AIdecoded · Board edition · internal concept for validationAustralia
AIdecoded  ›  AI Compass  ›  For Boards

AI oversight you can evidence, not just assert

Directors are personally accountable for taking reasonable steps on the risks AI brings into the organisation. Australia has no AI Act, so those steps are measured against existing law, regulator letters and published guidance. AI Compass gives the board a live risk position across every AI use case, traced to the exact obligations behind it, with a dated record that oversight happened.

The three questions every director must be able to answer

When a regulator, an insurer or a court asks whether the board exercised care and diligence over AI, the inquiry reduces to three questions. Most boards today cannot answer any of them with evidence.

1

What AI is running in our organisation?

Including the third-party tools and vendor APIs management adopted without a paper trail. You cannot oversee what is not on a register.

2

What law already reaches it?

No AI Act does not mean no obligations. Privacy, consumer, anti-discrimination and sector law apply now, and regulators have said so in writing to boards.

3

Can we show we took reasonable steps?

A defensible position is a dated record: assessments run, risks scored, obligations identified, decisions minuted. Assertions do not survive scrutiny. Records do.

What the board gets

Management operates AI Compass. The board receives its outputs: a defensible, current, clause-linked view of the organisation's AI risk, refreshed every cycle.

The AI register

Every AI use case in one place, bespoke and third-party, each with an owner. The answer to question one, kept current by management.

The obligation map

Each use case mapped to the instruments that reach it under Australia's technology-neutral approach, at clause level, in plain language.

The risk position

Deterministic risk levels per use case, rolled into one board view. Identical inputs always score identically, so the position is auditable and comparable cycle to cycle.

The committee pack

A board-ready document each cycle: the position, what changed, why, and the decisions sought. Written for directors, not developers.

Change alerts

A regulator letter, a statutory date, a new standard: the landscape moves, affected use cases re-score, and the risk committee hears about it before it matters.

The oversight record

Every assessment, score, alert and committee review, dated and preserved. If the reasonable-steps question is ever asked, the answer already exists.

The board cadence

AI Compass turns AI oversight into a repeatable governance rhythm, the way boards already govern financial, cyber and safety risk.

01

Inventory

Management registers every AI use case, including vendor tools and shadow adoption.

02

Map

Compass links each use case to the obligations that reach it, at clause level.

03

Assess

Owners complete curated, guided assessments. Scoring is deterministic and auditable.

04

Table

The risk committee receives the position, the changes and the decisions sought.

05

Evidence

The cycle is recorded and dated. The board's reasonable steps become a matter of record.

In the boardroom

A worked example, from a director's question to a minuted position. Step through it. Concept mockup, illustrative content.

Management wants to roll out an AI tool that screens job applications before a human sees them. What is our exposure as a board if we approve this?
This is automated decision-making in recruitment, using personal information. Three instruments reach it today, and one statutory date arrives on 10 December 2026. Before the board forms a view, management should complete the matching assessment: nine questions, owned by the hiring system's sponsor.
Routed to ADM-REC-01 · Automated screening in recruitment · from the curated bank, never improvised
1 · Does the tool score, rank or filter applicants before any human sees them?
Yes, it filtersIt only assistsNot sure
2 · What information does it use?
CVs and work historyFree-text responsesDemographic dataThird-party data
3 · Can an applicant find out a machine was involved, and ask for review?
Yes, bothNeither todayPartially
6 more questions · completed by the accountable owner, not the board · answers feed the deterministic scoring model
High risk
Automated filtering · no transparency or review path · statutory date approaching
ADM transparency obligations Privacy Act · from 10 Dec 2026
Disclosure of automated decision-making becomes a statutory requirement. The current design is out of position for the date.
Indirect discrimination exposure SDA s.5 · DDA s.6
Filtering on free-text responses can proxy for protected attributes. No bias testing evidence exists on the record.
Reasonable steps benchmark GfAA practices 2, 3, 6
Impact assessment, risk management and human oversight are the closest written benchmark a court or insurer would reach for.

Questions to put to management

  • What changes to the design close the transparency gap before 10 December 2026?
  • What bias testing will be run before go-live, and who signs off on the results?
  • Who is the accountable owner, and when does this return to the committee?
For the minutes: assessment ADM-REC-01 tabled, risk level High, deployment deferred pending remediation, review scheduled next cycle. The record is dated and preserved.

Why this is on the board's desk now

Regulators stopped writing to compliance teams and started writing to boards. The 2026 calendar sets the pace.

02 Dec 2025

Mandatory guardrails shelved

The National AI Plan confirms technology-neutral regulation. Responsibility shifts to organisations, and to the directors who govern them, under existing law.

30 Apr 2026

APRA writes to every regulated entity

Four named weak spots: information security, governance immaturity, supplier concentration, inadequate assurance.

May 2026

ASIC directs boards to table its AI letter

Addressed to board and risk-committee level. The letters become the closest written benchmark for reasonable steps under existing directors' duties.

15 Jun 2026

Mandatory AI requirements begin for Commonwealth agencies

Impact assessments, accountable officials and Chief AI Officers, with procurement pulling the supplier base into scope.

10 Dec 2026

ADM transparency takes effect

The hardest statutory date on the AI calendar, and the sharpest test of whether the board saw its own exposure coming.

Built for regulated boards first

Compass maps the landscape industry by industry, starting where regulator attention on boards is sharpest.

Financial services

  • APRA letter on AI · 30 April 2026
  • ASIC AI letter, tabled at board level
  • CPS 230 · Operational Risk Management
  • Privacy Act · ADM transparency
  • Australian Consumer Law · AI claims
and more

Healthcare and life sciences

  • Therapeutic Goods Act · software as a device
  • Privacy Act · health information, APPs
  • ADM transparency · from 10 Dec 2026
  • Anti-discrimination law · access decisions
  • Guidance for AI Adoption · six practices
and more

Government and suppliers

  • APS AI policy · mandatory from 15 Jun 2026
  • Full agency compliance · 10 Dec 2026
  • AI impact assessments · Chief AI Officers
  • Procurement AI clauses for suppliers
  • Australian Standards for AI · announced Jul 2026
and more

Start with one board cycle

The fastest way to evaluate AI Compass is to run it once, on your own register. In a single cycle the board sees its current AI risk position, the obligations behind it, and what the oversight record looks like when it exists.

The board briefing covers

  • Your sector's obligation map under the technology-neutral approach
  • A live walkthrough of the risk position and committee pack
  • The 2026 dates that apply to your organisation
  • What a first cycle would involve, and what it produces
Request a board briefing