Home · Framework

The 14-Dimension AI Security Framework

Four pillars. Fourteen dimensions. One operating model for AI governance — mapped to APRA CPS 230, CPS 234, AS ISO/IEC 42001, ASD ISM and AICD director-duty guidance.

LAST UPDATED 13 JUNE 2026 · FRAMEWORK v1.0
01 · Why this framework exists

Authored to fill a gap.

Australian boards are now formally accountable for AI under AICD director-duty guidance, APRA CPS 230, and AS ISO/IEC 42001. Existing AI frameworks define what to do — but rarely in a form a board can table, an auditor can defend, or an operator can use.

The Mycelium 14-Dimension AI Security Framework was authored to fill that gap. One operating model. Three practices. Evidence at every dimension.

02 · Four pillars

One operating model for AI.

The same four pillars sit behind every Mycelium Health Check, every Agent Build, and every Board Briefing.

DIM 01–05
Govern
  • Strategy & alignment
  • Accountability & ownership
  • Risk appetite & tolerance
  • Model governance
  • Vendor & third-party governance
DIM 06–09
Protect
  • Data governance & protection
  • Model security & integrity
  • Identity & access management
  • Supply chain & tooling security
DIM 10–12
Operate
  • Monitoring & observability
  • Incident response & recovery
  • Change & release management
DIM 13–14
Enable
  • Capability & skills
  • Culture & awareness
CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
03 · The 14 dimensions

Every dimension. What it covers.

Each dimension carries a control intent, an evidence expectation, and a clear pillar home. Together they form the scoring surface used in the AI Security Health Check.

Pillar I · Govern
DIM 01–05 · STRATEGY, ACCOUNTABILITY, RISK

The structural pillar. Names who is accountable, what the appetite is, and how AI is governed across its lifecycle.

D01
Strategy & alignment

AI strategy aligned to business strategy, with board-endorsed objectives, scope and explicit risk appetite.

D02
Accountability & ownership

Named board-level accountability for AI risk, with formal charter, RACI and reporting cadence.

D03
Risk appetite & tolerance

Explicit AI risk appetite, tolerance thresholds and escalation triggers, integrated with enterprise risk.

D04
Model governance

Lifecycle governance for AI models — approval gates, change control, performance review and decommissioning.

D05
Vendor & third-party governance

AI risk assessed at vendor onboarding and on annual re-certification cycle. Embedded AI explicitly covered.

Pillar II · Protect
DIM 06–09 · DATA, MODELS, ACCESS, SUPPLY CHAIN

The security pillar. Protects the data, the models, the access pathways and the upstream supply chain that feeds AI systems.

D06
Data governance & protection

Data lineage, classification, retention and protection for AI training and inference data.

D07
Model security & integrity

Protection against model tampering, data poisoning, model extraction and prompt injection.

D08
Identity & access management

Role-based access, least-privilege defaults, secrets management and segmentation for AI systems.

D09
Supply chain & tooling security

Provenance and integrity of models, libraries, datasets and tooling across the AI supply chain.

Pillar III · Operate
DIM 10–12 · MONITORING, INCIDENTS, CHANGE

The operational pillar. Covers the live-running discipline around AI systems — what you see, what you do when something breaks, how you change it safely.

D10
Monitoring & observability

Drift detection, performance baselines, anomaly alerting and audit logging on production AI systems.

D11
Incident response & recovery

AI-specific incident playbooks, kill-switch authority and tested rollback procedures.

D12
Change & release management

Controlled release process for AI model updates — documented testing, approval gates and rollback paths.

Pillar IV · Enable
DIM 13–14 · CAPABILITY, CULTURE

The human pillar. Without literacy and a healthy reporting culture, every other control degrades over time.

D13
Capability & skills

Role-specific AI literacy, including board-level training refreshed on regulatory change.

D14
Culture & awareness

Organisation-wide AI awareness, responsible use protocols and a healthy reporting culture.

04 · Standards mapping

Mapped to the standards your regulator reads.

Every dimension carries an explicit mapping to the Australian and international standards already in force or imminent. The framework is the bridge from your AI posture to your regulatory posture.

STD · 01

APRA CPS 230 · Operational Risk Management

In force. Names AI as material technology requiring board oversight and risk management. Anchors accountability, model governance and incident response.

PRIMARY: Govern · Operate  ·  SUPPORTS: Protect
STD · 02

APRA CPS 234 · Information Security

In force. Establishes board accountability for information security capabilities, including AI systems. Anchors the Protect pillar end-to-end.

PRIMARY: Protect  ·  SUPPORTS: Operate
STD · 03

AS ISO/IEC 42001 · AI Management System

Now an Australian standard. Defines management-system requirements for organisations using AI. Maps across all four pillars — the framework operationalises it for Australian boards.

PRIMARY: Govern · Protect · Operate · Enable
STD · 04

AICD Director-Duty Guidance on AI

Five major publications since 2024. Directly ties director duties of care and diligence to AI literacy, accountability and governance.

PRIMARY: Govern · Enable
STD · 05

Privacy Act 1988 (ADM 2026) · AI provisions

Expands obligations around automated decision-making, model transparency and consumer rights. Anchors data governance and accountability obligations.

PRIMARY: Govern · Protect  ·  SUPPORTS: Enable
STD · 06

NIST AI Risk Management Framework

The international reference. The Mycelium framework is structurally compatible with NIST AI RMF (Govern/Map/Measure/Manage) but mapped to Australian regulatory expectations.

CROSSWALK: Govern ↔ GOVERN · Protect ↔ MANAGE · Operate ↔ MEASURE · Enable ↔ MAP
STD · 07

ASD ISM · AI Controls (June 2026)

Australian Government Information Security Manual update. New AI-specific controls (ISM-2112 through 2123) covering human approval gates for risky actions, behavioural baselines and drift detection, shadow AI prevention, and secure prompt/output deletion. IRAP assessors will start demanding evidence against named controls.

PRIMARY: Protect · Operate  ·  SUPPORTS: Govern · Enable
04B · Standards mappings

One page per framework.

For Internal Audit, IRAP assessors and board sub-committees who need the trace in one walk. Each map shows where every named clause sits in the 14 dimensions — PRIMARY where the control lives natively, SUPPORTS where the dimension co-delivers it.

ISM × Mycelium 14-Dimension Framework mapping
ASD ISM · June 2026 update

ISM × 14-Dimension Framework

The new AI controls (ISM-2112 through 2123) mapped to the four pillars. For government, defence, critical infrastructure and IRAP-bound buyers.

PRIMARY: D06 · D09 · D10 · D12 · D04
Download as PDF ↓
APRA × Mycelium 14-Dimension Framework mapping
APRA · CPS Compendium

APRA × 14-Dimension Framework

CPS 220, 230 §§24-33, CPS 230 §§40-60, CPS 234, CPS 510 + CPG mapped. For CROs and CISOs at banks, insurers and superfunds defending controls to APRA.

PRIMARY: D02 · D05 · D06 · D07 · D08 · D10 · D11 · D12 · D14
Download as PDF ↓
NIST AI RMF × Mycelium 14-Dimension Framework mapping
NIST · AI Risk Management Framework

NIST AI RMF × 14-Dimension Framework

GOVERN, MAP, MEASURE and MANAGE functions mapped to the 14 dimensions. For boards comparing global frameworks and cross-border organisations.

PRIMARY: D01 · D02 · D03 · D04 · D05 · D06 · D07 · D08 · D10 · D11 · D12 · D13 · D14
Download as PDF ↓
OWASP LLM Top 10 × Mycelium 14-Dimension Framework mapping
OWASP · LLM Top 10 (2025)

OWASP LLM Top 10 × 14-Dimension Framework

All ten LLM-specific threats — prompt injection through unbounded consumption — mapped to the dimensions that govern them. For CISOs and AppSec teams.

PRIMARY: D06 · D07 · D08 · D09 · D10 · D11
Download as PDF ↓

Want to talk one through? Book a diagnostic call ↗

05 · How we use it

One framework. Three practices.

The framework is the operating model behind every Mycelium engagement. Each practice uses it differently — but the dimensions never move.

PRACTICE · 01

AI Security Health Check

A 4-week diagnostic that RAG-scores your organisation across all 14 dimensions. The framework provides the scoring surface, the evidence checklist and the standards mapping.

4 WEEKS · RAG-SCORED · BOARD-READY
See the Health Check ↗
PRACTICE · 02

AI Agent Build

Every agent is assessed at build time against the framework. The Approval Gate, Audit Log and Owner roles in the architecture map directly to D04, D10 and D02.

PER AGENT · AT BUILD · PRE-RELEASE
See the agent practice ↗
PRACTICE · 03

Board AI Briefing

Board literacy and posture briefings are anchored to the framework. Directors learn the four pillars; the board reads its posture against the 14 dimensions.

90-MIN BOARDROOM SESSION · POSTURE PACK
Download the Boardroom Diagnostic ↗
06 · Methodology

How dimensions are scored.

Every dimension is scored RAG against evidence, not opinion. The same scoring discipline is used across Health Check, Agent Build, and Board Briefing.

G · GREEN

In place. Evidenced.

Control is documented, owned, operating, and the evidence holds up to auditor review. Refreshed on the documented cadence.

A · AMBER

Partial. Untested.

Control is partially in place, or in place but not validated against the standard. Evidence exists but is incomplete, stale, or not consolidated.

R · RED

Missing. Material exposure.

Control is absent or fundamentally inadequate. Likely material exposure under CPS 230, ISO 42001 or director-duty obligations. Priority remediation item.

EVIDENCE TYPES

Each dimension expects evidence of one or more types: documented policy, operating artefact, system record, training record, tested procedure, or third-party attestation. The Detailed Findings Report names the evidence reviewed and the gaps observed, dimension by dimension.

REFRESH CADENCE · QUARTERLY · AT MATERIAL CHANGE · ON REGULATORY UPDATE
07 · Version & governance of the framework itself

Maintained. Versioned. Dated.

The framework is a living document. Updates are versioned, dated, and communicated to active clients. The Mycelium team maintains it against regulatory change so your posture stays current.

v1.0 · 8 JUN 2026

Initial public version. Four pillars established (Govern / Protect / Operate / Enable). Fourteen dimensions defined. Standards mapping established for APRA CPS 230, CPS 234, AS ISO/IEC 42001, ASD ISM (AI controls 2112-2123), IRAP, AICD director-duty guidance, Privacy Act 1988 (ADM 2026).

RAG scoring methodology codified. Evidence types defined. Refresh cadence published.

Next review scheduled for September 2026 in line with anticipated APRA AI prudential standard release.

08 · Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.

Book a diagnostic
30-MINUTE DIAGNOSTIC CALL · VIDEO OR MELBOURNE · BOOK DIRECTLY
Or download the Boardroom Diagnostic (PDF, 2 pages) ↗