AI GOVERNANCE · EMPLOYMENT SERVICES · BOARD BRIEFING
Since the Department of Employment and Workplace Relations published its Third-Party AI Assessment Framework in September 2025, eleven providers have applied to use AI in service delivery. As at Senate estimates on 3 June 2026, none had been approved.
I want to be fair to the Department here. The framework itself is sound. The questions it asks are the questions any board should be asking anyway, and I will happily defend most of them. The problem is not the bar. The problem is that clearing the bar does not appear to get you anywhere yet, and providers are carrying the cost of that in the meantime.
Most providers read the framework and take away a reasonable-sounding summary: there is a process now, we should probably do the paperwork.
That summary misses the most important sentence in the document. The framework’s default position is that organisations must not use AI to directly deliver services on behalf of the Department. Not “should assess carefully”. Not “must manage the risk”. Must not, unless the Department has given written approval for that specific use case.
If your service model already assumes an AI tool this contract period, that sentence is a costed risk sitting on your critical path. It belongs in front of the board, not in an IT steering committee minute.
Three things about the framework’s reach consistently surprise people.
It does not care where the AI came from. Machine learning, natural language processing and generative AI are all in scope, whether the system was built in-house, purchased from a vendor, or adapted from an existing tool. The copilot your case management vendor switched on in their last release is in scope. Nobody bought it. Nobody decided to deploy it. It is still your application to make.
Each use case needs its own approval. This is not a one-off accreditation you earn and move on from. Every proposed use requires a separate application and separate written approval before it goes live.
The internal-use carve-out is narrower than it reads. AI for internal tasks unrelated to service delivery is permitted only if the system is fully isolated from all service-related systems and data. If you cannot guarantee that isolation, the AI must not be used. In a mid-sized provider where the same staff, laptops and tenancy touch both worlds, “fully isolated” is a much higher bar than it sounds.
This is the cost nobody budgets for, because it does not look like a failure. You licence the tool, train the staff, redesign the process around it, submit a genuinely good application, and then wait.
How long is the open question. The framework details the process: an eligibility check, an eight-section application, a departmental review that may request further information, possible consultation with agencies including DSS or the National Indigenous Australians Agency, then a decision. What it does not do is commit the Department to a turnaround time.
Which brings us back to those eleven applications. DEWR officials told the Education and Employment Legislation Committee on 3 June 2026 that roughly six months after most were lodged, none had been approved. Three were described as nearing completion, with no date offered.
That is nine months from the day the rules landed to the day officials confirmed a zero approval rate. Some of those eleven will have submitted weak applications. Three, on the Department’s own evidence, were nearly there. Either way the outcome on the ground is identical: nobody is using the tool, and everybody is still paying for it.
So build your business case on the assumption that a good application still buys you a long wait. Whatever your current planning assumption is, it is probably too optimistic.
Here is the failure mode that should worry a board most, and it is not a rejected application.
It is a frontline consultant, three months from now, pasting participant case notes into a free chatbot to draft a job plan faster, because the approved path is slow and the workload is not. One person, one prompt, one afternoon.
That single act is a use of AI in service delivery without written approval. Depending on the data involved, it is also a privacy incident involving sensitive information about a vulnerable person. And it lands in the mechanism that gives this framework its teeth: approved AI use is monitored under Right Fit for Risk accreditation, and approved use cases are reviewed annually as part of the RFFR process.
That is the line boards need to understand. AI compliance is not a separate lane running alongside your accreditation. It has been wired into it. An AI failure is now an RFFR finding, and an RFFR finding is a threat to your ability to hold the contract at all.
Approval can also be withdrawn: if the technology becomes prohibited, if you fail to meet the conditions of your approval, or if you do not identify an AI Lead or AI Accountable Officer. That last one is worth reading twice. You can lose an approval you already hold because a named senior person left and nobody replaced them.
The application form runs to eight sections, from the use case itself through privacy, reliability and safety, fairness, contestability, transparency and cybersecurity.
Read the actual questions and a pattern emerges. The Department is not asking what you intend. It is asking what you can demonstrate. Three questions in particular tend to stop applications dead.
Is all data in the AI system processed and stored exclusively in Australia? For a large share of commercial AI tooling, the honest answer is no, or worse, we do not know. That is a procurement conversation you needed to have before you signed, not after.
Is there a contractual arrangement with the vendor about how your data is used, retained and disposed of securely? Not the vendor’s marketing page. The clause. Most standard SaaS terms do not give you what the Department is asking you to evidence, and renegotiating them mid-contract is slow.
Do you have suitably qualified and adequately resourced employees to run the system securely? A capability question, in writing, that the board is effectively attesting to.
Around those sit the rest: evidence of testing and monitoring, human oversight and safe shutdown procedures, a privacy impact assessment, bias measurement across groups, and a pathway for a participant to challenge a decision AI influenced.
A business case built on cost per placement will not clear the bar. You need a defined benefit for participants, communities or service delivery, supported by evidence.
Most providers find the gap between what they do and what they can evidence at application time. That is the most expensive moment to find it, because the clock has already started.
Six questions. They are all answerable in a single meeting, and the answers tell you your exposure.
The good news is that almost none of this work is single-purpose.
The framework points directly at the Protective Security Policy Framework, the Information Security Manual and ISO/IEC 27001, and notes that an information security management system can be integrated with an AI management system. Your RFFR obligations, an ISO 42001 aligned AI management system and the incoming Privacy Act transparency requirements for automated decision-making all draw on the same artefacts: an AI register, an impact assessment, defined human oversight, a contestability pathway and clear accountability.
Build that evidence base once, deliberately, and each of those regimes becomes a reporting exercise rather than a project. Build it reactively, one application at a time under contract pressure, and you will pay for it repeatedly.
Governance Works helps DEWR-contracted providers with RFFR accreditation, AI assessments and practical AI governance. If you would like a read on where your organisation sits against the Third-Party AI Assessment Framework, get in touch. hello@governanceworks.com.au · governanceworks.com.au
Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.