shield_person Andrew Roberts Advisory
Home  ›  Director's Guidance Hub
Director's Guidance Hub

Frameworks & Obligations

The key Australian cyber and AI governance references, regulatory commencement dates and director duties, curated for the boardroom, not the IT department. Every date and threshold is drawn from the primary instrument.

The regulatory landscape

What governs a director's cyber and AI accountability

Cyber and AI failures are not judged against a technical standard, they are judged against a director's duties. These are the instruments that define the boundary of that accountability in Australia.

gavel Directors' duties

Duty of Care and Diligence

Corporations Act 2001 (Cth), s.180

The statutory standard of care a director must exercise. Cyber and AI risk oversight failures are increasingly tested through this lens, not as a separate technical duty.

For the board: the question a regulator or court asks is not "did the system fail?" but "did the director exercise reasonable care in overseeing the risk?"
Federal Register of Legislation open_in_new
security Cyber, primary law

Cyber Security Act 2024

Cyber Security Act 2024 (Cth), Royal Assent 29 November 2024

Australia's first standalone cyber security law. Introduces mandatory ransomware payment reporting, mandatory security standards for smart devices, and a Cyber Incident Review Board.

For the board: reporting obligations and limited-use protections change how an incident must be managed in the first 72 hours. See the commencement timeline below.
Dept. of Home Affairs open_in_new
account_balance Critical infrastructure

Security of Critical Infrastructure

Security of Critical Infrastructure Act 2018 (Cth), "SOCI"

Risk management program and mandatory incident reporting obligations for responsible entities of critical infrastructure assets across energy, water, health, data, finance and more.

For the board: responsible entities must report ransomware payments regardless of turnover, and carry board-attested risk management program duties.
Cyber & Infrastructure Security Centre open_in_new
policy Privacy

Privacy Act & Data Breach Scheme

Privacy Act 1988 (Cth) + Notifiable Data Breaches scheme

Governs handling of personal information and mandatory notification of eligible data breaches. A significant reform package is progressively amending the Act.

For the board: data governance, what is held, where, who can access it, and retention, is now an explicit board oversight expectation under the AICD Principles.
Office of the Australian Information Commissioner open_in_new
verified_user APRA-regulated

CPS 234 Information Security

APRA Prudential Standard CPS 234 (+ related CPS 230 Operational Risk)

Requires APRA-regulated entities to maintain information security capability commensurate with threats, with clear board and senior management accountability.

For the board: for banks, insurers and superannuation trustees, information security is a board-accountable prudential obligation, not delegated assurance.
APRA open_in_new
checklist Technical baseline

The Essential Eight

ASD / ACSC, Essential Eight Maturity Model

Eight prioritised mitigation strategies and a maturity model. The most common technical baseline a board will see referenced in management cyber reporting.

For the board: a useful benchmark to challenge management against, "what maturity level are we at, against what target, and why?"
cyber.gov.au open_in_new
Cyber Security Act 2024, rollout

What commences, and when

The Act commences in stages. These dates are taken verbatim from the Act, the supporting Rules and Department of Home Affairs guidance. Confirm against the source before relying on any date for a board paper.

29 November 2024
Cyber Security Act 2024 receives Royal Assent
Australia's first standalone cyber security law becomes law. Framework provisions for ransomware reporting, smart-device standards and the Cyber Incident Review Board are set in motion.
30 May 2025 In force
Mandatory ransomware & cyber-extortion payment reporting commences
Reporting business entities must report a ransomware or cyber-extortion payment to the Australian Signals Directorate within 72 hours. Applies to entities with annual turnover of $3 million or more, and to responsible entities for critical infrastructure assets regardless of turnover. Failure to report carries a civil penalty of up to 60 penalty units (currently $19,800).
30 May – 31 December 2025
Education-first transition period
The Department applied an education-first approach for the first six months, prioritising awareness and support over enforcement action except for serious non-compliance.
1 January 2026 In force
Full enforcement of ransomware reporting obligations
The education-first period ends and the reporting obligation moves to full compliance and enforcement.
AICD & CSCRC, Version 2, November 2024

Cyber Security Governance Principles

The de facto standard for board cyber oversight in Australia. Version 2 strengthened guidance on digital supply-chain risk, data governance, and incident response and recovery. All five principles, in full.

1

Set clear roles and responsibilities

Establish unambiguous accountability across board and management for how cyber risk is governed. Cyber is a whole-of-organisation strategic risk, not an IT issue, supported by appropriate delegations and board reporting.

2

Develop, implement and evolve a comprehensive cyber strategy

A strategy that identifies the organisation's key digital assets and data, accounts for third-party and supply-chain risk, and enables business objectives rather than constraining them.

3

Embed cyber security in existing risk management practices

Integrate cyber into the organisation's enterprise risk framework and regularly assess the effectiveness of controls against an evolving threat environment, rather than treating it as a standalone register item.

4

Promote a culture of cyber resilience

Cultivate resilience from the board down, through regular, relevant and engaging training, and by incentivising and reinforcing strong cyber practices across the whole organisation.

5

Plan for a significant cyber security incident

Prepare to respond effectively, and compassionately, to a significant incident, including simulation exercises and scenario testing, response and recovery planning, and clarity on regulatory reporting obligations. This is the area most strengthened in Version 2, informed by recent major Australian incidents.

Read the full Principles on the AICD site open_in_new

AI governance

Frameworks for board oversight of AI

Australia's AI settings remain principally voluntary today, with mandatory guardrails for high-risk settings under government consideration. Directors are expected to oversee AI as an extension of existing data, risk and accountability duties.

AI Governance Checklist for Directors

A quick-reference checklist on data privacy, ethical AI use, and vendor risk management when your organisation deploys automated systems. Built for SME and not-for-profit boards.

Request the checklist
policyverified_user

AICD Guidance for Boards

The AICD updated its Cyber Security Governance Principles in November 2024. Version 2 introduced explicit board obligations around digital supply chain risk, data governance, and governing through a cyber crisis. These are now the benchmark standard against which board conduct will be assessed post-incident, by regulators, auditors, and courts. The five principles establish clear roles and responsibilities, cyber strategy, risk management integration, culture, and incident preparedness.

AICD Cyber Security Governance Principles arrow_forward
gavelaccount_balance

APRA AI Governance Obligations, April 2026

On 30 April 2026, APRA wrote to all regulated entities naming four AI governance failures found across major banks, insurers, and superannuation trustees. APRA confirmed that existing standards, CPS 230, CPS 234, CPG 235, and CPS 510, already apply to AI, and signalled active enforcement where governance is not keeping pace with adoption. Boards of APRA-regulated entities must have documented AI strategy, risk appetite, board reporting, and supplier oversight to demonstrate compliance. The CPS 230 deadline for pre-existing supplier arrangements is 1 July 2026.

Read the director's guidance note arrow_forward
About this hub. This page summarises publicly available regulatory and framework information for the convenience of company directors. Dates and thresholds are drawn from the primary instruments and were correct at the time of publication, but legislation and guidance change. Nothing here is legal advice, and it should not be relied on as a substitute for advice on your specific board, sector and circumstances. Always confirm current obligations against the primary source or qualified counsel.
From frameworks to defensible governance

Understanding the frameworks is the first step

Applying them to your specific board, sector and regulatory context is where independent, conflict-free advisory makes the difference. Every enquiry is treated as strictly confidential.