Search Precision Consulting
Type to search · ↑↓ to navigate · Enter to open · Esc to close
Independent AI Review and Governance
AI governance consulting
one bar for every AI system you run
AI governance is how an organisation decides which AI it uses, who is accountable for each system, what each may do, and how each is checked. We help you set that bar once, for the whole organisation, before every team builds its own: one register, one data spine, one set of criteria, and every AI tool held to the same standard.
The first conversation is confidential, without obligation and without charge.
This is not legal advice. Your counsel decides the legal position.
Why set one bar before every team builds its own?
Because if the bar is not set once, centrally, every team sets its own, and AI ends up competing with AI. The cost shows up as numbers nobody can reconcile, verdicts nobody can compare and the same tool paid for twice.
It shows up in four ways:
- Competing numbers. Finance, operations and a vendor's platform each forecast the same thing with different models and data, and the executive spends its time reconciling them.
- Competing verdicts. Divisions score risks or proposals with their own prompts and thresholds, and the scores cannot be compared.
- Adversarial loops. Proposals drafted with AI are tuned to pass screens run by AI.
- Duplicated build. Several teams pay to solve the same problem on different tools, and none reaches production quality.
Many organisations are already there. In a 2025 study of trust in and use of AI by KPMG and the University of Melbourne, 30 per cent of Australian employees said their organisation had a policy on generative AI, and 48 per cent admitted using AI in ways that went against policy. ASIC found financial services licensees adopting AI faster than they updated their governance, across 624 use cases at 23 licensees.
What is set centrally is the standard: the bar, the register, the data spine, the approved platforms and models, the evaluation standard and decision rights, each set once. Business units then build inside the bar. A central team that insists on building every use case itself becomes a bottleneck, and people drift back to their own tools.
AI held to account. One bar. One baseline. One role per system.
What each one meansWho is the AI Governance Gap Assessment for?
It is for the executive who answers for how the organisation uses AI: a chief risk officer, chief information officer, chief AI officer, company secretary or general counsel, and for a board that wants one standard for all of it.
It fits when:
- teams are adopting AI tools faster than your policy and your register can keep up;
- different teams forecast, score or screen the same things with different tools, models and criteria;
- nobody can say with confidence which AI is already in use, sanctioned or not;
- the Privacy Act's automated decision rules apply from 10 December 2026, and you do not yet know where those decisions sit in your systems;
- you are APRA-regulated and want your governance mapped to APRA's letter of April 2026;
- your board wants to know what it should be able to challenge.
It does not fit when:
- you need certification. Only a certification body can certify an AI management system, and we are not one;
- you need a legal opinion. That is for your counsel;
- you want an independent opinion on a governance framework we wrote for you, or on a governance process we run for you. That goes to another firm;
- you need one programme or system reviewed against the rules. That is an Independent AI Review.
What does the AI Governance Gap Assessment cover?
It measures your current governance against the six essential practices in the Australian Government's Guidance for AI Adoption, finds the AI already in use across your organisation, and tells you what to fix first. It is planned at three to five weeks.
- a gap assessment against the six practices, with an ISO/IEC 42001 lens where you want one;
- a register of the AI in use, sanctioned and not, found by an engineer working through your systems and licences as well as by interview;
- the obligations each gap touches, set out as questions for your counsel;
- a ranked set of fixes, and what a governance foundation would cost if you want help building it.
The six practices are: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control.
Who does it: a governance lead, an engineer for register discovery and an analyst, each named in the proposal. Where legal characterisation is needed, your counsel provides it.
Fees: the assessment is scoped to your situation, and its fee is agreed before work starts.
Where a finding depends on what the law requires, we record the facts and the question, and your counsel answers it.
How does the assessment run?
Over three to five weeks, led by a governance lead with an engineer for register discovery and an analyst.
Planned elapsed time Three to five weeks
| When | What happens |
|---|---|
| Week 1 | The scope agreed: the business units and systems in scope, the framework, and the people we interview. Access to the systems and licence records the engineer needs for register discovery. |
| Middle weeks | Interviews with the people accountable for AI. The engineer works through your systems and licences to find the AI in use, sanctioned and not. Your current governance is measured against the six practices. |
| Final week | The gap assessment, the register, the obligations set out as questions for your counsel, and the ranked fixes, taken through with the sponsor. |
Three to five weeks is the planned elapsed time. It depends mainly on how many business units and systems are in scope.
What is the Consolidated AI Bar?
It is our template for one organisation-wide standard for AI, in ten parts, and it is the standard we build to.
The ten parts:
- An AI register: every tool and use, its owner, its risk tier, the data it uses and its next review date.
- A decision rights matrix: what AI may draft, flag, recommend or carry out, and what only a person may decide.
- A data spine: one taxonomy, shared identifiers, data quality rules and retained snapshots.
- Published criteria for proposals, risk scoring and status ratings, applied the same way by every tool and every person.
- Approved platforms and models, with where each stores and processes data.
- An evaluation standard: accuracy thresholds, back-testing, calibration reporting and pre-release testing.
- A traceability rule: every output links to its sources, and prompts and model versions are under change control.
- An impact assessment trigger: which uses need a formal AI and privacy impact assessment.
- A disclosure rule: staff, proponents, vendors and consultants declare AI use in material they submit.
- Value and incident reporting: value against baseline, forecast calibration and AI incidents, reported each quarter to the executive and the audit and risk committee.
We review another supplier's system against the bar only where you have adopted it as your own, and the scope says so.
What changes on 10 December 2026?
The Privacy Act's automated decision rules apply from 10 December 2026, and your counsel decides which of your systems they reach. Many organisations do not yet know where those decisions sit inside the systems they run and buy.
We find them. Our engineers trace where systems make or substantially assist decisions about people, and we give your counsel the facts they need to decide what the privacy policy must say. For existing clients this is available as an automated decision inventory within a governance engagement.
This is not legal advice. Your counsel decides the legal position.
What does a governance foundation include?
Everything you need to run AI to one bar, built with you over a planned six to twelve weeks: the enterprise Consolidated AI Bar, an AI policy, controls for AI agents that take actions, an operating cadence, a board reporting pack, an automated decision inventory, and a staff rule on consumer AI tools.
The bar is set centrally and business units build inside it. We hand everything over for your people to run, and any provider can use it.
One rule applies. Once we have written your governance framework or run a governance process for you, we give no independent opinion on that framework or on how well that process works. An independent review of it would go to another firm.
Foundations are scoped after the gap assessment.
We are APRA-regulated. How does this map to the April 2026 letter?
The APRA version of the gap assessment maps your governance to APRA's letter of 30 April 2026 and to the service provider obligations in CPS 230. It supports your CPS 230 obligations; whether you meet them is for you and APRA.
APRA found that "assurance practices are not keeping pace" with AI. It expects boards to be literate in AI, and second line risk management and internal audit to have the capability and tooling to assess AI systems independently.
Where your second or third line needs the testing capability itself, our engineers can work inside it on request. Engineers inside your second or third line
What about ISO/IEC 42001?
The gap assessment can apply an ISO/IEC 42001 lens where you want one. Certification is given only by a certification body, and we are not one.
How do you work with our lawyers?
We find and map; your counsel decides. Our work records where AI sits, what it does, which obligations it touches and the questions those raise.
Your counsel, or a law firm you appoint, answers the legal questions.
What should a board be able to challenge?
The register, the decision rights, the value against baseline, the independent review of high-risk systems, where the data is processed, and whether one bar is set for all of it.
APRA has criticised boards' "overreliance on vendor presentations", and the AICD updated its director's guide to AI governance in June 2026.
Our Board and Executive AI Briefing is a half-day session on those questions, mapped to APRA's letter or the Commonwealth policy where they apply, with a one-page question set the board keeps. It is aligned to the AICD guide. The presenters, and the roles they have held, are named in the proposal. Role-based sessions are available for accountable officials, use case owners and portfolio staff.
Common Questions
The questions we are asked most
What is AI governance consulting?
It is help to decide which AI an organisation uses, who is accountable for each system, what each may do and how each is checked, and then to run that as one standard. Our version starts by finding the AI already in use, because a register built from interviews alone can miss the tools staff brought themselves.
What are the six essential practices?
They are the core of the Guidance for AI Adoption, published by the National AI Centre in October 2025: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. Our gap assessment measures your governance against all six.
How much does an AI governance gap assessment cost?
It is scoped to your situation, and its fee is agreed with you before work starts. The fee depends mainly on how many business units and systems are in scope.
Is there an AI policy template for Australian organisations?
The Guidance for AI Adoption includes an AI policy template and an AI register template. Our Consolidated AI Bar goes further: it sets out the ten parts of one organisation-wide standard.
How do you govern AI agents that can take actions?
With a decision rights matrix that says what each agent may draft, flag, recommend or carry out, and approval points wherever an action moves money, affects a person or changes a production system. Every action is recorded, and a named person is accountable for each decision.
If you write our AI policy, can you also review our systems against it?
We can review another supplier's system against a policy you have adopted as your own, and the scope says we wrote it. We give no independent opinion on the policy itself, or on a governance process we run for you.
How we work, in writing
Set the bar before every team sets its own.
The first conversation is confidential, without obligation and without charge.