
Establishing an AI register is an important first step towards responsible AI governance, but it is not a one-off exercise.
AI use changes quickly. New systems are introduced, existing platforms gain AI capabilities and business areas find new ways to use tools already in place. Without regular review, an AI register can quickly become incomplete or outdated.
Organisations must ensure their registers continue to capture all AI use, contain the appropriate governance information and remain aligned with current Australian Government guidance.
Recent findings from the NSW Audit Office demonstrate why this matters.
The Australian Government’s Guidance for AI Adoption: Foundations recommends maintaining an AI register containing the AI systems an organisation uses, including their key characteristics, use cases, accountable people and appropriate level of governance.
As discussed in our previous article, Why Every Organisation Needs an AI Register, this central record provides visibility of where AI is being used, why it is being used and who is accountable for it.
However, creating the register is only the beginning. Its effectiveness depends on whether it captures the full extent of AI use and remains accurate as systems, capabilities and organisational practices evolve.
The NSW Audit Office’s Internal controls and governance 2026 report examined technology governance at ten NSW Government agencies with more significant AI use.
All ten agencies maintained an AI register, but only six captured all AI use. The remaining four recorded only the AI use that had been assessed under the NSW AI Assessment Framework, leaving other uses outside their registers.
The audit also found:
The report noted that the NSW AI Assessment Framework should be applied across the lifecycle of an AI solution. Existing AI solutions must therefore be considered as part of ongoing governance, not only when they are first introduced.
The findings highlight an important lesson: an AI register is only effective when it provides a complete and current view of AI across the organisation.
AI use rarely remains static.
A system recorded when the register is first created may later introduce new AI capabilities, begin using different information or support additional business processes. New tools may be purchased by individual business units, while AI can also be activated through software updates or embedded in services supplied by third parties.
Staff may begin using freely available generative AI tools without formal approval or use an approved platform for a purpose that has not been assessed.
Without an ongoing discovery and review process, an AI register may list formally approved projects without capturing the full range of AI that is actually in use.
Keeping the register current requires input from technology, information management, cybersecurity, privacy, procurement, legal, finance and individual business areas. It also requires clear processes for reporting new, changed and retired AI uses.
A useful AI register must contain enough information to support governance, assurance and decision-making. At a minimum, organisations should consider the following information for every AI system or use case.
Record the name of the system, the AI capability it provides and the business purpose for which it is used.
The register should distinguish between the software product and its individual use cases. One system may be used for several purposes, each involving different information, risks and governance requirements.
Identify the business owner, system owner and the person or role accountable for each AI use.
Accountability must remain clear even when the system is supplied, hosted or operated by an external provider.
Record whether the AI use is proposed, being trialled, in development, operational, suspended or retired.
This helps ensure appropriate governance is applied throughout the lifecycle rather than only when a system is first approved.
Document the information used to train, configure, prompt or operate the system.
This should include whether it handles personal, sensitive, security-classified or confidential information and whether organisational information may be retained or used to train an external provider’s models.
Identify the records produced by the AI system and those needed to demonstrate how it has been used.
These may include assessments, approvals, prompts, outputs, decisions, human reviews, system logs, model versions and configuration changes.
The records may be required to explain decisions, respond to complaints, support audits or demonstrate compliance.
Link each entry to relevant privacy, cybersecurity, ethical, legal, procurement and AI impact assessments.
The register should indicate whether each assessment has been completed, any actions arising from it and when it must next be reviewed.
Capture the provider, contract owner, licensing model, hosting arrangements and relevant contractual conditions.
Organisations should understand how suppliers store and use their information, how changes to the system are communicated and what happens to organisational data when the contract ends.
Record procurement, licensing, implementation and ongoing consumption costs where possible.
As AI pricing increasingly moves towards usage-based models, central visibility can help organisations identify unexpected expenditure, duplicate services and opportunities for consolidation.
Explain where people remain involved in reviewing AI outputs or making decisions.
The register should identify who performs this oversight, what they are expected to check and how the review is documented - particularly where a process could affect people’s rights, obligations or access to services.
Assign a review date and document how the system and its information will be managed when it is replaced or retired.
This includes retaining required records, exporting organisational information, removing access and confirming that suppliers have securely returned or deleted information where required.
An AI register should be treated as a governed information asset and an ongoing organisational process, not a spreadsheet created once and then forgotten.
Regular reviews help ensure the register continues to capture all AI use and the information recommended by Australian Government guidance.
A quarterly review process could include:
The register should also be integrated into existing organisational processes. Procurement, project initiation, privacy assessments, cybersecurity reviews, information asset management, contract renewal and system retirement should all prompt a review or update.
The NSW audit findings provide a timely reminder that creating an AI register does not automatically provide complete visibility of AI use.
A reliable register must be comprehensive, current and connected to the organisation’s wider governance processes. It must capture more than formally approved AI projects and continue to evolve as systems, suppliers, risks and government guidance change.
FYB’s AI Register Development Service helps organisations establish, review and strengthen their AI registers in line with Australian Government guidance.
We work with your organisation to identify approved, embedded, third-party and potentially unapproved AI use; capture the appropriate governance information; and establish a sustainable process for keeping the register complete and current.
Whether your organisation is creating its first AI register or reviewing an existing one, FYB can help ensure it provides a reliable foundation for responsible AI governance.
