Governance framework & guidance
Products and suppliers
Most organisations do not build their own AI systems. They use capabilities provided by software vendors, technology partners, cloud services and other suppliers. Responsible governance therefore requires enough information about the products and suppliers behind organisational AI Uses to make informed decisions.
Swell brings this information together so it can be reused across the organisation rather than investigated separately every time the same product is used.
Why supplier assurance matters
A supplier may influence how the AI was developed and tested, how information is processed, whether customer data is retained or used for improvement, which subprocessors are involved, security and privacy protections, known limitations, monitoring, and how material changes are communicated.
The objective is not to audit the internal engineering of every supplier. Assurance should be proportionate to the way the organisation intends to use the product.
Australian guidance on AI suppliers
Australian Government guidance emphasises supply-chain transparency and information sharing between developers and deployers. The Office of the Australian Information Commissioner recommends due diligence when selecting commercially available AI products, including suitability for the intended use, human oversight, privacy and security risks, and access to information.
Knowing who supplies a product is useful. Understanding enough about that product to determine whether it is suitable for the intended use is much more important.
Supplier transparency, evidence and use-case risk are separate
A well-known supplier does not automatically make every use of its AI product appropriate. Likewise, incomplete supplier information does not prove that the product is unsafe. Swell keeps supplier transparency, evidence coverage, product characteristics and the risk of a particular organisational AI Use separate.
Having a document is also not the same as having assurance. Evidence should be interpreted according to what it actually establishes.
What should we understand about a Product?
- Product purpose and intended use.
- Supplier and material delivery dependencies.
- The role AI performs in the product.
- Known limitations and expected human oversight.
- Data handling, privacy and security arrangements.
- Testing and assurance information.
- How material product or supplier changes are communicated.
What if information is unavailable?
Do not guess. Record what is known and what remains unknown or needs confirmation. The governance question then becomes whether the missing information matters for the proposed AI Use.
For a simple low-consequence activity, some uncertainty may have limited effect. For a higher-consequence use involving sensitive information or important decisions, the same uncertainty may require further assurance, restrictions or reconsideration.
Using Swell AI
Reuse supplier and product information
Supplier → Product → Organisational AI Use is a reusable relationship. Product and supplier facts can be shared across multiple Uses, while each AI Use retains its own purpose, owner, assessment, risks, controls and approval decision.
This reduces duplicated questionnaires without pretending one supplier assessment can decide whether every use of the product is appropriate.