Responsible AI by Design: What Every Organisational Role Needs to Do
- Raj Nair

- Jul 15
- 7 min read
Updated: 3 days ago

Artificial intelligence should not be governed by one policy, one technology team or one annual compliance review.
Effective AI governance is an organisational capability.
What State and Federal Government requires from organisation
The NSW Government has established a clear model for responsible AI through its Artificial Intelligence Ethics Policy and AI Assessment Framework.
At the Commonwealth level, the Australian Government’s current approach continues to build on existing laws covering areas such as privacy, consumer protection, workplace relations, anti-discrimination, corporations, intellectual property, safety and cyber security. Its 2026 Guidance for AI Adoption establishes six essential practices:
Decide who is accountable.
Understand impacts and plan accordingly.
Measure and manage AI-specific risks.
Share essential information.
Test and monitor.
Maintain human control.
Organisations should also prepare for new automated decision-making transparency requirements. From 10 December 2026, relevant entities covered by the Australian Privacy Principles will need to include additional information in their privacy policies where personal information is used in automated decisions that could significantly affect an individual’s rights or interests.
The direction is clear: organisations will increasingly need evidence showing not only that they have an AI policy, but that they understand where AI is being used, who is accountable and how outcomes are monitored.
Start with a proportionate governance model
Responsible AI does not mean applying the same assessment to every use.
An employee using an approved AI tool to improve the wording of an internal communication does not require the same oversight as an AI system influencing recruitment, access to services, funding, safety, financial outcomes or customer rights.
A practical framework can classify AI into four levels.
LOW RISK
The output remains subject to human review and does not materially determine an outcome. Examples include drafting, summarising, brainstorming or analysing public and approved non-sensitive data.
MODERATE RISK
May involve confidential information or create operational dependence, but they do not independently determine a high-impact outcome. Examples include support internal analysis, workflow prioritisation, reporting or recommendations.
HIGH RISK
AI system that may materially influence decisions affecting an individual’s rights, employment, access to services, financial position, health, safety or wellbeing, or that uses personal or sensitive information. These systems require documented assessment, clear accountability, meaningful human oversight and ongoing monitoring before and throughout their use.
UNACCEPTABLE RISK
AI use that could cause serious harm, unlawfully discriminate, remove meaningful human control, breach fundamental rights or create risks that cannot be adequately mitigated, and therefore should not proceed. Examples could include fully automated high-impact decisions without meaningful human review, unlawful surveillance, unacceptable discrimination risk or the use of sensitive information without appropriate authority and safeguards. An organisation should not proceed where an AI use cannot be made lawful, safe, fair, transparent or adequately controlled.
The purpose of risk classification is not to prevent AI use. It is to apply the lightest effective governance appropriate to the risk.
Evolve.i Responsible AI Governance Framework
Download is a practical, role-based guide designed to help Boards, executives, leaders and teams introduce, manage and monitor AI responsibly while supporting productivity, innovation and organisational value.
What each role needs to do
Board
The Board does not need to approve every AI tool or operational experiment.
It should establish the organisation’s AI risk appetite, ethical expectations and boundaries for unacceptable use. Before high-impact AI is introduced, the Board or its delegated risk committee should understand:
how the initiative aligns with strategy
who could be affected
the expected organisational and community benefit
the principal risks and safeguards
who is accountable for the outcome
how meaningful human oversight will be maintained.
The Board should receive a concise quarterly dashboard covering high-risk AI systems, material incidents, performance, complaints, regulatory readiness, residual risks and decisions requiring escalation.
Chief Executive Officer
The CEO is accountable for ensuring that responsible AI is embedded across the organisation rather than delegated solely to technology.
The CEO should appoint an executive AI sponsor, approve the governance model, provide appropriate resources and establish the expectation that productivity and ethical responsibility must evolve together.
Monitoring should include the AI portfolio, high-risk approvals, exceptions, workforce impact, benefits realised, unapproved AI use and material incidents.
AI Governance Committee or Executive AI Sponsor
A small cross-functional AI Governance Committee can provide coordination without creating unnecessary bureaucracy.
It should include representation from business operations, technology, data, privacy, risk, legal, people and finance. Its responsibilities should include:
maintaining the AI register
confirming risk classifications
coordinating assessments
approving or escalating material uses
recording risk-treatment decisions
monitoring incidents and exceptions
ensuring reviews occur when a system, model, dataset or purpose changes.
Small organisations may assign these responsibilities to the CEO and nominated advisers rather than establishing a formal committee.
Chief Operating Officer or Transformation Lead
AI should be introduced through redesigned work, not added to an ineffective process.
The COO or transformation lead should assess how the end-to-end process, controls, handovers, service model and fallback arrangements will change.
Monitoring should cover cycle time, service quality, rework, adoption, customer impact, operating dependencies and whether the expected productivity improvements are genuinely being realised.
Chief Financial Officer
The CFO has a broader role than approving the technology budget.
Before AI is introduced, finance should validate the business case, total cost, procurement controls, financial delegation, value assumptions and potential reporting or fraud risks.
Monitoring should cover:
realised savings and productivity
ongoing licensing and implementation costs
duplicated or underutilised products
financial errors caused by AI outputs
return on investment
changes in workforce or operating costs
financial exposure arising from system failure.
The CFO can help ensure AI investment creates measurable organisational capacity rather than simply adding another subscription.
Chief People Officer
AI changes tasks, skills, roles and expectations. It is therefore a workforce matter as much as a technology matter.
The Chief People Officer should consider employee consultation, acceptable use, capability development, role redesign, fairness, psychological safety and the potential impact of AI on recruitment or performance decisions.
Monitoring should include training completion, confidence, adoption, workload, grievances, inclusion, changing skill needs and any unintended consequences for employees.
Employees should understand how AI will support their work, what remains their responsibility and when human judgement must override an AI-generated output.
Chief Technology Officer (CIO or CISO)
Technology and data leaders are responsible for ensuring that AI can operate securely, reliably and within the organisation’s architecture.
Their assessment should cover:
system integration
data quality and provenance
identity and access
privacy and cyber security
logging and traceability
model and vendor changes
resilience and business continuity
the security of connected organisational systems.
Monitoring should include access anomalies, data leakage, system performance, vendor incidents, model changes, security events and whether the system remains technically fit for its approved purpose.
The OAIC recommends that organisations avoid entering personal information, particularly sensitive information, into publicly available generative AI tools because of the associated privacy risks.
Legal, Risk and Compliance
These functions should identify which laws, contractual requirements and sector regulations apply to each use case.
They should determine whether the organisation requires a privacy impact assessment, legal review, specific disclosure, consent, record retention, complaint mechanism or regulatory notification process.
They should not become the team that simply says “no”. Their role is to help the organisation determine how a valuable use can proceed within an acceptable control environment.
Procurement and Vendor Management
Many AI risks enter the organisation through third-party products, including AI capabilities quietly added to existing software.
Procurement should consider:
how organisational data is used
whether inputs or outputs train vendor models
data hosting and retention
subcontractors
security and privacy controls
model changes
incident-notification timeframes
audit rights
service continuity
data extraction and exit arrangements.
Vendor assessment should occur at acquisition, renewal and whenever there is a material change to the product, model or terms.
Leadership and People Managers
Managers convert organisational policy into daily practice.
They should ensure employees use approved tools, understand data restrictions, review outputs and escalate unexpected behaviour.
They should also create space for employees to identify valuable AI opportunities. Responsible governance should make safe experimentation easier, not force innovation into unapproved or invisible channels.
Internal Audit and Independent Assurance
Internal audit should independently assess whether the governance system operates as intended.
A risk-based review may examine:
whether all material systems are registered
whether risk classifications are reasonable
whether approvals and assessments are current
whether human oversight actually occurs
whether monitoring information is reliable
whether vendor controls are evidenced
whether incidents and corrective actions are closed.
The frequency and depth of assurance should reflect the potential impact of the AI system.
All Staff, Contractors and Volunteers
Every user remains responsible for how they use AI.
At a minimum, people should:
use only approved tools
follow organisational data-handling requirements
verify outputs before relying on them
recognise that AI can be inaccurate or biased
disclose AI use where required
protect confidential and personal information
report concerning or unexpected outputs
never present an AI output as a substitute for their own accountability.
What should the organisation monitor?
An effective AI dashboard should measure both value and risk. For each material AI system, organisations should consider monitoring:
Business Value
time saved, cost avoided, service capacity, quality improvement, revenue impact and adoption
Accuracy and quality
error rates, rework, overrides, false positives, false negatives and output consistency
Fairness and people impact
complaints, accessibility, workforce impact, outcome differences and effects on vulnerable groups
Privacy and security
personal information use, access anomalies, data leakage, retention and cyber incidents
Human control
review completion, intervention time, override capability, traceability and appeal outcomes
Vendor and technology change
model versions, contract changes, availability, incidents and subcontractors
Compliance and assurance
current approvals, completed assessments, training, audit findings and overdue corrective actions
Monitoring frequency should reflect risk. Low-risk systems may be reviewed every six or twelve months, while high-impact systems may require monthly or continuous monitoring.
Governance should enable AI to evolve
The objective is not to remove every possible risk.
It is to make risk visible, assign ownership, maintain meaningful human control and use evidence to improve both organisational performance and stakeholder trust. AI governance is most effective when it is integrated into strategy, process design, workforce planning, procurement, technology, finance and risk management.
How Evolve.i Approaches Responsible AI Governance
Evolve.i approaches AI governance as an organisational design responsibility, not simply a technology, policy or compliance exercise.
Our Business-first approach emphasis begins by understanding the organisation’s strategy, operating model, processes, workforce capability, systems, data and existing governance environment. This allows AI opportunities to be assessed in the context of how the organisation actually operates and the outcomes it intends to achieve.
We belive that AI should not start with a tool. It should start with the business.
Evolve.i Responsible AI Governance Framework
Download is a practical, role-based guide designed to help Boards, executives, leaders and teams introduce, manage and monitor AI responsibly while supporting productivity, innovation and organisational value.
DISCLAIMER
This article and the accompanying framework provide general information to support organisational discussion and planning. They do not constitute legal, regulatory, privacy, cyber security, financial, employment or other professional advice.
The regulatory obligations applying to an organisation will depend on its sector, jurisdiction, activities, data, technology, contractual commitments and the way AI is being used. Organisations should obtain appropriate independent professional advice and review current government guidance before making material AI governance, compliance, procurement or implementation decisions.
Artificial intelligence technologies, regulatory expectations and government guidance continue to evolve. While reasonable care has been taken in preparing this material, Evolve.i does not guarantee that it is complete or suitable for every organisation or circumstance.
The responsibility for assessing, approving, implementing and monitoring any AI system remains with the organisation using that system.

