AI Governance Foundations
What AI governance is and what it is not
Why AI governance focuses on decisions and accountability
The eight pillars of AI governance
Governance across the AI lifecycle
Governance expectations in government and enterprise contexts
Privacy-safe participation and responsible use of AI during activities
Practical activity: Participants use an AI tool to research governance themes, risks and relevant standards for an organisation or industry, then evaluate where the AI-generated response may be vague, incorrect or oversimplified.
Decision Authority and Accountability
Who should approve AI use cases
Accountability for AI-supported decisions
Risk ownership and decision ownership
Human oversight requirements
Escalation pathways and exception handling
Governance differences between government and enterprise
Accountability across the AI lifecycle
Practical activity: Participants complete a governance reflection to examine who currently approves AI use, who owns the associated risk, where human oversight is required and what should trigger escalation.
AI Risk Management
Common AI risks, including bias, model drift, data leakage and operational impacts
Risk appetite and approval thresholds
Governed versus ungoverned AI use
Identifying gaps in informal AI adoption
Assessing impact and likelihood
Selecting controls and assigning ownership
Documenting risk acceptance and escalation decisions
Practical activity: Participants identify missing controls and accountability in an ungoverned AI scenario.
Workshop: Participants complete a live AI risk assessment for a customer-facing AI assistant. They identify risk events, calculate risk scores, select controls, assign owners and make an approval, conditional approval, escalation or redesign decision.
Transparency and Assurance
Explainability and defensibility of AI-supported decisions
Transparency as an accountability mechanism
Audit trails, logging and documentation
Evidence required for internal and external assurance
Transparency expectations across different organisational contexts
Communicating AI decisions to non-technical stakeholders
Practical activity: Participants complete a transparency test by evaluating whether an AI-generated explanation is understandable, honest, complete and defensible if challenged.
Regulatory and Policy Alignment
Understanding the AI regulatory and policy landscape
Translating external obligations into internal policies
Government and enterprise governance requirements
Australian AI governance reference points
Using principles, standards and frameworks appropriately
Recognising where requirements are unclear or evolving
Confirming obligations with legal, risk and policy specialists
Practical activity: Participants use AI-supported research to identify regulatory and policy signals relevant to their organisation or industry, evaluate the credibility of the findings and determine what requires professional confirmation.
Data Governance for AI
Data classification and sensitivity
Data provenance and ownership
Privacy-by-design
Retention and deletion requirements
Secure handling of prompts, inputs and outputs
Defining acceptable data boundaries
Matching governance controls to data risk
Practical activity: Participants assess a workplace AI use case, classify the data involved and compare their judgement with risks identified by an AI tool.
Operating AI Responsibly
Integrating AI governance with existing operational practices
Incident and problem management
Controlled change and release management
Knowledge, configuration and asset management
Monitoring AI use after deployment
Assigning responsibility when an AI-related issue occurs
Establishing governance trigger points
Practical activity: Participants define the review, evidence, decision owner and escalation route required when an AI use case involves sensitive data, customer-facing outputs, employment decisions, financial or safety impacts, or significant vendor changes.
Practical Adoption and Value
Minimum viable AI governance
Risk-proportionate governance
Lightweight governance patterns
AI use-case triage
Balancing implementation speed with responsible oversight
Integrating governance into business value streams
Supporting innovation without unnecessary bureaucracy
Practical activity: Participants design minimum viable governance for an AI use case by defining its accountable owner, approval process, permitted data boundaries and review cadence.
Governance Toolkit and Artefacts
AI policies and acceptable-use rules
AI use-case registers and AI registries
Risk assessments
Governance committee charters
Approval workflows
Monitoring registers
Connecting governance artefacts across the AI lifecycle
Selecting governance artefacts proportionate to organisational risk and maturity
Participants examine how governance artefacts make AI decisions visible, repeatable and defensible, including what information should be captured in an AI registry.
AI Governance Board Simulation
Participants act as an AI Governance Board and review a proposed customer-facing AI assistant that uses customer conversation data.
The group must:
Identify the most significant risks
Define non-negotiable controls
Establish appropriate data boundaries
Determine required human oversight
Identify evidence required before approval
Assign an accountable owner
Define escalation and review requirements
Approve, approve with conditions, escalate, reject or redesign the proposed use case
Document a defensible decision rationale.
Skills and Workforce Expectations
AI literacy and safe-use training
Role-specific capability requirements
Technical, risk, ethical and communication skills
Critical thinking and responsible judgement
Workforce capability differences across organisational contexts
Continuous learning as part of ongoing governance
Participants consider where capability gaps exist and how targeted AI upskilling can reduce governance risk.
30-60-90 Day Governance Action Plan
Participants convert the course content into a practical implementation roadmap:
First 30 Days: Establish the Foundations
Identify accountable owners
Document current AI use
Begin an AI use-case register
Establish an initial policy or acceptable-use position
Days 31 to 60: Introduce Governance Controls
Introduce risk assessment and approval steps
Define data boundaries
Establish escalation pathways
Pilot governance processes on selected AI use cases
Days 61 to 90: Embed Operational Governance
Introduce monitoring and review cycles
Review approved use cases
Establish reporting arrangements
Embed governance and training into business-as-usual practices
Each participant identifies priority actions, accountable stakeholders, evidence of progress and key dependencies.