AI governance assessment
Northbridge Community Services
Not-for-profit · ~85 staff · Victoria
Executive summary
Developing
Northbridge has begun to govern its use of AI but the arrangements rest on a small number of individuals and are not yet evidenced. The most material exposure is in data and privacy, where client information is being entered into tools that have not been assessed. Three priorities below would move the organisation to a defensible position within one quarter.
AI is in use across five teams
Two of those uses touch client records. Neither was assessed before adoption.
Accountability is implied, not assigned
No individual is formally accountable, and the board has not recorded a decision on AI.
Controls exist but cannot be evidenced
A policy is in place. There is no record of who has read it or how it is enforced.
Maturity by domain
Findings
Each finding records what we observed, the evidence behind it, and the action we would take. The instrument that motivates each action is named, so the board can see whether it is responding to a legal obligation, a standard, or a governance choice.
Oversight and accountability
47/100Is accountability for AI governance formally assigned?
Ad hoc- The Chief Executive is understood to hold it informally.
- No position description, delegation or board minute records the responsibility.
Assign accountability to a named executive and record it in the next board minute, together with what they are accountable for.
Voluntary AI Safety Standard, Guardrail 1
Does the board receive reporting on AI use and risk?
Ad hoc- AI has been raised twice in discussion during 2026.
- No written report has been tabled and no decision is recorded.
Add AI as a standing item under the risk report, with a one-page summary covering use, change, incidents and decisions required.
Directors' duties of care and diligence; AICD Director's Guide
Strategy and risk appetite
58/100Has the board expressed an appetite for AI-related risk?
Developing- The 2026 strategy refers to improving efficiency through technology.
- No statement distinguishes acceptable from unacceptable AI use.
Agree a short appetite statement. Three sentences naming what the organisation will not do with AI is more useful than a page of principles.
ISO/IEC 42001; NIST AI Risk Management Framework
Are AI uses assessed for risk before adoption?
Developing- Larger purchases go through the usual procurement review.
- Free tools adopted by teams bypass that review entirely.
Extend the existing triage to cover free tools. Cost is a poor proxy for risk, and the unassessed tools are the ones touching client data.
Voluntary AI Safety Standard, Guardrail 2
Policy and controls
61/100Is there an AI policy, and do staff follow it?
Managed- An AI acceptable use policy was issued in March 2026.
- No acknowledgement record exists, and two teams were unaware of it.
Record acknowledgement at induction and annually. A policy nobody can be shown to have read is not a control.
Voluntary AI Safety Standard, Guardrail 1; ISO/IEC 42001
Is meaningful human review applied to AI-assisted decisions?
Managed- Draft client correspondence is reviewed by a team leader before sending.
- Review of AI-assisted intake summaries is inconsistent under workload.
Confirm reviewers have the time and authority to overturn an output. Oversight that cannot realistically be exercised is not oversight.
Voluntary AI Safety Standard, Guardrail 5
Data and privacy
34/100Is client information protected from entry into public AI tools?
Ad hoc- Staff in two teams have entered client details into a free assistant to summarise case notes.
- No technical control prevents this and no approved alternative is provided.
Provide an approved tool that handles this task, then restrict the unapproved ones. Prohibition without a workable alternative does not hold.
Australian Privacy Principles; Voluntary AI Safety Standard, Guardrail 3
Have automated decision-making obligations been considered?
Ad hoc- AI assists in prioritising intake, which affects the order in which clients are seen.
- No assessment has been made of what must be disclosed to those clients.
Identify every decision about a person that AI influences and determine the disclosure required. Treat this as the first priority.
Privacy Act 1988 (Cth); Voluntary AI Safety Standard, Guardrail 6
Suppliers and models
44/100Do supplier arrangements address the supplier's use of AI?
Developing- Two of eleven current agreements mention AI.
- The case management vendor introduced an AI feature without notice in April 2026.
Add two questions to onboarding and renewal: do you use AI on our data, and where is it processed. Most AI exposure now arrives through a vendor.
Voluntary AI Safety Standard, Guardrail 8
Culture and capability
68/100Do staff understand what is and is not acceptable?
Managed- Awareness is good in the teams that attended the March briefing.
- Staff who joined since have received nothing.
Fold a short AI segment into induction. Twenty minutes at the start is worth more than an annual module.
Voluntary AI Safety Standard, Guardrail 10; ISO/IEC 42001
Can staff raise concerns about an AI output?
Developing- The general feedback channel exists and is used.
- No concern relating to AI has been raised, which is unlikely given usage levels.
Name AI explicitly in the existing channel so people recognise it covers them, and report what is raised to the board.
Voluntary AI Safety Standard, Guardrail 7
Instruments applied
What each one is matters as much as what it says. A legal obligation and a good practice guide are not the same thing, and a board spending money should know which it is responding to.
Voluntary AI Safety Standard (Australia)
Ten guardrails for safe and responsible AI, published by the Department of Industry, Science and Resources.
Privacy Act 1988 (Cth) and the Australian Privacy Principles
Obligations for handling personal information, including transparency about automated decision-making.
NIST AI Risk Management Framework
A structured approach to identifying, measuring and managing AI risk.
Directors' duties of care and diligence
The general duty that requires directors to inform themselves on matters material to the organisation.
AICD Director's Guide to AI Governance
Sector guidance on what boards are expected to ask and record.
Roadmap
Sequenced so that each stage makes the next one possible. Nothing here requires a programme of work.
First 30 days
Stop the bleeding and assign ownership.
- Assign accountability for AI governance to a named executive and minute it.
- Instruct staff that client information must not be entered into unapproved tools, and say which tool to use instead.
- Complete a one-page inventory of AI tools in use across all teams.
By 90 days
Make the controls real and evidenced.
- Assess the two client-facing uses for privacy and automated decision-making obligations.
- Record policy acknowledgement for all staff and add AI to induction.
- Add AI questions to supplier onboarding and the next three renewals.
- Table the first written AI report to the board.
By 180 days
Hold the position and demonstrate it.
- Agree and publish a short AI risk appetite statement.
- Extend risk triage to cover free and low-cost tools.
- Collect the evidence each control produces and file it as you go.
- Reassess the two weakest domains and report the trend to the board.
What we would put in front of the board
Suggested board agenda items
- Who is accountable for AI in this organisation, and what are they accountable for?
- Where is AI touching client information today, and was that assessed?
- What is our appetite: what will we not do with AI?
- If a regulator asked for evidence tomorrow, what could we produce?
- What do we want reported to this board about AI, and how often?
Suggested management actions
- Complete and maintain the AI inventory, reviewed quarterly.
- Provide an approved tool for case note summarisation and restrict the alternatives.
- Record policy acknowledgement and add AI to induction.
- Add AI questions to supplier onboarding and renewals.
- Produce a one-page AI report for each board meeting.
This sample is provided for illustration only. It is not legal advice, an audit, an assurance opinion or a compliance determination, and no person should rely on it. A real report reflects the evidence provided by the organisation assessed. See our Terms and Conditions.
This is the output you would receive.
Scored, evidenced, traced to the instruments behind it, and written so a board can act on it. Start with a conversation about what yours would cover.