Practical guides to the work.
Each guide walks through one piece of AI governance work, answers the question it opens with in the first paragraph and ends on the primary source. They are written to be useful whether or not you use Aicura.
How to build an AI system register
A practical build guide for a lean compliance team. It covers the fields to capture, how to find the AI nobody registered, how to classify which systems make automated decisions that significantly affect people and how to keep the register current as systems change.
Read the guide→How to work out which of your systems make automated decisions
A practical walkthrough for sorting your own system list into what the Privacy Act's automated decision-making rules cover and what they leave out, including the systems most organisations wrongly assume are out of scope.
Read the guide→How to write an ADM transparency statement
A practical guide to writing the automated decision-making disclosure your privacy policy needs under APP 1.7 to 1.9, with worked examples of adequate and inadequate wording.
Read the guide→How to build and maintain an AI risk register
A practical guide for governance and risk leads on what an AI risk register holds, how to source risks from assessments rather than build them by hand, and how to keep the register current as systems change.
Read the guide→How to derive and manage AI controls from frameworks and assessments
A practical guide to what an AI governance control is, where controls come from and how to get them in place and keep them current by deriving them from enabled frameworks and the assessments you run.
Read the guide→How to stand up AI governance policies from templates
What policies an AI governance program actually needs, how to build them from templates grounded in AI6 and the NSW AI Assessment Framework instead of drafting by hand, and how to keep them current as your AI use changes.
Read the guide→Building the evidence trail for an AI incident
The evidence trail for an AI incident is the record that lets you show, afterwards, that you handled the incident properly. What to capture, how to keep it and how to show it without asking anyone to trust you.
Read the guide→Governing AI agents: what changes when a system acts, not just advises
Most AI governance work starts with systems that advise. An AI agent is different. It does not stop at the output. What changes for oversight, surface area and accountability.
Read the guide→How to assess and oversee an AI agent
Assessing an AI agent is the risk work you would do for any consequential system, extended to cover the fact that the agent acts. How to run the assessment and put the oversight in place.
Read the guide→How to demonstrate AI governance
A guide to demonstrating AI governance to the board, a regulator or an enterprise customer and matching the evidence to the reader.
Read the guide→How to keep AI governance records that stand up to scrutiny
What AI governance records to keep, how long to keep them and how to make them verifiable, anchored to Guardrail 9 and ISO/IEC 42001.
Read the guide→How to measure AI governance against a framework
A guide to measuring your AI governance against a recognised framework, choosing the reference, mapping your practice and reading the findings.
Read the guide→How to prepare for an AI governance audit
A step-by-step guide to getting ready for an AI governance audit in Australia, anchored to ISO/IEC 42001 and the Voluntary AI Safety Standard.
Read the guide→How to respond to an AI governance due-diligence questionnaire
How to answer an AI governance or AI security questionnaire from an enterprise customer, from records rather than assurances, mapped to recognised standards.
Read the guide→How to respond to an AI incident
Respond to an AI incident by moving through a set order, triage the event, contain the harm, investigate the cause, remediate, notify anyone you are required to notify and review what happened.
Read the guide→How to run an AI impact assessment
A step-by-step guide to running a defensible AI system impact assessment in Australia, anchored to ISO/IEC 42005 and the Voluntary AI Safety Standard.
Read the guide→ISO 42001 readiness
An explainer on ISO/IEC 42001 readiness, what the standard asks for, how to judge how ready you are and where organisations most often fall short.
Read the guide→What counts as AI audit evidence
An explainer on what an auditor will accept as evidence of AI governance, and what separates a record that stands up from one that does not.
Read the guide→What is AI assurance
An explainer on AI assurance, what it means, how it differs from AI governance, who provides it and what evidence it depends on.
Read the guide→What is an AI incident?
An AI incident is an event where the development, use or malfunction of an AI system leads to harm. What counts, how it differs from an IT incident and why the record matters.
Read the guide→What to record about an AI agent
Recording an AI agent is the first governance step, not the last. What to record about each agent, why each field matters and how the record earns its keep.
Read the guide→Privacy compliance kits: what they do, what they miss and when software is the better buy
Compliance kits and template packs give you documents as at the day you buy them. The ADM obligation is standing. Here is how to decide between a kit and a living register.
Read the guide→AI governance under APRA's expectations
APRA wrote to regulated entities setting out its expectations for AI risk. What the letter asks for, what each expectation means in practice and how the work gets done.
Read the guide→How to run an AI risk assessment
A practical method for assessing the risks of an AI system: scope from the register, work the harm dimensions, rate what remains, derive controls and record the result.
Read the guide→Who should build your AI register and run your assessments
In-house, a consultant or software: what each route to an AI governance program is genuinely good at, what each costs and the structural difference between them.
Read the guide→Who should do your ADM disclosure work: a lawyer, a consultant, your own people or software
Four ways to get your privacy policy ready for the December ADM rules, being a lawyer, a consultant, your own people or software. What each is best at and what each costs.
Read the guide→How to evaluate an AI governance platform
Vendor feature lists in this category all use the same words. These are the questions that reveal what each product actually is, on enforcement, evidence, discovery, agents, frameworks and buying, asked of any vendor including Aicura.
Read the guide→How to find shadow AI in your organisation
The AI your organisation uses without knowing it leaves traces in systems you already run. Where to look, how to correlate what you find and how to bring it into governance without turning discovery into a witch hunt.
Read the guide→How to monitor AI systems for drift
Every AI assessment describes the system on the day it was signed. Drift is the distance that opens afterwards. What to watch, how to set thresholds a person will actually act on and why vendor model changes are the drift source most organisations miss.
Read the guide→How to write and enforce AI guardrails
A guardrail is a governance decision made executable. How to get from policy intent to rules that act on live traffic, what belongs in a guardrail versus a policy document and why the enforcement record matters as much as the enforcement.
Read the guide→What belongs in an agent decision log
When an AI agent acts on your organisation's behalf, someone will eventually ask why it did what it did. What a decision log needs to capture for that question to have an answer, and what a register entry alone cannot tell you.
Read the guide→What is an AI governance platform?
Three quite different kinds of product have converged on the label "AI governance platform" and they do not do the same job. What the category actually covers, where products cluster by lineage and what no platform can do for you.
Read the guide→What makes AI governance evidence independently verifiable
Governance software promises immutable audit trails, and almost all of them mean the same thing, which is trust our database. What independent verifiability actually requires, why the difference is categorical and the question to ask any vendor.
Read the guide→How to assess your AI governance maturity
A method for working out how mature your organisation's AI governance actually is. The seven areas to measure, the five levels each one can sit at, how to score practice rather than intention and what to do with the result.
Read the guide→Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.