Most organisations meet governance as a brake. A policy that arrives after the decision, a control that stops something useful, a framework sized for an organisation ten times larger.
It does not have to work that way.
Done properly, governance is the thing that lets you move: it tells you which risks you have accepted, which you have not, and who decides. That is what makes a Board comfortable saying yes.
Decide where AI actually helps, what it will cost, and what needs to be in place first.
Practical frameworks for oversight and accountability, sized to your risk rather than to a standard.
Twenty minutes online gets team using AI well, not avoiding it.
Board Briefing or in person training.
Right Fit for Risk accreditation for Government contracted providers, including the new AI assessment requirements.
Get AI use in departmental service delivery assessed, approved and kept approved. For those that already have RFFR.
Build an AI management system that works in practice and survives certification.
Information security management, proportionate controls, certification readiness.
If you hold a departmental contract, AI just became part of your accreditation. This is in force right now.
DEWR now requires AI use in contracted service delivery to be formally assessed and approved, and once approved it sits inside your RFFR accreditation and maintenance lifecycle.Most providers have not caught up with this yet. If you are one of them, it is worth a conversation before your next milestone.
From 10 December 2026, the Privacy Act requires privacy policies to describe the automated decision-making an organisation uses. Three things specifically: what personal information feeds it, which decisions are made solely by a computer program, and which decisions it substantially contributes to. It bites where those decisions could reasonably be expected to significantly affect someone's rights or interests.
The writing is not the hard part. Knowing what you are actually running is, because much of it arrived inside software you already licensed and nobody logged it as automation. The OAIC can issue infringement notices for a policy that does not meet the requirement, and civil penalties apply. A policy describing something other than what you actually do is not a comfortable place to be with fourteen months to go.
One of my IT leadership roles began two weeks after a ransomware attack destroyed the IT environment of a children’s services organisation. There were no computing services running on the day I walked in.
Rebuilding it taught me more about governance than any framework has. You find out quickly which controls would have changed the outcome, which ones were theatre, and how fast an organisation loses the ability to do its actual job when the systems are simply gone.
Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.