Australia AI Ethics Framework
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AI Ethics Principles
AI systems should benefit individuals, society and the environment. Positive and negative impacts on individual, social and environmental wellbeing should be accounted for throughout the AI system lifecycle, including impacts outside the organisation.
- Assessment of individual/social/environmental impacts across the lifecycle
- Evidence of accounting for impacts beyond the organisation
- Decision records weighing benefit vs harm
- Wellbeing impacts not assessed
- Only internal/business impacts considered
- Environmental impact ignored
AI systems should respect human rights, diversity and the autonomy of individuals throughout their lifecycle, augmenting rather than undermining human control, and avoiding deception, unfair manipulation or unjustified surveillance.
- Human-rights risk assessment
- Evidence individuals retain effective control
- Diverse, multidisciplinary design input
- Human-rights risks unassessed
- AI undermines autonomy or uses manipulation/surveillance
- Homogeneous design team missing key perspectives
AI systems should be inclusive and accessible and should not involve or result in unfair discrimination against individuals, communities or groups, with measures to comply with anti-discrimination laws.
- Fairness/discrimination assessment across the lifecycle
- Stakeholder consultation incl. vulnerable/underrepresented groups
- Evidence of compliance with anti-discrimination law
- No fairness assessment
- Disparate impact on vulnerable groups unaddressed
- Accessibility/inclusion not considered
AI systems should respect and uphold privacy rights and data protection and ensure the security of data, with proper data governance, anomalisation where appropriate, and resilience to adversarial attacks and abuse.
- Data governance for all data used/generated by the AI
- Privacy measures (e.g. anonymisation) and ongoing assessment of inferences
- Security vulnerability identification and adversarial-attack resilience
- No data governance for AI data
- Inferences from data not reassessed
- Adversarial/abuse risks not mitigated
AI systems should reliably operate in accordance with their intended purpose, be accurate and reproducible as appropriate, pose no unreasonable safety risk, and be monitored and tested with ongoing risk management.
- Reliability/accuracy/reproducibility testing
- Proportionate safety measures
- Ongoing monitoring, testing and risk management with assigned responsibility
- Reliability not tested
- Safety risks not proportionate or unmanaged
- No ongoing monitoring of intended purpose
There should be transparency and responsible disclosure so people can understand when they are significantly impacted by AI and can find out when an AI system is engaging with them, with timely, reasonable justifications for outcomes.
- Responsible disclosure that AI is in use
- Explanations of key factors in decisions suited to each stakeholder
- Timely justification of outcomes
- AI engagement not disclosed
- No explanation of significant decisions
- Disclosure not timely or meaningful
When an AI system significantly impacts a person, community, group or environment, there should be a timely, accessible process to allow people to challenge the use or outcomes of the AI system, with human oversight where rights are affected.
- Accessible challenge/redress mechanism
- Defined threshold for significant impact
- Human oversight for decisions significantly affecting rights
- No way to challenge AI use or outcomes
- Significant-impact threshold undefined
- No human oversight of consequential decisions
People responsible for the different phases of the AI system lifecycle should be identifiable and accountable for outcomes, with mechanisms ensuring responsibility and appropriate human control or oversight before and after deployment.
- Identifiable accountable owners for each lifecycle phase
- Mechanisms ensuring responsibility for outcomes
- Appropriate level of human control/oversight defined per use case
- No identifiable accountable owner
- Accountability undefined after deployment
- Human oversight level not determined
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia AI Ethics Framework framework page.