Reference Architecture

BCOM Adaptive Governance Framework (AGF)

A vendor-neutral AI governance framework for Australian organisations — the operational governance model that turns ISO/IEC 42001 implementation, AI risk management and day-to-day AI oversight into repeatable behaviour, with or without enterprise tooling.

Explore the architecture Operational patterns

Specification v1.0 · Framework v2.2.0 · Last updated July 2026

Governance outlasts technology

Standards define what a management system must achieve. Vendors define how to configure their products. Neither defines how organisations translate governance principles into repeatable operational behaviour — regardless of which intelligent technology they adopt. The AGF is that bridge.

Technology enforces policy — it does not define policy

Whether your organisation runs Microsoft Purview, Google Workspace, or no DLP tooling at all, the governance rules remain identical. Technical controls strengthen governance; they never replace organisational accountability.

Only the technology layer changes

Microsoft Copilot governance today. Google, Anthropic or OpenAI enterprise controls tomorrow. Agentic and quantum-era systems after that. The governance and operational layers above them endure unchanged.

Built for Australian assurance

Aligned to ISO/IEC 42001, ISO 31000 and the NIST AI RMF, and mapped to the Australian Government's AI assurance expectations — including accountable officials and AI use-case registers.

The Five Bones

Five layers ordered by stability — enduring governance at the top, replaceable technology below. Select each bone to expand it.

AGF architecture diagram: five bones from enduring Governance to volatile Technology Controls, with the Evidence layer and the Bone 5 continual-improvement loop
Bone 1 Governance — the organisation decides
Why intelligent systems are used, who owns them, risk appetite, accountability and policy.
  • Maps to ISO/IEC 42001 clauses 4–6, ISO/IEC 38507 and the NIST AI RMF Govern function
  • In government settings, this is where accountable officials are designated
Bone 2 Operational Governance — how people actually work THE DIFFERENTIATOR
The eight vendor-neutral operational patterns (OP-01 to OP-08) that translate principle into repeatable behaviour: approvals, registers, tiered human review, escalation, data boundaries, drift review, controlled overrides and named decision authority.
  • This is the layer no standard fully specifies and no vendor provides
  • Maps to ISO/IEC 42001 clauses 7–8, ISO 31000 and NIST AI RMF Map/Manage
Bone 3 Technology Controls — replaceable by design
The current instantiation of control objectives in specific products: Microsoft Purview, DLP and sensitivity labels today; Google, Anthropic, OpenAI enterprise controls, agentic and quantum-era systems tomorrow.
  • Technology changes; control objectives remain
  • Maps to ISO/IEC 27001 Annex A, the Essential Eight and ISO/IEC 23894
Bone 4 Evidence — governance you can prove
Logs, monitoring, audit records, management review and assurance evidence — the material that satisfies ISO audits and government AI Impact Assessments.
  • Maps to ISO/IEC 42001 clause 9 and Australian Government assurance evidence requirements
Bone 5 Governance Intelligence — the framework learns
The continual-improvement lifecycle: Observe → Validate → Map → Decide → Version → Publish. New standards, policies and technologies are ranked by authority and mapped to the framework; every change passes a human-signed decision gate and is published with rationale and provenance.
  • Maps to ISO/IEC 42001 clause 10 (PDCA) — the framework applies continual improvement to itself

The Eight Operational Patterns

Each pattern is a normative statement of required behaviour — instantiable with any vendor's tooling, or none.

OP-01

Use-Case Intake & Approval

No intelligent system enters operational use without a documented, risk-rated, approved use case. Prevents shadow AI.

OP-02

AI Register

One authoritative inventory of every AI use case — owner, risk rating, data boundary, review date. The spine everything attaches to.

OP-03

Tiered Human Review

AI proposes; a human disposes. Tier A: mandatory review before use. Tier B: sampled quality assurance. Tier C: logging and monitoring only.

OP-04

Escalation & Kill-Switch

A named Escalation Handler may suspend AI capability immediately where unacceptable risk is identified. Operational, not political — management reviews after, not before.

OP-05

Data Boundary Control

Only approved data classes reach each system. The rule survives the absence of tooling — enforced behaviourally where technical controls don't exist.

OP-06

Change & Drift Review

Model updates, vendor changes and scope creep re-enter governance instead of accumulating silently. Every register entry has a maximum review interval.

OP-07

Exception & Override

Not "no exceptions" — no undocumented exceptions. Every override is documented, named, justified, time-limited, reviewed and closed.

OP-08

Authority Matrix

Every gate names a role with the power to decide, up to an accountable executive. The cure for governance theatre.

Three principles anchor every implementation

P1 — Govern capabilities, not vendors

Control objectives are enduring; the technologies satisfying them are volatile. Only the technology layer changes as vendors come and go.

P2 — Governance effective regardless of tooling

Operational governance shall remain effective regardless of the technical controls available. Technology enforces policy; it does not define policy.

P3 — Governance proportionate to risk

Review, approval and monitoring effort scale with impact and autonomy. Uniform controls do not scale — and collapse in practice.

Anchored to recognised standards

The AGF does not compete with standards or policy — it operationalises them. If you are working out where to start, our guides cover how ISO/IEC 42001 differs from ISO/IEC 27001, what an AI use policy should contain, and the AI impact assessment requirement facing Australian Government agencies and their suppliers.

AGF elementAligns to
Bone 1 · GovernanceISO/IEC 42001 (cl. 4–6) · ISO/IEC 38507 · NIST AI RMF (Govern)
Bone 2 · Operational GovernanceISO/IEC 42001 (cl. 7–8) · ISO 31000 · NIST AI RMF (Map / Manage)
Bone 3 · Technology ControlsISO/IEC 27001 Annex A · Essential Eight · ISO/IEC 23894
Bone 4 · EvidenceISO/IEC 42001 (cl. 9) · Australian Government AI assurance evidence
Bone 5 · Governance IntelligenceISO/IEC 42001 (cl. 10, PDCA) · NIST AI RMF (continuous Govern)
Whole frameworkPolicy for the Responsible Use of AI in Government v2.0 · Australia's 8 AI Ethics Principles

From first assessment to living management system

Every engagement follows the same governance-first sequence — the technology comes last, because it is the most replaceable part.

Governance
Operational governance
Technology controls
Evidence
Continual improvement

A framework under version control

The AGF is maintained as a controlled, versioned specification. Every change is published with rationale, provenance and a named approver.

v2.2.0 — July 2026

AGF Specification v1.0 published — the canonical definition all implementations follow. Official architecture diagram released.

v2.1.0 — July 2026

Bone 2 Operational Pattern Library (OP-01 to OP-08) ratified. Core principles P1–P3 elevated to the canonical framework.

v2.0.0 — July 2026

Framework established as a living, versioned governance system: five-bone architecture, six-tier evidence hierarchy, governance lifecycle.

Implement the framework

The AGF is delivered by Bcom — Australia's dedicated ISO/IEC 42001 AI governance specialist, with a BSI-certified Lead Implementer. From a first AI risk assessment to a full AI Management System.

Call 07 3041 8993 support@bcomservices.com