Frameworks & Obligations
The key Australian cyber and AI governance references, regulatory commencement dates and director duties, curated for the boardroom, not the IT department. Every date and threshold is drawn from the primary instrument.
What governs a director's cyber and AI accountability
Cyber and AI failures are not judged against a technical standard, they are judged against a director's duties. These are the instruments that define the boundary of that accountability in Australia.
Duty of Care and Diligence
The statutory standard of care a director must exercise. Cyber and AI risk oversight failures are increasingly tested through this lens, not as a separate technical duty.
Cyber Security Act 2024
Australia's first standalone cyber security law. Introduces mandatory ransomware payment reporting, mandatory security standards for smart devices, and a Cyber Incident Review Board.
Security of Critical Infrastructure
Risk management program and mandatory incident reporting obligations for responsible entities of critical infrastructure assets across energy, water, health, data, finance and more.
Privacy Act & Data Breach Scheme
Governs handling of personal information and mandatory notification of eligible data breaches. A significant reform package is progressively amending the Act.
CPS 234 Information Security
Requires APRA-regulated entities to maintain information security capability commensurate with threats, with clear board and senior management accountability.
The Essential Eight
Eight prioritised mitigation strategies and a maturity model. The most common technical baseline a board will see referenced in management cyber reporting.
What commences, and when
The Act commences in stages. These dates are taken verbatim from the Act, the supporting Rules and Department of Home Affairs guidance. Confirm against the source before relying on any date for a board paper.
Cyber Security Governance Principles
The de facto standard for board cyber oversight in Australia. Version 2 strengthened guidance on digital supply-chain risk, data governance, and incident response and recovery. All five principles, in full.
Set clear roles and responsibilities
Establish unambiguous accountability across board and management for how cyber risk is governed. Cyber is a whole-of-organisation strategic risk, not an IT issue, supported by appropriate delegations and board reporting.
Develop, implement and evolve a comprehensive cyber strategy
A strategy that identifies the organisation's key digital assets and data, accounts for third-party and supply-chain risk, and enables business objectives rather than constraining them.
Embed cyber security in existing risk management practices
Integrate cyber into the organisation's enterprise risk framework and regularly assess the effectiveness of controls against an evolving threat environment, rather than treating it as a standalone register item.
Promote a culture of cyber resilience
Cultivate resilience from the board down, through regular, relevant and engaging training, and by incentivising and reinforcing strong cyber practices across the whole organisation.
Plan for a significant cyber security incident
Prepare to respond effectively, and compassionately, to a significant incident, including simulation exercises and scenario testing, response and recovery planning, and clarity on regulatory reporting obligations. This is the area most strengthened in Version 2, informed by recent major Australian incidents.
Frameworks for board oversight of AI
Australia's AI settings remain principally voluntary today, with mandatory guardrails for high-risk settings under government consideration. Directors are expected to oversee AI as an extension of existing data, risk and accountability duties.
Australian references
The domestic baseline directors are expected to be conversant with.
International standards
Increasingly referenced in Australian board and vendor due diligence.
AI Governance Checklist for Directors
A quick-reference checklist on data privacy, ethical AI use, and vendor risk management when your organisation deploys automated systems. Built for SME and not-for-profit boards.
AICD Guidance for Boards
The AICD updated its Cyber Security Governance Principles in November 2024. Version 2 introduced explicit board obligations around digital supply chain risk, data governance, and governing through a cyber crisis. These are now the benchmark standard against which board conduct will be assessed post-incident, by regulators, auditors, and courts. The five principles establish clear roles and responsibilities, cyber strategy, risk management integration, culture, and incident preparedness.
AICD Cyber Security Governance Principles arrow_forwardAPRA AI Governance Obligations, April 2026
On 30 April 2026, APRA wrote to all regulated entities naming four AI governance failures found across major banks, insurers, and superannuation trustees. APRA confirmed that existing standards, CPS 230, CPS 234, CPG 235, and CPS 510, already apply to AI, and signalled active enforcement where governance is not keeping pace with adoption. Boards of APRA-regulated entities must have documented AI strategy, risk appetite, board reporting, and supplier oversight to demonstrate compliance. The CPS 230 deadline for pre-existing supplier arrangements is 1 July 2026.
Read the director's guidance note arrow_forwardPrimary sources, directly
- menu_bookAICD Cyber Security Governance PrinciplesVersion 2, the board standardopen_in_new
- policyASIC Corporate Governance GuidanceRegulator expectations of directorsopen_in_new
- securityOAIC Privacy GuidancePrivacy Act & data breach obligationsopen_in_new
- shieldAustralian Cyber Security CentreASD, guidance & incident reportingopen_in_new
- descriptionAICD Cyber Security Governance Principles, Version 2November 2024, the board standardopen_in_new
- policyAPRA AI Governance Letter, April 2026CPS 230, CPS 234, CPG 235, CPS 510open_in_new
The Essential Eight
Assessed against a four-level maturity model (Maturity Level Zero to Three). Ask management which level applies, against what target.
Understanding the frameworks is the first step
Applying them to your specific board, sector and regulatory context is where independent, conflict-free advisory makes the difference. Every enquiry is treated as strictly confidential.