AI Framework

Sample frameworks

Two complete frameworks with almost nothing in common but the six practices they’re built on.

Both are complete, unedited documents, exactly as they were produced. Each opens with the profile it was built from, so you can see what changed and why.

Sample oneTransport and logistics, three states

AI Governance Framework

Structured around the six essential practices (AI6) in the National AI Centre's Guidance for AI Adoption, October 2025.

Prepared for
Tallowood Freight Pty Ltd
Generated 22 August 2026
Transport & Logistics · Medium (20–199 employees) · Turnover More than $3 million · New South Wales, Victoria, Queensland
AI use: Data analytics and forecasting, Computer vision or image analysis
Data: Personal information (as defined under the Privacy Act 1988), Financial records, Employee / HR data

Tallowood Freight Pty Ltd operates a depot network and a mixed fleet, moving palletised goods for commercial customers across three states.

Legislative and Regulatory Context

Applies
  • Privacy Act 1988 (Cth) - Turnover above $3 million means the organisation is not a small business operator, so the Australian Privacy Principles and the Notifiable Data Breaches scheme apply to its handling of personal information. Which particular records it holds are personal information turns on facts the profile does not capture.
  • Privacy and Other Legislation Amendment Act 2024 (Cth) - APP 1.7–1.9 require an APP entity to disclose in its privacy policy the kinds of personal information used in substantially automated decisions and the kinds of decisions made, where those decisions could significantly affect an individual's rights or interests. Effective 10 December 2026.
  • Fair Work Act 2009 (Cth) - Binds national system employers, which in practice means most private sector employers. It governs terms and conditions of employment, so it reaches AI that informs rostering, hours, performance management, discipline or termination.
  • Racial Discrimination Act 1975 (Cth), Sex Discrimination Act 1984 (Cth), Disability Discrimination Act 1992 (Cth), Age Discrimination Act 2004 (Cth), Australian Human Rights Commission Act 1986 (Cth) - Statutes of general application. An organisation whose AI produces or informs decisions about individuals is covered. The Australian Human Rights Commission Act 1986 (Cth) provides the complaints and inquiry framework.
May apply depending on facts you hold
  • Heavy Vehicle National Law - Applies to vehicles above a gross mass threshold, which the profile does not capture.
  • Work Health and Safety Amendment (Digital Work Systems) Act 2026 (NSW) - Amends the Work Health and Safety Act 2011 (NSW) to require a person conducting a business or undertaking to ensure, so far as is reasonably practicable, that workers' health and safety is not put at risk by the business's use of digital work systems, defined as an algorithm, artificial intelligence, automation or an online platform. Assented to 18 February 2026. The provisions creating the duty are not in force and no commencement date has been fixed. Commencement is by proclamation and cannot occur earlier than one month after SafeWork NSW publishes its first guidelines, which have not been published.

Practice 1AccountabilityDecide who is accountable

Ownership of AI systems

Accountability structures at this scale map each AI system to a specific position or function with authority over how that system is configured, used, and reviewed. For Data analytics and forecasting and Computer vision or image analysis, those ownership assignments cover the full lifecycle: procurement or configuration, ongoing operation, and decisions about modification or withdrawal.

Governance of decisions affecting workers

Where AI informs decisions touching rostering, performance management, or other employment matters governed by the Fair Work Act 2009 (Cth), accountability arrangements record who holds authority over those decisions and how that authority relates to the output of the AI system. Employee / HR data is in scope wherever those processes draw on it.

Third-party and vendor accountability

Depot and fleet operations commonly involve AI systems supplied by third parties. A framework for this profile records what each vendor is responsible for, what the organisation retains responsibility for, and how accountability is maintained where a vendor supplies the model and the organisation supplies the data or context.

Escalation and dispute pathways

Accountability arrangements identify how concerns about AI outputs - from workers, commercial customers, or internal functions - are received and directed to whoever holds authority over the relevant system. This is distinct from the operational monitoring addressed under Testing & Monitoring.

Practice 2Impact AssessmentUnderstand impacts and plan accordingly

Identifying affected parties

Impact assessment for this profile covers the range of parties whose interests an AI system touches. For Data analytics and forecasting, that typically includes commercial customers whose freight movements are modelled and workers whose rosters or performance records contribute to the data. For Computer vision or image analysis deployed across a depot network, it includes workers and visitors whose images or behaviour may be captured.

Assessments before deployment and at review

An impact assessment is conducted before a system goes into operation and revisited when the system's scope, data inputs, or operating context changes. For AI drawing on Employee / HR data, the assessment records the nature of the decisions the system informs and whether those decisions could significantly affect individuals' rights or interests - which is the condition that engages APP 1.7–1.9 under the Privacy and Other Legislation Amendment Act 2024 (Cth) from 10 December 2026.

Discrimination and equity considerations

AI that informs decisions about individuals is within scope of the anti-discrimination statutes listed above. An impact assessment records what characteristics are represented in training or input data, what outputs the system produces about individuals, and what mechanisms exist to detect disparate outcomes across groups protected under those statutes.

Documentation of assessment findings

Findings are recorded in a durable form that can be retrieved when a system is modified, when a complaint is received, or when accountability arrangements are reviewed. The record distinguishes between risks identified, controls applied, and residual considerations that are carried forward to Risk Management.

Practice 3Risk ManagementMeasure and manage risks

Risk identification across systems and data

Risk management under this practice addresses the specific failure modes that Data analytics and forecasting and Computer vision or image analysis present in a depot and fleet environment. For forecasting systems, relevant risks include model drift as freight volumes or route patterns shift, and outputs that embed historical patterns in ways that produce inequitable results. For Computer vision or image analysis, risks include misidentification, inappropriate capture or retention of images, and outputs that inform consequential decisions about individuals without adequate verification.

Controls matched to risk level

Controls are proportionate to the risk level assigned during impact assessment. Higher-risk applications - particularly those producing outputs about identifiable individuals or informing employment-related decisions - attract more frequent review cycles, stricter data handling controls over Personal information (as defined under the Privacy Act 1988) and Employee / HR data, and documented limits on automated action.

Financial records and data integrity

AI drawing on Financial records introduces risks around data integrity and output reliability. Risk management for those applications records the quality assurance steps applied to inputs and the validation checks applied to outputs before they are acted upon.

Residual risk and review triggers

Residual risks identified after controls are applied are documented and assigned a review trigger - an event, a time interval, or a performance threshold that causes the risk profile to be revisited. The commencement status of the Work Health and Safety Amendment (Digital Work Systems) Act 2026 (NSW) is a regulatory development that, when it enters into force, constitutes a review trigger for AI systems operating in the New South Wales part of the organisation's network.

Practice 4Transparency & Information SharingShare essential information

Disclosure to workers

Workers who interact with or are subject to Data analytics and forecasting or Computer vision or image analysis are given accessible information about what the systems do, what data they use, and how outputs are used in decisions that affect them. This covers both operational transparency - what the system is doing - and decisional transparency - what weight its outputs carry.

Privacy policy obligations

The Privacy Act 1988 (Cth) requires APP entities to maintain a privacy policy that addresses personal information handling. APP 1.7–1.9, effective 10 December 2026, add a requirement to disclose in that policy the kinds of personal information used in substantially automated decisions and the kinds of decisions made, where those decisions could significantly affect individuals' rights or interests. Transparency arrangements record how and when those disclosures are updated as AI systems change.

Information for commercial customers

Commercial customers whose freight data contributes to forecasting outputs have an interest in understanding how their information is used. Transparency arrangements for this profile typically address what is disclosed in contractual or operational documentation about the use of customer data in AI-driven analysis.

Internal reporting lines

Those with accountability for AI systems receive timely information about system performance, incidents, and changes in risk profile. Internal Transparency arrangements record what information flows to whom, at what frequency, and in what format, supporting the human oversight structures addressed under Practice 6.

Practice 5Testing & MonitoringTest and monitor

Pre-deployment testing

Before a system is used operationally, testing establishes that it performs as intended against the data and conditions it will encounter. For Computer vision or image analysis, that includes testing across the lighting, angle, and volume conditions present in depot environments. For Data analytics and forecasting, it includes validation against representative freight data spanning the three states of operation.

Ongoing performance monitoring

Once deployed, systems are monitored against defined performance criteria. Monitoring intervals and metrics are set at deployment and reviewed when operating conditions change. For systems drawing on Employee / HR data, monitoring addresses whether outputs remain stable across the workforce population and whether any drift produces patterns that warrant investigation under the applicable anti-discrimination statutes.

Incident recording and response

Incidents - outputs that are wrong, unexpected, or harmful - are recorded, investigated, and fed back into risk management and accountability processes. The framework records what constitutes a notifiable incident, how it is escalated, and how findings inform subsequent testing cycles.

Vendor-supplied system testing

Where Computer vision or image analysis or forecasting systems are supplied by third parties, the framework records what testing and monitoring the vendor conducts, what results are reported to the organisation, and what independent validation the organisation applies. Accountability for testing outcomes is mapped back to the ownership assignments under Practice 1.

Practice 6Human OversightMaintain human control

Override and intervention capacity

Human Oversight structures ensure that a person with appropriate authority can intervene in, override, or halt an AI-driven process. For Computer vision or image analysis operating across a depot network, this includes the capacity to suspend automated outputs and revert to manual processes. For Data analytics and forecasting informing operational or employment decisions, it includes the authority to disregard or adjust an output before action is taken.

Limits on automated action

The framework records which categories of decision may not be taken on the basis of AI output alone. Decisions that could significantly affect workers' employment conditions - directly implicating the Fair Work Act 2009 (Cth) - are a category where human review before action is a standard feature of oversight arrangements at this profile.

Oversight of high-frequency outputs

Forecasting systems can produce outputs at a frequency that makes individual review impractical. Human Oversight arrangements for high-frequency outputs define the sampling approach, escalation triggers, and periodic review cycles that ensure automated volume does not displace human judgment over consequential decisions.

Review of oversight effectiveness

Oversight structures are themselves subject to periodic review. That review examines whether intervention pathways are understood and exercised, whether override records are complete, and whether the balance between automated output and human judgment remains appropriate as systems, data, and operational conditions evolve.

This framework is generated for informational purposes only and does not constitute legal, compliance, or professional advice. Organisations should engage qualified professionals for implementation guidance specific to their circumstances.

Sample twoManufacturing, single site, one state

AI Governance Framework

Structured around the six essential practices (AI6) in the National AI Centre's Guidance for AI Adoption, October 2025.

Prepared for
Bellbrook Components Pty Ltd
Generated 22 August 2026
Manufacturing · Small (5–19 employees) · Turnover $3 million or less · Tasmania
AI use: Customer-facing chatbots or virtual assistants, Internal document summarisation or search
Data: Personal information (as defined under the Privacy Act 1988), Employee / HR data

Bellbrook Components Pty Ltd is a family-owned engineering workshop producing machined components for domestic industrial customers, running a small permanent team across one site.

Legislative and Regulatory Context

Applies
  • Fair Work Act 2009 (Cth) - Binds national system employers, which in practice means most private sector employers. It governs terms and conditions of employment, so it reaches AI that informs rostering, hours, performance management, discipline or termination.
  • Competition and Consumer Act 2010 (Cth), Schedule 2 (Australian Consumer Law) - Applies to conduct and representations toward consumers, including statements produced or shaped by AI. Customer-facing chatbots or virtual assistants used to communicate with domestic industrial customers bring this instrument directly into play.
  • Racial Discrimination Act 1975 (Cth), Sex Discrimination Act 1984 (Cth), Disability Discrimination Act 1992 (Cth), Age Discrimination Act 2004 (Cth), Australian Human Rights Commission Act 1986 (Cth) - Statutes of general application. An organisation whose AI produces or informs decisions about individuals is covered. The Australian Human Rights Commission Act 1986 (Cth) provides the complaints and inquiry framework.
Applicability turns on your own status
  • Privacy Act 1988 (Cth) - At $3 million or less the small business exemption is the threshold, and it is displaced regardless of turnover by categories drawn from ss 6D and 6E: providers of a health service; operators of a residential tenancy database; entities trading in personal information; contracted service providers under a Commonwealth contract; credit reporting bodies; and reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). Which of those categories the organisation falls into is a fact the profile does not capture.
  • Privacy and Other Legislation Amendment Act 2024 (Cth) - APP 1.7–1.9 require an APP entity to disclose in its privacy policy the kinds of personal information used in substantially automated decisions and the kinds of decisions made, where those decisions could significantly affect an individual's rights or interests. Effective 10 December 2026. The obligation binds APP entities, so where APP entity status is itself conditional - as it is here - this obligation is conditional with it. Whether this obligation applies turns on APP entity status, which this organisation may hold independently of turnover as set out above.

Practice 1AccountabilityDecide who is accountable

Ownership of AI tools in use

A framework at this scale identifies a named individual - or, where governance is shared across a family-owned leadership group, a designated decision-making position - with clear ownership over each AI tool in operation. For Bellbrook Components, that covers the customer-facing chatbot or virtual assistant and the internal document summarisation or search tool. Ownership means responsibility for authorising changes, responding to incidents, and ensuring the tool continues to operate within agreed limits.

Supplier accountability

Where AI tools are sourced from third-party vendors, the accountability structure records what each vendor is responsible for and how the organisation receives notice of changes to the tool's behaviour, training data, or terms of service. Documentation at this level typically names the vendor, the nature of the service, and the point of contact for issues.

Escalation and decision authority

At this scale, governance documents commonly set out who has authority to suspend or withdraw an AI tool if a problem is identified. Given the single-site structure, escalation paths are short - but documenting them ensures that authority is exercised consistently and is not dependent on any one person being available.

Practice 2Impact AssessmentUnderstand impacts and plan accordingly

Customer interactions and the chatbot

The customer-facing chatbot or virtual assistant interacts with domestic industrial customers and produces or shapes representations about Bellbrook Components' products, services, and capabilities. Impact assessment under this practice records what kinds of interactions the tool handles, which customer decisions those interactions may influence, and what would occur if the tool produced an inaccurate or misleading response.

Internal document summarisation and employee data

The internal document summarisation or search tool operates across documents that may contain Employee / HR data and Personal information (as defined under the Privacy Act 1988). Assessment under this practice records which document sets are accessible to the tool, who within the organisation can query it, and what the consequences of an inaccurate summary or an unintended disclosure would be.

Proportionality at a small-scale site

Impact assessment for a single-site operation with a small permanent team does not require enterprise-scale methodology. Documentation that is proportionate to the tools in use and the people affected - customers and staff - and that is reviewed when a tool changes or a new use case is introduced, satisfies the intent of this practice.

Practice 3Risk ManagementMeasure and manage risks

Risks from customer-facing outputs

The customer-facing chatbot or virtual assistant carries risks associated with inaccurate product or service information reaching domestic industrial customers. Under this practice, risk documentation records the failure modes relevant to that tool: factual errors, responses outside the intended scope, and representations that could be inconsistent with the Australian Consumer Law obligations identified in the Legislative and Regulatory Context.

Risks from internal search and summarisation

The internal document summarisation or search tool presents risks linked to the data it can access. Where that data includes Employee / HR data, a mis-summarised document or a response surfaced to the wrong person could affect employment-related decisions or disclose personal information. Risk management under this practice records access controls, the data categories in scope, and how errors in AI-generated summaries are identified and corrected.

Review triggers

Risk documentation at this scale commonly includes a short list of conditions that trigger a review: a new AI feature is activated, a vendor updates the underlying model, an error is identified in a customer or employee-facing output, or a complaint is received. Recording these triggers in advance means review is systematic rather than reactive.

Practice 4Transparency & Information SharingShare essential information

Disclosure to customers

Where the customer-facing chatbot or virtual assistant handles enquiries from domestic industrial customers, those customers are entitled to know they are interacting with an automated tool. Transparency under this practice covers how that disclosure is made - at the start of an interaction, in terms of service, or both - and what the customer is told about the tool's limitations and the availability of a human point of contact.

Disclosure to staff

The internal document summarisation or search tool operates in an environment where staff are the primary users and, where the accessible documents include Employee / HR data, also the subject of the data being processed. Transparency arrangements address how staff are informed that the tool exists, what it can access, and how outputs from it may be used in a workplace context.

Privacy policy obligations

Where Bellbrook Components holds APP entity status (the condition for which is set out in the Legislative and Regulatory Context), the Privacy and Other Legislation Amendment Act 2024 (Cth) will, from 10 December 2026, require disclosure in the organisation's privacy policy of the kinds of personal information used in substantially automated decisions and the kinds of decisions made, where those decisions could significantly affect individuals' rights or interests. Transparency arrangements under this practice record what information is handled through each AI tool and whether any outputs constitute or inform decisions of that kind.

Practice 5Testing & MonitoringTest and monitor

Pre-deployment and change testing

Testing under this practice covers verification of each AI tool before it is first used and when material changes occur - including vendor-side model updates. For the customer-facing chatbot or virtual assistant, testing typically examines whether responses are accurate, within scope, and consistent with how the organisation represents its products and services. For the internal document summarisation or search tool, testing examines whether summaries are faithful to source documents and whether access is appropriately scoped.

Ongoing monitoring

Monitoring arrangements record how errors, unexpected outputs, and complaints are captured after a tool is in active use. At a single-site scale, monitoring can take a light form - a log of flagged outputs, a periodic review of chatbot interaction records, and a process for staff to report issues with the summarisation tool - provided those mechanisms produce actionable information and are reviewed regularly.

Monitoring where employee data is in scope

Where the internal document summarisation or search tool accesses Employee / HR data, monitoring arrangements include periodic checks that outputs involving that data are accurate, appropriately accessed, and not used in ways inconsistent with the employment framework described in the Legislative and Regulatory Context.

Practice 6Human OversightMaintain human control

Control over customer-facing outputs

Human Oversight for the customer-facing chatbot or virtual assistant covers the conditions under which a human takes over or reviews an automated interaction. Oversight arrangements record the circumstances that trigger handover to a person - complex enquiries, complaints, requests the tool cannot resolve - and how the chatbot communicates that handover to the customer.

Control over internal AI outputs

Outputs from the internal document summarisation or search tool are used by staff who bring their own judgment to those outputs. Human Oversight under this practice records that AI-generated summaries are treated as a starting point rather than a final record, and that decisions affecting staff - including any that draw on documents containing Employee / HR data - involve human review of the underlying material.

Suspension and withdrawal

Oversight arrangements at this scale document who holds authority to suspend or withdraw an AI tool, the conditions that would prompt that decision, and how operations continue in the tool's absence. For a small permanent team across one site, continuity planning for each tool ensures that its removal does not create a gap in a function that the organisation depends on.

This framework is generated for informational purposes only and does not constitute legal, compliance, or professional advice. Organisations should engage qualified professionals for implementation guidance specific to their circumstances.

A framework for your own business

Answer seven questions about your organisation and see a free preview covering two of the six practices. The full framework is $88 including GST.

See your free preview

These frameworks are generated for informational purposes only and do not constitute legal, compliance, or professional advice.
© 2026 Kentron Pty Ltd · ABN 31 123 944 927 · Privacy Policy · Terms of Use