Service 03 · Phase One
003 / 08
Governance · risk
1 month

Rules before something goes wrong.

Your staff are already using AI. Some of it is useful. Some of it is risky. One month to build the governance layer before a problem becomes a liability.

Phase Phase one
Engagement Fixed scope · compliance-ready
§ 01 · Overview
Service Practical AI Governance Setup
Follows Service 02 · Data and Systems Health Check
Phase Phase one
Duration One month
Format Policy design + internal review sessions
Team Principal consultant
Output Governance framework + AI use register
Aligned to Voluntary AI Safety Standard (10 guardrails)

Staff are using AI tools nobody approved, sharing data nobody vetted, in workflows nobody documented. The governance gap is not a future risk. It is a current exposure.

This service builds the governance layer the business needs before AI use gets ahead of you. I work with your team to understand how AI is currently being used, where the real risks sit, and what rules will actually work in practice, not just on paper.

Every output is aligned to the Australian Government's Voluntary AI Safety Standard (10 guardrails) and the National AI Centre's AI6 essential practices. This is practical governance designed for your business, built to be used, not filed away.

§ 02 · Service map

Governance that
staff actually use.

Plain-English rules, a named internal owner, and a framework aligned to the Australian Government's Voluntary AI Safety Standard.

Inputs · workflow · data
Outputs · decision · handover
Guardrails covered 10
Duration 1 month
Staff review sessions 2 to 3
Final artefacts 3
§ 03 · Fit

Right for you if
nobody has written the rules.

This layout is for explaining a service as a repeatable operating shape: who it is for, how the work moves, and what the client leaves with.

001

AI is already in use.

Staff are using AI tools in daily work, but nobody has defined which tools are approved, what data can be used, or where human review is required.

002

Client data is at risk.

The business handles confidential client information. AI tools are being used in that context without clear rules about what can and cannot be shared.

003

Leadership wants defensible answers.

A board, partner group, or executive team wants to know the business has its house in order on AI, and can point to the policies that prove it.

§ 04 · How it works

One month.
Four stages.

Stage 01

Map current AI use.

Identify every AI tool in use across the business, who is using it, in what context, and what data is being shared with it.

Week 01
Stage 02

Identify the risks.

Assess each tool and use case against client data exposure, confidentiality obligations, and operational risk. Name the gaps that need rules.

Week 02
Stage 03

Write the governance layer.

Draft the approved tool list, data-sharing rules, human review requirements, risk categories, AI use register, and accountability assignments.

Week 03
Stage 04

Install and brief staff.

Review the governance framework with leadership and relevant staff. Assign the internal owner. Confirm the operating cadence for governance review.

Week 04
§ 05 · Outputs

What the client
leaves with.

Plain-English AI Use Rules

What staff can and cannot use AI for, written for people, not lawyers.

Proof

Clear enough to be used on Monday.

Approved and Not-Approved Tool Lists

A clear register of tools, not a vague principle.

Proof

Staff know what is allowed and what is not.

Data-Sharing Rules

Specific guidance on what data must not go into AI platforms.

Proof

Protects client, financial, and confidential business material.

Human Review Requirements

Where AI output must be checked before it is used.

Proof

Keeps judgement and accountability inside the business.

AI Use Register

A live record of how AI is being used in the business.

Proof

Gives leadership a single view of AI exposure.

Staff Briefing Pack

A practical summary staff can read and understand.

Proof

Turns governance from policy into behaviour.

Named Internal Owner and Escalation Path

Someone is accountable, and everyone knows who.

Proof

Accountability does not fall into a gap between teams.

Alignment Note

Mapped against the Voluntary AI Safety Standard and NAIC AI6 guidance.

Proof

Gives boards, clients, and auditors a credible answer.