Skip to content
Sam AkbariFractional CXO
All insights

AI & transformation

AI governance checklist for Australian boards

A practical AI governance checklist for Australian mid-market boards and leadership teams, built on the National AI Centre's six essential practices.

Sam Akbari · 7 min read

Short answer: good AI governance in an Australian mid-market company means a named senior owner, a short AI use policy, a register of where AI is used, a risk check before anything new goes live, and regular reporting to the board. The National AI Centre’s six essential practices give you the structure. The checklist below turns them into board questions.

Most boards I speak with know they should be governing AI. Fewer know what that means in practice, and some worry it means building the kind of framework a big bank has. It doesn’t. What follows is proportionate, based on current Australian guidance, and written so you can take it into your next board meeting.

This is general guidance, not legal advice. Check your specific obligations with your own advisers.

What the current Australian guidance says

The guidance has moved quickly, so it’s worth being clear on what’s current.

The Voluntary AI Safety Standard has been updated. The federal government released the Voluntary AI Safety Standard, with 10 guardrails, in 2024. In October 2025 the National AI Centre (NAIC) published the Guidance for AI Adoption, which it describes as the first update to that standard. It condenses the 10 guardrails into six essential practices:

  1. Decide who is accountable
  2. Understand impacts and plan accordingly
  3. Measure and manage risks
  4. Share essential information
  5. Test and monitor
  6. Maintain human control

There are two versions. Foundations is for organisations in the early stages of adopting AI. Implementation guidance is for higher-risk or more complex use; its current edition was published in May 2026. NAIC also provides free tools, including an AI policy template, an AI register template and an AI screening tool, on ai.gov.au. Importantly, the guidance says it doesn’t replace your existing data, privacy and cyber security frameworks. Those should be reviewed and extended to cover AI.

Directors have their own guide. In June 2026 the AICD and the Human Technology Institute at UTS released Version 2 of A Director’s Guide to AI Governance, with a summary and checklist for SME and not-for-profit boards. As an AICD member, I find two of its points especially useful for mid-market boards: oversight of AI forms part of directors’ existing duties, and the board needs visibility of how AI is managed, monitored and governed, backed by enough AI literacy to ask good questions. It also asks boards to test whether AI is delivering genuine returns, not just activity.

Privacy obligations are tightening. The OAIC’s guidance on using commercially available AI products recommends, as best practice, that organisations don’t enter personal information, and particularly sensitive information, into publicly available generative AI tools. And from 10 December 2026, under changes made by the Privacy and Other Legislation Amendment Act 2024, organisations covered by the Privacy Act must explain in their privacy policy when they use computer programs, using personal information, to make or substantially inform decisions that could significantly affect people’s rights or interests. The OAIC published guidance on this new obligation (APP 1.7–1.9) on 30 September 2026. If you use AI or automation in decisions about customers or staff, check your privacy policy before that date.

Keep it proportionate

The NAIC guidance is explicit that you don’t have to do everything at once. Start across all six practices at a basic level and add more as your use of AI grows.

For a mid-market company, that usually means a one- or two-page policy, a register kept in a spreadsheet, a short screening check for new uses, and a regular paper to the board. The effort should follow the risk. An AI tool that drafts marketing copy needs a lighter touch than one that shortlists job applicants or decides who gets a discount.

The AI governance checklist

Twelve questions, split between what the board should ask and what management should be able to show. “What good looks like” is the answer you’re hoping to hear.

For the board

Question What good looks like
1. Who is accountable for AI? One named senior executive owns AI governance, with the authority, time and budget to do it. The board knows who it is, and each AI system in use also has a named owner.
2. What’s our appetite for AI risk? The board and management have agreed which uses are fine, which need approval and which are off-limits, and that view is reflected in the risk management framework.
3. Do we know where AI is being used? There’s a current register of AI use, including AI features built into software you already pay for and tools staff use on their own initiative. The board sees it at least once a year.
4. Do we have the skills to oversee this? Directors have had a practical AI briefing in the last year, and have used the tools themselves. Management has a plan to train staff, starting with the people who own or oversee AI systems.
5. What does the board hear, and how often? A regular report covers changes to the register, any higher-risk uses, incidents, and whether each AI initiative is delivering the return in its business case.

For management

Question What good looks like
6. Do staff know the rules? A short AI use policy sets out the approved tools, the data that must never go into them and when a person must check the output. Staff have read it and know who to ask.
7. How are we protecting personal information? No personal or sensitive information goes into public AI tools. Privacy impacts are checked before new uses go live, and the privacy policy is updated for automated decisions ahead of 10 December 2026.
8. How do we check risk before something goes live? Every new use goes through a quick screen. Higher-risk uses, especially decisions about people, get a fuller assessment, a person reviewing the outcome and a clear point where someone can pause or override it.
9. What do our vendors do with our data? Contracts cover how your data is used and stored, whether it’s used to train the vendor’s models, and how you’ll be told about changes. You’ve asked for evidence the product has been tested for your use.
10. How do we know it’s still working? Each system is tested on real examples before launch, and its owner checks accuracy and behaviour after launch, because AI systems can change over time. Existing data and cyber security controls cover AI too.
11. Do customers and staff know when AI is involved? Chatbots are clearly labelled as AI, AI use is disclosed where it affects people, and anyone affected by an AI-assisted decision can question it and reach a person.
12. What happens when it goes wrong? There’s a simple incident process: record it, pause or roll back the system, check whether privacy or other obligations are triggered, fix the cause and report it to the board. Critical functions can keep running without the AI.

If management can answer all twelve with evidence, you’re in good shape for a mid-market company. If several answers are “not yet”, that’s normal. Start with questions 1, 3, 6 and 8: an owner, a register, a policy and a risk check. Those four cover most of the exposure.

Governance should help you move faster

Good governance isn’t there to slow AI down. It’s what lets a board approve AI initiatives with confidence instead of worrying about what’s happening out of sight.

When I moved a global brand’s translation onto an AI-first platform across 14 languages, saving around US$1M a year, the key control was simple: people reviewed and refined the AI’s work rather than translating from scratch. That’s governance built into the workflow, not bolted on afterwards. The same thinking sits behind the four questions I suggest asking of any AI initiative in AI in the mid-market, including “what happens when it’s wrong, and who catches it?”

The most common gap I see is question 1. AI governance needs an owner with the time to do it, and in many mid-market companies nobody senior has that time. If that’s you, I’ve written about whether your company needs a Chief AI Officer.

Where to start

To see where you stand, take my free AI Readiness Scorecard. It takes about five minutes, and governance is one of the five areas it covers. If you’d like help putting this checklist into practice, I work with mid-market leadership teams as a fractional Chief AI Officer, or you can get in touch to talk through your situation.

Common questions

Is AI governance mandatory in Australia?

For most businesses there is no AI-specific law that requires a governance framework, and the National AI Centre's Guidance for AI Adoption is voluntary. But the National AI Plan, released in December 2025, says the government will build on existing legal and regulatory frameworks, and existing laws on privacy, consumer protection, discrimination and work health and safety still apply to how you use AI.

Does the Privacy Act apply to AI?

Yes. The OAIC says the Privacy Act applies to all uses of AI involving personal information, including the information you put into an AI tool and anything it generates about an identifiable person. Businesses with an annual turnover above A$3 million are generally covered, and some smaller businesses are too.

Who on the board should own AI?

The board as a whole is responsible for overseeing AI, and the AICD's guidance notes that a dedicated AI committee isn't necessary for every organisation. In a mid-market company I'd usually give it to the audit and risk committee, or the full board if there isn't one, with one senior executive owning it day to day.

Do we need a full AI policy if we're small?

No. The National AI Centre's own guidance says responsible AI practices are simple to put in place when you're starting small, and should grow as your use of AI matures. A short policy that people actually read beats a long framework nobody opens.

How often should the board look at AI?

I'd suggest a short update at least quarterly, as part of the risk report, and a fuller review of the AI register and policy once a year. Look more often if you're using AI in decisions about customers or staff.

Keep reading

Let's talk about what's next for your business.

A 30-minute conversation, no pitch deck. If I'm not the right fit, I'll tell you, and point you to someone who is.