AI governance · A Cipher Projects practice

The system around the AI you already run.

We prepare you for the disclosure rules that start 10 December 2026. Inventory, owners, a risk register and the evidence — built with your people.

A single user, or a team cohort.

Book 30 minutes
A person in a dark suit walking along a walkway in front of a wide grey panel wall

Governance is unglamorous: an inventory, an owner and a record. It is also the part an auditor, a customer or a regulator will ask for first.

Inventory

Every AI system and feature in use, bought or built — including the ones that arrived inside another tool.

Owners

A named person for every system. The register lives in your tools. The owners sit in your org chart.

Risk register

Risks against the NIST AI RMF — govern, map, measure, manage — each with a treatment, an owner and a review date.

Evidence

The export a lawyer, auditor, insurer or customer can read without you in the room.

Purpose

Australia has no AI Act. You still have duties.

Most organisations are not missing a policy. They are missing the record — what AI they run, which decisions it makes or materially contributes to, and who answers for it.

The duties already exist: the Privacy Act 1988 and the Australian Privacy Principles, Australian Consumer Law, employment and anti-discrimination law, work health and safety, APRA's standards for regulated entities — plus what your customers, insurers and tender processes now ask for in writing.

We build the record with your people. The evidence trail keeps working after we leave.

Clear Direction AI is the AI governance practice of Cipher Projects. AI strategy, architecture and the build sit next door, when the fix is technical rather than procedural.

Deliverables

What you get

Every engagement produces artefacts you keep.

  1. 01

    AI inventory

    Every AI system and feature in use, bought or built — including the ones that arrived inside another tool. Each row gets an owner, a business purpose and the data it touches.

  2. 02

    Classification and materiality

    Which uses touch personal information, which decide things about people, and which the law actually reaches today. The point is a list short enough to run.

  3. 03

    Decision map

    For each in-scope automated decision: the inputs, the logic, the human hand in it, and the outcome. This is the raw material for the APP 1 disclosure and for any conversation with a regulator.

  4. 04

    Risk register

    Risks recorded against the NIST AI RMF functions — govern, map, measure, manage — each with a treatment, an owner and a review date. Reviewed on a cadence, not filed.

  5. 05

    AI management system

    Scope, policy, objectives, documented procedures, internal audit and management review, shaped to ISO/IEC 42001:2023 — so certification becomes a decision rather than a rebuild.

  6. 06

    Controls and evidence pack

    Logging, human oversight, vendor and model review, change control, and the export a lawyer, auditor, insurer or customer can read without you in the room.

  7. 07

    Board summary

    One page: what you run, what the law requires, what is missing, who owns it, and what it takes to close the gaps.

How it runs

Four stages, then a cadence.

Each stage stands on its own. You can stop after any of them and keep what was built.

Baseline

What you run

We inventory the systems, map the decisions and score the gaps against the law you are actually exposed to — not the whole statute book.

Build

The system

The inventory, the register, the management system documents, the controls and the evidence trail, written where your team already works.

Assure

The test

Internal audit and management review with your people running the meeting, against ISO/IEC 42001:2023. That is the rehearsal for a real one.

Operate

The cadence

Review dates, new systems, vendor changes and the next disclosure cycle — on a rhythm your team owns and we can sit in on.

Engagements are advisory, project-based, or a standing retainer. Scope and fee are agreed before work starts. Nothing here is legal advice, and we are not a certification body.

Who it is for

This is for

Boards and executives

The person who answers for the system when a customer, a regulator or a journalist asks what it does. You get a one-page position and a review cadence.

Risk, compliance and privacy

The people who own the register, the assessments and the wording of the disclosure — and who currently hold it together in a spreadsheet.

Technology, data and security

The people who know where the model runs, what it touches and what could go wrong at 2am. They get controls that match how the system is actually built.

Legal and procurement

The people who have to sign, and who keep getting the AI questionnaire attached to a tender. They get an export they can read.

Pricing · Cipher Projects

The public price is the audit.

AI strategy — what to automate first, when to build, when not to — is the parent company. The assurance audit is the fixed-scope way in. Governance work on this site is scoped separately, and the fee is agreed before it starts.

01 — AI assurance audit

A written roadmap

$2,650

AUD in Australia. SGD $2,400 in Singapore. USD $1,830 everywhere else. Exclusive of tax.

  • Fixed scope. The AI and systems you already run.
  • Security and compliance reviewed.
  • Written roadmap and a delivery session.
  • The fee is credited if you proceed to the build.
See the rate card

02 — Build

One figure, after the audit

No public parts list. Agreed from what the audit found.

  • One fixed cost, then we build.
  • You own what we ship.
  • Cloud runtime bills stay yours.

03 — After go-live

Maintenance, if you want it

Optional. No public rate. Scoped with you.

  • We keep it running and ship updates.
  • You can stop when you do not need us.
  • Architecture retainers are kept to a few clients.

Tax is extra. ISO 27001 or SOC 2 certification is a third-party audit. The build can support those controls. It does not include the certificate.

Questions

Straight answers

Does an engagement make us compliant or certified?

No. We are not a law firm, a compliance assessor, or a certification body. Sign-off on your privacy policy stays with your lawyer. An engagement does not make you compliant, and it does not award a badge.

Does Australia have an AI Act?

It does not. The duties that already exist are the Privacy Act, Australian Consumer Law, employment and anti-discrimination law, work health and safety, and APRA’s standards where they apply. APP 1 automated-decision disclosures commence on 10 December 2026.

What is the AI assurance audit?

Cipher Projects looks at the AI and systems the business already runs, reviews security and compliance, and hands over a written roadmap plus a delivery session. The fee is credited if you go on to the build.

Where does AI strategy sit?

With Cipher Projects: what to automate first, when to build, when not to, and which path. Clear Direction AI is the governance practice — the inventory, the owners, the risk register and the evidence pack. Engineering sits next door.

What do we keep?

The artefacts. The register lives in your tools. The owners sit in your org chart. The evidence trail keeps working after we leave. You can stop after any stage and keep what was built.

Get started

Tell us what you already run.

We will tell you what the law already asks for, what we would put in place first, and whether governance work is the right next step. If it is not, we will say so.