Australia - New South Wales - AI Assurance Framework (2022)

New South Wales AI Assurance Framework

Australia

RAI-AU-NS-NSWAAXX-2022
Effective: March 31, 2022
In Force(In Force)
PolicyGovernance and OversightRisk ManagementTransparency and Disclosure
Export PDF

The NSW AI Assurance Framework, updated in 2024, guides government agencies in ethical AI use, managing risks, and building public trust.

Overview

The New South Wales (NSW) AI Assurance Framework stands as a landmark initiative, having been initially mandated in March 2022 as the world's first government-led framework of its kind to ensure the responsible use of Artificial Intelligence (AI) systems. Developed as a cornerstone of the NSW AI Strategy and in conjunction with the NSW AI Ethics Policy, its primary purpose is to guide government agencies in the ethical design, development, deployment, procurement, and ongoing operation of AI technologies. The framework emerged from a recognition of AI's transformative potential for public services, alongside the imperative to manage associated risks such as bias, privacy concerns, and accountability gaps. It provides a systematic and comprehensive methodology for identifying, documenting, and mitigating AI-specific risks throughout the entire lifecycle of an AI solution, thereby fostering public trust and ensuring that AI deployments align with community values and expectations.

In response to the rapid evolution of AI technology, including the emergence of Generative AI, the NSW AI Assurance Framework underwent significant updates and was re-released in May 2024 as the "AI Assessment Framework." This updated iteration has been integrated into the broader NSW Digital Assurance Framework, streamlining the assessment and oversight of AI components within all government digital projects, particularly those exceeding $5 million in budget or funded by the Digital Restart Fund. The evolution reflects NSW Government's commitment to maintaining its leadership in safe and responsible AI use, providing enhanced risk management guidance and tools to address new and emerging challenges while continuing to promote innovation. The framework remains mandatory for all NSW Government agencies, underscoring its critical role in upholding ethical standards and ensuring beneficial outcomes for the citizens of NSW.

Definitions

To ensure clarity and consistent application across all NSW Government agencies, the framework relies on a set of defined terms. At its core, "Artificial Intelligence (AI)" is understood as intelligent technology, programs, and the application of advanced computing algorithms capable of augmenting decision-making by identifying meaningful patterns within data. This broad definition encompasses various forms of AI, from custom-built systems to those developed using generic AI platforms, and applies to both customisable and off-the-shelf AI components. The "NSW AI Assurance Framework," the original document mandated in March 2022, served as a foundational self-assessment tool. It provided a structured set of questions and guidelines to help project teams rigorously analyse and document AI-specific risks, implement mitigation strategies, and establish clear governance and accountability measures for their projects.

The framework has since evolved into the "AI Assessment Framework," an updated and enhanced version released in May 2024. This iteration builds upon the original principles, offering improved risk management guidance and tooling, specifically tailored to address the complexities introduced by advancements in AI technology, such as Generative AI. Central to both iterations are the "NSW AI Ethics Principles," a mandatory set of guidelines that underpin all AI initiatives within the NSW Government. These principles are designed to ensure trustworthy AI by promoting responsible stewardship, respecting human rights, and upholding democratic values. Oversight is provided by the "NSW AI Review Committee (AIRC)," an independent body tasked with guiding and reviewing AI projects, particularly those identified as having high or critical residual risk, to ensure their compliance with the framework and ethical standards. Finally, the "Digital Assurance Framework (DAF)" represents the overarching governance structure for all significant ICT and digital projects within the NSW Government, into which the AI Assessment Framework has been integrated to provide a unified approach to assurance.

Governance and Institutional Framework

The governance structure for AI within the NSW Government is multi-layered, designed to ensure robust oversight and accountability. A key component is the NSW AI Review Committee (AIRC), which plays a pivotal role in guiding and overseeing the use of AI. This committee, described as the first of its kind in Australia, was instrumental in the development of the original AI Assurance Framework and continues to be central to building community trust in government AI initiatives. The AIRC is responsible for reviewing AI projects, especially those with budgets exceeding $5 million or those supported by the Digital Restart Fund, to ensure compliance with the framework and alignment with NSW AI governance requirements. Projects with high or critical residual risks, even after mitigation efforts, must be submitted to the AI Secretariat for AIRC review, ensuring an additional layer of scrutiny for potentially impactful AI systems.

The framework itself is mandatory for all NSW Government agencies, signifying a whole-of-government commitment to responsible AI. This mandate ensures that the principles and practices outlined in the framework are consistently applied across the public sector, from the initial design phase through to deployment and ongoing operation of AI systems. The integration of the AI Assessment Framework into the broader Digital Assurance Framework (DAF) further embeds AI governance within existing project delivery and oversight mechanisms. This ensures that AI-enabled projects are not treated in isolation but are subject to the same rigorous assurance processes as other significant digital initiatives, fostering a cohesive and comprehensive approach to digital and AI governance across the NSW Government. Agencies are explicitly responsible for ensuring appropriate governance and assurance oversight for AI use across its entire lifecycle, reinforcing a culture of accountability at all levels.

Key Focus Areas

The NSW AI Assurance Framework, and its successor, the AI Assessment Framework, are built upon several key focus areas designed to ensure the responsible and ethical deployment of AI within government operations. A paramount focus is on ethical considerations, with the framework explicitly aligning with the mandatory NSW AI Ethics Principles. These principles serve as the bedrock for all AI initiatives, ensuring that AI systems are developed and used in a manner that respects human rights, promotes fairness, and upholds democratic values. The framework guides agencies to consider the ethical implications at every stage of an AI project, from data collection and algorithm design to deployment and monitoring, thereby embedding ethics-by-design into the government's approach to AI.

Another critical area is comprehensive risk management. The framework provides a structured methodology for identifying, evaluating, and mitigating potential risks associated with AI systems. This includes assessing risks of harm, bias magnification, privacy breaches, and security vulnerabilities. Agencies are required to undertake thorough risk assessments, document these risks, and implement robust mitigation strategies. The framework also delineates a process for escalating risks, particularly for systems with high or critical residual risk, to the NSW AI Review Committee for further scrutiny and guidance. Furthermore, transparency, privacy, security, and accountability are central tenets. The framework mandates strong privacy and data management safeguards, ensuring that personal data is handled responsibly. It also promotes transparency in AI operations, aiming to build public confidence by clarifying how AI systems are designed, used, and the decisions they influence. Clear accountability measures for the design and use of AI systems are established, ensuring that responsibilities are well-defined throughout the AI lifecycle.

Implementation Framework

The implementation of the NSW AI Assurance Framework, now the AI Assessment Framework, is designed to be practical and integrated into the daily operations of NSW Government agencies. It functions primarily as a self-assessment tool, guiding project teams and solution owners through a series of questions that must be answered at every stage of an AI project, from conception to operation. This systematic approach ensures that ethical and risk considerations are addressed proactively and continuously. The framework is applicable to a wide range of AI systems, including custom AI, customisable AI, and projects utilising generic AI platforms, ensuring comprehensive coverage across the government's diverse technological landscape. Agencies are required to apply the framework before deploying any AI system and to conduct pilots prior to scaling, allowing for early identification and resolution of issues.

To facilitate its application, Digital NSW provides an Excel-based version of the AI Assessment Framework, which serves as the current official tool for agencies to complete their AI risk assessments. This accessible format helps manage AI risk consistently across various projects and departments. For projects with budgets exceeding $5 million or those funded through the Digital Restart Fund, additional central oversight is provided under the broader Digital Assurance Framework to confirm compliance with the AI Assessment Framework and alignment with NSW AI governance requirements. Moreover, systems identified with high or critical residual risk, even after internal mitigation efforts, must be submitted to the AI Secretariat for review by the NSW AI Review Committee (AIRC). This tiered approach ensures that while agencies are empowered to manage lower-risk AI deployments, significant or high-risk initiatives receive expert scrutiny, reinforcing the government's commitment to safe and responsible AI use. Digital NSW is also actively working on a system-based version of the AIAF to further streamline the assessment and assurance process, indicating a commitment to continuous improvement in implementation.

Monitoring and Evaluation

The NSW AI Assurance Framework incorporates mechanisms for both the ongoing monitoring of AI systems and the periodic evaluation of the framework itself to ensure its continued effectiveness and relevance. Agencies are mandated to apply the framework not only before deploying an AI system but also after deployment to ensure appropriate monitoring of its performance and adherence to ethical guidelines. This continuous monitoring throughout the operational life of an AI system is crucial for detecting unintended consequences, biases, or performance degradations that may emerge over time. The framework's self-assessment nature encourages agencies to regularly review their AI solutions against the established principles and controls, fostering a proactive approach to risk management and ethical compliance. The aim is to ensure that AI systems continue to operate as expected, delivering intended benefits without causing unforeseen harm.

Beyond individual AI projects, the AI Assessment Framework itself is subject to regular review and updates. This commitment to continuous improvement ensures that the framework remains responsive to the rapid advancements in AI technology, strengthens risk management practices, and aligns with evolving national and international standards. The Department of Customer Service, through Digital NSW, actively works with government departments to make AIAF compliance easier to assess and track, which helps identify areas needing additional support and strengthens overall assurance for safe and responsible AI use. This iterative process of review and enhancement is vital for maintaining the framework's utility and ensuring that NSW Government remains at the forefront of responsible AI governance, capable of addressing new and emerging risks, such as those posed by generative AI, while supporting innovation.

Penalties, Liability, and Appeals

The New South Wales AI Assurance Framework, as a policy and guidance framework, primarily focuses on establishing best practices, ethical principles, and risk management methodologies rather than prescribing direct penalties, specific liability regimes, or formal appeal processes within the framework itself. Its strength lies in its mandatory application across NSW Government agencies, meaning that compliance with its principles and assessment requirements is an obligation for any agency deploying or procuring AI systems. The framework aims to prevent adverse outcomes through rigorous upfront assessment and continuous monitoring, thereby reducing the likelihood of issues that might necessitate penalties or liability claims. It functions as a preventative and proactive mechanism, embedding responsible AI practices from the outset of a project.

While the framework does not outline specific fines or sanctions, non-compliance by agencies would typically fall under broader government accountability mechanisms, public service codes of conduct, and existing legislative frameworks governing data privacy, administrative law, and public sector operations. For instance, failures in data protection or ethical breaches could lead to investigations by relevant oversight bodies, reputational damage, or legal action under existing privacy or anti-discrimination laws. For projects identified with high or critical residual risk, the mandatory review by the NSW AI Review Committee (AIRC) serves as a critical control point. Should the AIRC identify significant unmitigated risks or non-compliance, it can recommend project modifications, halting deployment, or other corrective actions, effectively providing a mechanism for internal accountability and redress before external issues arise. The emphasis is on proactive risk mitigation and strong governance to ensure that AI systems are used safely and responsibly, thereby avoiding the need for punitive measures.

Relationship to Other Instruments

The NSW AI Assurance Framework is not a standalone document but is intricately linked to a broader ecosystem of policies and strategies, both within New South Wales and at the national and international levels. It was developed as an integral part of the NSW AI Strategy and is underpinned by the NSW AI Ethics Policy, which sets out the mandatory ethical principles for all AI projects within the NSW Government. These foundational documents provide the strategic direction and ethical mandate that the Assurance Framework translates into practical implementation guidelines. The framework ensures that the high-level aspirations of the AI Strategy and the ethical imperatives of the AI Ethics Policy are operationalised through concrete assessment and risk management processes, making them actionable for agencies.

Furthermore, the framework's evolution into the AI Assessment Framework saw its integration into the NSW Digital Assurance Framework (DAF). This integration signifies a strategic move to embed AI governance within the existing, comprehensive assurance processes for all significant ICT and digital projects across the NSW Government. This ensures consistency and avoids parallel, potentially conflicting, assurance pathways. At a national level, the NSW framework is consistent with Australia's AI Ethics Principles, which were first published in 2019 by CSIRO's Data61 and the Department of Industry, Science and Resources (DISR). These national principles inform the assurance practices found in the NSW framework, demonstrating a commitment to a harmonised approach to trustworthy AI across Australian jurisdictions. The framework also aligns with the broader work on safe and responsible AI being undertaken by the Australian Government and reflects the OECD principles for responsible stewardship of trustworthy AI, which Australia committed to in 2019. This layered relationship ensures that NSW's approach to AI governance is robust, coherent, and aligned with best practices at multiple levels of government and international standards.

International Alignment

The New South Wales AI Assurance Framework demonstrates a strong commitment to international best practices and ethical standards in the development and deployment of Artificial Intelligence. A significant aspect of its international alignment stems from its consistency with Australia's AI Ethics Principles. These national principles, developed by CSIRO's Data61 and the Department of Industry, Science and Resources (DISR) and first published in 2019, define the ethical considerations that inform the assurance practices within the NSW framework. By adhering to these national principles, the NSW framework inherently aligns with a broader Australian commitment to fostering innovation and trust in AI, while ensuring respect for human rights and democratic values. This consistency provides a unified ethical foundation that resonates with global discussions on responsible AI.

Moreover, the NSW AI Assurance Framework is explicitly aligned with the Organisation for Economic Co-operation and Development (OECD) principles for the responsible stewardship of trustworthy AI. The Australian Government committed to these OECD principles when they were first published in 2019, signifying a national endorsement of their importance. By building upon these internationally recognised principles, the NSW framework ensures that its approach to AI governance is not only locally relevant but also globally informed. This alignment helps position NSW as a leader in safe and responsible AI, contributing to cross-border cooperation and the potential for mutual recognition of AI governance standards. The framework's design, which focuses on ethical use, risk management, transparency, and accountability, reflects the core tenets promoted by leading international bodies, underscoring NSW's dedication to contributing to a global ecosystem of trustworthy AI.

Implementation Timeline

MilestoneDateNotes
Work on the Framework began2021-04-01Initiated by the NSW AI Advisory Committee.
NSW AI Assurance Framework mandated and came into effect2022-03-31First mandated AI assurance framework for government globally.
Release of updated AI Assessment Framework (integrated into Digital Assurance Framework)2024-05-01Enhanced to address new and emerging risks, including Generative AI.
Implementation of updated frameworks across NSW Government agenciesQ3 2024Streamlining AI risk management and offering better oversight.
Regular review and updates to the AI Assessment FrameworkOngoingEnsures reflection of AI advancements and evolving standards.

Compliance Checklist

CheckRequired Action
AI Ethics Principles AlignmentEnsure the AI system's design, development, and operation adhere to the mandatory NSW AI Ethics Principles.
Risk Assessment CompletionComplete the AI Assessment Framework (AIAF) self-assessment to identify, document, and evaluate AI-specific risks.
Risk Mitigation StrategyImplement robust strategies and controls to mitigate identified AI risks throughout the system's lifecycle.
Privacy and Data ManagementVerify that strong privacy and data management safeguards are in place for all data used by the AI system.
Transparency and ExplainabilityEnsure appropriate levels of transparency regarding the AI system's purpose, operation, and decision-making processes.
Accountability MeasuresEstablish clear roles, responsibilities, and accountability for the design, deployment, and use of the AI system.
AIRC Review for High RiskSubmit systems with high or critical residual risk (after mitigation) to the NSW AI Review Committee (AIRC) for review.
Integration with DAFFor projects over $5 million or Digital Restart Fund-backed, ensure compliance is confirmed under the Digital Assurance Framework (DAF).
Pilot and ScalingConduct pilots for all AI systems before scaling up deployment.
Continuous MonitoringImplement ongoing monitoring of the AI system's performance and ethical compliance post-deployment.

Sources and References

SourceType
NSW Artificial Intelligence Assessment Framework | Digital NSWGovernment
National framework for the assurance of artificial intelligence in government - Department of FinanceGovernment
Artificial intelligence assurance framework | NSW GovernmentGovernment
Plain English

The New South Wales AI Assurance Framework is a mandatory policy guiding all NSW Government agencies on the ethical and responsible use of Artificial Intelligence, aiming to build public trust and manage risks.

This framework applies to all NSW Government agencies, regardless of the size or type of AI system they develop, procure, or deploy. This includes custom-built AI, off-the-shelf solutions, and those using generic AI platforms. Initially mandated in March 2022, the framework was significantly updated in May 2024 as the "AI Assessment Framework" and is being implemented across agencies starting in Q3 2024.

Agencies must adhere to several key obligations. First, all AI systems must align with the mandatory NSW AI Ethics Principles, ensuring fairness, human rights, and democratic values are upheld. Second, agencies are required to conduct thorough risk assessments using the provided AI Assessment Framework tool, identifying and mitigating potential harms like bias, privacy breaches, and security vulnerabilities throughout the AI system's lifecycle. Third, strong measures for privacy, transparency, and accountability must be in place, clearly defining who is responsible for the AI system's design and operation. Finally, any AI project identified with high or critical residual risks, even after internal mitigation, must be submitted to the independent NSW AI Review Committee (AIRC) for additional scrutiny.

The framework itself does not impose direct fines or penalties. Instead, non-compliance would fall under broader government accountability mechanisms, existing laws (such as privacy or anti-discrimination legislation), and public service codes of conduct. The AIRC has the power to recommend modifications or even halt the deployment of high-risk projects. A practical pitfall for agencies is the continuous nature of compliance; the framework requires ongoing monitoring of AI systems post-deployment to ensure continued ethical operation and performance, not just a one-time check.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Australia - New South Wales - AI Assurance Framework (2022). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasBefore placing on market

    Applies to: All NSW Government agencies developing or deploying AI systems.

    The framework explicitly aligning with the mandatory NSW AI Ethics Principles.
  2. #2CriticalImplementation FrameworkBefore deploying any AI system

    Applies to: All NSW Government agencies developing or deploying AI systems.

    Agencies are required to apply the framework before deploying any AI system
  3. #3CriticalKey Focus AreasBefore placing on market

    Applies to: All NSW Government agencies developing or deploying AI systems.

    Agencies are required to undertake thorough risk assessments, document these risks, and implement robust mitigation strategies.
  4. #4CriticalKey Focus AreasBefore placing on market

    Applies to: All NSW Government agencies developing or deploying AI systems.

    The framework mandates strong privacy and data management safeguards, ensuring that personal data is handled responsibly.
  5. #5CriticalGovernance and Institutional FrameworkBefore deployment

    Applies to: NSW Government agencies with high or critical residual risk AI systems.

    Projects with high or critical residual risks... must be submitted to the AI Secretariat for AIRC review
  6. #6ImportantKey Focus AreasBefore placing on market

    Applies to: All NSW Government agencies developing or deploying AI systems.

    Clear accountability measures for the design and use of AI systems are established
  7. #7ImportantKey Focus AreasBefore placing on market

    Applies to: All NSW Government agencies developing or deploying AI systems.

    It also promotes transparency in AI operations, aiming to build public confidence
  8. #8ImportantImplementation FrameworkBefore scaling deployment

    Applies to: All NSW Government agencies deploying AI systems.

    Agencies are required... to conduct pilots prior to scaling
  9. #9ImportantMonitoring and EvaluationAfter deployment

    Applies to: All NSW Government agencies operating AI systems.

    Agencies are mandated to apply the framework... after deployment to ensure appropriate monitoring
  10. #10ImportantImplementation FrameworkBefore deployment

    Applies to: NSW Government agencies with AI projects exceeding $5 million or funded by the Digital Restart Fund.

    For projects with budgets exceeding $5 million or those funded through the Digital Restart Fund, additional central oversight is provided under the broader Digital Assurance Framework

© Regulations.AI — created on 09-Jan-2026 using Gemini 2.5 Flash