, architecture and the build sit next door, when the fix is technical rather than procedural.
Deliverables
Every engagement produces artefacts you keep.
Every AI system and feature in use, bought or built — including the ones that arrived inside another tool. Each row gets an owner, a business purpose and the data it touches.
Which uses touch personal information, which decide things about people, and which the law actually reaches today. The point is a list short enough to run.
For each in-scope automated decision: the inputs, the logic, the human hand in it, and the outcome. This is the raw material for the APP 1 disclosure and for any conversation with a regulator.
Risks recorded against the NIST AI RMF functions — govern, map, measure, manage — each with a treatment, an owner and a review date. Reviewed on a cadence, not filed.
Scope, policy, objectives, documented procedures, internal audit and management review, shaped to ISO/IEC 42001:2023 — so certification becomes a decision rather than a rebuild.
Logging, human oversight, vendor and model review, change control, and the export a lawyer, auditor, insurer or customer can read without you in the room.
One page: what you run, what the law requires, what is missing, who owns it, and what it takes to close the gaps.
How it runs
Each stage stands on its own. You can stop after any of them and keep what was built.
We inventory the systems, map the decisions and score the gaps against the law you are actually exposed to — not the whole statute book.
The inventory, the register, the management system documents, the controls and the evidence trail, written where your team already works.
Internal audit and management review with your people running the meeting, against ISO/IEC 42001:2023. That is the rehearsal for a real one.
Review dates, new systems, vendor changes and the next disclosure cycle — on a rhythm your team owns and we can sit in on.
Engagements are advisory, project-based, or a standing retainer. Scope and fee are agreed before work starts. Nothing here is legal advice, and we are not a certification body.
Who it is for
The person who answers for the system when a customer, a regulator or a journalist asks what it does. You get a one-page position and a review cadence.
The people who own the register, the assessments and the wording of the disclosure — and who currently hold it together in a spreadsheet.
The people who know where the model runs, what it touches and what could go wrong at 2am. They get controls that match how the system is actually built.
The people who have to sign, and who keep getting the AI questionnaire attached to a tender. They get an export they can read.
Pricing · Cipher Projects
AI strategy — what to automate first, when to build, when not to — is the parent company. The assurance audit is the fixed-scope way in. Governance work on this site is scoped separately, and the fee is agreed before it starts.
01 — AI assurance audit
$2,650
AUD in Australia. SGD $2,400 in Singapore. USD $1,830 everywhere else. Exclusive of tax.
02 — Build
No public parts list. Agreed from what the audit found.
03 — After go-live
Optional. No public rate. Scoped with you.
Tax is extra. ISO 27001 or SOC 2 certification is a third-party audit. The build can support those controls. It does not include the certificate.
Questions
No. We are not a law firm, a compliance assessor, or a certification body. Sign-off on your privacy policy stays with your lawyer. An engagement does not make you compliant, and it does not award a badge.
It does not. The duties that already exist are the Privacy Act, Australian Consumer Law, employment and anti-discrimination law, work health and safety, and APRA’s standards where they apply. APP 1 automated-decision disclosures commence on 10 December 2026.
Cipher Projects looks at the AI and systems the business already runs, reviews security and compliance, and hands over a written roadmap plus a delivery session. The fee is credited if you go on to the build.
With Cipher Projects: what to automate first, when to build, when not to, and which path. Clear Direction AI is the governance practice — the inventory, the owners, the risk register and the evidence pack. Engineering sits next door.
The artefacts. The register lives in your tools. The owners sit in your org chart. The evidence trail keeps working after we leave. You can stop after any stage and keep what was built.
Get started
We will tell you what the law already asks for, what we would put in place first, and whether governance work is the right next step. If it is not, we will say so.
Tell us what you already run. We will tell you what the law already asks for, and whether this is the right next step.