# 🏛️ AiA Governance & Audit Mapping

**AiA · Advanced Intelligence Academy — founded by Husnu Konak & Adam Milankovic**
*How each sector portal feature supports Australian AI governance & audit readiness.*
*Updated: July 2026 · Educational — not legal advice.*

---

## ⚖️ The honest baseline (read this first)

Australia has **no standalone AI Act**. The proposed mandatory guardrails were **paused** in the
December 2025 National AI Plan; obligations arise from **existing technology-neutral laws + sector
regulators + (mostly voluntary) national guidance**. The **one** binding AI-specific framework with
a **December 2026** milestone applies to **Australian Government (non-corporate Commonwealth) entities**
via the **DTA Policy for the Responsible Use of AI in Government (v2.0)**.

Every AiA portal feature below is therefore positioned honestly:
- 🔴 **Mandatory** — required by law/binding policy
- 🟠 **Regulator-expected** — regulators expect it under existing frameworks
- 🟢 **Voluntary / better practice** — VAISS 10 Guardrails / Guidance for AI Adoption (AI6)

> **What the portal certifies:** completion of AI governance & compliance **training** that
> *supports* an organisation's compliance program. It is **not**, by itself, a determination of
> legal compliance. Real compliance also requires the AI register, impact assessments, controls,
> and human oversight — which the portal helps you build and evidence.

---

## 🧭 Feature → obligation map

| AiA portal feature | Supports (obligation) | Tier | Primary source |
|---|---|---|---|
| **Sector training courses** (Gov, Medical, Defence, Banking, Education) | Staff AI capability / "internal capability" & foundational AI training | 🔴 Gov / 🟢 others | DTA Policy v2.0; VAISS G1 |
| **Employee login (keychained, per-employee)** | Accountability & attributable records | 🟠 | VAISS G1; audit practice |
| **Progress tracking & roster** | Evidence staff are trained; workforce capability reporting | 🟠 | DTA Policy; VAISS G9 |
| **Attestation + policy acknowledgement** | Human accountability; policy awareness (stronger than a tick-box) | 🟠 | VAISS G1/G5 |
| **Completion certificate (founder-signed, cert ID)** | Verifiable training evidence for audit | 🟢 | Better practice |
| **Recertification / training currency (12-mo)** | Keeping capability current across the AI lifecycle | 🟢 | VAISS G2/G4 |
| **AI System Register** (use case, accountable official, risk, oversight) | **AI use-case inventory with an accountable owner** | 🔴 Gov (from 15 Jun 2026) / 🟢 others | DTA Policy v2.0; VAISS G9 |
| **AI Impact Assessment register** | **AI Impact Assessment before deployment** | 🔴 Gov (from Dec 2026) / 🟠 high-risk | DTA Policy v2.0 |
| **AI Incident register** | **AI incident detection, escalation & reporting** | 🔴 Gov (from Dec 2026) | DTA Policy v2.0 |
| **Tamper-evident, hash-chained audit log** | Records third parties can rely on to assess compliance | 🔴/🟢 | VAISS G9; audit assurance |
| **Auditor read-only mode** | Transparency to regulators without data-tampering risk | 🟠 | ANAO/audit readiness |
| **Certificate verification page** | Independent verification of credentials | 🟢 | Better practice |
| **Audit Evidence Pack (per-sector & whole-org, integrity hash)** | One-hand-over evidence set for an audit | 🟠 | ANAO; conformity records |
| **Org-wide overview + audit-chain integrity** | Executive/CAIO oversight & governance | 🔴 Gov / 🟠 others | DTA Policy; VAISS G1 |
| **Australian data-residency posture** | Data governance & sovereignty | 🔴 | Privacy Act 1988; APPs |
| **Defence-only ethics harness across all content** | Responsible-use governance | 🟠 | AI Ethics Principles; VAISS |

---

## 🏢 Per-sector: what the portal maps to

### 🏛️ Government Departments — *the sector with real Dec-2026 duties*
- **AI register + accountable official** → in effect **15 June 2026** ✔ built (AI System Register)
- **AI Impact Assessments before deployment** → **December 2026** ✔ built (Impact register)
- **Approve/oversee AI use + incident reporting** → **December 2026** ✔ built (Incident register, oversight fields)
- **Public AI transparency statement**, **Chief AI Officer**, **APS AI training** → supported by training + roster
- Source: **DTA Policy for the Responsible Use of AI in Government (v2.0)**; Privacy Act 1988.

### 🏥 Medical & Health
- **Software as a Medical Device** (ARTG, Essential Principles, post-market) → register captures device status, risk, oversight
- **Health-information privacy & provenance** → data fields + residency posture
- Source: **Therapeutic Goods Act 1989 / TGA** (confirmed fit-for-purpose Jan 2026); **Privacy Act 1988**; My Health Records Act.

### 🛡️ Defence Force
- **MEAID** facets (responsibility, governance, trust, law, traceability) → training + audit traceability
- **Article 36 legal review** of AI-enabled means of warfare → register/impact records
- **PSPF / ASD ISM / SOCI** protection & assurance → data governance + audit log
- Source: **MEAID (DSTG)**; Additional Protocol I Art. 36; PSPF; ASD ISM; SOCI Act 2018.

### 🏦 Banking & Financial Services
- **APRA CPS 230** (operational/model/third-party risk) & **CPS 234** (information security) → register + audit log
- **ASIC conduct**, anti-discrimination, **CDR**, no "AI-washing" → training + contestability content
- Source: **APRA CPS 230/234**; Corporations Act/ASIC; Privacy Act & Consumer Data Right.

### 🎓 Education
- **Australian Framework for Generative AI in Schools** (6 principles, 25 statements) → training + transparency
- **Student-data privacy**, no sale of student data, walled-garden → data governance posture
- **HESF 1.4 assessment integrity / TEQSA** → training content
- Source: Gen-AI in Schools Framework; **Privacy Act 1988**; **HESF/TEQSA**; Copyright Act 1968.

---

## 🔐 How "keychained & logged" is delivered

1. **Identity** — per-sector, per-employee sessions; production uses your org SSO with
   **Cloudflare Access** and Keychain/EncryptedSharedPreferences token storage.
2. **Tamper-evidence** — every action is **SHA-256 hash-chained** (each event embeds the prior
   event's hash). Any later edit breaks the chain and is flagged with the exact event number.
3. **Authoritative store** — the append-only log, roster and registers live server-side on the
   **Rust · Cloudflare (Workers + D1/Durable Objects)** backend; this front-end mirrors the exact
   structure so wiring in is drop-in.
4. **Verifiability** — auditors verify the chain offline, verify any certificate by ID, and receive
   an **Evidence Pack** carrying an overall integrity hash.

---

## 🧾 Running an audit with AiA (the 5-minute version)

1. Give the auditor an **auditor read-only** link (`admin.html?sector=…&role=auditor`).
2. They review the **roster** (who's trained, currency), the **three registers**, and the
   **tamper-evident audit log** (integrity banner shows green if intact).
3. They **verify any certificate** by ID on `verify.html`.
4. You hand over the **Audit Evidence Pack** (per-sector or whole-org) — one file, integrity-hashed.

---

## 📌 Primary sources
- DTA — Policy for the Responsible Use of AI in Government (v2.0)
- Dept of Industry, Science & Resources — Voluntary AI Safety Standard (10 Guardrails) & Guidance for AI Adoption (AI6)
- Privacy Act 1988 (Cth) & Australian Privacy Principles (OAIC)
- TGA — Software as a Medical Device; Dept of Health — Safe & Responsible AI in Health Care (Jan 2026)
- MEAID (DSTG); Additional Protocol I Article 36; PSPF; ASD ISM; SOCI Act 2018
- APRA CPS 230 & CPS 234; ASIC; Consumer Data Right
- Australian Framework for Generative AI in Schools; HESF / TEQSA; Copyright Act 1968

*Always confirm current obligations with the relevant regulator. This document is education, not legal advice.*
