SERVICE 08

AI Governance

The rules arrive in 2027. The evidence should already exist.

What is coming

Mandatory is no longer a rumour.

In July 2026 the Australian Government announced the Australian Standards for AI: a single, mandatory framework to be legislated in early 2027, coordinated by a new Office of AI, with enforcement staged through 2028. The signalled shape reaches every business that uses AI: a current register of the AI in use and the data it touches, named accountable owners, impact assessments, audit trails and incident reporting, alongside consent rules for training on Australian creative work. And the laws that already exist, privacy, consumer, anti-discrimination, keep applying to AI today. The detail will move before Parliament settles it. The direction will not.

What we do

Governance as engineering, not paperwork.

Most firms entering this market will sell you policy documents. We operate production AI platforms under exactly the disciplines the Standards will demand: deterministic calculation behind every reported number, citation-or-reject evidence gates, adversarial review, evaluation suites that block releases, immutable audit trails. Our governance work starts from readiness, a register of your AI, a risk classification and a gap report against the Standards trajectory and ISO 42001. It builds to a working management system with the engineering evidence behind it, and it can stand as continuous assurance: monitoring, adversarial testing and an annual attestation pack your board can sign against.

How we work

Inventory, classify, remediate, assure.

Inventory

Every AI system in use across the business, the data each one touches, and a named accountable owner.

Classify

Each use risk-rated against the Standards trajectory, the six essential practices and ISO 42001, so effort lands where exposure lives.

Remediate

Policy and engineering together: oversight points, provenance and consent trails, testing harnesses, logging, incident response.

Assure

Continuous monitoring, periodic adversarial testing and an annual evidence pack, kept current as the law finalises.

NOTHING CROSSES UNEXAMINED

What you get

Evidence, not assurances.

Register

An AI system register with data flows, owners and a risk classification for every use.

Gap report

Where you stand against the Standards trajectory and ISO 42001, with a remediation roadmap in priority order.

Governance

Impact assessments, policies with named owners, vendor clauses and an incident runbook that has been rehearsed.

Evidence pack

Test results, provenance and consent registers, audit trails and model documentation, assembled for inspection.

Briefings

Board and team briefings that make the obligations concrete for the people who own them.

Assurance

Board reporting, annual attestation and ISO 42001 certification support as the regime hardens.

SAMPLE · ISO 42001 GAP ASSESSMENT
Sample ISO 42001 gap assessment with maturity bars and status chips
Where you stand, domain by domain, against ISO 42001 and the Standards trajectory. Illustrative sample.

When the regulator asks how your AI is governed, the answer should already be a file, not a scramble.

Schedule a Consultation