AI capability portfolio · Governance
We build a board-endorsed AI use policy for your organisation, grounded in the Privacy Act 2020 and MBIE's Responsible AI Guidance — plus a lightweight governance structure so it stays a living document, not a PDF nobody opens again.
The policy is the document. The structure underneath it is what keeps it real.
The problem
Staff are already using AI tools day to day. Without a policy grounded in privacy law and endorsed by the board, that use happens without any shared understanding of what's appropriate, what's risky, or who's accountable if something goes wrong.
A policy someone drafted once but the board never actually signed off carries no real authority when it's tested.
Without a clear read on the Privacy Act 2020, it's easy to put client or beneficiary information somewhere it shouldn't go.
A policy with no review cycle and no named owner quietly goes out of date the moment it's filed.
What's included
PART ONE — THE POLICY
Written for your organisation specifically, grounded in the Privacy Act 2020 and MBIE's Responsible AI Guidance, and taken through your board for formal sign-off.
A short version staff can actually read and follow, alongside the full policy document.
PART TWO — THE GOVERNANCE STRUCTURE
A fixed point each year (or more often) where the policy is checked against how AI is actually being used.
A named person responsible for the policy, and a clear path for raising a concern before it becomes a problem.
How it works
A short look at how AI is already being used across your organisation, and where the gaps and risks actually sit.
A policy written for your organisation's actual size, risk profile and way of working — not a generic template.
We take the draft through your board, answer questions directly, and get it formally signed off.
Review cycle, ownership and escalation path are set up alongside the policy — and briefed to staff.
Who it's for
Boards who know they need a policy but haven't had the time or the template to get one endorsed.
Organisations handling sensitive beneficiary information who need privacy risk addressed properly.
Boards of Trustees needing a policy that covers staff, students and third-party data appropriately.
Growing organisations that need governance to catch up with how staff are already working.
Let's talk
We'll talk through your current state and what a right-sized policy looks like for your board.