AI governance for Australian business
AI governance for businesses that will never have a Chief AI Officer
Most published AI governance material is written for organisations with a risk function, a legal team and a procurement process. That is not the business using Copilot for email and a transcription tool in client meetings. The practices still apply. The scale does not.
This is what the Australian guidance actually asks for, translated into what a ten, twenty, fifty or hundred-person business would do about it.
General information about Australian obligations, not legal advice.
What does AI governance actually mean for a small or medium business?
It means the organisation, rather than each individual employee, has decided what AI is used, for what, with what information, under whose authority, and with what checking. Governance is not a document or a committee. It is the location of the decision.
A business with no AI governance has not decided nothing. It has delegated every decision to whoever happens to be doing the task, without telling them they are making it.
The Australian Government's Guidance for AI Adoption, published by the National AI Centre in October 2025, sets the benchmark. It replaces the 2024 Voluntary AI Safety Standard, condensing its ten guardrails into six essential practices, and it comes in two versions: Foundations for organisations starting out or using AI in low-risk ways, and Implementation guidance for those with mature governance or higher-risk uses. Most Australian SMBs are squarely in the first.
It is voluntary. It carries no legal force of its own. It is also the clearest Australian statement of what reasonable AI governance looks like, which makes it the thing a client, insurer or larger customer is likely to measure you against, and a sensible thing to be able to say you follow.
Source: Guidance for AI adoption: foundations (National AI Centre, October 2025).
Eleven steps, in the order they actually work
The six practices are the right framework and they are not a sequence. This is the order to do them in when you are starting from nothing, which is where most businesses are.
-
Find out what AI is already in use
Ask, without consequences attached. Include the tools nobody classifies as AI: transcription in meetings, assistants inside your email and document software, chat widgets, summarisation in your CRM or practice system, generative features in design tools, screening in a hiring platform. Expect the list to be longer and stranger than you think.
You cannot govern, assess or explain what you have not enumerated, and the enumeration is genuinely the hard part.
-
Give it to one named person
A senior person with the authority to approve and refuse. In a smaller business this is usually the owner, a director or an operations lead. It should not default to your IT provider, who has no control over what staff type into a browser and no standing to set business rules.
-
Classify the use cases, not the tools
The same tool carries different risk depending on the job. Drafting a marketing email and screening job applicants are not the same decision. Three bands are enough: routine, needs a decision, and not without explicit approval.
-
Work out what information is involved
For each use: does it touch personal information, sensitive information, client material held in confidence, or nothing much? This is what connects AI governance to your privacy obligations, and it is where the real exposure usually is.
-
Assess the providers
What the service receives, where it is processed, how long it is kept, whether inputs are used for training, which subprocessors are involved, what the security posture is, and what happens when you leave. Record the answers and the decision, because an unassessed provider you have used for two years is harder to explain than one you refused.
-
Set the rules and write them down
Approved services, information categories, verification requirements, who approves the next tool, how to report a problem. This is the policy, and it should follow the decisions rather than replace them.
-
Tell people, and train the counter-intuitive parts
That a personal account used for work is work use. That a file summary contains personal information. That a confident answer can be fabricated. That an uploaded document exposes far more than a typed question. None of that is obvious to someone doing their job.
-
Require human verification where it matters
Match the checking to the stakes. Low-stakes internal drafting needs no formal review. Anything going to a client, a regulator, a court or a decision about a person needs a named human who checked it and can stand behind it.
-
Give exceptions and incidents somewhere to go
A route to report that something was put where it should not have been, that an output was wrong, or that a tool is needed which is not on the list. If the first person to use it gets punished, you will not hear about the second.
-
Review the position on a cadence
AI providers change terms, add features and change what is enabled by default. Staff turn over. A tool that was approved for one purpose gets used for another. An annual review with a trigger for material change is the minimum that stays honest.
-
Keep the record as you go
The Australian guidance says it directly: keep clear records of the actions you take under each practice, because good documentation supports audits and reviews and helps the organisation improve. Records built as the work happens are worth considerably more than records assembled afterwards.
What this looks like at different sizes
The guidance is explicit that you adapt each practice to your organisation's size, use cases and risk profile. Here is what that adaptation reasonably looks like.
| Element | Around 10 people | 20 to 50 | 50 to 100 |
|---|---|---|---|
| Accountability | The owner or a director, named in the policy. | A named owner plus a second person who assesses providers. | A named owner, an assessor, and AI on the management meeting agenda. |
| AI register | A short list of systems in use, with purpose and owner. | Register with information types, provider, location and review date. | Register linked to the supplier register and the risk register. |
| Use-case screening | A conversation before a new tool goes into use, with the outcome written down. | A short screening form, held by the assessor. | Screening plus a risk assessment for anything touching people's rights. |
| Rules | One page staff have acknowledged. | An AI policy plus the staff-facing rules in acceptable use. | Policy set with role-specific expectations for managers. |
| Training | One session, plus induction for new starters. | Role-based, with completion tracked. | Role-based, tracked, refreshed, with extra depth for anyone overseeing AI output. |
| Verification | Rule of thumb: anything leaving the business gets read by a person. | Defined by output type, with the reviewer named. | Defined by output type, with spot checks on the high-stakes categories. |
| Review | Annual, by the owner. | Annual, plus triggers, with the outcome recorded. | Semi-annual, reported to whoever exercises oversight. |
Two things do not scale down: someone has to be accountable, and there has to be a record. A business of six can do both in an afternoon. A business of six that does neither is in the same position as a business of six hundred that does neither.
What should an AI register contain?
Enough that a person who was not there can answer what we use, for what, with whose information, on whose authority, and when it was last looked at. The Australian guidance recommends maintaining a register of all AI systems, including AI embedded in other software and systems you built yourself.
- System and provider. Named, with the plan or tier, because the tier often decides the data handling.
- What it is used for. By purpose, in the business's own words.
- Who owns it. A person, not a department.
- Information involved. Personal, sensitive, health, financial, client-confidential, or none of those.
- Where it is processed. Including whether that is outside Australia.
- Retention and training use. How long inputs are kept and whether they are used to improve models.
- Subprocessors. Whether they are known, and who they are if so.
- Approval. Who approved it, on what date, on what basis.
- Human oversight. Who checks the output, and for which outputs.
- Risk band. Routine, needs a decision, or requires explicit approval.
- Contract status. Terms accepted, data processing arrangement in place, or neither.
- Next review. A date, owned by a person.
Where this record should live
A spreadsheet is a legitimate answer if somebody maintains it. The failure mode is that it is built once for a questionnaire and never updated, which produces a register that is worse than none because it is confidently wrong. If your organisation already keeps a supplier or vendor register, AI providers belong in it rather than in a parallel list, because they are third parties receiving your information and they should be reviewed on the same cycle as everyone else.
Three bands are enough for most businesses
Enterprise risk frameworks produce elaborate tiering. A smaller organisation needs to be able to sort a use case in about a minute, which means three bands and a clear test for each.
Routine
No personal or confidential information, no external audience, no decision about a person. Drafting an internal note, explaining a concept, restructuring your own text. Use it under the general rules and move on.
Needs a decision first
Personal information, client material, or output that reaches a customer. Requires an approved service, a recorded assessment of the provider, and a named person who checks the output before it leaves.
Not without explicit approval
Anything contributing to a decision that significantly affects someone: hiring, credit, eligibility, care, discipline. Also sensitive information, and anything customer-facing that operates without a person watching it.
Band three is where the obligations concentrate
It attracts the most privacy risk, it is where accuracy obligations bite hardest, and it is the band that triggers the automated decision-making disclosure in your privacy policy from 10 December 2026. It is also, in most small businesses, empty. Being able to say that it is empty, and to show why, is itself a governance position worth having.
What an owner or director should be able to answer without checking
This is the practical measure of whether governance exists. Not whether a document exists, but whether the person accountable can answer these in a meeting.
- What AI systems does this business use? Including features inside software we already pay for.
- Who is accountable for that? By name.
- Which of them receive personal information? And whose.
- Where is that information processed? Australia or elsewhere.
- Which providers have we actually assessed? And what did we decide.
- What are staff allowed to put in? And do they know that.
- What do we check before it goes out? And who does the checking.
- Has anything gone wrong? And would we know if it had.
- When did we last look at any of this? With a date.
If the honest answer to most of these is "I would have to find out", that is the finding. It is also a completely normal starting point, and the work to change it is measured in days rather than months.
The governance layer is the part that decays
Establishing a position is a project. Keeping it true is not, and that is where most of these programmes come apart. Cleverer holds the organisational layer: who owns what, what was decided, who was trained, what is overdue and what can be shown.
AI providers in the supplier register
Data types received, purpose, whether sensitive or health information is involved, storage country, offshore disclosure, whether subprocessors are known, contract status, a business owner, a review owner and a next review date.
AI risks in the risk register
Recorded against a category, with likelihood and impact, a derived rating band, an owner, a treatment decision and a review date. A risk that is deliberately accepted requires a written acceptance rather than silence.
Policies, training and review as one cycle
An AI Governance Policy with an approver and acknowledgement records, role-based training with named completions, and a review calendar that surfaces what is due before it is overdue.
What it is not
Cleverer does not discover AI tools on your network, monitor prompts, inspect model behaviour or connect to your systems. It is not an AI security product. It is where the decisions, ownership, training, supplier assessments, risks, incidents and reviews are recorded and kept current, so the organisational half of your position is something you can produce rather than reconstruct.
There is no dedicated AI control area in the platform's control framework today. AI governance is carried through the AI Governance Policy, the supplier register, the risk register and the training and review cycle.
Start with the nine questions
The Readiness Check covers the same ground across your whole compliance position: policies, responsibilities, training, suppliers, registers and evidence. It will tell you where the answers currently are.
Questions about AI governance in Australia
Is AI governance mandatory in Australia?
Not as a standalone requirement. The Guidance for AI Adoption is voluntary and no mandatory AI guardrails are in force for the private sector. What is mandatory are the underlying obligations that AI use engages: privacy, security of personal information, consumer law, work health and safety and the rest. Governance is how an organisation meets those consistently rather than by luck.
Who should own AI governance in a small business?
A named senior person with authority to approve or refuse a tool. Australian guidance says to assign a senior leader as the overall AI governance owner, with enough understanding of AI capabilities and risks to oversee its use. In a smaller organisation that is the owner, a director or an operations lead. It should not sit with the IT provider by default.
Do we need ISO 42001 or the NIST AI Risk Management Framework?
It depends on the organisation. Both are credible frameworks. ISO/IEC 42001 in particular can be the right choice where a customer or a contract calls for a certified AI management system, where AI is central to what the business sells, or where the organisation already runs a certified management system and can extend it. The NIST AI Risk Management Framework is a useful reference for structuring risk work at any size. For a smaller Australian organisation the Guidance for AI Adoption is a proportionate place to begin, and it aligns with both closely enough that starting there does not close off certification later. Match the choice to your actual risks, obligations and customer requirements rather than to the profile of the framework.
How often should AI use be reviewed?
Annually as a floor, with triggers for material change: a new tool in use, a provider changing its terms or defaults, an incident, or the business starting to use AI in a decision that affects people. The register of what is in use needs attention more often than that, because tools get added without anyone deciding to add them.
What is the first thing to do if we have no AI governance at all?
Find out what is actually in use, without attaching consequences to the answer. Every other step depends on that list, and the list is almost always longer than management expects. It usually takes one email and a week of replies.
Should AI governance sit with our IT provider?
Parts of it can, but not the ownership. An IT provider can block or allow services, configure a tenant and advise on provider security. It cannot decide what your business considers acceptable use of client information, approve a use case on your behalf, or be accountable to your customers for an output. Those are business decisions and they stay with the business.