4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

What Goes in an AI Governance Framework

An AI governance framework is the written structure that says who decides what AI your business uses, how the risk is assessed, what staff may and may not do with it, and how you review the lot as things change. For an Australian SME it should run to a handful of documents, not a shelf of them: an AI policy, an AI register, an impact assessment process, named ownership and a review cadence. That is the whole thing, and most businesses can stand it up in a fortnight.

Open notebook and laptop on a meeting room table.

Key facts

  • Australia's Voluntary AI Safety Standard sets out ten guardrails covering accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply chain, record keeping and conformity.
  • The Department of Industry, Science and Resources later published Guidance for AI Adoption, which consolidates those ten guardrails into six essential practices that scale from a small business up to an enterprise.
  • The guardrails were crosswalked to ISO/IEC 42001:2023 and the NIST AI Risk Management Framework, so building to one of them largely builds to the others.
  • An AI register is the single highest value artefact: one row per AI tool, recording purpose, data touched, owner and approval status.
  • Risk assessment and impact assessment are different questions. Risk is what could go wrong for the business. Impact is what could go wrong for the people affected by the output.
  • Nothing in the framework needs to be long. A four page policy that staff follow beats a forty page one that nobody has read.

What goes in the framework?

Five components, in the order worth building them.

  1. The AI register. Every AI tool in use, including the ones that arrived inside software you already pay for. Purpose, what data goes in, who owns it, approved or not, and when it was last reviewed.
  2. The AI policy. Approved tools, prohibited data, who is accountable for checking output before it reaches a client, what must be disclosed, and who owns the policy.
  3. Assessment. A short risk and impact assessment for anything that touches personal information, affects a decision about a person, or produces output a client relies on. For most SME tools this is half a page.
  4. Roles. One accountable owner for AI overall, plus a named owner per system. In a thirty person business the first is usually a director and the second is whoever asked for the tool.
  5. Review. Quarterly. The tool list changes far faster than the policy, so the review is mostly about the register.

Which framework should an SME build to?

Start with the Australian material, because it is free, written for this jurisdiction and designed to scale down. The ten guardrails in the Voluntary AI Safety Standard are the detailed control catalogue, and the six essential practices in Guidance for AI Adoption are the version to hand to a small business, because they compress the same expectations into something a non-specialist can act on.

Use ISO/IEC 42001 as the structure if you are heading toward certification, or if a client has asked whether you have an AI management system. Use the NIST AI Risk Management Framework if your customers are American and ask for it by name. All three cover the same ground: govern, map, measure, manage.

What you should not do is build to the EU AI Act unless you actually place AI systems on the EU market. It is a far heavier regime, it is not Australian law, and for a Sydney SME serving Sydney clients it imports cost with no benefit.

Where do frameworks fail?

Three failure modes, and we have seen all three this year.

The first is the register that was accurate once. It is built, it is correct in March, and by September three new tools have appeared and nobody updated it. The fix is the quarterly review being somebody's named job rather than a good intention.

The second is policy without enforcement. If the policy says staff must not paste client data into unapproved AI tools and there is no technical control behind it, you have documented an expectation, not managed a risk. The controls that make it real are tenant restrictions on which services are reachable, data loss prevention rules on what can be uploaded or pasted, and logging.

The third is governance written for a business that does not exist. Frameworks copied from a bank include model validation, bias testing and lifecycle controls for models you are not building. If you consume AI rather than develop it, most of that is not applicable, and writing it down anyway makes the document longer and less likely to be followed.

Frequently asked questions

What is the difference between an AI policy and an AI governance framework?

The policy is one document inside the framework. It tells staff what they may do. The framework is the whole structure: the register, the assessment process, the roles, the review cadence and the technical controls, with the policy as the staff-facing part of it.

Do we need an AI governance framework if we only use Copilot?

You need a smaller one, not none. One tool still means a register entry, a short policy covering what may go into it, a decision about which staff have it, and the permission clean-up that Copilot makes urgent because it surfaces anything a user can already open. That is a lot less work than a full framework, but it is not zero.

Who should own AI governance in a small business?

A director or an operations manager, not the IT provider. We can build the register, write the policy and implement the controls, but the decisions about acceptable use are business decisions and an auditor will expect them to sit with the business.

How often should the framework be reviewed?

Quarterly for the register, annually for the policy, and immediately whenever you adopt a new AI tool, change what data you put into an existing one, or something goes wrong. The register is the part that drifts.

Is any of this legally required in Australia?

No framework is mandated by name. The Privacy Act, consumer law and your own contractual obligations already apply to how you use AI, and the Australian guidance is voluntary. The practical driver for most SMEs is commercial rather than legal: clients and insurers are asking.

If you want the register and the policy built rather than described, that is a short engagement and it is the part that makes everything else possible.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on AI governance, Microsoft 365 security, Privacy Act obligations and the Essential Eight, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Book a meeting

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details