Tuned to APRA CPS 230, CPS 234, CPS 220 and AFSL obligations. Heavy emphasis on vendor AI risk and customer-facing decisioning.
Download Boardroom Diagnostic · HC-BNK v1.0 ↗A 4-week diagnostic across 14 dimensions and 4 pillars. RAG-scored, evidence-graded, designed for board, audit and regulator conversations.
Designed to sit on a board table without further translation.
One page. RAG-scored across 14 dimensions and 4 pillars. The artefact your Chair can read in three minutes and your risk committee can table the same day.
10–15 pages. Evidence, findings, prioritised remediation roadmap, control owners, standards mapping. The artefact your auditor and CISO will work from.
| Dimension | Govern | Protect | Operate | Enable |
|---|---|---|---|---|
| D01 Strategy & alignment | A | |||
| D02 Accountability & ownership | R | |||
| D03 Risk appetite & tolerance | G | |||
| D04 Model governance | A | |||
| D05 Vendor & third-party governance | R | |||
| D06 Data governance & protection | G | |||
| D07 Model security & integrity | A | |||
| D08 Identity & access management | G | |||
| D09 Supply chain & tooling security | A | |||
| D10 Monitoring & observability | A | |||
| D11 Incident response & recovery | R | |||
| D12 Change & release management | A | |||
| D13 Capability & skills | G | |||
| D14 Culture & awareness | A |
Each dimension is scored RAG against the Mycelium AI Security Framework, mapped explicitly to APRA CPS 230, CPS 234 and AS ISO/IEC 42001.
AI strategy aligned to business strategy, with board-endorsed objectives, scope and explicit risk appetite.
Named board-level accountability for AI risk, with formal charter, RACI and reporting cadence.
Explicit AI risk appetite, tolerance thresholds and escalation triggers, integrated with enterprise risk.
Lifecycle governance for AI models — approval gates, change control, performance review and decommissioning.
AI risk assessed at vendor onboarding and on annual re-certification cycle. Embedded AI explicitly covered.
Data lineage, classification, retention and protection for AI training and inference data.
Protection against model tampering, data poisoning, model extraction and prompt injection.
Role-based access, least-privilege defaults, secrets management and segmentation for AI systems.
Provenance and integrity of models, libraries, datasets and tooling across the AI supply chain.
Drift detection, performance baselines, anomaly alerting and audit logging on production AI systems.
AI-specific incident playbooks, kill-switch authority and tested rollback procedures.
Controlled release process for AI model updates — documented testing, approval gates and rollback paths.
Role-specific AI literacy, including board-level training refreshed on regulatory change.
Organisation-wide AI awareness, responsible use protocols and a healthy reporting culture.
A diagnostic, not a consulting engagement. Fixed scope. Fixed timeline. Fixed deliverables.
Executive interviews, scope confirmation, evidence-request schedule. Stakeholder map agreed.
Document review, control walkthroughs, system inventory, frontline input. Artefacts collected.
RAG scoring across 14 dimensions. Findings drafted. Priority items identified.
Executive Scorecard finalised. Detailed Findings Report delivered. Board read-out optional.
Core 14 dimensions are constant. Evidence requirements and standards mapping are tuned to your sector.
Tuned to APRA CPS 230, CPS 234, CPS 220 and AFSL obligations. Heavy emphasis on vendor AI risk and customer-facing decisioning.
Download Boardroom Diagnostic · HC-BNK v1.0 ↗Tuned to SOCI Act, CIRMP, AEMO and AESCSF. Heavy emphasis on operational technology AI, grid events and control-system safety.
Download Boardroom Diagnostic · HC-ENG v1.0 ↗Cross-sector edition for organisations spanning regulated industries, or where the sector edition is in development.
Download Boardroom Diagnostic · HC-MST v2.0 ↗An Executive Scorecard your Chair can table at the next risk committee.
A Detailed Findings Report your CISO and internal audit can work from immediately.
A defensible position before the auditor walks in or the regulator asks.
Thirty minutes. No pitch. No proposal until it makes sense.
Book a diagnostic