A vendor-neutral AI governance framework for Australian organisations — the operational governance model that turns ISO/IEC 42001 implementation, AI risk management and day-to-day AI oversight into repeatable behaviour, with or without enterprise tooling.
Standards define what a management system must achieve. Vendors define how to configure their products. Neither defines how organisations translate governance principles into repeatable operational behaviour — regardless of which intelligent technology they adopt. The AGF is that bridge.
Whether your organisation runs Microsoft Purview, Google Workspace, or no DLP tooling at all, the governance rules remain identical. Technical controls strengthen governance; they never replace organisational accountability.
Microsoft Copilot governance today. Google, Anthropic or OpenAI enterprise controls tomorrow. Agentic and quantum-era systems after that. The governance and operational layers above them endure unchanged.
Aligned to ISO/IEC 42001, ISO 31000 and the NIST AI RMF, and mapped to the Australian Government's AI assurance expectations — including accountable officials and AI use-case registers.
Five layers ordered by stability — enduring governance at the top, replaceable technology below. Select each bone to expand it.
Each pattern is a normative statement of required behaviour — instantiable with any vendor's tooling, or none.
No intelligent system enters operational use without a documented, risk-rated, approved use case. Prevents shadow AI.
One authoritative inventory of every AI use case — owner, risk rating, data boundary, review date. The spine everything attaches to.
AI proposes; a human disposes. Tier A: mandatory review before use. Tier B: sampled quality assurance. Tier C: logging and monitoring only.
A named Escalation Handler may suspend AI capability immediately where unacceptable risk is identified. Operational, not political — management reviews after, not before.
Only approved data classes reach each system. The rule survives the absence of tooling — enforced behaviourally where technical controls don't exist.
Model updates, vendor changes and scope creep re-enter governance instead of accumulating silently. Every register entry has a maximum review interval.
Not "no exceptions" — no undocumented exceptions. Every override is documented, named, justified, time-limited, reviewed and closed.
Every gate names a role with the power to decide, up to an accountable executive. The cure for governance theatre.
Control objectives are enduring; the technologies satisfying them are volatile. Only the technology layer changes as vendors come and go.
Operational governance shall remain effective regardless of the technical controls available. Technology enforces policy; it does not define policy.
Review, approval and monitoring effort scale with impact and autonomy. Uniform controls do not scale — and collapse in practice.
The AGF does not compete with standards or policy — it operationalises them. If you are working out where to start, our guides cover how ISO/IEC 42001 differs from ISO/IEC 27001, what an AI use policy should contain, and the AI impact assessment requirement facing Australian Government agencies and their suppliers.
| AGF element | Aligns to |
|---|---|
| Bone 1 · Governance | ISO/IEC 42001 (cl. 4–6) · ISO/IEC 38507 · NIST AI RMF (Govern) |
| Bone 2 · Operational Governance | ISO/IEC 42001 (cl. 7–8) · ISO 31000 · NIST AI RMF (Map / Manage) |
| Bone 3 · Technology Controls | ISO/IEC 27001 Annex A · Essential Eight · ISO/IEC 23894 |
| Bone 4 · Evidence | ISO/IEC 42001 (cl. 9) · Australian Government AI assurance evidence |
| Bone 5 · Governance Intelligence | ISO/IEC 42001 (cl. 10, PDCA) · NIST AI RMF (continuous Govern) |
| Whole framework | Policy for the Responsible Use of AI in Government v2.0 · Australia's 8 AI Ethics Principles |
Every engagement follows the same governance-first sequence — the technology comes last, because it is the most replaceable part.
The AGF is maintained as a controlled, versioned specification. Every change is published with rationale, provenance and a named approver.
AGF Specification v1.0 published — the canonical definition all implementations follow. Official architecture diagram released.
Bone 2 Operational Pattern Library (OP-01 to OP-08) ratified. Core principles P1–P3 elevated to the canonical framework.
Framework established as a living, versioned governance system: five-bone architecture, six-tier evidence hierarchy, governance lifecycle.
The AGF is delivered by Bcom — Australia's dedicated ISO/IEC 42001 AI governance specialist, with a BSI-certified Lead Implementer. From a first AI risk assessment to a full AI Management System.