shield_person Andrew Roberts Advisory

Briefing No. 027

What an Independent AI Governance Review Actually Involves for Australian Boards

·8 min read·1,696 words

Your organisation is using AI. Your board approved the business case, the technology team deployed the tools, and now a regulator asks how you are governing it. What does your answer look like? If it involves a slide deck from management and a verbal assurance that controls are in place, that answer is not going to hold.

Does this apply to you?

ASX-listed: Yes. ASIC has published REP 798 signalling direct expectations around how boards oversee AI use. [1] Listed entities using AI in customer-facing decisions, market disclosures, or operational risk functions are squarely in scope.

APRA-regulated: Yes. Banks, insurers, and superannuation funds using AI in credit, pricing, or claims decisions face intersecting obligations under prudential risk management requirements and ASIC conduct expectations. [2]

NFP / SME: Proportionally yes. If your organisation uses AI tools that affect people, make decisions, or process data, directors still carry a duty of care. An independent review does not need to be elaborate to be effective.

Why ASIC REP 798 Matters to Every Board Using AI

ASIC published REP 798 as a direct statement of how Australia's corporate regulator views AI governance at the board level. The message is clear: boards cannot treat AI as a purely technical matter delegated to management. [3] ASIC expects directors to understand how AI is being used inside their organisations, what risks it introduces, and what oversight mechanisms are in place to catch failures before they cause harm to customers or markets.

This is not a future obligation. It reflects existing directors' duties under the Corporations Act, applied to a new class of operational risk. [3] A director who cannot explain how AI decisions are made, reviewed, or challenged in their organisation is exposed. The question is not whether your organisation uses AI responsibly. The question is whether your board can demonstrate it.

Data Governance Is the Foundation, Not the Footnote

Before any board can meaningfully govern AI, it has to govern the data that AI depends on. This is the step most boards skip, and it is the step that causes AI governance frameworks to collapse under scrutiny.

AI systems do not generate insight from nothing. They draw on data, and the quality, completeness, provenance, and bias of that data determines the quality and fairness of the AI output. If your organisation does not have a clear picture of what data it holds, where it came from, who controls it, how it is maintained, and what legal obligations attach to it, then any AI governance framework built on top of that data is structurally unsound.

An independent AI governance review therefore starts with data. It examines whether the organisation has a data governance framework that is actually operational, not just documented. It looks at data classification, data lineage, data quality controls, and whether responsibilities for data stewardship are assigned and enforced. Only once that foundation is established does it become meaningful to assess how AI is layered on top.

What an Independent Review Actually Examines

An independent AI governance review is not an audit of the AI models themselves. It is a board-level assessment of whether the governance structures around AI are fit for purpose. That distinction matters. The review is examining the oversight system, not the code.

At the board and executive level, a review examines whether there is a clear AI policy, who owns it, and whether the board has approved it. It looks at whether AI use cases are inventoried and classified by risk. It assesses whether the board receives meaningful reporting on AI risk, not just system uptime and accuracy metrics, but information about decisions the AI is making and outcomes those decisions are producing.

At the operational level, a review examines whether AI systems are subject to human oversight at appropriate points. It looks at model validation practices, change management controls, and whether there is a process for identifying and responding to AI failures. It asks whether staff who operate AI tools understand the limits of those tools and have authority to override AI outputs when something does not look right.

At the data level, as discussed, it examines whether the underlying data is governed in a way that makes the AI trustworthy. If the data is not governed, the AI is not governed, regardless of what the policy document says.

What Makes the Review Independent

Internal assessments have a role, but they cannot replace independent review. The people closest to an AI system are the least well-positioned to identify its governance gaps. They are invested in the system working, they understand it in ways that make its weaknesses feel manageable, and they report to the same management chain that approved the system in the first place.

Independence means the reviewer has no prior involvement in the design, deployment, or management of the AI systems being reviewed. It means the reviewer reports findings directly to the board, not through management. It means the methodology is structured and documented, so findings can be tested and compared over time. And it means the reviewer has genuine expertise in AI risk, data governance, and board-level governance obligations, not just technical AI knowledge alone.

The AICD, as the professional body for Australian directors, has consistently emphasised that boards need external assurance on significant risk areas. AI now qualifies. The ACS, as the professional body for technology practitioners in Australia, has similarly highlighted that AI governance requires multi-disciplinary expertise spanning technology, ethics, law, and risk management. An independent review draws on all of these.

What the Board Should Actually Do

Start by asking whether your board has formally approved an AI governance policy and whether you have seen an inventory of AI use cases in the organisation. If the answer to either question is no, that is the starting point. Not the model documentation, not the vendor contract, the governance policy and the use case register.

Then commission an independent review. Not a gap analysis from the team that built the AI system, and not a maturity model self-assessment completed by management. An independent, structured review conducted by someone with no stake in the outcome, reporting directly to the board.

Governance red flags

  • The board has no approved AI governance policy and has never seen an inventory of AI use cases across the organisation.
  • Management describes AI governance by referencing vendor compliance certifications rather than internal oversight controls.
  • There is no data governance framework underpinning the AI systems in use, or the framework exists on paper but is not operationally enforced.
  • Board reporting on AI risk is limited to technical performance metrics with no information on decision outcomes, errors, or customer impact.
  • The last review of AI governance was conducted internally by the team responsible for deploying the AI systems.

Questions to ask management

  1. Can you provide the board with a complete inventory of AI systems in use, classified by their level of risk and the types of decisions they influence?
  2. What data governance framework underpins our AI systems, and who is responsible for maintaining data quality and data lineage for each AI use case?
  3. When an AI system produces an incorrect or harmful output, what is the process for detecting it, escalating it, and correcting it, and has that process been tested?
  4. What human oversight exists at the decision points where AI outputs are acted on, and do staff have a clear mandate to override AI recommendations?
  5. Has our AI governance framework been reviewed by an independent party with no involvement in the design or deployment of our AI systems, and did that reviewer report directly to the board?

ASIC REP 798 is not a warning about the future. It is a description of expectations that apply now, to boards governing organisations that are already using AI. Directors who treat AI governance as a technical matter for management to handle are misreading their obligation. The duty of care does not have a technology exemption. [4]

"The board reviewed the organisation's AI governance framework and underlying data governance controls, considered findings from an independent AI governance review conducted by an external party reporting directly to the board, and resolved that management provide a remediation plan addressing identified gaps within 90 days."

Suitable for board minutes or a risk register entry

Frequently Asked Questions

How is an AI governance review different from a technology audit?

A technology audit examines whether systems are built and operated correctly. An AI governance review examines whether the board has the structures, information, and oversight mechanisms to govern the risks those systems create. The two can overlap but the governance review is focused on the board and executive layer, not the technical layer.

Do we need an independent review if we only use off-the-shelf AI tools?

Yes. Off-the-shelf AI tools still produce decisions and outputs that your organisation is responsible for. ASIC REP 798 does not distinguish between bespoke and commercial AI. The governance obligation attaches to the use of AI, not the origin of it.

Where does data governance fit if we already have a privacy compliance program?

Privacy compliance is necessary but it is not the same as data governance. Privacy compliance addresses how personal data is handled lawfully. Data governance addresses the quality, lineage, classification, stewardship, and integrity of all data the organisation relies on, including the data feeding AI systems. AI governance requires both, and a privacy program alone does not close the data governance gap.

What should board minutes reflect after an AI governance review is completed?

Minutes should record that the board received the findings of an independent review, that it considered the adequacy of the current AI governance framework and the data governance controls underlying it, and that it directed management to address specific gaps on a defined timeline. A general statement that the board noted the report is not sufficient to demonstrate active oversight.

Related briefings

AI Governance

AI Ethics Governance for Australian Boards: A Director's Framework

Briefing No. 006

AI Governance

AI Risk Management Framework for Directors: A Defensible 2026 Guide for Australian Boards

Briefing No. 008

AI Governance

Board Oversight of Generative AI Risks: A Defensible Governance Framework for 2026

Briefing No. 015

If this resonates, I would welcome a conversation. AI Governance Board Review.

Sources

Andrew Roberts

Article by

Andrew Roberts

Founder and Principal Advisor at Andrew Roberts Advisory. I work directly with Australian boards and non-executive directors on cyber governance, AI governance, and IT general controls and strategy, translating complex regulatory terrain into clear, defensible oversight frameworks that directors can own and act on. I have founded and exited two technology companies. I founded Field Solutions Group, served as Group CEO for a decade, and led the ASX listing in 2017. During that time I held direct board accountability for cyber risk, ISO 27001 certification, and governance at the listed company level. I have also served as Deputy Chairman of a federally funded Cooperative Research Centre. I am a Member of the Australian Institute of Company Directors (AICD) and the Australian Computer Society (ACS), holding the ACS designation MACS (Snr) CP (Cyber), and am a Member of ISACA.

More Articles

Cyber Governance & Oversight

Cyber Governance for Boards Australia: Moving Beyond Technical Metrics to Defensible OversightNew

Aug 01, 2026
Cyber Governance & Oversight

What is a Technology Consultant? A Director’s Guide to Strategic Advisory in 2026New

Aug 01, 2026
Governance Strategy & Advisory

Digital Strategy Consulting: A Board-Level Governance Template for 2026New

Aug 01, 2026
Cyber Governance & Oversight

Defensible Oversight: A Cyber Security Audit Checklist for Australian BoardsNew

Aug 01, 2026
Governance Strategy & Advisory

Tech Consulting for Australian Boards: Bridging the Governance Gap in 2026New

Aug 01, 2026
AI Governance

AI Ethics Governance for Australian Boards: A Director's FrameworkNew

Aug 01, 2026
Board Reporting & Disclosure

Cyber Risk Reporting to the Board Australia: Establishing Defensible Oversight in 2026New

Aug 01, 2026
AI Governance

AI Risk Management Framework for Directors: A Defensible 2026 Guide for Australian BoardsNew

Aug 01, 2026
Regulation & Compliance

Regulatory Settlement Agreements: A Director’s Guide to Defensible GovernanceNew

Aug 01, 2026
Cyber Governance & Oversight

Cyber Security for Australian Boards: Moving from Technical Metrics to Defensible OversightNew

Aug 01, 2026
Regulation & Compliance

Privacy Act Obligations and the Crimes Act: A Director’s Guide to Defensible OversightNew

Aug 01, 2026
Third-Party & Supply Chain Risk

Third Party Cyber Risk Governance Australia: A Director’s Guide to Defensible OversightNew

Aug 01, 2026
Cyber Governance & Oversight

Board Cyber Governance Strategy Australia: A 2026 Reference for DirectorsNew

Aug 01, 2026
Cyber Governance & Oversight

How to Challenge a CISO Report: A Director’s Guide to Defensible OversightNew

Aug 01, 2026
AI Governance

Board Oversight of Generative AI Risks: A Defensible Governance Framework for 2026New

Aug 01, 2026
AI Governance

AI Governance Reporting for Boards: A Guide to Defensible OversightNew

Aug 01, 2026
AI Governance

Questions for Boards to Ask About Corporate AI Strategy: A 2026 Director’s ChecklistNew

Aug 01, 2026
AI Governance

Director's Guide to Artificial Intelligence Risks: Defensible Oversight in 2026New

Aug 01, 2026
Board Reporting & Disclosure

Linking Cyber Risk to Financial Impact: A Director’s Guide to Defensible Board ReportingNew

Aug 01, 2026
Regulation & Compliance

APRA CPS 234: Board Obligations Checklist for DirectorsNew

Aug 01, 2026
Board Reporting & Disclosure

Investor Expectations for Board Cyber Oversight in 2026New

Aug 01, 2026
Cyber Governance & Oversight

Essential Eight Board Oversight for Australian DirectorsNew

Aug 01, 2026
Regulation & Compliance

Cyber Security Act 2024: Australian Director ObligationsNew

Aug 01, 2026
Cyber Governance & Oversight

Board Cybersecurity Duties: A Director's Guide to Defensible Oversight in AustraliaNew

Aug 01, 2026
Cyber Governance & Oversight

AICD Cyber Security Governance Principles Version 2: What Australian Directors Need to KnowNew

Aug 01, 2026
Third-Party & Supply Chain Risk

Third-Party Cyber Risk: A Director's Guide to Defensible Board Oversight in AustraliaNew

Aug 01, 2026