{
  "schema": "yarn-pack/2",
  "id": "framework-au",
  "version": "0.1.0",
  "name": "Australia: GfAA and the AI6 (framework self-assessment)",
  "engagement": "AISG — framework self-assessment: workshop prep, workshop, or diagnostic strand",
  "intro": "A guided conversation against Australia: GfAA and the AI6, not a form. Answer in your own words and name the document or record that shows it if you can. About 20 minutes. Assesses against the six AI6 practices in the Guidance for AI Adoption (Oct 2025) and the existing Australian laws that already catch AI use. Does not assess against announced but uncommenced AI legislation.",
  "tone_default": "professional",
  "prefill_fields": {
    "department": [
      "Executive",
      "Finance",
      "Operations",
      "Customer / Sales",
      "Technology / IT",
      "Data & Analytics",
      "People & Culture",
      "Risk & Compliance",
      "Marketing",
      "Product"
    ]
  },
  "scales": [
    {
      "id": "maturity5",
      "name": "Maturity (distilled model)",
      "levels": [
        {
          "value": 1,
          "label": "Does not exist",
          "gloss": "No capability. Absent, or purely ad hoc / accidental."
        },
        {
          "value": 2,
          "label": "Partially exists",
          "gloss": "Emerging and inconsistent. Pockets of activity, not joined up."
        },
        {
          "value": 3,
          "label": "Fully exists",
          "gloss": "Defined, documented and operating across the organisation."
        },
        {
          "value": 4,
          "label": "Fully exists & optimised",
          "gloss": "Measured, refined and improving against targets."
        },
        {
          "value": 5,
          "label": "Fully exists & adaptive",
          "gloss": "Continuously self-adjusting; a source of advantage."
        }
      ],
      "signals": {
        "1": [
          "no ",
          "not ",
          "none",
          "never",
          "don't",
          "do not",
          "nothing",
          "absent",
          "unaware",
          "haven't",
          "ad hoc",
          "ad-hoc",
          "nonexistent",
          "no idea",
          "not really"
        ],
        "2": [
          "some ",
          "starting",
          "beginning",
          "emerging",
          "pilot",
          "trial",
          "informal",
          "inconsistent",
          "pockets",
          "a bit",
          "occasionally",
          "early",
          "experiment",
          "trying",
          "patchy"
        ],
        "3": [
          "documented",
          "defined",
          "standard",
          "standardised",
          "established",
          "policy",
          "framework",
          "process",
          "consistent",
          "across the",
          "in place",
          "formal",
          "governed",
          "rolled out"
        ],
        "4": [
          "measured",
          "metrics",
          "optimis",
          "improving",
          "kpi",
          "monitored",
          "reviewed",
          "refined",
          "benchmarked",
          "targets",
          "tracked",
          "mature",
          "regularly review"
        ],
        "5": [
          "continuous",
          "adaptive",
          "self-",
          "automated end",
          "best in class",
          "best-in-class",
          "competitive advantage",
          "industry leading",
          "always",
          "real-time monitoring",
          "feedback loop"
        ]
      }
    }
  ],
  "categories": [
    {
      "id": "govern",
      "name": "Accountability, impacts and risk",
      "order": 1,
      "target_default": 3
    },
    {
      "id": "operate",
      "name": "Transparency, testing and control",
      "order": 2,
      "target_default": 3
    },
    {
      "id": "law",
      "name": "Existing law that already bites",
      "order": 3,
      "target_default": 3
    }
  ],
  "audiences": [
    {
      "id": "lead",
      "name": "Governance / risk lead",
      "desc": "Owns the policy, the register or the risk framework",
      "deep_dive_sections": []
    },
    {
      "id": "owner",
      "name": "System or use-case owner",
      "desc": "Runs an AI system or use case day to day",
      "deep_dive_sections": []
    },
    {
      "id": "exec",
      "name": "Executive / sponsor",
      "desc": "Accountable for the outcome, not the mechanics",
      "deep_dive_sections": []
    }
  ],
  "sections": [
    {
      "id": "core",
      "title": "AI6 elements",
      "blurb": "Everyone answers these. The accountable executive for AI, the governance or risk lead, the privacy officer and whoever owns testing and monitoring; a board or audit committee member for the directors’ duties element.",
      "optional": false,
      "questions": [
        {
          "id": "ai6-1",
          "type": "scored_text",
          "category": "govern",
          "name": "Decide who is accountable",
          "text": "If one of your AI tools produced a bad outcome tomorrow, who would be expected to answer for it, and do they know that?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No named owner for AI. Accountability sits nowhere, or with ‘IT’ in general, and the board has not been told it carries AI risk.",
            "3": "A named accountable executive for AI exists, each AI system in use has a named owner, and the board has accepted accountability for AI risk on the record.",
            "5": "Ownership updates as systems, roles and the law change; the board reviews AI accountability on a set cadence and assignments are re-confirmed without prompting."
          },
          "help": "Evidence that would show it: Named accountable executive for AI in a policy or charter; Owner recorded per AI system in the use case register; Board or committee minute accepting AI risk accountability; RACI for AI decisions across the lifecycle.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "ai6-2",
          "type": "scored_text",
          "category": "govern",
          "name": "Understand impacts and plan accordingly",
          "text": "Pick one AI system you rely on. Before it went live, who worked out who it could affect and what could go wrong for them, and where is that written down?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "AI is deployed without anyone having asked who it affects or how; no impact assessment exists for any system.",
            "3": "Every AI use case has a documented impact assessment covering the people affected, completed before deployment and revisited when the use changes.",
            "5": "Impact assessments re-run on a trigger (model change, new data, new user group) and their findings feed the risk register and the design without being chased."
          },
          "help": "Evidence that would show it: Completed impact assessment per use case; Intake form capturing purpose, owner, data and affected groups; Stage-gate record showing the impact assessment preceded go-live; Workforce consultation record for AI affecting staff.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "ai6-3",
          "type": "scored_text",
          "category": "govern",
          "name": "Measure and manage risks",
          "text": "How do you tell which of your AI uses are the risky ones, and what happens differently for those?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "AI risks are not identified or recorded anywhere; nothing distinguishes a low-stakes tool from one making decisions about people.",
            "3": "AI risks are tiered with a documented method, recorded in a live register with owners and treatments, and the residual rating is reviewed on a cadence.",
            "5": "Risk ratings change as monitoring data and incidents arrive; new use cases are tiered on intake and controls are adjusted without a special exercise."
          },
          "help": "Evidence that would show it: Use case risk classification method; AI risk register with owners, treatment and residual rating; Controls mapped to risks with a verification mechanism; Risk appetite statement covering AI.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "ai6-4",
          "type": "scored_text",
          "category": "operate",
          "name": "Share information",
          "text": "If a customer asked whether AI was involved in a decision about them, what would they be told, by whom, and where would they find it themselves?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Nobody outside the project team knows where AI is in use; customers and staff are not told when AI is involved in decisions or interactions.",
            "3": "A documented approach to disclosing AI use to customers, staff and the public is applied; each live use case has a plain statement of what it does and its limits.",
            "5": "Disclosures update as the use case register changes; affected people can find out what AI touched them and raise a query through a channel that answers."
          },
          "help": "Evidence that would show it: Disclosure and transparency mechanism; Model card or equivalent per use case; Staff-facing acceptable use guidelines; Public AI position statement.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "ai6-5",
          "type": "scored_text",
          "category": "operate",
          "name": "Test and monitor",
          "text": "Show me the last time you checked that one of your AI systems was still behaving. What did you look at, and what would have happened if it wasn’t?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Systems go live without recorded testing; nothing is monitored after deployment and there is no evidence that any AI6 practice is operating.",
            "3": "Test results are recorded per system before go-live, live systems are monitored against set measures, and an assurance schedule and evidence log show the controls run.",
            "5": "Monitoring thresholds trigger review or rollback on their own; the assurance cadence covers every AI6 practice and its findings change the controls."
          },
          "help": "Evidence that would show it: Assurance schedule for AI; Verification log or evidence register showing controls operating; Monitoring output for a live system; Independent challenge or audit report on AI.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "ai6-6",
          "type": "scored_text",
          "category": "operate",
          "name": "Maintain human control",
          "text": "For your highest-stakes AI use, who can stop it today, how would they know they needed to, and have they ever had to?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No one has decided where a human sits in any AI-driven process; systems cannot be paused or overridden by the people who rely on them.",
            "3": "Each use case has a documented human oversight decision with rationale, named people who can intervene, override or stop the system, and a working way to do it.",
            "5": "Oversight levels are revisited as risk ratings or monitoring results change; interventions are logged and reviewed, and the loop tightens without being asked."
          },
          "help": "Evidence that would show it: Human oversight model per use case with rationale; Named intervention or override authority per system; Incident response SOP with stop and escalation steps; Log of human overrides or interventions.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "law-privacy",
          "type": "scored_text",
          "category": "law",
          "name": "Privacy Act: ADM transparency (10 Dec 2026)",
          "text": "Which of your systems make or shape decisions about individuals without a person in the middle, and does your privacy policy say so yet?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No one has listed where AI touches personal information; the privacy policy is silent on automated decisions and there is no plan for 10 Dec 2026.",
            "3": "AI uses of personal information are inventoried; automated decisions significantly affecting individuals are listed and the privacy policy discloses them by 10 Dec 2026.",
            "5": "New or changed AI uses of personal information update the inventory and the privacy policy disclosure as part of intake, with the privacy officer signing off each time."
          },
          "help": "Evidence that would show it: Inventory of AI uses of personal information; Privacy policy with the ADM disclosure ready for 10 Dec 2026; Use case register flagging automated decisions about individuals; Human oversight decision for each automated decision.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "law-consumer",
          "type": "scored_text",
          "category": "law",
          "name": "Australian Consumer Law: claims and outputs",
          "text": "What does your AI tell your customers, who checks that it is true, and what happens when it gets something wrong?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No one reviews what is claimed about the organisation’s AI or what customer-facing AI tells people; outputs go to consumers unchecked.",
            "3": "Claims about AI products and capabilities are reviewed before release; customer-facing AI outputs are tested for accuracy and a route exists to correct and remedy errors.",
            "5": "Consumer-facing AI outputs are monitored for misleading content and corrections propagate to every system grounded on them; complaint data feeds back into testing."
          },
          "help": "Evidence that would show it: Review record for AI-related marketing and product claims; Test results for accuracy of customer-facing AI output; Withdrawal or correction process for AI content; Complaint or remedy log for AI outputs.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "law-discrim",
          "type": "scored_text",
          "category": "law",
          "name": "Anti-discrimination law: biased outcomes",
          "text": "Where does AI touch who gets hired, promoted, served or refused, and how would you know if it was treating one group worse than another?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "AI is used in hiring, promotion or service decisions with no check for biased outcomes and no way to show who was affected.",
            "3": "AI used in employment or service decisions is identified, tested for biased outcomes before use and monitored after, with results recorded and an owner for each system.",
            "5": "Fairness measures are monitored continuously with thresholds that trigger review; affected groups are re-examined whenever the data or the model changes."
          },
          "help": "Evidence that would show it: Register of AI used in employment or service decisions; Bias test results before deployment and from monitoring; Impact assessment covering affected groups; Workforce consultation record for AI affecting staff.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "law-directors",
          "type": "scored_text",
          "category": "law",
          "name": "Directors’ duties and sector regulators",
          "text": "When did your board last see AI risk on its agenda, what did it see, and which regulators do you think would care about how you use AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "The board has not been briefed on AI risk; no one has mapped which regulators’ existing expectations reach the organisation’s AI use.",
            "3": "A defined reporting line takes AI risk to the board or audit committee on a set cadence; applicable regulators and their expectations are mapped and have an owner.",
            "5": "Board reporting changes with the risk profile and regulator activity; regulatory changes are picked up and assigned on arrival, and the board asks for evidence itself."
          },
          "help": "Evidence that would show it: Board or audit committee AI risk paper and minutes; Regulator obligation map with owners; Board reporting cadence and content definition; AI risk appetite statement endorsed by the board.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        }
      ]
    }
  ],
  "grids": {},
  "outputs": [
    "Level per element and per category, gated",
    "Contested-element view (spread of 2 or more)",
    "Coverage of evidence: confirmed, stated, inferred",
    "Where to start, foundations first",
    "Printable client report"
  ],
  "report_defaults": [
    "rpt-maturity-standard"
  ],
  "playbook": {
    "sequence": [
      "govern",
      "law",
      "operate"
    ],
    "sequence_note": "Foundations first: name the owner and build the register, then meet the dated December obligations, then make testing and monitoring an audit cadence with evidence. Anchor on AI6, deliver on 42001.",
    "actions": {
      "govern": {
        "to_3": [
          "Name an accountable executive for AI and an owner per system",
          "Build the AI use case register",
          "Complete an impact assessment for each live use case",
          "Tier use cases by risk and stand up the AI risk register"
        ],
        "to_5": [
          "Re-run impact assessments and risk ratings on model, data or user-group change triggers",
          "Put AI accountability and risk on the board agenda on a set cadence"
        ]
      },
      "law": {
        "to_3": [
          "Disclose automated decisions in the privacy policy before 10 Dec 2026",
          "Map applicable regulators and their expectations, with an owner",
          "Brief the board on AI risk and set a reporting line and cadence"
        ],
        "to_5": [
          "Pick up regulatory changes on arrival and assign them; do not build against uncommenced AI law"
        ]
      },
      "operate": {
        "to_3": [
          "Tell staff and customers where AI is used",
          "Record pre-deployment testing and monitor live systems against defined measures",
          "Document human oversight per use case with a working override route"
        ],
        "to_5": [
          "Turn Practice 5 into an audit cadence with evidence covering all six practices",
          "Let monitoring thresholds trigger review or rollback"
        ]
      }
    }
  }
}