An AI project is not ready when the model works
A working model answers whether the system can run. An evidence record answers whether the organisation can defend running it — and that is the project milestone regulators are moving toward.
Most AI project plans have a launch milestone and a model owner. Far fewer have a durable record that shows what was approved, what was tested, who can stop the system, and what changed after it went live.
That gap matters because the assurance question is changing. A project is not evidence-ready because its policy exists or its model card is complete. It is evidence-ready when somebody can reconstruct the control decision from dated artefacts without relying on the project team's memory.

The milestone that matters is not launch
Launch proves that a system can run. It does not prove that the organisation understood the use, made a proportionate decision, tested the controls, or kept watching when the system changed.
That is the distinction in two 2026 Australian regulator interventions. APRA's letter to industry said point-in-time and sample-based assurance methods are ill-suited to probabilistic models that learn, adapt and degrade over time. ASIC's cyber-resilience letter made the complementary point: governance should be supported by evidence, including test results, audit findings, incident lessons and independent validation.
Governance should not rely only on assurances. It should be supported by evidence — test results, audit findings, lessons from incidents, and independent validation.
The operational implication is simple: the project record has to survive the people who created it. If the only answer to “why did we approve this?” is a meeting that happened six months ago, the control is not yet durable.
What an evidence-ready project contains
An evidence-ready record is not a giant questionnaire. It is a small chain of linked decisions and artefacts:
- Identity. What the system does, which model or vendor it uses, what data it touches, and who owns it in operation.
- Decision. What risk was identified, who approved the use, what conditions were attached, and where the assessment is stored.
- Test. Which control was tested, when it was tested, what happened, and who reviewed the result.
- Change. What changed in the model, prompt, data, vendor or surrounding workflow, and whether that change reopened the assessment.
- Challenge. How a person can contest an outcome, how a human can intervene, and what happens to the record when an issue is raised.
Ready to build
- A named sponsor and a promising use case
- A model selected for the workflow
- A policy link in the project folder
Ready to defend
- A named operational owner and stop authority
- A dated approval tied to a specific system
- A test result, monitoring record and change path
The difference is not bureaucracy for its own sake. It is the difference between describing an intention and showing that the intention operated.
The short assessment still needs a long memory
NSW's modernised AI Assessment Framework is a useful example of the distinction. The redesigned flow reduced the low-risk assessment to 16 questions and about 15 minutes; higher-risk uses are flagged for additional review. The Digital NSW explanation also says high- and critical-risk uses must be referred to the AI Review Committee within five business days of completing the assessment.
16
questions in the modernised low-risk AIAF flow
Digital NSW, 27 Jan 2026
5 days
maximum referral window for high- and critical-risk uses
Digital NSW AIAF guidance
30 Jun 2027
Audit Office recommendation for agencies to assess all required AI solutions
Audit Office of NSW, Aug 2026
The lesson for a private-sector project is not to copy the NSW form. It is to separate assessment friction from evidence continuity. A short intake is valuable. It becomes a control only when the answer is attached to a named system, a decision owner and a record that can be revisited after a model or vendor changes.
Run the owner test before you run the model
For each live AI project, ask four questions:
- Which exact system is this record about?
- Who can pause or restrict it without asking the model team for permission?
- Which three artefacts would we show an auditor first?
- What event reopens the assessment, and where is that event logged?
If the team cannot answer the second question, it has a sponsor but not stop authority. If it cannot answer the third, it has activity but not an evidence pack. If it cannot answer the fourth, it has a one-time approval rather than an operating control.
The fastest improvement is deliberately small. Pick one active project, write down its system identity and owners, link the approval and latest test result, then schedule the next review against a real change event. The record will be more useful than a new policy because it can be inspected, challenged and updated.
Primary sources
- APRA letter to industry on artificial intelligence, 30 April 2026.
- ASIC calls for urgent cyber uplift as AI accelerates cyber threats, 8 May 2026.
- NSW strengthens AI oversight with modernised assessment framework, 27 January 2026.
- AI for public servants: understanding the new AI Assessment Framework, Digital NSW.
- Internal controls and governance 2026, Audit Office of NSW, 12 August 2026.

