Australia - Queensland - AI Risk Assessment (2024)

Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline (Queensland Government)

Australia

RAI-AU-QL-FAIRAXX-2024
Effective: September 1, 2024
In Force(In Force)
GuidelineRisk ManagementGovernance and OversightAccountability and Documentation
Export PDF

The Queensland Government's Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline (v1.0.0) provides non-mandatory, best-practice guidance for public sector agencies to identify, assess and manage risks across the AI lifecycle. Issued as part of the Queensland Government Enterprise Architecture (QGEA) suite in September 2024, FAIRA complements the Queensland AI governance policy and aligns with ISO guidance and the National Framework for the Assurance of AI in Government.

Overview

The Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline is published by the Queensland Government within the Queensland Government Enterprise Architecture (QGEA) directions and guidance. FAIRA (v1.0.0, effective September 2024) provides a structured, foundational approach for Queensland public sector agencies to identify, evaluate, communicate and treat risks across an AI lifecycle. The guideline is intended as practical, non-mandatory guidance that complements mandatory AI governance requirements; agencies are advised to use FAIRA (or an equivalent) in conjunction with the Queensland Artificial Intelligence governance policy and to align assessments with recognised international standards such as ISO/IEC 42001 and ISO 22989. FAIRA comprises three parts (component analysis, values assessment and control catalogue) designed to be proportionate and iteratively updated as systems evolve; it also provides templates to record decisions when an assessment is not required. The guideline is accessible on the QGEA website and FAIRA framework materials are available for agencies to download and adapt.

Definitions

FAIRA adopts working definitions tailored for government use. Key terms include "AI solution" (any product, service or system that performs functions commonly described as AI or that stakeholders reasonably regard as AI), "AI lifecycle" (conception, design, procurement, development, deployment, operation, monitoring and decommissioning), "component analysis" (technical and integration mapping of system parts and data flows), and "values assessment" (systematic mapping of stakeholder and public values to potential harms, such as privacy, fairness and human rights). FAIRA emphasises pragmatic classification over rigid definitional thresholds: when in doubt, teams are encouraged to complete a basic record or ‘‘When is a FAIRA needed’’ template to demonstrate decision-making. FAIRA also references types of AI functions in international guidance (e.g., ISO 22989) to assist risk proportionality judgments.

Governance and Institutional Framework

FAIRA sits within the broader QGEA and is administered as guidance by the Department of Customer Services, Open Data and Small and Family Business. The guideline advises agencies to embed FAIRA outcomes into existing governance structures—ICT governance, audit and risk committees, investment assurance and procurement approvals—and to establish clear responsibilities for FAIRA delivery and sign-off (e.g., project sponsors, business owners, CIOs and risk managers). Agencies must consider FAIRA outputs when preparing submissions to the Digital Investment Governance Framework and in ICT profiling. FAIRA recommends multi-disciplinary AI assessment teams that include legal, privacy, security, business continuity and subject-matter experts. The guideline also maps reporting channels and suggests agency-level escalation pathways for unresolved high risks. For additional governance context, see the QGEA AI governance policy page and the Department of Customer Services’ guidance for digital and data governance on the QLD government site (Department of Customer Services, Open Data and Small and Family Business).

Key Focus Areas

FAIRA identifies recurring domains of risk to be analysed and recorded. These include: (1) Purpose and context risk—ensuring AI use aligns with legitimate government functions and intended benefits; (2) Data risk—data quality, provenance, bias, privacy and lawful basis for processing; (3) Model risk—training methods, validation, drift, explainability and robustness; (4) Human–machine interface—clarity of roles, oversight, escalation and human-in-the-loop mechanisms; (5) Operational risk—system dependencies, third-party hosting and procurement arrangements; (6) Security and resilience—cybersecurity posture, supply chain risk and continuity planning; (7) Societal and rights impacts—discrimination, access to services, civic freedoms and public trust; (8) Accountability and transparency—records, documentation, decision logs and explainability measures; and (9) Regulatory and legal alignment—privacy principles, administrative law, procurement law and sector-specific obligations (health, social services, corrections, etc.). Each focus area includes suggested indicators and sample controls drawn from the FAIRA control catalogue: governance controls, technical measures (e.g., testing and validation), contractual protections with vendors, privacy-by-design, and user-facing transparency measures. FAIRA encourages agencies to rate the potential consequence and likelihood within their existing risk frameworks and escalate material risks for cross-agency review where appropriate.

Implementation Framework

FAIRA provides a phased implementation approach: Establish Context (scope, stakeholders, regulatory constraints); Component Analysis (map system architecture, data flows, integration points and third-party dependencies); Values Assessment (map affected values to potential harms and stakeholders); Risk Analysis and Evaluation (assess likelihood and consequence within agency risk matrices); Risk Treatment (document controls, residual risk and monitoring plans); and Reporting/Assurance (record FAIRA outputs in assurance submissions and ICT profiling). The guideline supplies templates and a controls catalogue to ensure repeatability. Implementation emphasizes proportionate assessment: simple AI components warrant concise FAIRA records, while high-impact systems require detailed analysis, external assurance and independent testing. Agencies are encouraged to maintain version control, re-assess on significant model or context changes, and link FAIRA outputs to procurement contracts and SLAs for ongoing compliance and vendor management.

Monitoring and Evaluation

FAIRA recommends continuous monitoring and periodic re-evaluation. Monitoring metrics include model performance drift, incident and complaints reporting, user feedback, privacy impact metrics, security incident rates and audit outcomes. Agencies should define trigger conditions for re-running FAIRA assessments (e.g., new purpose, different population, new data sources, substantial model retraining or shift to new vendor). The guideline suggests integration with existing assurance cycles (assurance reviews, audit programs, ICT profiling) and storing FAIRA records in accessible digital repositories to support oversight and transparency. Where relevant, agencies should use external or third-party assurance (independent testing, red-teaming, external audits) for high-consequence AI. FAIRA also highlights the importance of documenting monitoring plans, KPIs and responsibilities for remedial actions in the event of harm or performance degradation.

Penalties, Liability, and Appeals

FAIRA itself is guidance and does not prescribe statutory penalties. However, the guideline makes clear that inadequate risk assessment and control may lead to administrative or legal consequences through other legal instruments—e.g., breaches of privacy principles, procurement rules, sector-specific regulation or obligations to maintain appropriate systems of internal control. Potential consequences for agencies include failed assurance submissions, procurement approval delays, internal audit findings, mandatory remediation directives and, where governed by other laws, regulatory enforcement or civil liability. FAIRA also recommends establishing internal appeal and escalation pathways for contested risk findings and maintaining records of decisions (including the ‘‘When is a FAIRA needed’’ template) to provide an evidentiary trail for oversight bodies and, if necessary, external review.

Relationship to Other Instruments

FAIRA is designed to be complementary to a suite of instruments: the Queensland AI governance policy (which sets governance obligations), the Digital Investment Governance Framework (assurance process), privacy frameworks (Queensland privacy principles and agency privacy management), cybersecurity policies, procurement rules and national and international standards (ISO/IEC 42001, ISO 22989, ISO 38507). FAIRA references the National Framework for the Assurance of AI in Government and is intended to support agencies in meeting obligations under those frameworks. Agencies are advised to map FAIRA outputs to these instruments when preparing business cases, procurement documentation and assurance reviews to ensure consistent compliance and to avoid duplication of effort.

International Alignment

FAIRA explicitly references international standards and frameworks to promote interoperability and comparability of assessments across jurisdictions. The guideline aligns its structure with ISO guidance (notably ISO/IEC 42001 management-system concepts and ISO 22989 technical function categories) and draws on the National Framework for the Assurance of AI in Government to reflect national coordination. This alignment facilitates adoption of FAIRA outputs in multi-jurisdictional procurement, cross-jurisdiction assurance and for benchmarking against international good practice, and supports vendor engagement where suppliers need to demonstrate compliance with both Queensland public-sector expectations and internationally recognised standards.

Implementation Timeline

MilestoneDateNotes
FAIRA guideline published (QGEA)2024-09-01Guideline v1.0.0 published as Current (Non-mandated)
AI governance policy issued (QGEA)2024-09-01Policy sets governance obligations; cross-references FAIRA
FAIRA framework update (docx) timestamp2025-08-06Framework document metadata shows update (agencies should check for later updates)
Recommended: agency adoption planningOngoingAgencies to integrate FAIRA into procurement and assurance cycle

Compliance Checklist

Checklist ItemCompliant/Notes
Has a FAIRA (or equivalent) been initiated for the AI solution?Yes/No — record using template
Is the AI component analysis complete (architecture, data flows, integrations)?Yes/No — include diagrams and version
Has a values assessment been performed and risks logged?Yes/No — link to ICT risk register
Are mitigation controls documented and assigned?Yes/No — include owners and timelines
Has the FAIRA been integrated into procurement/assurance submissions?Yes/No — attach FAIRA to Digital Investment Governance submission
Is a monitoring plan and trigger set for re-assessment?Yes/No — define KPIs and re-assessment triggers

Sources and References

SourceType
Foundational artificial intelligence risk assessment guidelinePrimary Source
FAIRA framework (QGEA framework document)Primary Source
Artificial intelligence governance policy (QGEA)Primary Source
Plain English

The Foundational Artificial Intelligence Risk Assessment (FAIRA) guideline offers best-practice guidance for Queensland government agencies to identify and manage risks associated with artificial intelligence (AI) solutions.

This guideline, effective September 1, 2024, applies to all Queensland public sector agencies. While not legally mandatory, it strongly advises agencies to adopt its framework or an equivalent to complement the mandatory Queensland Artificial Intelligence governance policy. The core purpose is to provide a structured way to identify, evaluate, communicate, and treat risks throughout an AI solution's entire lifecycle, from conception to decommissioning.

Agencies are expected to undertake several key steps. This includes performing a "component analysis" to map the technical architecture, data flows, and third-party dependencies of an AI system, and a "values assessment" to systematically identify potential harms to public values like privacy, fairness, and human rights. The outcomes from these assessments should then be integrated into existing governance structures, such as Information and Communications Technology (ICT) governance, audit committees, and procurement approvals. Furthermore, agencies must continuously monitor AI solutions for performance drift, incidents, and user feedback, establishing clear triggers for re-assessment when significant changes occur.

FAIRA itself does not impose direct penalties. However, failing to conduct adequate risk assessments or implement appropriate controls could lead to significant administrative or legal consequences under other laws. This includes breaches of privacy principles, procurement rules, or sector-specific regulations, potentially resulting in failed project approvals, audit findings, or even civil liability. A practical point to remember is that if you are unsure whether an AI solution needs a full FAIRA, the guideline encourages completing a basic record to document your decision-making, emphasizing pragmatic classification over rigid definitions.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Australia - Queensland - AI Risk Assessment (2024). Not legal advice — verify against the official text before relying on it.

  1. #1ImportantGovernance and Institutional FrameworkBefore preparing submissions

    Applies to: Queensland public sector agencies

    Agencies must consider FAIRA outputs when preparing submissions to the Digital Investment Governance Framework and in ICT profiling.
  2. #2ImportantOverviewBefore placing AI solutions on market

    Applies to: Queensland public sector agencies

    agencies are advised to use FAIRA (or an equivalent) in conjunction with the Queensland Artificial Intelligence governance policy
  3. #3ImportantCompliance ChecklistBefore deploying AI solutions

    Applies to: Queensland public sector agencies using FAIRA

    Is the AI component analysis complete (architecture, data flows, integrations)?
  4. #4ImportantCompliance ChecklistBefore deploying AI solutions

    Applies to: Queensland public sector agencies using FAIRA

    Has a values assessment been performed and risks logged?
  5. #5ImportantCompliance ChecklistBefore deploying AI solutions

    Applies to: Queensland public sector agencies using FAIRA

    Are mitigation controls documented and assigned?
  6. #6ImportantCompliance ChecklistBefore submitting procurement or assurance documents

    Applies to: Queensland public sector agencies using FAIRA

    Has the FAIRA been integrated into procurement/assurance submissions?
  7. #7ImportantCompliance ChecklistBefore deploying AI solutions

    Applies to: Queensland public sector agencies using FAIRA

    Is a monitoring plan and trigger set for re-assessment?
  8. #8RecommendedGovernance and Institutional FrameworkOngoing

    Applies to: Queensland public sector agencies

    The guideline advises agencies to embed FAIRA outcomes into existing governance structures
  9. #9RecommendedGovernance and Institutional FrameworkOngoing

    Applies to: Queensland public sector agencies

    establish clear responsibilities for FAIRA delivery and sign-off
  10. #10RecommendedImplementation FrameworkOngoing

    Applies to: Queensland public sector agencies using FAIRA

    Agencies are encouraged to maintain version control, re-assess on significant model or context changes
  11. #11RecommendedMonitoring and EvaluationOngoing

    Applies to: Queensland public sector agencies using FAIRA

    storing FAIRA records in accessible digital repositories to support oversight and transparency.
  12. #12RecommendedMonitoring and EvaluationBefore deploying high-consequence AI

    Applies to: Queensland public sector agencies deploying high-consequence AI

    Where relevant, agencies should use external or third-party assurance (independent testing, red-teaming, external audits) for high-consequence AI.

© Regulations.AI — created on 13-Jun-2026