Australia - Queensland - AI Governance Policy (2024)

Artificial intelligence governance policy (Queensland Government)

Australia

RAI-AU-QL-AIGQGXX-2024
Effective: September 1, 2024
In Force(In Force)
PolicyGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The Queensland Government Artificial Intelligence Governance Policy (issued September 2024) mandates consistent, evidence-based planning and governance for AI across Queensland Government agencies, requiring agency-level risk assessment and ISO 38507-aligned governance arrangements. It is supported by the Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline and framework to guide ethical risk assessment and assurance practices.

Overview

The Queensland Government Artificial Intelligence Governance Policy (issued September 2024) is a mandated Queensland Government Enterprise Architecture (QGEA) policy requiring departments and specified statutory bodies to adopt consistent, evidence-based approaches when planning, procuring, and using AI systems. The policy has two core mandatory requirements: (1) agencies must use a comprehensive, consistent and evidence-based process that incorporates an ethical framework to evaluate transparency, accountability and risk across the AI lifecycle; and (2) agencies must establish AI governance arrangements aligned to the current version of ISO 38507. The policy is published on the Queensland ForGov portal (Artificial intelligence governance policy) and is supported by the Foundational Artificial Intelligence Risk Assessment (FAIRA) framework and guideline to assist agencies with ethical risk assessment and assurance.

Definitions

Key terms used in the policy follow common public-sector and standards-based meanings: "AI" refers to systems that use data-driven or rule-based techniques to perform tasks that ordinarily require human intelligence; "AI lifecycle" covers planning, procurement, development/configuration, testing/validation, deployment, monitoring and decommissioning; "ethical framework" denotes a structured set of principles and procedures used to identify and mitigate ethical risks such as fairness, explainability, privacy and accountability; "agency" means Queensland Government departments (per the Public Sector Act 2022) and statutory bodies in scope under the Financial and Performance Management Standard 2019. The policy also cross-references the FAIRA materials for more granular risk taxonomy and assessment terminology.

Governance and Institutional Framework

The policy positions the Department of Customer Services, Open Data and Small and Family Business (CDSB) as the administering authority for QGEA AI directions, with agencies accountable for implementing governance and controls locally. It directs agencies to embed AI governance within existing structures — for example, ICT governance committees, enterprise risk committees and ISMS governance — and to align AI governance with ISO 38507. This alignment requires clear assignment of roles and responsibilities (executive sponsor, accountable officer, program/system owner), documented decision rights, investment gate approvals and integrated reporting to enterprise risk and investment boards. The policy also mandates that agencies satisfy reporting requirements in the QGEA ICT profiling standard, which supports whole-of-government visibility. For practical support, CDSB provides FAIRA materials and guidance and coordinates cross-agency advice; independent oversight, assurance and audit activity may be provided by the Queensland Audit Office (QAO report) and internal audit functions.

Key Focus Areas

The policy highlights multiple focus areas to manage benefit and harm: (1) risk assessment and proportionate governance — agencies must undertake comprehensive risk assessments before deploying AI and select evaluation approaches proportional to system risk; (2) ethical considerations — agencies must apply an ethical framework (FAIRA or equivalent where justified) addressing fairness, bias mitigation, non-discrimination, human oversight and explainability; (3) data protection and privacy — data handling, de-identification and privacy impact assessment obligations must be observed in line with privacy law and QGEA guidance; (4) information security — the policy requires integration with ISMS and cybersecurity controls to mitigate model and data security risks; (5) transparency and documentation — agencies must maintain documentation of assessment outcomes, decision rationale and model provenance to support accountability and future assurance; and (6) monitoring, evaluation and continuous assurance — agencies must plan for post-deployment surveillance, performance monitoring, and periodic reassessment. These areas draw on international standards and national frameworks to support consistent, auditable practice across the Queensland public sector.

Implementation Framework

Operationalisation of the policy is supported by the FAIRA framework and guideline, which provide step-by-step assessment processes, risk taxonomies and example controls. Agencies are expected to integrate AI evaluation with existing project and investment governance processes, use the ICT profiling standard for reporting, and adopt ISO 38507-informed governance arrangements. The policy permits proportionate approaches where lower-risk AI may use simplified assessment processes, but agencies must document and justify any deviation from FAIRA. Procurement and contract terms should require suppliers to provide evidence of model documentation, testing, and security controls. Training, capability building and access to evaluation tools are included in the implementation roadmap to ensure agencies can meet the policy's expectations.

Monitoring and Evaluation

Monitoring mechanisms include required reporting under the QGEA ICT profiling standard and periodic assurance activities. CDSB collects agency reports and offers guidance; the Queensland Audit Office and internal audit functions provide independent evaluation of policy adherence and ethical risk management. The QAO has already recommended that CDSB implement a formal evaluation plan to assess the effectiveness of the AI governance policy and supporting tools. Agencies are expected to maintain records that enable post-deployment performance monitoring, incident reporting and continuous improvement across the AI lifecycle.

Penalties, Liability, and Appeals

The policy itself does not create new criminal sanctions. Compliance and enforcement are delivered through administrative and governance mechanisms (requirement to meet QGEA standards, internal remediation, audit findings and reporting). Non-compliance can lead to remedial action, removal or suspension of AI deployments, internal performance or disciplinary consequences, and potential civil or regulatory liability under existing laws (privacy, discrimination, administrative law). Agencies should incorporate redress mechanisms and review paths into their governance arrangements and ensure individuals impacted by automated decisions have accessible appeal or review pathways consistent with legal obligations.

Relationship to Other Instruments

The policy is explicitly linked to the QGEA ICT profiling standard (reporting), the Financial and Performance Management Standard 2019 (scope for statutory bodies), the Public Sector Act 2022 (agency definitions and accountable officers), and the FAIRA framework/guideline (operational risk assessment). It also references international and national standards such as ISO 38507 and suggests agencies consider ISO 42001/ISO 22989 where relevant. The policy complements Queensland guidance on generative AI and other AI-specific guidance documents already published by the Queensland Government.

International Alignment

The policy requires alignment with ISO 38507 and cross-references national developments, positioning Queensland to align with Australian Government voluntary AI safety instruments and emerging international good practice. By referencing ISO standards and the FAIRA materials (which incorporate international ethical principles), the policy supports compatibility with cross-jurisdictional assurance regimes and facilitates information-sharing and mutual recognition of governance approaches in federated or multinational contexts.

Implementation Timeline

MilestoneDate
Issue and approvalSeptember 2024
Policy effective from2024-09-01
FAIRA framework & guideline publishedSeptember 2024
QAO audit referencing policy2025 (QAO report published)
Latest page update (ForGov)2025-08-08

Compliance Checklist

RequirementAction
Structured, evidence-based evaluationAdopt FAIRA or documented alternative; complete risk assessment pre-deployment
ISO 38507-aligned governanceMap roles, committees and reporting lines; update governance charters
Documentation and reportingRecord assessments, decisions, testing results and maintain ICT profiling reports
Privacy & SecurityComplete privacy impact assessments; integrate with ISMS
Monitoring & reviewEstablish post-deployment monitoring and incident response processes

Sources and References

SourceType
Artificial intelligence governance policy (QGEA)Primary Source
Foundational artificial intelligence risk assessment guideline (FAIRA)Primary Source
Queensland Audit Office — Managing the ethical risks of artificial intelligencePrimary Source
Plain English

This Queensland Government policy sets mandatory rules for how all Queensland Government departments and specified statutory bodies must plan, procure, and use artificial intelligence systems. It aims to ensure consistent, evidence-based governance for AI across the public sector and took effect on September 1, 2024.

Under the policy, agencies must adopt a comprehensive, consistent, and evidence-based process to evaluate AI systems. This includes using an ethical framework, such as the Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline, to assess transparency, accountability, and risks throughout the AI system's entire lifecycle. Agencies are also required to establish AI governance arrangements that align with the international standard ISO 38507, which means clearly defining roles, responsibilities, decision-making processes, and reporting lines. Key focus areas include robust data protection, privacy impact assessments, information security, and maintaining thorough documentation of all assessments and decisions.

The policy itself does not introduce new criminal penalties. Instead, compliance is enforced through administrative and governance mechanisms. Non-compliance can lead to remedial actions, suspension of AI deployments, internal disciplinary consequences, or potential civil and regulatory liability under existing laws, such as those related to privacy or discrimination. The Queensland Audit Office also provides independent oversight. A practical point to note is that while the policy allows for proportionate approaches and simplified assessments for lower-risk AI, agencies must still meticulously document and justify any deviation from the detailed FAIRA framework.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Australia - Queensland - AI Governance Policy (2024). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalOverviewBefore deploying AI

    Applies to: Queensland Government agencies

    agencies must use a comprehensive, consistent and evidence-based process that incorporates an ethical framework to evaluate transparency, accountability and risk across the AI lifecycle
  2. #2CriticalOverviewSep 1, 2024

    Applies to: Queensland Government agencies

    agencies must establish AI governance arrangements aligned to the current version of ISO 38507.
  3. #3CriticalKey Focus AreasBefore deploying AI

    Applies to: Queensland Government agencies

    agencies must undertake comprehensive risk assessments before deploying AI and select evaluation approaches proportional to system risk
  4. #4CriticalKey Focus AreasBefore deploying AI

    Applies to: Queensland Government agencies

    agencies must apply an ethical framework (FAIRA or equivalent where justified) addressing fairness, bias mitigation, non-discrimination, human oversight and explainability
  5. #5CriticalKey Focus AreasBefore deploying AI

    Applies to: Queensland Government agencies

    data handling, de-identification and privacy impact assessment obligations must be observed in line with privacy law and QGEA guidance
  6. #6ImportantKey Focus AreasBefore deploying AI

    Applies to: Queensland Government agencies

    the policy requires integration with ISMS and cybersecurity controls to mitigate model and data security risks
  7. #7ImportantKey Focus AreasOngoing

    Applies to: Queensland Government agencies

    agencies must maintain documentation of assessment outcomes, decision rationale and model provenance to support accountability and future assurance
  8. #8ImportantKey Focus AreasBefore deploying AI

    Applies to: Queensland Government agencies

    agencies must plan for post-deployment surveillance, performance monitoring, and periodic reassessment.
  9. #9ImportantGovernance and Institutional FrameworkOngoing

    Applies to: Queensland Government agencies

    The policy also mandates that agencies satisfy reporting requirements in the QGEA ICT profiling standard
  10. #10ImportantGovernance and Institutional FrameworkSep 1, 2024

    Applies to: Queensland Government agencies

    This alignment requires clear assignment of roles and responsibilities (executive sponsor, accountable officer, program/system owner)
  11. #11ImportantImplementation FrameworkBefore deploying AI

    Applies to: Queensland Government agencies

    agencies must document and justify any deviation from FAIRA.
  12. #12ImportantPenalties, Liability, and AppealsBefore deploying AI

    Applies to: Queensland Government agencies

    Agencies should incorporate redress mechanisms and review paths into their governance arrangements and ensure individuals impacted by automated decisions have accessible appeal or review pathways consistent with legal obligations.

© Regulations.AI — created on 13-Jun-2026