Practical governance for AI, security and risk

Governance should speed you up

Most organisations meet governance as a brake. A policy that arrives after the decision, a control that stops something useful, a framework sized for an organisation ten times larger.

It does not have to work that way.

Done properly, governance is the thing that lets you move: it tells you which risks you have accepted, which you have not, and who decides. That is what makes a Board comfortable saying yes.

Making sense of the AI mess

AI can get messy fast. Don't leave it too long to sort it out.

AI Strategy

Decide where AI actually helps, what it will cost, and what needs to be in place first.

AI Governance

Practical frameworks for oversight and accountability, sized to your risk rather than to a standard.

AI Awareness Training

Twenty minutes online gets team using AI well, not avoiding it.
Board Briefing or in person training.

Right Fit for Risk - RFFR

Right Fit for Risk accreditation for Government contracted providers, including the new AI assessment requirements.

RFFR AI Assessment

Get AI use in departmental service delivery assessed, approved and kept approved. For those that already have RFFR.

ISO 42001

Build an AI management system that works in practice and survives certification.

ISO 27001

Information security management, proportionate controls, certification readiness.

Important News 

AI Assessment is now part of the RFFR accreditation

If you hold a departmental contract, AI just became part of your accreditation. This is in force right now.

DEWR now requires AI use in contracted service delivery to be formally assessed and approved, and once approved it sits inside your RFFR accreditation and maintenance lifecycle.Most providers have not caught up with this yet. If you are one of them, it is worth a conversation before your next milestone.

Click here for more information on AI Assessments

Changes to the Australian Privacy Principles come into effect on 10th December 2026

From 10 December 2026, the Privacy Act requires privacy policies to describe the automated decision-making an organisation uses. Three things specifically: what personal information feeds it, which decisions are made solely by a computer program, and which decisions it substantially contributes to. It bites where those decisions could reasonably be expected to significantly affect someone's rights or interests.

The writing is not the hard part. Knowing what you are actually running is, because much of it arrived inside software you already licensed and nobody logged it as automation. The OAIC can issue infringement notices for a policy that does not meet the requirement, and civil penalties apply. A policy describing something other than what you actually do is not a comfortable place to be with fourteen months to go.

Experience

I have seen what a bad day actually looks like

One of my IT leadership roles began two weeks after a ransomware attack destroyed the IT environment of a children’s services organisation. There were no computing services running on the day I walked in.

Rebuilding it taught me more about governance than any framework has. You find out quickly which controls would have changed the outcome, which ones were theatre, and how fast an organisation loses the ability to do its actual job when the systems are simply gone.

Not sure where to start?

Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.

Book a conversation