The PolyGovern AI Governance Framework
Stand up AI governance a regulator can inspect, one element at a time.
This page takes the eleven elements of the framework in the order we build them. Each element names the work and the record it leaves behind, with a worked example from Australian or New Zealand practice. You finish with eleven artefacts to produce and the order to produce them in.
Neither Australia nor New Zealand has a single AI governance law. Australia's National AI Plan keeps regulation on existing technology-neutral legislation, and New Zealand's AI Strategy calls its approach light-touch and principles-based. Both governments publish voluntary guidance and expect organisations to show their work.
The steps below follow the four phases of the Evidence-First Method (Australia, New Zealand). The order matters because a policy written before the register exists describes systems nobody has counted, and a control built before the board approves an appetite has no threshold to test against. Most organisations need 6 to 9 months to reach a position they can defend to a regulator, with steps 1 to 3 built and the first assurance cycle of step 4 complete.
Three companion pages sit alongside the framework. The AI Risk Calculator classifies one system at a time, and the maturity model shows how far along each element you are today. The crosswalk sets ISO 42001, NIST AI RMF, the Australian and New Zealand guidance and the privacy principles side by side.
Step 1 · Map
Find every AI system and put it on the register.
This step has one element and produces one document. Every later step is measured against the register, so it comes first. A system that is not on it does not move to step 2.
- 07
Evidence artefacts.
What to do
List every AI system, including the AI embedded in HR, customer service and productivity tools. Record where each system's data comes from and classify each entry against the obligations it triggers. The AI Risk Calculator classifies one system at a time.
What it produces
A dated AI register with an obligations column. It opens the evidence pack, and every later step adds a document to it.
Worked example
A hardship team's scoring spreadsheet goes on the register. The OAIC reads computer program in APP 1.7 to 1.9 broadly enough to cover spreadsheets, and human review does not take a tool out of scope when its output is a key factor. In New Zealand, scraped, inferred or vendor-sourced personal information is indirect collection, and IPP 3A has required reasonable steps to tell the person since 1 May 2026.
The National AI Centre's Guidance for AI Adoption ships an AI register template under essential practice 4, and guardrail 9 of the Voluntary AI Safety Standard (VAISS) asks for records a third party can use to assess compliance.
Step 2 · Frame
Decide who owns AI and what the organisation will accept.
Each of the six elements here is a decision written down and approved. Controls are not built against an appetite nobody has approved, so the board paper closes this step.
- 02
AI policy.
What to do
Write one organisation-wide policy covering what AI is used for, what it will not be used for, who approves a new use and what every user must do. Business unit policies sit under it.
What it produces
An approved policy with a version, an owner and a review date. A staff acknowledgement record. Links to the register, the risk screening and the approval route.
Worked example
Start from the National AI Centre's AI policy template for essential practice 1. A New Zealand business can write against MBIE's Responsible AI Guidance for Businesses, which is voluntary and relies on existing law.
The OAIC expects Australian organisations to update their privacy policy and label public-facing AI, so the AI policy and the privacy policy have to agree.
- AI policy development: Australia · New Zealand
- AI policy template
- 04
Risk appetite.
What to do
Write down which decisions may be automated, the error rate the organisation will tolerate, where a human must sign off and which data may never be used. Set the thresholds that monitoring will later be measured against.
What it produces
A risk appetite statement with thresholds, ready for board approval. A log of uses declined because they sat outside it.
Worked example
The Algorithm Charter rates a use for likelihood (probable, occasional, improbable) against impact (low, moderate, high). At a high rating the Charter must be applied, and at moderate it should be. A New Zealand agency can use the same bands to decide which uses go to the board.
NAIC essential practice 3 includes a risk screening template for flagging uses the organisation will not accept.
- AI risk management framework: Australia · New Zealand
- Public Service AI Framework
- 01
Board oversight.
What to do
Take the policy and the risk appetite to the board. Name the senior leader who owns AI governance, set the cadence of the board's AI report and send any use above appetite back to the board for sign-off.
What it produces
The board paper approving the policy and the appetite. Minutes showing AI on the agenda at the agreed cadence. A named senior owner.
Worked example
In an APRA-regulated entity the owner is the accountable executive named under FAR. Commonwealth entities already have the accountable official the DTA policy requires, and the GCDO generative AI guidance recommends a senior official, such as a chief risk officer, for New Zealand agencies.
NAIC essential practice 1 asks for a senior leader as overall owner of AI governance.
- Board-level AI governance: Australia · New Zealand
- 03
Roles and accountability.
What to do
Name three people against every system on the register: the accountable person, the technical owner and the risk reviewer. Then map the vendors and model providers behind each bought system.
What it produces
A RACI for each system. Supply-chain accountability notes for each third-party model. Position descriptions that include the AI duties.
Worked example
For a bought model, NAIC implementation item 1.2.1 splits accountability across the model developer, the system developer and the deployer, and the notes record which role the organisation holds. A blank cell in the register's owner column is a system nobody answers for.
NAIC essential practice 1 asks for a named accountable person for each AI system.
- Third-party AI risk: Australia · New Zealand
- 08
Three lines of defence.
What to do
Place AI inside the lines the organisation already runs for other risk. Operational teams run the controls, risk and compliance set the standard and challenge each approval, and internal audit tests independently. AI gets no separate committee outside those lines.
What it produces
Line responsibilities written into the AI policy. Second line review records. Internal audit reports on AI controls.
Worked example
An APRA-regulated entity puts its AI systems into the CPS 230 operational risk framework it already runs. Internal audit can work from the IIA AI Auditing Framework, which is built on the Three Lines Model.
ISO 42001 clause 9.2 requires internal audit of the AI management system.
- 09
Federated governance.
What to do
In a group, the centre sets the standard and keeps the single register. Each business unit or subsidiary runs AI inside that standard with its own named owners and keeps the decision.
What it produces
A group standard with unit supplements. One register with a unit ownership field. An escalation route from each unit to the group risk committee.
Worked example
A group with a bank, an insurer and a wealth arm ends up with three incompatible AI programmes when each unit writes its own. One standard and one register stop that, and each unit still approves its own uses.
ISO 42001 clause 4 asks for the scope of the AI management system, and the group standard is where that scope is written.
- AI governance consulting: Australia · New Zealand
Step 3 · Control
Wire the controls into the workflows that carry the risk.
These three elements live inside the work itself. Each one leaves a record as it runs, so the evidence exists before anyone asks for it.
- 05
Governance loop.
What to do
Build one path for every new AI use: proposal, risk screening, impact assessment where triggered, privacy impact assessment where personal information is involved, approval, deployment and review. A vendor tool takes the same path as a model built in house.
What it produces
A documented intake and approval workflow. A completed screening for each live system, with the impact and privacy assessments it triggered.
Worked example
The New Zealand Privacy Commissioner expects senior approval, a privacy impact assessment before use, human review of outputs and engagement with Māori where taonga data is involved. The Algorithm Charter does not fully address Māori data sovereignty, so a New Zealand loop adds a classification step and an engagement step for Māori data.
The OAIC treats developing a generative AI model on large volumes of personal information as high risk warranting a privacy impact assessment, and Commonwealth entities complete the DTA impact assessment for each in-scope use case.
- AI impact assessment: Australia · New Zealand
- AI risk assessment: Australia · New Zealand
- AI risk assessment template
- Māori data governance
- 11
Human oversight.
What to do
Document where a person sees each system's decision and can override it, and train the people who hold that override. Give affected people a way to learn that AI was used and a channel to challenge the outcome, sized to the impact.
What it produces
Override points for each system. Training records for the overseers. A contestability channel with its log. Published disclosure text.
Worked example
From 10 December 2026, APP 1.7 to 1.9 require an Australian privacy policy to describe the kinds of personal information used in, and the kinds of decisions made by, computer programs where a decision could significantly affect a person. The duty is disclosure only and gives no right to contest. The challenge channel comes from VAISS guardrail 7 and the Algorithm Charter, and its log is what the organisation shows when a complaint tests it.
NAIC essential practice 6 asks for human override points and an alternative pathway for when the AI fails.
- AI ethics implementation: Australia · New Zealand
- Privacy Act 2020
- 10
Agentic AI.
What to do
Give every system that takes actions its own control set. Write down what it may do without a human, which tools and data it may reach, how it is stopped and how its actions are logged for reconstruction. Then test the stop.
What it produces
An authority matrix for each agent. Tool and data access lists. Kill switch and rollback procedures with test records. Retained action logs.
Worked example
The Australian and New Zealand instruments were written for systems whose output a person then acts on. None of them addresses a system that books the appointment, moves the money or changes the record itself. Until a local reference exists we use the Model Governance Framework for Agentic AI from Singapore's IMDA.
The NIST Generative AI Profile lists human-AI configuration and value chain among its twelve risks.
- Model governance: Australia · New Zealand
Step 4 · Assure
Run the assurance calendar and keep the evidence current.
One element keeps the evidence for the other ten current. The cycle has no exit, and a new system joins at step 1.
- 06
Assurance rhythm.
What to do
Set the assurance calendar. Monitoring frequency scales with each system's risk and runs against the appetite thresholds. Internal audit covers AI on a defined cycle, management reviews the results and the board receives its report. Refresh the evidence pack on the same calendar.
What it produces
An assurance calendar. Monitoring reports measured against the thresholds. Internal audit plan entries for AI, management review records and an evidence pack that matches production.
Worked example
ISO 42001 clause 9 requires internal audit and management review. NIST AI RMF has no internal audit construct, and neither the NAIC guidance nor the Public Service AI Framework requires an audit. Put AI on the audit plan anyway, because clause 9 evidence is what a certification auditor reads first.
NAIC essential practice 5 asks for monitoring matched to risk, and the Algorithm Charter commits signatory agencies to regular peer review.
- AI audit and assessment: Australia · New Zealand
- Ongoing advisory: Australia · New Zealand
- ISO 42001 certification: Australia · New Zealand
Frequently asked.
Answers describe the instruments as they stand on 10 October 2026. Where a government has announced a change and not enacted it, we say so.
Is there a single Australian AI governance framework?
No. Australia has five instruments that matter to a deployer: the Voluntary AI Safety Standard, the National AI Centre Guidance for AI Adoption that evolved it, the AI Ethics Principles, the DTA policy for Commonwealth entities and the Privacy Act. The PolyGovern framework maps every element to each of them.
Are the ten guardrails still current in Australia?
Yes. The ten guardrails of the Voluntary AI Safety Standard remain in place, and the Guidance for AI Adoption evolves them into six essential practices. Our framework references both.
Did Australia introduce mandatory guardrails for high-risk AI?
No legislation was introduced. The National AI Plan keeps the regulatory approach on existing technology-neutral laws, leaves regulators in charge of their domains and sets up an AI Safety Institute that advises and tests without enforcement powers.
What is actually mandatory for a private Australian organisation right now?
Existing law: the Privacy Act, consumer law, anti-discrimination law, the Online Safety Act and sector regulators such as APRA and ASIC. From 10 December 2026, APP 1.7 to 1.9 require privacy policies to describe automated decisions that significantly affect people. That is a disclosure duty only.
Does the Public Service AI Framework bind New Zealand agencies?
No. The framework is non-binding and agencies are encouraged to align with it. It does not apply to private companies. The private-sector equivalent is MBIE’s Responsible AI Guidance for Businesses, which is also voluntary.
Is New Zealand planning an AI Act?
No. New Zealand's AI Strategy takes a light-touch, principles-based approach and relies on existing law. The one live reform process is the Law Commission review of automated decision-making by government, which is at scoping stage.
How does the framework relate to ISO 42001 certification?
The eleven elements cover ISO 42001 clauses 4 to 10 and the nine Annex A control objectives. An organisation that runs the framework has the evidence an ISO 42001 stage 1 and stage 2 audit asks for. Certification is a separate decision and is covered on the ISO 42001 service pages.
Is NIST AI RMF 2.0 available?
No. AI RMF 1.0 is under revision, and no draft, version number or date for its successor exists yet. We align to AI RMF 1.0 (NIST AI 100-1) and the Generative AI Profile (NIST AI 600-1).
Where does the maturity model fit?
The maturity model describes five levels of evidence across the eleven elements. The AI Risk Calculator classifies each system and lists the obligations it triggers. Together they tell you which systems carry the risk and how much of the framework is in place to govern them.
Find out which of the eleven elements you can evidence today.
Run the calculator on your highest-risk system to see the obligations it triggers. Then read the maturity model to see what evidence each level requires. A thirty-minute call with a senior consultant covers the rest.
Free tool · No login
AI Risk Calculator.
Classify one system against the Australian and New Zealand instruments in ten questions. Print the result for the board pack.
Run the calculatorThirty-minute call
Framework gap review.
A senior consultant walks through the eleven elements against what you can produce now and names the phase to start in.