A useful AI governance framework tells people how the organisation will choose, use, review and retire AI. It should help good ideas move forward with clear ownership while directing more scrutiny to uses with greater impact or uncertainty.
Use current Australian guidance as the baseline
The National AI Centre's 2026 Guidance for AI Adoption sets out six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control.
The guidance distinguishes between foundations for early or lower-risk use and implementation guidance for complex or higher-risk use. This is an important design principle. Governance should become deeper as the use becomes more consequential, not impose the same process on every experiment.
The AICD and Human Technology Institute add a board and operating-model view. Their 2026 guide organises AI governance around strategy, governance structure, governance practices and organisational enablers, followed by the measurement of AI returns.
Layer 1: direction and accountability
Begin with the organisation's purpose for using AI. Define the outcomes AI should support, the principles that guide adoption and the areas where risk appetite is lower. The strategy should help management prioritise useful opportunities rather than accumulate disconnected pilots and licences.
Assign an executive sponsor and an operational governance owner. Then assign a business owner to every material use. The business owner is accountable for purpose, outcomes and continued suitability. Technology, privacy, security, procurement, people and sector specialists contribute where their expertise is relevant.
Layer 2: discovery and the AI register
A framework cannot govern what the organisation cannot see. Run a structured discovery exercise across business units, supported by procurement records, software inventories, expense data, project lists and supplier reviews.
Register each distinct organisational use. A product name alone is not enough. Using the same product for internal drafting and for shortlisting applicants creates different impacts, evidence needs and approval decisions.
The National AI Centre specifically recommends maintaining a register that covers internally developed, procured and embedded AI. Keep unknown information visible and assign follow-up rather than treating blank fields as low risk.
Layer 3: proportionate assessment
Start with a short screening step. The result should determine the depth of assessment, specialist review, testing and approval needed. Consider:
- the purpose and expected benefit;
- people who may be affected and the seriousness of the impact;
- personal, sensitive or confidential information;
- accuracy, fairness, transparency and contestability;
- autonomy and the strength of human oversight;
- operational criticality and fallback arrangements;
- supplier dependency, evidence and data flows;
- security, misuse and change over time.
The same AI tool can create very different risk depending on its use. Assessment therefore belongs at the use-case level, supported by separate supplier and product information.
Layer 4: controls, evidence and decisions
Turn important findings into work. Each control or action should have an owner, due date, status and evidence requirement. Approvers should receive a concise view of the purpose, expected value, material issues, completed controls, open items and proposed conditions.
Keep the decision, rationale, conditions and framework version with the registered use. This gives future reviewers the context needed to understand what was known at the time.
Supplier transparency describes what the provider disclosed. Evidence coverage shows what is available or missing. Use-case suitability considers whether the product is appropriate for this purpose, data, group of people and operating context.
Layer 5: testing, monitoring and change
The National AI Centre recommends testing before deployment, monitoring after deployment and matching the monitoring approach to the risk identified. Higher-impact uses may need independent testing and stronger human override points.
Define the changes that return a use to review. Common triggers include a new purpose, different data, wider deployment, greater autonomy, supplier or model changes, new affected groups, an incident, poor performance or expired evidence.
Layer 6: strategy and governance reporting
Management reporting should connect AI strategy and governance. Show progress against strategic objectives, the status of roadmap initiatives, portfolio growth, higher-impact uses, approvals, incidents, overdue actions and decisions required.
Board reporting should focus on material information and changes since the previous report. It should also state the basis of management's view, including business-unit response coverage and known information gaps.
A practical first 90 days
- Appoint an executive sponsor and governance owner.
- Agree strategic objectives, principles, risk appetite and escalation thresholds.
- Run organisation-wide discovery and create the first AI register.
- Prioritise material uses and assign accountable owners.
- Assess higher-impact and uncertain uses first.
- Record controls, evidence, decisions and review dates.
- Create a roadmap for governance improvements and priority AI initiatives.
- Issue the first management or board report with clear coverage and information gaps.
Sources and further reading
- National AI Centre, Guidance for AI adoption: foundations
- National AI Centre, Guidance for AI adoption: implementation guidance
- AICD and Human Technology Institute, A Director's Guide to AI Governance, Version 2
- OAIC, Guidance on privacy and the use of commercially available AI products
- ASIC Report 798, Beware the gap
This framework is general guidance. It should be adapted to the organisation's sector, obligations, stakeholders, operating model and risk profile.