Executive Summary
Writing an artificial intelligence policy is relatively easy. Knowing whether it is working is considerably harder.
A policy can define acceptable use, allocate responsibility and establish principles. It cannot, by itself, show whether employees understand those expectations, whether material AI use is visible, whether controls are being followed or whether systems continue to operate as intended.
That requires assurance.
AI assurance gathers evidence that governance arrangements operate effectively. It helps leaders determine whether AI use is known, accountability is real, risks are managed and problems are identified early enough to act.
Scrutiny should reflect potential consequence. A low-risk productivity tool may require rules, training and periodic review. A system influencing clinical, employment, financial, educational or public-service decisions requires stronger evidence, monitoring and independent challenge.
The objective is not more paperwork.
It is better evidence.
Practical AI assurance can be built around five questions:
- Do we know where material AI is being used?
- Is somebody genuinely accountable for each use?
- What evidence shows the controls are operating?
- Will failures be detected and escalated?
- Can governance adapt when the technology or context changes?
For regional organisations, the answer is not to reproduce the assurance machinery of a large regulator or bank. It is to make a small number of important claims testable.
Introduction
Across Australia, organisations are publishing AI policies covering approved tools, prohibited uses, privacy, security, human oversight, transparency and accountability.
Their publication is an important step.
It is not the destination.
The existence of a policy can create a misleading sense of completeness. Leaders may assume risk has been addressed because expectations have been documented. Employees may know a policy exists while remaining uncertain about how it applies to everyday decisions.
Australia's current Policy for the responsible use of AI in government requires accountable officials, use-case registers, training, accountability and impact assessment. Responsible use must be operationalised, not merely stated. (Digital Transformation Agency)
The same applies outside government. A council may have no reliable view of AI embedded in procured systems. A health service may require human review without testing whether it is meaningful.
Each may have policy.
The unanswered question is whether it has assurance.
Policy Is Not Evidence
Policies establish a common position. They define boundaries, clarify expectations and provide a basis for accountability.
But a policy does not prove its own implementation.
An organisation may prohibit entering personal information into public AI tools yet have no evidence that the rule is understood. It may require human oversight without examining whether reviewers can challenge an output. It may require vendors to report model changes but have no owner responsible for assessing them.
The gap is between a documented control and an operating control.
The Office of the Australian Information Commissioner advises organisations to avoid a “set and forget” approach to commercial AI products. It recommends regular review of product performance, staff training, monitoring and human verification throughout the lifecycle. (OAIC)
Governance cannot be assumed to work simply because it has been designed.
Assurance Is a Confidence System
Assurance is sometimes understood too narrowly as formal audit. Audit may form part of the process, particularly for high-risk uses, but assurance is broader. It is how leaders obtain sufficient, relevant and reliable evidence to support confidence in a claim.
If management claims all material AI use is recorded, what supports that claim? If a system requires human review, what shows that review occurs and changes outcomes when necessary? If employees are trained, how does the organisation know the training is understood and applied?
These questions turn broad principles into claims that can be examined.
Australia's National framework for the assurance of artificial intelligence in government treats assurance as an essential part of broader AI governance and provides mechanisms for applying Australia's AI Ethics Principles. It is designed to complement existing governance rather than replace it. (Department of Finance)
AI assurance can be integrated into existing risk, privacy, cybersecurity, procurement, audit and board-reporting processes. Attention should focus on what they may miss: changing models, probabilistic outputs, opacity, bias and behaviour that changes with data, users or context.
Assurance makes important governance claims visible, testable and open to challenge.
Start With Material Use
An organisation cannot assure what it cannot see.
The first requirement is a reliable view of where AI is used and which uses matter most. Boards do not need a register of every feature that a vendor calls AI. They need visibility of uses capable of affecting people, sensitive information, significant decisions, essential services, legal obligations, strategy or reputation.
AI may enter through projects, vendor upgrades, embedded features or employee experimentation. Governing only centrally approved initiatives will miss part of the operating environment.
ASIC's review of 23 financial services and credit licensees examined 624 AI use cases and warned that governance could lag adoption. Sixty-one per cent of licensees planned to increase AI use while some were updating governance as adoption accelerated. (ASIC)
Assurance begins with discovery. Procurement records, software inventories, privacy assessments, business-unit attestations and staff surveys can establish a sufficiently reliable picture.
The register itself is not the assurance outcome.
The important question is how the organisation knows it remains current.
Make Accountability Testable
Governance documents often allocate responsibility at a high level. These arrangements can look clear on paper while remaining ambiguous in practice.
For each material use, assurance should establish who owns the outcome, who operates the control, who monitors performance and who can pause or stop the use. These roles may sit with different people. What matters is that they are understood before an incident exposes the gaps.
Accountability becomes testable when it is connected to decisions and evidence.
- Did the owner approve the use?
- Are reviews assigned?
- Do incidents reach someone able to act?
- When a vendor changes the system, who decides whether the previous approval remains valid?
The Australian Government's policy requires accountability at both agency and AI use-case levels and requires accountable officials to monitor implementation. (Digital Transformation Agency)
Enterprise accountability sets the governance system. Use-case accountability keeps responsibility close to where consequences arise.
One cannot substitute for the other.
Seek Evidence That Controls Operate
The central work of assurance is gathering evidence that controls function as intended.
For a low-risk productivity assistant, evidence may include approved-tool settings, training completion, periodic sampling and incident trends. For a system influencing recruitment, service eligibility, clinical documentation or financial decisions, it may require performance testing, review of affected groups, sampling of decisions, validation of human oversight, complaint analysis, privacy checks, vendor evidence and independent review.
The test is not whether the organisation has accumulated documents.
It is whether the evidence answers the governance claim.
Training completion shows attendance, not understanding. An impact assessment shows risks were considered at a point in time, not that mitigations remain effective. Vendor certification does not establish suitability for the organisation's context.
In the Digital Transformation Agency's 21-agency pilot, close to two-thirds of respondents said the assessment identified risks existing processes missed, while close to 90 per cent found the guidance helpful or very helpful. (Digital Transformation Agency)
Good assurance combines evidence with judgement.
Detect Failure Before It Becomes Harm
Governance will not prevent every failure.
The more realistic standard is that an organisation can detect when performance, behaviour or context moves outside acceptable boundaries and respond before harm becomes entrenched.
Accuracy will rarely be the only measure. Monitoring may also need to consider bias, privacy, security, override rates, complaints, service quality and whether human reviewers exercise genuine judgement. Signals need thresholds: when does a pattern require investigation, executive escalation or a pause?
Without predetermined escalation paths, warning signs can remain dispersed across technology teams, business units, complaints functions and vendors. Each may see only part of the problem.
Assurance connects those signals to accountable decision-makers. Scenario exercises and reviews of near misses can test whether escalation works.
The purpose is not to turn every error into a crisis.
It is to ensure material failure cannot remain invisible.
Reassess When the Context Changes
Models change. Vendors introduce features. Data changes. Employees discover new uses. A tool approved for drafting may later influence decisions, while a low-risk pilot may become an operational dependency without a clear moment of reapproval.
Assurance must operate across the lifecycle.
Review should be triggered by material change: a new model, new data source, expanded purpose, reduced human oversight, significant incident, changed legal obligation or evidence that performance has drifted.
The Australian Government's technical standard reflects this lifecycle approach through requirements covering auditability, success criteria, data quality, testing, monitoring and continuous improvement. (Digital Transformation Agency)
This does not mean every update requires committee approval. It means organisations need criteria for distinguishing routine change from change that invalidates earlier assumptions.
An approval without reassessment becomes a historical record.
Assurance keeps it relevant.
Proportionality Prevents Bureaucracy
The greatest practical risk is applying the same process to every use. Burdening low-risk experimentation may drive activity outside the process, while giving high-impact uses only a checklist creates false confidence.
Proportionality matches evidence and oversight to materiality.
The Digital Transformation Agency's pilot used a threshold assessment so low-risk uses could conclude earlier while uses with medium or high risks proceeded to more extensive assessment. Its recommendations supported integrating requirements into existing governance where those mechanisms already addressed the risks. (Digital Transformation Agency)
A regional organisation might use three levels. Routine uses would rely on approved tools, clear boundaries and periodic sampling. Material uses would add a named owner, impact assessment, measures and change triggers. High-impact uses would require stronger validation, executive or board visibility and independent challenge.
The categories matter less than the principle.
More consequence requires stronger evidence.
Good assurance asks which claims matter, what evidence supports them and who is entitled to rely upon it.
What Boards and Leaders Should Ask For
Boards do not need raw system logs, lengthy registers or technical test reports. They need information that supports judgement.
Useful reporting should show whether material use is changing, agreed controls are operating, incidents reveal emerging risk, significant assumptions remain valid and management requires a decision.
The most valuable questions are often simple:
- Where are we relying upon AI for outcomes that matter?
- What evidence supports confidence that the use remains appropriate?
- Which controls have failed or been overridden?
- What has changed since approval?
- What would cause us to stop?
Boards should understand the source of assurance. Evidence produced by an operating team may require challenge from risk, privacy, legal, cybersecurity, internal audit or external specialists.
Independence should increase with materiality.
The board's role is to decide whether the assurance available is strong enough for the organisation's exposure.
A Practical Starting Point
Regional institutions do not need to wait for a perfect framework.
They can select a small number of material AI uses and make the governance claims explicit. For each, leaders can document the intended outcome, accountable owner, principal risks, key controls, evidence source, review frequency, escalation threshold and change triggers.
Then they can test the system.
- Can the evidence be located?
- Does it support the claim?
- Do employees understand their responsibilities?
- Would an incident reach the right person?
- Has anything changed that makes the original approval unreliable?
This exercise may expose unclear ownership, missing measures, vendor dependencies or controls that cannot be evidenced. Those findings are the value of assurance: gaps become visible while the organisation can still address them deliberately.
Regional organisations can collaborate on common questions about vendor evidence, privacy, procurement and board reporting. They do not need one framework applied everywhere. They need a shared expectation that important governance claims are supported by evidence.
From Confidence to Trust
Assurance is sometimes treated as an internal management concern. Its wider value is trust.
Employees are more likely to engage when concerns are heard and systems are monitored. Communities are more likely to accept responsible use when organisations can explain how risks are controlled and what recourse exists.
In regional communities, institutions are visible and relationships overlap. A failure in one organisation can shape confidence across the region, while credible governance can strengthen responsible adoption elsewhere.
Assurance is not only a control function.
It is part of the infrastructure of institutional trust.
Conclusion
An AI policy is an important beginning. It establishes expectations and gives an organisation a position from which to act. But policy alone cannot show whether AI use is visible, responsibilities are understood, controls operate or failures will be detected.
That is the work of assurance.
Effective assurance requires leaders to identify the claims that matter, match scrutiny to consequence, gather reliable evidence and make gaps visible to those accountable for acting.
The question is no longer simply whether an organisation has an AI policy.
It is whether the organisation can demonstrate that its governance works.
Policy creates intention.
Assurance creates confidence.
About BRAIN
The Ballarat Region Artificial Intelligence Network (BRAIN) is a regional institution focused on understanding the impact of artificial intelligence across Ballarat and surrounding communities and strengthening the capability required to respond.
Through research, publications and regional collaboration, BRAIN examines how AI can contribute to regional prosperity and wellbeing while helping institutions navigate its risks and wider consequences.
About the Author
Matt Bowd is Co-Founder and Chief Executive Officer of the Ballarat Region Artificial Intelligence Network (BRAIN). His work focuses on AI governance, institutional capability and the implications of artificial intelligence for regional organisations and communities.
Next in the Series
Governing AI When Things Go Wrong
No governance system can prevent every failure. The next paper in the BRAIN Governance Insights Series will examine how organisations prepare for AI incidents: recognising weak signals, assigning decision rights, responding transparently and learning without allowing a single failure to become a lasting loss of trust.
The next governance question is:
“What happens when the system does not behave as expected?”