An AI compliance checklist for Australian businesses
A working checklist that maps ISO 42001, ISO 27001, the Privacy Act and the Essential Eight onto one set of artefacts instead of four parallel programmes.
Why a checklist beats a framework debate
Most Australian organisations do not fail AI compliance because they picked the wrong framework. They fail because obligations sit in four places — a privacy register, a security ISMS, a vendor spreadsheet and somebody’s inbox — and nobody can produce a single view on demand.
The fix is unglamorous. One register, one owner per obligation, one evidence store. The framework you cite matters far less than whether the artefacts exist and are current.
Step one: inventory every AI system in use
List every AI capability actually in use, including the ones nobody approved: embedded vendor features, browser extensions, copilots bundled into productivity suites, model APIs called from internal scripts and agents wired into workflow tools.
For each entry record purpose, business owner, data classes touched, whether personal information is involved, whether output influences a decision about a person, and the vendor and hosting region. That single table drives everything downstream.
Step two: classify by impact, not by excitement
Tier systems by consequence. A drafting assistant that never touches customer data belongs in a light tier. Anything that influences credit, employment, eligibility, clinical or safety outcomes belongs in the highest tier with a documented human decision-maker.
Tiering is what keeps the programme proportionate. Applying high-tier controls everywhere is the fastest way to have the whole thing quietly ignored.
Step three: map the obligations once
Against each tiered system, record which obligations apply: Australian Privacy Principles where personal information is involved, sector rules such as APRA CPS 234 or the SOCI Act where relevant, contractual and customer security schedules, and any certification commitments you have made.
Then map controls, not documents. An access-control statement in your ISMS may already satisfy an ISO 42001 operational control. Note the reuse explicitly so you are not writing the same policy twice under two headings.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
Step four: the security floor still applies
AI compliance sits on top of ordinary security hygiene. Essential Eight maturity, identity and privileged access discipline, patching, logging and backup are the floor. Governance documentation over a weak security base does not survive scrutiny.
The most common finding in AI assessments is not an exotic model risk. It is over-shared data that a copilot has now surfaced to everyone who could technically always have reached it.
Step five: assemble the evidence pack
A defensible pack contains the inventory, impact assessments for high-tier systems, approval records with conditions, acceptable-use policy and training records, supplier assurance evidence, monitoring output and any incident records with their resolution.
Rehearse it. Ask someone outside the programme to answer, using only the pack, which AI systems touch customer data and who approved them. If that takes more than ten minutes, the pack is not ready.
Step six: set the review cadence
AI estates drift faster than most control environments because vendors ship new capability into products you already own. Review the inventory quarterly and re-assess any system whose data, autonomy or user base has materially changed.
General information only — not legal advice. Confirm your specific obligations with your legal adviser and current regulator guidance.
Sources and further reading
- ISO/IEC 42001 AI management systems
- ISO/IEC 27001 information security management systems
- OAIC guidance on privacy and the Privacy Act
- Australian Signals Directorate Essential Eight
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read article