Assess your organisation's AI governance maturity against six Australian regulatory frameworks in under 5 minutes. Receive a personalised gap report with actionable recommendations.
Step 1 of 7
About Your Organisation
We'll use this to personalise your report. Your information is kept confidential.
1. Privacy Act Compliance
The Privacy Act 1988 (2026 reforms) introduces mandatory transparency for automated decision-making, effective December 2026.
Does your organisation have a register of all AI systems that process personal information?
Can you demonstrate to an individual how an AI-assisted decision about them was made?
Do you have technical controls preventing personal information from being sent to external AI models without authorisation?
Are you prepared for the December 2026 automated decision-making transparency requirements?
2. APRA CPS 234 (Information Security)
APRA CPS 234 requires regulated entities to maintain information security capability commensurate with threats to their information assets, including AI systems.
Are AI systems classified within your information asset register with appropriate security controls?
Do you test the security controls around AI systems at least annually?
Can you notify APRA of a material AI-related security incident within 72 hours with full audit evidence?
3. Essential Eight (Cyber Security)
The ASD Essential Eight provides baseline cyber security mitigation strategies. AI systems introduce new attack surfaces that must be addressed.
Are AI applications included in your application control (whitelisting) policies?
Is multi-factor authentication enforced for all AI platform access (including API keys)?
Are administrative privileges to AI systems restricted and regularly reviewed?
4. AASB S2 (AI Sustainability Reporting)
AASB S2 requires disclosure of climate-related risks and emissions. AI compute is a material Scope 3 Category 1 emission source for many organisations.
Can you measure the carbon emissions (CO2e) of your AI workloads?
Are AI emissions included in your Scope 3 disclosure?
Do you have emissions reduction targets for AI compute?
5. Corporations Act s.180 (Director Duties)
Directors must exercise their powers with the degree of care and diligence that a reasonable person would exercise. AI governance is now within scope.
Does your board receive regular reporting on AI risks, usage, and governance posture?
Has your board formally approved an AI governance framework or policy?
Could your directors demonstrate they exercised reasonable care regarding AI risks if challenged?
6. Shadow AI Governance
Shadow AI — unsanctioned AI tools used without IT or compliance oversight — represents the fastest-growing governance gap in Australian enterprise.
Do you have visibility into which AI tools employees are using outside of sanctioned channels?
Can you prevent corporate data from being uploaded to unsanctioned AI tools on personal devices?
Do you offer a governed AI alternative that is better than free-tier tools (so employees choose it voluntarily)?
Your AI Governance Gap Report
0
Level 0 out of 5 (Maturity Scale)
Want to close these gaps?
Our Discovery & Assessment service maps your specific regulatory exposure and produces a prioritised remediation roadmap in 2-4 weeks.