August 5, 2026

How Government Organisations Can Maintain an Effective AI Register

More Info

Establishing an AI register is an important first step towards responsible AI governance, but it is not a one-off exercise.

AI use changes quickly. New systems are introduced, existing platforms gain AI capabilities and business areas find new ways to use tools already in place. Without regular review, an AI register can quickly become incomplete or outdated.

Organisations must ensure their registers continue to capture all AI use, contain the appropriate governance information and remain aligned with current Australian Government guidance.

Recent findings from the NSW Audit Office demonstrate why this matters.

Having an AI register is only the beginning

The Australian Government’s Guidance for AI Adoption: Foundations recommends maintaining an AI register containing the AI systems an organisation uses, including their key characteristics, use cases, accountable people and appropriate level of governance.

As discussed in our previous article, Why Every Organisation Needs an AI Register, this central record provides visibility of where AI is being used, why it is being used and who is accountable for it.

However, creating the register is only the beginning. Its effectiveness depends on whether it captures the full extent of AI use and remains accurate as systems, capabilities and organisational practices evolve.

What the NSW audit found

The NSW Audit Office’s Internal controls and governance 2026 report examined technology governance at ten NSW Government agencies with more significant AI use.

All ten agencies maintained an AI register, but only six captured all AI use. The remaining four recorded only the AI use that had been assessed under the NSW AI Assessment Framework, leaving other uses outside their registers.

The audit also found:

  • Only half of the agencies had a formal AI strategy.
  • Only half had an agency-level AI policy.
  • Only five had reviewed their risk management frameworks in response to AI.
  • Only one had considered AI in procurement documentation and contractual arrangements.
  • Most did not centrally track AI expenditure or establish AI budgets.
  • Of the 15 AI projects reviewed, 13 had been assessed under the NSW AI Assessment Framework.
  • Four of the 15 projects had not undergone a cyber risk assessment.

The report noted that the NSW AI Assessment Framework should be applied across the lifecycle of an AI solution. Existing AI solutions must therefore be considered as part of ongoing governance, not only when they are first introduced.

The findings highlight an important lesson: an AI register is only effective when it provides a complete and current view of AI across the organisation.

Why AI registers need to be regularly reviewed

AI use rarely remains static.

A system recorded when the register is first created may later introduce new AI capabilities, begin using different information or support additional business processes. New tools may be purchased by individual business units, while AI can also be activated through software updates or embedded in services supplied by third parties.

Staff may begin using freely available generative AI tools without formal approval or use an approved platform for a purpose that has not been assessed.

Without an ongoing discovery and review process, an AI register may list formally approved projects without capturing the full range of AI that is actually in use.

Keeping the register current requires input from technology, information management, cybersecurity, privacy, procurement, legal, finance and individual business areas. It also requires clear processes for reporting new, changed and retired AI uses.

What should an AI register capture?

A useful AI register must contain enough information to support governance, assurance and decision-making. At a minimum, organisations should consider the following information for every AI system or use case.

1. System and purpose

Record the name of the system, the AI capability it provides and the business purpose for which it is used.

The register should distinguish between the software product and its individual use cases. One system may be used for several purposes, each involving different information, risks and governance requirements.

2. Ownership and accountability

Identify the business owner, system owner and the person or role accountable for each AI use.

Accountability must remain clear even when the system is supplied, hosted or operated by an external provider.

3. Status and lifecycle stage

Record whether the AI use is proposed, being trialled, in development, operational, suspended or retired.

This helps ensure appropriate governance is applied throughout the lifecycle rather than only when a system is first approved.

4. Data and information sources

Document the information used to train, configure, prompt or operate the system.

This should include whether it handles personal, sensitive, security-classified or confidential information and whether organisational information may be retained or used to train an external provider’s models.

5. Records created

Identify the records produced by the AI system and those needed to demonstrate how it has been used.

These may include assessments, approvals, prompts, outputs, decisions, human reviews, system logs, model versions and configuration changes.

The records may be required to explain decisions, respond to complaints, support audits or demonstrate compliance.

6. Risk and assurance assessments

Link each entry to relevant privacy, cybersecurity, ethical, legal, procurement and AI impact assessments.

The register should indicate whether each assessment has been completed, any actions arising from it and when it must next be reviewed.

7. Procurement and supplier information

Capture the provider, contract owner, licensing model, hosting arrangements and relevant contractual conditions.

Organisations should understand how suppliers store and use their information, how changes to the system are communicated and what happens to organisational data when the contract ends.

8. Costs and resource requirements

Record procurement, licensing, implementation and ongoing consumption costs where possible.

As AI pricing increasingly moves towards usage-based models, central visibility can help organisations identify unexpected expenditure, duplicate services and opportunities for consolidation.

9. Human oversight

Explain where people remain involved in reviewing AI outputs or making decisions.

The register should identify who performs this oversight, what they are expected to check and how the review is documented - particularly where a process could affect people’s rights, obligations or access to services.

10. Review and retirement

Assign a review date and document how the system and its information will be managed when it is replaced or retired.

This includes retaining required records, exporting organisational information, removing access and confirming that suppliers have securely returned or deleted information where required.

Treat the register as an ongoing governance process

An AI register should be treated as a governed information asset and an ongoing organisational process, not a spreadsheet created once and then forgotten.

Regular reviews help ensure the register continues to capture all AI use and the information recommended by Australian Government guidance.

A quarterly review process could include:

  1. Asking business areas to confirm new, changed and retired AI uses.
  2. Reviewing technology purchases, software updates and procurement activity for embedded AI.
  3. Identifying third-party and potentially unapproved AI use.
  4. Checking that required risk and assurance assessments have been completed.
  5. Confirming that system owners and accountable roles remain current.
  6. Reviewing changes to information use, suppliers, costs and human oversight.
  7. Recording decisions and required follow-up actions.
  8. Reporting significant risks or gaps to the appropriate governance body.

The register should also be integrated into existing organisational processes. Procurement, project initiation, privacy assessments, cybersecurity reviews, information asset management, contract renewal and system retirement should all prompt a review or update.

Is your AI register still fit for purpose?

The NSW audit findings provide a timely reminder that creating an AI register does not automatically provide complete visibility of AI use.

A reliable register must be comprehensive, current and connected to the organisation’s wider governance processes. It must capture more than formally approved AI projects and continue to evolve as systems, suppliers, risks and government guidance change.

FYB’s AI Register Development Service helps organisations establish, review and strengthen their AI registers in line with Australian Government guidance.

We work with your organisation to identify approved, embedded, third-party and potentially unapproved AI use; capture the appropriate governance information; and establish a sustainable process for keeping the register complete and current.

Whether your organisation is creating its first AI register or reviewing an existing one, FYB can help ensure it provides a reliable foundation for responsible AI governance.

Contact us

Request a demo

Thank you! Your submission has been received and an FYB Team Member will be in contact soon.
Oops! Something went wrong while submitting the form.

Request a demo

Thank you! Your submission has been received and an FYB Team Member will be in contact soon.
Oops! Something went wrong while submitting the form.

Access Power Automate Masterclass on demand

Learn how to streamline repetitive processes and ensure you are meeting recordkeeping compliance requirements with Microsoft Power Automate, Power2CM and Micro Focus Content Manager.
Thank you, a link to access the resource will arrive in your inbox soon.

In the meantime, check our our blog for more helpful resources.
Oops! Something went wrong while submitting the form.

Our Other Blogs

What Records and Information Professionals Told Us About Microsoft 365 Governance in 2026
OpenText Content Manager 26.2 Release
Bridging the Gap Between Microsoft 365 and Content Manager