| Software vendor whose product now includes an AI feature, bidding to a bank or insurer | Each security review asks new AI questions, answered from scratch by whoever is free | One current register, impact assessments and control set the sales team can draw on | Enterprise buyers increasingly bolt AI questions onto their existing vendor security review, so the questions arrive through procurement rather than a formal standard. Having the evidence ready shortens the review, and that is usually worth more than the certificate itself. |
| Professional services firm on a government panel using AI to draft client work | AI use is informal, undocumented, and nobody is sure what the contract allows | Documented scope of permitted use, named owners, and records of human review | Australian government buyers increasingly ask suppliers how AI is used on their work and whether outputs are checked by a person. The answer that survives scrutiny is a documented process with sampling evidence, not a verbal assurance from the partner. |
| Health or allied health provider trialling AI scribes and triage assistants | A clinician-led trial spreads across the practice with no formal assessment | Impact assessment per system, consent and retention settled, clinical oversight recorded | Health data raises the stakes under the Privacy Act and the Australian Privacy Principles, and patient-facing AI needs a clear answer on what happens when it is wrong. The impact assessment is worth doing before the trial spreads. Clinical judgement stays with your practitioners, and the standard only asks you to show how it is exercised and recorded. |
| Recruitment or HR team using automated screening and ranking | A vendor tool scores candidates and nobody can explain how or audit the outcome | Documented purpose, fairness checks, human decision point, and a review path for candidates | Decisions about people carry the highest impact assessment burden in the standard, and Fair Work and discrimination exposure sits behind them. The control that matters most is the recorded human decision, not the model documentation the vendor supplies. |
| NDIS or aged care provider adding AI to rostering, notes and client communication | AI creeps in through the software the organisation already uses, unregistered | Vendor-embedded AI captured at contract renewal and assessed like anything else | Providers in regulated care are asked to show governance over anything touching participant outcomes. The vendor-embedded case is the one that catches people out, because the AI arrived in a product update rather than a purchase decision. |
| Business already certified to ISO 27001, now asked about AI governance | A separate parallel program is proposed, doubling the audit and document burden | One integrated management system, one internal audit program, one management review | The clause structure is shared, so the context, leadership, competence, internal audit and improvement work is largely reusable. Bringing both standards to the same certification body for an integrated audit generally takes less audit time than running two separate programs, though the body sets its own audit duration. |