Governing Artificial Intelligence in an Asset-Intensive Organisation
- Alex Afshar

- Jul 24
- 19 min read
Updated: Jul 24
An Assurance Framework for Confident, Accountable Leadership
By Dr Fay Saleh, John Zhang, Peter Kohler, Sally Nugent, Alex Afshar
About the authors
Dr Fay Saleh is Chief Technology Officer and AI Scientist at Dolanto, bringing over a decade of experience across Australia, the Middle East and Europe. Her expertise spans Natural Language Processing and Generative AI, with a particular focus on Evaluation Frameworks for AI systems.
John Zhang is an AI Scientist at Dolanto with more than five years of experience across public and infrastructure projects. His work centres on the design and development of AI solutions that create efficiency and speed at scale.
Alex Afshar is the Founder of Dolanto, with over two decades of experience delivering infrastructure projects across mining, road, rail, health and telecommunications. He has worked across government and private sectors in the Middle East, South America and Australia.
Peter Kohler has a keen appreciation for the strategic function provided by the discipline of asset management. Peter is a mechanical engineer who spent 26 years in the Royal Australian Navy, where he championed the discipline of asset management. In conjunction with three other people, he campaigned for the establishment of the Asset Management Council (achieved in 2005), becoming its first AMBoK Commissioner.
Sally Nugent, a qualified Materials Engineer with extensive experience in corrosion and extrusion research, helped establish the Corrosion Prevention Centre in the 1990s, the Asset Management Council Ltd in the 2000s, and the global "Certified Asset Management Practitioner" certification program.
1 Introduction
This paper is written for Board members, senior executives, and public sector leaders responsible for governing organisations in which Artificial Intelligence (AI) is already active, whether or not those leaders are aware of the use of AI in their organisation.
2 Executive Summary
AI is already embedded in how asset-intensive organisations analyse, prioritise, and decide. For most, it has arrived not through a strategic choice but through the procurement of productivity tools and vendor platforms.
The leadership challenge is not adoption; it is, as always, good practice, assurance and governance.
The central argument in this paper | AI is no longer a technology option. It is a decision-quality, accountability and assurance requirement, and it demands board-level leadership to achieve desired outcomes. |
Who is this paper for? | Senior executives and senior leadership teams in public and social infrastructure, including transport, energy, health, housing, and community services. |
What does this paper provide? | A verified, evidence-based Four Quadrant knowledge model, Four Pillar governance framework, and eight risk strategies able to be applied by Boards. |
What does this paper ask of leaders? | Stewardship of the application of AI toolsets. The same rigour and accountability should be applied to the use of AI as for every other domain of organisational governance. |
What are the author's contributions? | An executive governance model for AI in asset-intensive organisations. |
This paper does not recommend that executives become AI experts. It does recommend that they be aware of the use of AI tools, and assure themselves of the appropriate application of appropriate AI toolsets with the same rigour and accountability needed for every other domain of stewardship, like risk, finance and performance.
"The organisations that lead well in the age of AI will not be remembered for how cautiously they spoke about it but for whether they built the governance capability to use it responsibly, intelligently, and accountably in order to identify and create value for their stakeholders."
Keywords: Assurance, Governance, Judgment, Leadership, Capability, Value
3 Decision Context
3.1 Value and Benefit Realisation
Effective value realisation begins with the end in mind, defining the intended benefits across the value chain before work begins. In any asset-intensive organisation, the volume of data and information being generated and managed is growing at an unprecedented rate. Global data generation is projected to triple between 2025 and 2029 (Statista, 2025), driven by the rapid growth of IoT devices, real-time data processing and cloud-based infrastructure. Organisations are under increasing pressure to harness this data to create value for both shareholders and the communities they serve.
Yet despite this opportunity, organisations often remain focused on project deliverables rather than the broader benefits those projects are intended to achieve. This gap is largely driven by a lack of clear communication and alignment between project stakeholders, strategy owners and those responsible for benefit realisation.
As a result, the productivity gains that AI projects are designed to deliver remain largely untapped. Just as with any other major investment decision, a structured Cost-Benefit Analysis should be a standard requirement for an AI initiative, applied consistently across the organisation to drive accountability and informed decision-making.
3.2 Starting with the Right Question
Good governance has always begun with good questions. Before any framework, any policy, or any technology decision, leaders need to ask:
What decisions are already being shaped by AI in our organisation, and do we have full visibility of them?
Where do we have justified confidence, and where are we relying on assumptions, vendor promises, or institutional momentum?
If challenged by the board, a regulator, a minister, or the community, could we clearly explain how an AI-influenced decision was reached?
What might we already know that we have not yet surfaced to leadership, and what risks may still be completely hidden from view?
As AI capabilities grow, how do we ensure that human judgment, accountability, and public trust are strengthened rather than displaced?
What are the particular risks associated with AI?
These questions sit at the heart of why leaders in public infrastructure must move beyond hype or fear toward rigorous, evidence-based governance.
3.3 The Four Quadrants of Knowledge
Before any governance framework can be designed, leaders need a clear model of the knowledge terrain they are navigating. AI governance is not simply about managing known risks. It requires confronting the full landscape of organisational knowledge, including its gaps, blind spots, and hard limits.
The Four Quadrant model, adapted from Luft and Ingham's Johari Window (1955) and applied here to AI governance, provides exactly this structure, Table 1. It is one of the most powerful diagnostic tools available to senior leaders because it maps both what an organisation knows and what it does not yet know it knows.
Table 1 - The Four Quadrants of AI Knowledge: A Strategic Navigation Framework | Adapted from Luft & Ingham (1955)
The Four Quadrants of Knowledge | |
Unknown Knowns What we don't know that we know
| Unknown Unknowns What we don't know that we don't know
|
Known Knowns What we know that we know
| Known Unknowns What we know that we don't know
|
Quadrant 1: Known Knowns , Leverage What You Have.
These are the AI capabilities, frameworks, processes, and decisions your organisation can already see, evidence, and explain. The strategic response is not to reinvent governance from scratch, but to apply the rigour of your existing assurance, risk, and audit frameworks to the new context of AI.
Quadrant 2: Known Unknowns, Research and Risk Manage.
These are the gaps your organisation is already aware of — risks that can be named, estimated, and actively managed, and they should sit at the heart of your AI assurance programme.
Quadrant 3: Unknown Knowns , Provide Visibility and Document.
This is the most underestimated quadrant: tacit knowledge in the expertise of experienced practitioners and frontline staff. When AI is introduced, this knowledge is frequently bypassed. Good governance requires surfacing and documenting it before it is lost.
Quadrant 4: Unknown Unknowns , Build Resilience and Scan the Horizon.
These are risks that cannot yet be named. No organisation can fully prepare for these, but the best-governed ones invest in the resilience to absorb shocks faster and maintain a disciplined practice of horizon scanning and board-level scenario planning.
Good governance does not eliminate unknown unknowns. It builds the organisational capability to detect them earlier, respond faster, and prevent confidence from outrunning evidence.
The leadership task across all four quadrants is the same: increase the area of known knowns, actively surface unknown knowns before they become incidents, rigorously manage known unknowns through structured assurance, and create governance mechanisms that detect emerging unknowns before they become crises.
The novel threat patterns coming from societal push back on AI are emerging and could be said to represent not any direct threat by AI, but rather poorly handled disruption to jobs, to living quality and to autonomy.
Source: AI isn't the future. It's History Repeating Itself.
3.4 What Good Governance Looks Like in Practice
Good practice does not begin by asking where AI can be inserted into existing workflows. It begins by asking whether the workflow itself is fit for purpose.
Good practice starts with a more fundamental question: if this process were designed today, from first principles, what would it look like?
What decisions actually matter, and what standard of evidence is required to make them defensibly?
What information is genuinely needed, and what is simply inherited from how things have always been done?
Where must human judgement sit, and where can AI safely assist without compromising accountability?
What quality assurance measures are necessary to maintain confidence in outputs over time?
What should trigger escalation, override, or suspension of AI involvement?
The organisations that succeed will treat AI not as a shortcut around poor process design, but as a capability that must be anchored in sound logic, clear decision rights, robust quality measures, and meaningful oversight.
4 Using AI as a Tool for Assurance
4.1 Why Does This Matter Now?
Across Australia, public and social infrastructure leaders are under compounding pressure. The Victorian Auditor-General's Office (VAGO, 2026) has noted that public reporting on major projects does not always allow Parliament and communities to fully assess progress.
Infrastructure Australia's 2024 Infrastructure Market Capacity Report found that Australia's five-year major public infrastructure pipeline stood at $213 billion, with persistent skills shortages, material cost pressures, and stagnant productivity. In this environment, many organisations are turning to AI to strengthen analysis, support prioritisation, and improve throughput.
Yet AI adoption raises a governance question that cannot be deferred: who owns the decision, and how has the decision been made? The Australian Productivity Commission's 2025 report on Harnessing Data and Digital Technology confirms that human decision-making is already AI-assisted in most organisations, and that the level of human oversight may diminish further as AI capabilities increase.
"AI is no longer an innovation or digital transformation concept. It is a vital issue for governance, assurance, and institutional legitimacy."
Public sentiment reflects this urgency. A 2025 global study by Gillespie et al. found that only a minority of Australians believe the advantages of AI outweigh its risks the lowest proportion of any country surveyed. Eighty per cent expect government and regulators to provide oversight. Seventy-seven per cent believe AI regulation is necessary.
The Australian Institute of Company Directors AICD, in partnership with the Human Technology Institute at UTS (2024), has identified a clear imperative for boards to move from passive awareness to active oversight, establishing governance frameworks that can adapt to the unique and evolving characteristics of AI systems.
If leaders act
+ Visible, defensible AI use
+ Stronger decision quality
+ Public legitimacy maintained
+ Assurance as a competitive advantage
+ Capability built ahead of regulation
+ Stakeholder engagement
If leaders do nothing
− AI still enters, ungoverned
− False confidence from polished outputs
− Accountability quietly eroded
− Hidden assumptions in key decisions
− Exposure at audit, inquiry, or incident
– Stakeholder disruption
4.2 What AI Looks Like in Infrastructure
AI in public and social infrastructure is not a single technology. It is a growing and diverse set of capabilities applied across operational and decision-making contexts:
Domain | Example AI Applications | Key Governance Consideration |
Transport & Infrastructure | Failure prediction, demand forecasting, and contract compliance monitoring | Safety assurance; explainability of prioritisation decisions |
Health & Community Services | Case prioritisation, resource allocation, risk stratification | Equity; bias auditing, contestability of individual outcomes |
Energy & Utilities | Grid optimisation, fault detection, and environmental monitoring | Regulatory compliance; fail-safe override; data integrity |
Finance & Corporate Services | Expenditure analysis, fraud detection, and reporting automation | Audit trail; data provenance; human review thresholds |
Project & Asset Management | Schedule forecasting, risk flagging, contract performance analysis | Accountability for recommendation; integration with assurance gates |
Legal & Procurement | Contract review, verification, vendor assessment, compliance assessment | Accuracy validation; professional accountability; liability |
The spectrum of decision influence runs from low-stakes analytical assistance to high-consequence recommendations affecting public safety and service delivery. A critical governance principle follows directly from this – assurance must scale with consequence. The higher the stakes of an AI-influenced decision, the more rigorous the assurance requirement.
AI should be understood not by the technology it uses but by the decisions it shapes, and assurance requirements must be calibrated to the consequences of those decisions.
5 Assuring Yourself of the AI Tool
5.1 Why Assurance Is the Right Governance Lens
Assurance means a level of justified confidence that a goal has been or will be achieved. (AUASB, 2020). Assurance Reviews are objective, fact-based evaluations, often undertaken independently by a knowledgeable team, to provide confidence in a defined subject matter within an undertaking such as public transport.
The assurance team’s scope may extend across financial and non-financial domains depending on the nature of the undertaking and stakeholder needs. This can include safety, systems engineering, asset management, contract management, environmental performance, regulatory compliance, governance, operational performance, stakeholder and management systems. The scope also includes the context of use, the quality of supporting evidence, the analytical methods applied, and the intended audience and use of the assurance outcome. In doing so, the Assurance Audit/Review analyses assurance of the AI tool and assurance of the outcome, Table 4.
Table 4 - Assurance Model
Assurance question | Assurance of the AI tool | Assurance of the assurance outcome |
What is the scope and context of use? | Defines the intended use of the tool, operating boundaries, users, decision context, and prohibited uses. | Defines the purpose, subject matter, decision context, and reliance being placed on the output or report. |
Is the method fit for purpose? | Assesses whether the model, rules, workflows, and system architecture are appropriate for the stated use case. | Assesses whether the analytical approach, judgement process, and assurance method applied to the matter are appropriate for the intended conclusion. |
Is the data relevant and of sufficient quality? | Examines training data, retrieval sources, input data, reference materials, metadata, and data governance controls. | Examines whether the specific evidence used in the assurance activity is complete, relevant, current, and reliable enough to support the conclusion. |
Are controls in place and operating effectively? | Reviews model controls, access controls, versioning, audit logs, human oversight, testing, and change management. | Reviews review checkpoints, evidence traceability, sign-off processes, challenge mechanisms, and governance over the assurance engagement. |
Are the outputs reliable and explainable? | Tests consistency, robustness, reproducibility, explainability, and failure modes of the tool. | Tests whether the conclusion is supported by transparent reasoning, evidence linkage, and defensible interpretation. |
Are the people involved competent? | Considers whether designers, implementers, operators, and reviewers understand the tool and its limitations. | Considers whether those performing and reviewing the assurance work have the domain, analytical, and governance expertise required. |
What are the limitations and risks? | Identifies model limitations, bias, drift, uncertainty, misuse risk, and operational constraints. | Identifies limitations in the evidence, assumptions, scope, interpretation, and confidence level of the assurance conclusion. |
Who is the audience and how will the output be used? | Clarifies who can use the tool, for what purpose, and with what degree of reliance or oversight. | Clarifies who will rely on the assurance result and whether it is intended for management, regulators, boards, or external stakeholders. |
What level of confidence is justified? | Determines whether the tool can be trusted for advisory, augmented, or higher stakes use within defined conditions. | Determines the degree of confidence that can reasonably be placed in the assurance finding, recommendation, or decision. |
Assurance grounded in ISO/IEC 17029:2019 principles on validation and verification is the discipline that connects intent to outcome. It asks not just whether AI is being used, but whether its use can be justified, defended, and continuously improved.
Assurance programmes should define their level of confidence explicitly:
Table 5 - Assurance Type
Absolute assurance | Rarely achievable; reserved for the highest consequence, most fully evidenced decisions. |
Reasonable assurance | The standard for most public infrastructure decisions: justified confidence based on robust evidence and independent review. |
Limited assurance | Appropriate for lower-consequence or preliminary applications: nothing has come to attention to suggest the claim is not valid. |
In public infrastructure, where decisions affect safety, service delivery, public value, and community trust, assurance is not an added layer on top of governance. It is the governance element that provides credibility because it moves beyond compliance to ask whether decisions supported by AI can be understood, challenged, defended, and continuously reviewed.
Assurance is not a brake on innovation. It is what makes innovation trustworthy and what separates organisations that use AI well from those that simply use AI fast.
5.2 What AI Accountability Requires
As AI becomes embedded in how decisions are informed, prioritised, and executed, accountability must be strengthened, not assumed. It is not sufficient to say that a human remains in the loop. Meaningful accountability in the age of AI requires four things simultaneously, as detailed in Table 6.
Table 6 - Assurance Key Element
Element | What it means for leaders | |
1 | Meaningful oversight | Decision-makers understand the role AI is playing and can exercise genuine judgement not simply endorse outputs. This requires AI literacy. (AI expertise should not be required). |
2 | Evidence | Confidence in AI-supported decisions can be justified, documented, and explained at the point of decision, not reconstructed after the fact. |
3 | Escalation pathways | Uncertainty, anomalies, and higher-risk outcomes are reviewed at the appropriate level, with triggers defined and tested in advance, not discovered during incidents. |
4 | Contestability | Decisions influenced by AI can be questioned by affected parties, overridden by authorised decision-makers, and reviewed by assurance and audit bodies. |
These four requirements ensure that AI does not dilute responsibility but operates within a governance framework where accountability remains visible, active, and defensible.
5.3 The Governance Framework: Four Pillars
The governance framework proposed in this paper is built around four pillars: Transparency, Accountability, Contestability, and Continuous Review. These pillars are not a new standalone model. They are a cross-cutting lens applied to the maturity frameworks organisations already operate across projects, contracts, assets, IT, safety, and risk (Source: Department of Industry, Science and Resources, 2024).
Table 7 - The Four Pillars of AI Governance - applicable across existing organisation maturity frameworks
Pillar | What it means | In practice, this means... | Board-level question to ask |
Transparency | Know where AI operates, what it decides and on what evidence basis | Knowing where AI operates, what inputs shape outputs, what logic or model behaviour matters, and how decisions are recorded and retrievable. | Do we have a complete and current inventory of AI use across the enterprise, including shadow use and vendor-embedded AI? |
Accountability | Named human responsibility for every AI-influenced consequential decision based on risk | Decision rights remain visible and named. Humans remain meaningfully responsible for consequential outcomes they can explain, not just approve. | Who is personally responsible when an AI-influenced decision leads to a poor outcome and is that accountability documented? |
Contestability | AI outputs can be challenged, overridden and corrected by authorised parties | AI outputs can be questioned by affected parties, escalated by staff, overridden by authorised decision-makers, and reviewed by internal and external assurance bodies. | Is there a clear, accessible, and tested pathway to challenge or reverse any AI-influenced decision in this organisation? |
Continuous Review | Ongoing monitoring of performance, drift, and alignment with public value | AI system performance, data quality, model drift, failure modes, and operational fit are monitored over time and reported to senior leadership team and board not assumed to remain stable. | How do we know our AI systems are still performing as intended and what triggers a formal review, suspension, or replacement? |
In mature organisations, AI governance should not sit outside existing management systems. It should be woven through them so that leaders see capability, risk, and improvement as part of one integrated assurance picture.
5.4 Eight Strategies to Manage AI Risk
Table 8 - The Four Quadrants of AI Knowledge: A Strategic Navigation Framework | Adapted from Luft & Ingham (1955)
The Four Quadrants of Knowledge This is how AI can reduce decision risk by closing knowledge gaps | |
Unknown Knowns What we don’t know that we know
| Unknown Unknowns What we don’t know that we don’t know
|
Known Knowns What we know that we know
| Known Unknowns What we know that we don’t know
|
The Four Quadrant framework is both diagnostic and prescriptive. Each quadrant calls for a different strategic response. Together, the eight strategies below form an integrated and actionable approach to AI risk management, incorporating both the assurance discipline of this paper's framework and the governance breadth recommended by the AICD (2024).
Table 9 - AI Risk Management: Eight Strategic Responses Mapped to the Four Knowledge Quadrants
AI Risk Management – Eight Strategic Responses | |||
Known Knowns | Known Unknowns | ||
1 Establish AI Register Catalogue everyone system what it does, who own it, what decisions it shapes.
| 2 Redesign Before Automate Apply blank sheet test to high impact processes before embedding AI in to them. | 3 Embedded Assurance Checkpoints Independent validation at design, deployment and ongoing operation stages. | 4 Define Human Override Rights Every AI output has a clear, documented, and testable override pathway.
|
Unknown Knowns | Unknown Unknowns | ||
5 Build Capability Across Enterprise AI Literacy for boards, senior leadership team, Operations, and frontline teams | 6 Surface Tacit Knowledge Formalise frontline insights and institutional wisdom before AI overrides it. | 7 Horizon Scanning & Scenario Planning Board-level stress testing against emerging AI risks and unknown features. | 8 Transparent Public Reporting Public-facing summaries showing AI’s role in outcomes with accountability evidence |
Strategies for Known Knowns: Leverage and Improve
Strategy 1: Establishh an AI Register | Catalogue every AI system in use: what it does, who owns it, what decisions it shapes, what data it consumes, and what assurance coverage currently exists. This register is the foundation of all subsequent governance activity. Its absence is itself a governance failure. |
Strategy 2: Redesign Before Automating | Apply a blank-sheet test to high-impact processes before embedding AI. Ask what the process would look like if designed from scratch today. Clarify decision criteria, simplify roles, define evidence requirements, and establish assurance checkpoints. Only then introduce AI as an enabler within a coherent operating model. |
Strategies for Known Unknowns: Research and Risk Management
Strategy 3: Embed Assurance Checkpoints | Build structured review gates into AI design, deployment, and ongoing operation aligned with ISO/IEC 17029:2019 levels of assurance. Define the level of confidence required for each use case (absolute, reasonable, or limited) and ensure that level is actually achieved before consequential decisions are made. |
Strategy 4: Define Human Override Authorities and Accountabilities | Every AI output must have a clearly documented, accessible, and periodically tested override pathway. Override frequency data is itself a governance intelligence signal, high override rates reveal where AI is performing outside required bounds and require investigation, not just recording. |
Strategies for Unknown Knowns: Surface and Document
Strategy 5: Build Capability Across the Enterprise | AI literacy must extend beyond technology functions. Boards, senior leadership team, risk teams, assurance functions, procurement specialists, and frontline decision-makers all need structured literacy programmes tailored to their accountability role. Access to specialist advisors should be available for high-consequence AI decisions. |
Strategy 6: Surface Tacit Organisational Knowledge | Before AI systems are deployed, formalise the tacit knowledge, expert judgement, and institutional wisdom that currently guides human decisions in that domain. This knowledge should inform AI design, constrain AI scope, and provide the baseline against which AI performance is evaluated. |
Strategies for Unknown Unknowns: Build Resilience and Scan
Strategy 7: Horizon Scanning and Scenario Planning | Maintain an active board-level practice of horizon scanning for emerging AI capabilities, failure modes, regulatory developments, and societal signals. Run structured scenario exercises that test the organisation's resilience to unexpected AI-related events including cascading system failures, model drift, and unforeseen societal impacts. |
Strategy 8: Transparent Public Reporting | Provide public-facing summaries that show how AI contributes to decisions and outcomes, while demonstrating the oversight, accountability, and assurance applied. In public infrastructure, transparency is not optional it is the mechanism by which public trust is earned and maintained over time. |
6 Towards the Future: What Leadership Means in the Age of AI
Leadership has always been defined by the ability to build organisations that perform, adapt, and make sound decisions. What has changed is the environment, more complex, data-rich, and fast-moving, and the tools, where human judgement now works in close partnership with AI. The leaders who succeed will be those who master that interface.
At the heart of this shift is capability, not just technical capability, but the combined ability to interpret evidence, exercise judgement where context matters, collaborate across functions, and operate effectively in an environment where human and machine intelligence increasingly work together.
Many organisations remain anchored in legacy ways of thinking and cautious decision habits shaped for a different era. The future will not be led by those who automate existing routines or use AI to reinforce comfortable processes. It will be led by those prepared to rethink how decisions are made, how work is organised, and how learning occurs across the enterprise.
There is also a competitive dimension. Organisations that fail to build these capabilities risk more than inefficiency. They risk becoming slower to respond, weaker in decision quality, less able to attract funding confidence, and less able to defend decisions under scrutiny. Those that act early will create conditions for better judgement, faster learning, and stronger public legitimacy.
Those who lead well in the age of AI will not be remembered for playing it safe but for building organisations capable of combining human judgement, machine intelligence, and public accountability into a stronger model of performance.
7 Conclusions
This paper began with questions. It ends with a call to action.
AI is already changing how public institutions think, decide, and act. The leadership challenge is not whether to engage with it, that decision has, in most organisations, already been made by default. The challenge is whether its use can be trusted, explained, challenged, and improved over time.
The Four Quadrant framework makes the knowledge landscape visible, mapping what we know, what we know we do not know, what exists within the organisation but has not yet been surfaced, and what remains beyond current sight. The Four Pillars, transparency, accountability, contestability, and continuous review, provide the governance architecture within which AI can operate safely and legitimately. The eight risk strategies provide a sequenced and actionable path from awareness to embedded governance.
The public is watching. Regulators are responding. Communities expect more. And the consequences of poor decisions in public infrastructure fall not on shareholders, but on the people these organisations serve.
The Assurance Imperative. The legacy of today's leaders will not be measured by how cautiously they spoke about AI but by whether they built organisations capable of using it responsibly, intelligently, and accountably. Boards and the senior leadership team are encouraged to use the Four Quadrants in their next strategy session, apply the Four Pillar lens to their existing governance systems, and pilot the eight risk strategies on one high-consequence AI use case within the next quarter. That is the assurance imperative and the opportunity now before us.
References
Luft, J. and Ingham, H. (1955) 'The Johari Window: a graphic model of interpersonal awareness', Proceedings of the Western Training Laboratory in Group Development. Los Angeles: UCLA Extension Office.
Victorian Auditor-General's Office (VAGO) (2026) Major Projects Performance Reporting. Melbourne: Victorian Government.
Australian Productivity Commission (2025) Harnessing Data and Digital Technology. Canberra: Commonwealth of Australia.
Gillespie, N., Lockey, S., Curtis, C., Pool, J. and Akbari, A. (2025) Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025. Brisbane: The University of Queensland and KPMG.
Australian Institute of Company Directors (AICD) and Human Technology Institute, University of Technology Sydney (2024) A Director's Guide to AI Governance. Sydney: AICD.
Auditing and Assurance Standards Board (AUASB) (2020) ASAE 3000: Assurance Engagements Other than Audits or Reviews of Historical Financial Information. Melbourne: AUASB.
International Organisation for Standardisation (ISO) (2019) ISO/IEC 17029:2019 Conformity Assessment — General Principles and Requirements for Validation and Verification Bodies. Geneva: ISO.
Department of Industry, Science and Resources (2024) Australia's AI Ethics Principles. Canberra: Australian Government. Available at: https://www.industry.gov.au/publications/australias-artificial-intelligence-ethics-framework
Institute of Electrical and Electronics Engineers (IEEE) (2021) IEEE 7000-2021: IEEE Standard Model Process for Addressing Ethical Concerns during System Design. New York: IEEE.
International Organisation for Standardisation (ISO) (2023) ISO/IEC 42001:2023 Artificial Intelligence — Management System. Geneva: ISO.
Infrastructure Australia (2024) 2024 Infrastructure Market Capacity Report. Sydney: Infrastructure Australia.
McKinsey Global Institute (2023) The Economic Potential of Generative AI: The Next Productivity Frontier. New York: McKinsey and Company. Available at: https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-economic-potential-of-generative-ai



Comments