Home · Framework
The system

The 14-Dimension AI Governance Framework™

Four pillars. Fourteen dimensions. One operating model for AI governance: mapped to the standards your board, your auditor and your regulator are already reading.
01 · Why it exists

Authored to fill a gap.

The AICD, with the UTS Human Technology Institute, holds that board oversight of AI forms part of directors’ existing duties under the Corporations Act. APRA wrote to industry on artificial intelligence on 30 April 2026, setting supervisory expectations rather than new requirements. Existing frameworks define what good looks like; few do it in a form a board can table and an auditor can follow.

This framework was authored to close that gap: one operating model, an evidence expectation at every dimension, and a state rather than a colour at every finding.

02 · The fourteen dimensions

Every dimension. What it covers.

Four pillars, fourteen dimensions. Behind each sits a control intent and an evidence expectation, applied in the diagnostic and reported back dimension by dimension.
I · Govern
D01–D05
  • D01 · Strategy & alignment
  • D02 · Accountability, ownership & transparency
  • D03 · Risk appetite & tolerance
  • D04 · Model governance
  • D05 · Vendor & third-party governance
II · Protect
D06–D09
  • D06 · Data governance, quality & protection
  • D07 · Model security & integrity
  • D08 · Identity & access management
  • D09 · Supply chain & tooling security
III · Operate
D10–D12
  • D10 · Monitoring & observability
  • D11 · Incident response & recovery
  • D12 · Change & release management
IV · Enable
D13–D14
  • D13 · Capability & skills
  • D14 · Culture & awareness
D01
Strategy & alignment

Whether AI use is anchored to a stated business objective, whether AI is the right means to that objective, whether the anchor is reviewed, and whether the people the system acts on have been identified.

D02
Accountability, ownership & transparency

Who is named, at board and executive level, what happens when they leave, and what the organisation has told the people affected.

D03
Risk appetite & tolerance

What the organisation has said it will and will not accept, in terms that can be tested, including which uses are out of bounds and how systems are tiered.

D04
Model governance

Lifecycle control over models: approval, validation, monitoring, retirement. Validation covers whether the model can be explained to the people it affects, and whether it has been tested for differential performance and at the volumes it will actually meet.

D05
Vendor & third-party governance

Vendor AI exposure, attestation, and the material service provider test.

D06
Data governance, quality & protection

Lineage, rights, quality, representativeness, classification, protection and disposal of the data AI consumes and produces.

D07
Model security & integrity

Integrity of the model itself: poisoning, extraction, adversarial input, prompt handling, and whether anyone has tried it.

D08
Identity & access management

Who and what can reach the model, the data and the tooling, on what authority, and whether every non-human actor is separately identified and registered.

D09
Supply chain & tooling security

The libraries, weights, APIs and tooling in the path, who stands behind them, and which of them each agent may invoke.

D10
Monitoring & observability

What you can see while it is running, whether anyone is looking, and whether they can stop it.

D11
Incident response & recovery

What happens when it fails: authority, rollback, notification, recovery.

D12
Change & release management

How changes reach production, and what stops one that should not.

D13
Capability & skills

Whether the people operating and approving AI understand what they are approving, and whether that was established before access was granted.

D14
Culture & awareness

Whether someone who spots a problem will say so, whether anything happens when they do, and whether that includes the people the system acts on.

* Data is classified into Protect, and is a dependency of all four pillars.

* Agentic AI is not a fifteenth dimension. A single agent typically touches seven of the fourteen at once.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF 1.0 · AICD · Guidance for AI Adoption · Privacy Act 1988 (Cth) · APP 1.7 · EU AI Act
03 · Standards mapping

Mapped to the standards your regulator reads.

Each instrument below is labelled by what it actually is: binding legislation, a prudential standard, a voluntary standard, or regulator guidance. These are not the same kind of obligation and the site does not group them as though they were. Where a claim rests on our own analysis rather than a regulator’s published statement, we say so.
  • 01

    APRA CPS 230 · Operational Risk Management

    In force since 1 July 2026. Remade by determination No. 1 of 2026 (F2026L00475), which revoked the 2023 determination under which the previous CPS 230 took effect on 1 July 2025. The 2026 standard adds a limited carve-out from certain contractual obligations for non-traditional service providers, and carries no transitional provision. CPS 230 does not name AI. AI is captured where it supports a critical operation, or where an AI vendor meets the material service provider test.

  • 02

    APRA CPS 234 · Information Security

    In force since 1 July 2019. Establishes board accountability for information security capability. CPS 234 does not mention AI. In their joint information paper of 27 August 2026 APRA and ASIC name CPS 234 as a resource for frontier AI preparedness, which is the closest either regulator has come in print to connecting the two. Treating an AI system as an information asset under CPS 234 remains Mycelium’s application of the standard, not APRA’s stated position.

  • 03

    AS ISO/IEC 42001 · AI Management System

    Adopted in Australia. Management-system requirements for organisations developing, providing or using AI. The Mycelium framework is mapped to it across all four pillars; it is not derived from it, and the dimensions are independently authored.

  • 04

    AICD director-duty guidance on AI

    A Director’s Guide to AI Governance Version 2, June 2026, AICD with the UTS Human Technology Institute. Ties directors’ existing duties under the Corporations Act 2001 (Cth) to AI literacy and oversight. See also AICD–ASD Board Guidance on frontier AI cyber threats, 3 August 2026.

  • 05

    Guidance for AI Adoption · six essential practices

    Published 21 October 2025 by the National AI Centre, within the Department of Industry, Science and Resources. It evolves and replaces the 2024 Voluntary AI Safety Standard, condensing its ten guardrails into six practices: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. Issued in two tiers — Foundations, and Implementation Practices for more complex or higher-risk systems. Practice six is the approval gate this framework is built around.

  • 06

    Privacy Act 1988 (Cth) · automated decision-making

    From 10 December 2026, a caught privacy policy must disclose three things: the kinds of personal information used in the operation of such computer programs; the kinds of decisions made solely by them; and the kinds of decisions for which a thing substantially and directly related to making the decision is done by them. Australian Privacy Principles 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth). The trigger is a computer program, not “AI” — it captures deterministic rules engines too. It reaches decisions made after commencement even where the arrangement behind them pre-dates it.

  • 07

    NIST AI Risk Management Framework 1.0

    AI RMF 1.0 (2023), currently under revision. GOVERN is cross-cutting rather than a peer function, so the crosswalk is many-to-many at subcategory level. NIST publishes no coverage percentages, and states that crosswalked inclusion does not imply comprehensive coverage either way.

  • 08

    ASD ISM · AI controls

    The ISM states that an organisation is not required as a matter of law to comply with it unless legislation, or a direction given under legislation or by some other lawful authority, compels them to comply. The PSPF pathway reaches non-corporate Commonwealth entities; for corporate Commonwealth entities and Commonwealth companies the PSPF represents better practice, and others are reached only where a deed or agreement says so. An IRAP assessment does not change that: ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. Released on an approximately quarterly cycle.

  • 09

    EU AI Act · Regulation (EU) 2024/1689

    Not Australian law, and not confined to entities in Europe. Article 2(1)(a) applies to providers placing an AI system, or a general-purpose AI model, on the Union market “irrespective of whether those providers are established or located within the Union or in a third country”. Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. Amendment is in progress: the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force 27 July 2026 and moved the high-risk requirements to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Scope is established per entity and per limb, and dated.

  • 10

    PSPF Release 2026 · Artificial Intelligence

    Published 1 July 2026 by the Department of Home Affairs. Section 13.10.1 maps existing PSPF Requirements onto AI technology systems, including Requirement 0086 to authorise an AI technology system to operate, Requirement 0049 where the AI technology is not Australian owned and operated, and the procurement and contract requirements at Section 6.1. Non-corporate Commonwealth entities must apply the PSPF in accordance with section 21 of the PGPA Act; it represents better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. Not all of it is risk-based: Requirements 0099 to 0106 mandate all eight Essential Eight mitigation strategies at Maturity Level Two.

  • 11

    APRA and ASIC · Resilience at Frontier AI Speed

    Joint information paper, 27 August 2026. Published after nine industry roundtables held in June and July 2026 with more than 380 entities and 600 attendees, supported by the Australian Signals Directorate, with the Reserve Bank, Treasury and the ACCC participating. It follows APRA’s letter to industry of 30 April 2026 and ASIC’s of May 2026, and restates their expectations rather than creating new ones. Appendix 1 names CPS 230 and CPS 234 as resources entities may consider when strengthening frontier AI preparedness. Appendix 2 sets out board questions and, against each, what the regulators describe as evidence of preparedness.

04 · Standards mappings

One document per framework.

For Internal Audit, IRAP assessors and board sub-committees who need the trace in a single walk. Sent on request to a work email. APRA, NIST and OWASP are issued at Mapping v2.0, August 2026. The ISM mapping is at v2.1, September 2026, against ASD’s September release.
ASD ISM

ISM × 14-Dimension Framework

For government, defence, critical infrastructure and IRAP-assessed environments.

Open the mapping ↗
APRA

APRA × 14-Dimension Framework

CPS 220, 230, 234 and 510 mapped to the requirements each one carries, alongside APRA’s letter to industry on artificial intelligence, 30 April 2026. For CROs and CISOs at banks and insurers.

Open the mapping ↗
NIST

NIST AI RMF 1.0 × 14-Dimension Framework

For boards comparing global frameworks, and for cross-border organisations.

Open the mapping ↗
OWASP

OWASP LLM Top 10 × 14-Dimension Framework

The ten application-layer risks of the 2026 edition, published 4 August 2026, mapped to the dimensions that govern them. For CISOs and AppSec teams.

Open the mapping ↗

Superannuation. CPS 230 and CPS 234 bind RSE licensees. CPS 220 and CPS 510 do not: both carry a note excluding RSE licensees, and SPS 220 and SPS 510 apply instead. The APRA mapping is written for ADIs and insurers, so a trustee reading it should treat two of the four columns as indicative only. Prudential standards read 23 September 2026 against the Federal Register. CPS 220, CPS 230, CPS 234 and CPS 510 are each in force on their as-made text. A revised CPS 510 has been in consultation since 16 June 2026 and is not yet made.

05 · Methodology

How dimensions are scored.

Mycelium does not use red, amber and green. A colour that means “bad” tells a board how to feel; a state tells them what exists. These are the same marks used in the platform, the board pack and the Academy, because they are the same record.
Evidence states used in scoring.
StateMeans
AbsentAssessed. No evidence exists.
PartialEvidence exists but is incomplete, untested or stale.
EvidencedComplete evidence, reviewed by a named human.
AttestedEvidenced, and signed by the named owner.
ApprovedAttested, and accepted by the board or committee.
SupersededReplaced by a later record. Retained, never deleted.
What counts as evidence

Mycelium’s method is that a policy on its own does not reach Evidenced, the dimension has to show the control operating, on a date, reviewed by someone named. Each dimension carries its own evidence expectation, set before we look at yours. Refreshed quarterly, at material change, and on regulatory update.

06 · Version

Nothing published undated.

CURRENTFramework v2.0Approved
PUBLISHED15 August 2026Approved
NEXT REVIEWNovember 2026, and on regulatory changePending

Superseded versions are retained, never deleted, and are available to clients on request.

Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.