AI risk assessment for one Australian system, ending in a decision your executive can sign.

Bring us one AI system. We screen it, score the harm it can do to your organisation and to the people it makes decisions about, tie every treatment to a control, and write the go-live memo. Allow 1 to 2 weeks for a single system, or 4 to 6 weeks if you bring a portfolio of 10 to 20.

You keep two registers, a controls map and the signed memo. The five stages below show how each one is produced and who from your side is in the room.

How we run it

Built for

APRA-regulated entities 路 AFS and credit licensees 路 Commonwealth and NSW agencies 路 Any APP entity deploying automated decisions

What you hold at the end.

How we run it

Two-column risk register

Every risk with its likelihood, its consequence for the organisation and its consequence for customers, plus inherent and residual tiers and the automated-decision and third-party flags.

Impact assessment

The ISO/IEC 42005 view of the system: intended use, foreseeable misuse, interested parties, a best case and a worst case, and the measures for each harm and benefit.

Controls map

Each treatment as a control with an owner, mapped to an ISO/IEC 42001 Annex A theme and a NIST AI RMF category, with the evidence that it operates.

Go-live memo and triggers

One page for the accountable executive with the decision and its conditions, plus the changes (purpose, data, users, environment, law) and a 12-month backstop that reopen the assessment.

How we run it

The method is ISO 31000 as extended for AI by ISO/IEC 23894, with an ISO/IEC 42005 impact assessment beside it.

The method and workbook are public. The engagement is us running them on your system, with your people in the room.

Stage 01

Screen the system and name everyone who supplies it.

The screen decides whether the system needs a full assessment at all. It covers the system's effect on people's rights and access to services, its use of personal or sensitive information, and how much of the decision a computer program makes.

A system that screens in goes into your inventory with its model provider, hosting provider and any fine-tuning vendor recorded as separate parties. Risk, legal and privacy then agree which instruments are in scope.

Example

A claims triage model that uses health information and shapes how fast a claim is settled screens in. An internal meeting summariser that makes no decisions about individuals screens out, with the reason on file.

OUTPUT 路 Threshold decision, inventory entry, supply-chain map

APRA lists an AI inventory and a map of the full AI supply chain, down to fourth parties, among its minimum expectations.

Stage 02

Write the risks with the people who see the failures.

We run the workshops with the business owner, the data team, privacy, legal and whoever answers customer complaints. The complaints desk already knows where the model goes wrong.

Each risk gets its own row and a source from the ISO/IEC 23894 Annex B themes, such as opacity, automation level, machine learning behaviour or technology readiness. We record the source because it tells you which treatment fits.

Example

A vendor swaps the model version without telling you and the outputs shift. The source is the system life cycle, so the treatment is change control: version pinning in the contract and drift monitoring against a frozen test set.

OUTPUT 路 Draft risk register with category and source per row

ASIC asks licensees whether staff from multiple disciplines, beyond the technical experts, are assessing AI risk.

Stage 03

Score each risk for your organisation and for your customers.

Likelihood gets one score. Consequence gets two, one for the organisation and one for the consumer or community, and the higher of the pair sets the tier.

We use a five by five matrix whose consequence endpoints match the Commonwealth tool's descriptors. Medium or above means full treatment. High or Critical goes to your risk committee.

Example

The claims model declines or delays one demographic group more than others because that group is under-represented in its training data. On business consequence alone the risk scores 9, Medium. Scored for the policyholders it delays, it reaches 12, High, and goes to committee.

OUTPUT 路 Inherent tier per risk, overall rating for the system

ASIC found licensees that assessed fraud risk in overseas-developed identity verification models and missed the cohorts that would fail verification, because the models were not trained on representative Australian data.

Stage 04

Assess the effect on people and list the automated decisions.

The impact assessment follows ISO/IEC 42005. It sets out the intended use, the foreseeable misuse, who is affected and who was consulted, and it ends with a best case and a worst case in plain words.

Privacy is tested in the same pass. The OAIC expects a privacy impact assessment as part of privacy by design, and personal information an AI system generates or infers counts as a collection under APP 3. Every automated decision gets a flag.

Example

Worst case for the claims model: one cohort is systematically routed to manual review and delayed, and complaints and regulator attention follow. The model does a step and a person decides, so the decision is flagged as substantially related.

OUTPUT 路 Impact assessment, scenario pair, automated-decision list

From 10 December 2026, APP 1.7 to 1.9 require APP entities to describe in their privacy policy the kinds of decisions a computer program makes, or substantially contributes to, using personal information, and the flagged rows give your privacy team that list.

Stage 05

Treat, map to controls and sign.

Any risk above tolerance gets a treatment, an owner and a control ID. Each control is mapped to an ISO/IEC 42001 Annex A theme and a NIST AI RMF category, with the evidence that shows it works. Residual risk is then scored against your appetite.

The memo to the accountable executive states the decision, its conditions and the triggers that reopen the assessment. Every material change reopens it, and no system goes more than a year without review. With no appetite statement to test against, the memo records the gap, and the next piece of work is AI risk management framework development.

Example

Cohort fairness testing on Australian claims data before release, a monthly disparity report and human review of every decline bring the claims model's bias risk down to 6, inside tolerance. The release ticket showing the testing gate is the evidence.

OUTPUT 路 Controls map, residual tiers, signed memo, review triggers

APRA expects control libraries, change control for AI implementations, and risk assessment that continues throughout the lifecycle.

What changes by sector.

The five stages stay the same. Your sector decides which instruments are in scope and what evidence the memo has to carry.

Sector

Banks, insurers and superannuation trustees

We write the assessment for an APRA reader. An AI system inside a critical operation is tested against your CPS 230 tolerance levels, and its model provider is checked against the material service provider register. The security work covers the risks APRA named: prompt injection, data leakage and misuse of autonomous agents, including identity and access controls never adjusted for non-human actors. APRA has found that point-in-time, sample-based assurance suits probabilistic models poorly, which is why the memo runs on triggers. See financial services, insurance and superannuation.

Sector

AFS and credit licensees

The register answers ASIC's five questions for licensees line by line. Fairness, consumer disclosure and contestability each get a row: ASIC found fairness referenced at only 12 of the 23 licensees it reviewed, disclosure requirements at 10, and AI-specific contestability arrangements at none. Third-party models are held to the same expectations as in-house ones, which ASIC named as better practice.

Sector

Commonwealth, state and local government

Commonwealth agencies must complete an AI impact assessment for in-scope use cases under the DTA policy. NSW agencies must register use cases on the AI Assessment Framework platform, and high or critical assessments go to the AI Review Committee. We complete the mandated instrument and run the controls map and residual scoring beside it, so the agency holds the compliance artefact and a working register. The controls map aligns to AS ISO/IEC 42001, 23894 and 38507, the standards named in the National Framework for the Assurance of AI in Government. See government.

Sector

Technology and enterprise buyers of AI

Most assessments we run are of procured systems. You cannot see the vendor's weights and the vendor cannot see your use case, so we work from documentation, contract terms, security questionnaires and data processing terms. The contractual gaps (version pinning, change notice, retention and training on your data) are named before signature, and intellectual property risk is scored under NIST MAP 4.1. Outside the regulated sectors, the Voluntary AI Safety Standard's second guardrail and the National AI Centre's Guidance for AI Adoption describe this process without a mandate. See technology and third-party AI risk.

Questions Australian clients ask.

What does APRA expect an AI risk assessment to cover?

APRA's minimum expectations are an inventory of AI tooling and use cases, comprehensive risk and information security assessments before deployment and throughout the lifecycle, mapping of the full AI supply chain including fourth parties, globally recognised control frameworks with control libraries and change control, human involvement for high-risk decisions, and staff training. APRA places these under the existing CPS 230, CPS 234, CPS 220 and CPG 235 and has issued no new standard.

Why do you score consumer harm separately from business risk?

ASIC found that some licensees assessed AI risk through a business lens and did not consistently identify consumer harm such as algorithmic bias. Licensees assessed identity-verification models for fraud risk and missed the risk of cohorts failing verification. Our register scores the organisational consequence and the consumer or community consequence in separate columns, and the higher one sets the tier.

Does the assessment cover the APP 1.7 automated-decision obligation?

Yes. From 10 December 2026, APP entities must describe in their privacy policy the kinds of personal information used by, and the kinds of decisions made by or substantially shaped by, a computer program that significantly affects an individual. Every row in our register carries an automated-decision flag, so the assessment produces the list the privacy policy needs.

We are a Commonwealth or NSW agency. Do you use our mandated tool?

Yes. Commonwealth agencies must complete an AI impact assessment for in-scope use cases under the DTA policy, and NSW agencies must register and assess use cases on the AI Assessment Framework platform. We complete the mandated tool and run our register alongside it, so the controls map and residual scoring carry over.

Can you assess a vendor's model when we cannot see inside it?

Yes. ASIC found 30 percent of use cases ran on third-party models, and for four licensees every model was third-party. ASIC treats holding third-party models to the same expectations as in-house ones as better practice. We assess from vendor documentation, contracts, security questionnaires and data processing terms, and the register records the model provider, hosting provider and any fine-tuning vendor as separate parties so the supply-chain map APRA asks for exists at the end.

How is this different from an AI risk management framework?

An assessment examines one system and answers one question: should it go live, and under what conditions. A framework is the organisation-wide structure that decides how every system is assessed: taxonomy, risk appetite, method, controls library and board reporting. If the assessment finds there is no appetite statement to test residual risk against, that is a finding, and the next engagement is framework development.

Bring the system that is waiting on a decision.

A thirty-minute call. We run the threshold screen with you, name the regulators in scope, and tell you what a full assessment of that system would need to produce before anyone signs.

Or start with the framework

Get in Touch