Free · 10 minutes

AI Governance Health Check

Twenty questions across four pillars — modelled on the AICD/HTI AI Governance Operating Model. Completes in about 10 minutes and produces a shareable board report.

Progress

Rating scale

0 Not started
1 Ad hoc
2 In progress
3 Established
Pillar 1

Strategy

These questions explore whether your board has actively shaped its approach to AI — connecting it to mission, risk appetite, and the resources needed to use AI well.

The board has discussed what AI means for our strategy and mission.

Not just as a risk — as a topic that intersects with purpose, programs, and long-term direction.

The board has discussed what AI means for our strategy and mission.

AI initiatives are assessed against organisational strategy before adoption.

New AI uses are evaluated for mission fit, not just operational convenience.

AI initiatives are assessed against organisational strategy before adoption.

The board has articulated a risk appetite for AI use.

For example: stricter standards for client-facing or automated decision-making uses.

The board has articulated a risk appetite for AI use.

The board understands the data, systems, and budget needed to support AI.

Board has a realistic view of the enablers required, not just the benefits promised.

The board understands the data, systems, and budget needed to support AI.

We have agreed measures for whether AI is delivering value.

Not just anecdotes — some form of tracking time saved, quality improvements, or outcomes.

We have agreed measures for whether AI is delivering value.
Pillar 2

Structure

These questions examine whether your organisation has clear accountability, board reporting, and the director capability to govern AI effectively.

A named senior leader is accountable for AI oversight.

Accountability doesn't require a dedicated role — a named executive with clear responsibility is enough.

A named senior leader is accountable for AI oversight.

There is a proportionate process for approving new AI uses.

Even a light process — notifying a named person before using a new AI tool — counts.

There is a proportionate process for approving new AI uses.

The board receives regular reporting on AI use and risks.

At least annual; quarterly is better. Not just incidents — proactive updates on how AI is being used.

The board receives regular reporting on AI use and risks.

The board has invested in its own AI literacy.

Directors have taken steps to understand AI well enough to ask good questions and scrutinise management.

The board has invested in its own AI literacy.

AI roles and responsibilities are reviewed as use expands.

As AI capability grows, accountability structures are kept current — not left to drift.

AI roles and responsibilities are reviewed as use expands.
Pillar 3

Practices

These questions cover the operational policies, registers, and vendor due diligence that turn governance intent into daily reality for staff and volunteers.

We have an AI policy covering staff and volunteers.

Even a one-page acceptable-use guide adopted by the board meets this standard.

We have an AI policy covering staff and volunteers.

We keep a register of AI tools in use, including embedded software features.

Many platforms already include AI — Microsoft 365, Canva, CRMs. A register tracks what's active.

We keep a register of AI tools in use, including embedded software features.

AI risks appear in our risk register with identified controls.

Including risks from AI systems that take actions automatically (agentic AI) where relevant.

AI risks appear in our risk register with identified controls.

We conduct due diligence on AI vendors and their data handling.

Checking terms of service, data residency, and whether your data trains their models.

We conduct due diligence on AI vendors and their data handling.

Our privacy practices have been reviewed for AI, including automated decision-making.

The Privacy Act automated decision-making disclosure requirements commence December 2026.

Our privacy practices have been reviewed for AI, including automated decision-making.
Pillar 4

Enablers

These questions look at the human and cultural infrastructure — data quality, training, transparency, and client engagement — that makes AI governance real in practice.

We understand the quality and security of the data AI would rely on.

Poor data quality is one of the leading causes of AI failures in service organisations.

We understand the quality and security of the data AI would rely on.

Staff and volunteers receive AI training and ongoing support.

Not just a one-off session — people have somewhere to turn when they're unsure.

Staff and volunteers receive AI training and ongoing support.

People can openly discuss AI use, including unapproved or 'shadow' tools.

A culture where staff feel safe raising AI concerns prevents problems from being hidden.

People can openly discuss AI use, including unapproved or 'shadow' tools.

We engage clients, funders, and staff about how we use AI.

Proactive transparency — not just responding to questions — about AI in our services.

We engage clients, funders, and staff about how we use AI.

We monitor AI's impact on vulnerable clients and on our workforce.

Including whether AI use creates, reinforces, or reveals risk for those in our care.

We monitor AI's impact on vulnerable clients and on our workforce.

Optional context

Helps us show relevant sector comparisons on your board report. Neither field is required.

Your report is saved at a private URL you can share with your board. No login required.

Framework: AICD & UTS Human Technology Institute, A Director's Guide to AI Governance (2026); National AI Centre, Guidance for AI Adoption. Benchmark data: AITAI Research Platform, NFP AI in Australia (2026). These tools provide general guidance, not legal advice.