The 14-Dimension AI Governance Framework™
Authored to fill a gap.
This framework was authored to close that gap: one operating model, an evidence expectation at every dimension, and a state rather than a colour at every finding.
Every dimension. What it covers.
- D01 · Strategy & alignment
- D02 · Accountability, ownership & transparency
- D03 · Risk appetite & tolerance
- D04 · Model governance
- D05 · Vendor & third-party governance
- D06 · Data governance, quality & protection
- D07 · Model security & integrity
- D08 · Identity & access management
- D09 · Supply chain & tooling security
- D10 · Monitoring & observability
- D11 · Incident response & recovery
- D12 · Change & release management
- D13 · Capability & skills
- D14 · Culture & awareness
Whether AI use is anchored to a stated business objective, whether AI is the right means to that objective, whether the anchor is reviewed, and whether the people the system acts on have been identified.
Who is named, at board and executive level, what happens when they leave, and what the organisation has told the people affected.
What the organisation has said it will and will not accept, in terms that can be tested, including which uses are out of bounds and how systems are tiered.
Lifecycle control over models: approval, validation, monitoring, retirement. Validation covers whether the model can be explained to the people it affects, and whether it has been tested for differential performance and at the volumes it will actually meet.
Vendor AI exposure, attestation, and the material service provider test.
Lineage, rights, quality, representativeness, classification, protection and disposal of the data AI consumes and produces.
Integrity of the model itself: poisoning, extraction, adversarial input, prompt handling, and whether anyone has tried it.
Who and what can reach the model, the data and the tooling, on what authority, and whether every non-human actor is separately identified and registered.
The libraries, weights, APIs and tooling in the path, who stands behind them, and which of them each agent may invoke.
What you can see while it is running, whether anyone is looking, and whether they can stop it.
What happens when it fails: authority, rollback, notification, recovery.
How changes reach production, and what stops one that should not.
Whether the people operating and approving AI understand what they are approving, and whether that was established before access was granted.
Whether someone who spots a problem will say so, whether anything happens when they do, and whether that includes the people the system acts on.
* Data is classified into Protect, and is a dependency of all four pillars.
* Agentic AI is not a fifteenth dimension. A single agent typically touches seven of the fourteen at once.
Mapped to the standards your regulator reads.
- 01
APRA CPS 230 · Operational Risk Management
In force since 1 July 2026. Remade by determination No. 1 of 2026 (F2026L00475), which revoked the 2023 determination under which the previous CPS 230 took effect on 1 July 2025. The 2026 standard adds a limited carve-out from certain contractual obligations for non-traditional service providers, and carries no transitional provision. CPS 230 does not name AI. AI is captured where it supports a critical operation, or where an AI vendor meets the material service provider test.
- 02
APRA CPS 234 · Information Security
In force since 1 July 2019. Establishes board accountability for information security capability. CPS 234 does not mention AI. In their joint information paper of 27 August 2026 APRA and ASIC name CPS 234 as a resource for frontier AI preparedness, which is the closest either regulator has come in print to connecting the two. Treating an AI system as an information asset under CPS 234 remains Mycelium’s application of the standard, not APRA’s stated position.
- 03
AS ISO/IEC 42001 · AI Management System
Adopted in Australia. Management-system requirements for organisations developing, providing or using AI. The Mycelium framework is mapped to it across all four pillars; it is not derived from it, and the dimensions are independently authored.
- 04
AICD director-duty guidance on AI
A Director’s Guide to AI Governance Version 2, June 2026, AICD with the UTS Human Technology Institute. Ties directors’ existing duties under the Corporations Act 2001 (Cth) to AI literacy and oversight. See also AICD–ASD Board Guidance on frontier AI cyber threats, 3 August 2026.
- 05
Guidance for AI Adoption · six essential practices
Published 21 October 2025 by the National AI Centre, within the Department of Industry, Science and Resources. It evolves and replaces the 2024 Voluntary AI Safety Standard, condensing its ten guardrails into six practices: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. Issued in two tiers — Foundations, and Implementation Practices for more complex or higher-risk systems. Practice six is the approval gate this framework is built around.
- 06
Privacy Act 1988 (Cth) · automated decision-making
From 10 December 2026, a caught privacy policy must disclose three things: the kinds of personal information used in the operation of such computer programs; the kinds of decisions made solely by them; and the kinds of decisions for which a thing substantially and directly related to making the decision is done by them. Australian Privacy Principles 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth). The trigger is a computer program, not “AI” — it captures deterministic rules engines too. It reaches decisions made after commencement even where the arrangement behind them pre-dates it.
- 07
NIST AI Risk Management Framework 1.0
AI RMF 1.0 (2023), currently under revision. GOVERN is cross-cutting rather than a peer function, so the crosswalk is many-to-many at subcategory level. NIST publishes no coverage percentages, and states that crosswalked inclusion does not imply comprehensive coverage either way.
- 08
ASD ISM · AI controls
The ISM states that an organisation is not required as a matter of law to comply with it unless legislation, or a direction given under legislation or by some other lawful authority, compels them to comply. The PSPF pathway reaches non-corporate Commonwealth entities; for corporate Commonwealth entities and Commonwealth companies the PSPF represents better practice, and others are reached only where a deed or agreement says so. An IRAP assessment does not change that: ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. Released on an approximately quarterly cycle.
- 09
EU AI Act · Regulation (EU) 2024/1689
Not Australian law, and not confined to entities in Europe. Article 2(1)(a) applies to providers placing an AI system, or a general-purpose AI model, on the Union market “irrespective of whether those providers are established or located within the Union or in a third country”. Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. Amendment is in progress: the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force 27 July 2026 and moved the high-risk requirements to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Scope is established per entity and per limb, and dated.
- 10
PSPF Release 2026 · Artificial Intelligence
Published 1 July 2026 by the Department of Home Affairs. Section 13.10.1 maps existing PSPF Requirements onto AI technology systems, including Requirement 0086 to authorise an AI technology system to operate, Requirement 0049 where the AI technology is not Australian owned and operated, and the procurement and contract requirements at Section 6.1. Non-corporate Commonwealth entities must apply the PSPF in accordance with section 21 of the PGPA Act; it represents better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. Not all of it is risk-based: Requirements 0099 to 0106 mandate all eight Essential Eight mitigation strategies at Maturity Level Two.
- 11
APRA and ASIC · Resilience at Frontier AI Speed
Joint information paper, 27 August 2026. Published after nine industry roundtables held in June and July 2026 with more than 380 entities and 600 attendees, supported by the Australian Signals Directorate, with the Reserve Bank, Treasury and the ACCC participating. It follows APRA’s letter to industry of 30 April 2026 and ASIC’s of May 2026, and restates their expectations rather than creating new ones. Appendix 1 names CPS 230 and CPS 234 as resources entities may consider when strengthening frontier AI preparedness. Appendix 2 sets out board questions and, against each, what the regulators describe as evidence of preparedness.
One document per framework.
ISM × 14-Dimension Framework
For government, defence, critical infrastructure and IRAP-assessed environments.
Open the mapping ↗APRA × 14-Dimension Framework
CPS 220, 230, 234 and 510 mapped to the requirements each one carries, alongside APRA’s letter to industry on artificial intelligence, 30 April 2026. For CROs and CISOs at banks and insurers.
Open the mapping ↗NIST AI RMF 1.0 × 14-Dimension Framework
For boards comparing global frameworks, and for cross-border organisations.
Open the mapping ↗OWASP LLM Top 10 × 14-Dimension Framework
The ten application-layer risks of the 2026 edition, published 4 August 2026, mapped to the dimensions that govern them. For CISOs and AppSec teams.
Open the mapping ↗Superannuation. CPS 230 and CPS 234 bind RSE licensees. CPS 220 and CPS 510 do not: both carry a note excluding RSE licensees, and SPS 220 and SPS 510 apply instead. The APRA mapping is written for ADIs and insurers, so a trustee reading it should treat two of the four columns as indicative only. Prudential standards read 23 September 2026 against the Federal Register. CPS 220, CPS 230, CPS 234 and CPS 510 are each in force on their as-made text. A revised CPS 510 has been in consultation since 16 June 2026 and is not yet made.
How dimensions are scored.
| State | Means |
|---|---|
| Absent | Assessed. No evidence exists. |
| Partial | Evidence exists but is incomplete, untested or stale. |
| Evidenced | Complete evidence, reviewed by a named human. |
| Attested | Evidenced, and signed by the named owner. |
| Approved | Attested, and accepted by the board or committee. |
| Superseded | Replaced by a later record. Retained, never deleted. |
Mycelium’s method is that a policy on its own does not reach Evidenced, the dimension has to show the control operating, on a date, reviewed by someone named. Each dimension carries its own evidence expectation, set before we look at yours. Refreshed quarterly, at material change, and on regulatory update.
Nothing published undated.
Superseded versions are retained, never deleted, and are available to clients on request.
The first call is diagnostic.
Thirty minutes. No pitch. No proposal until it makes sense.