Insights · Compliance
The NSW AI Assessment Framework and your AI consultant.
The obligation sits with the agency. The evidence is produced by the supplier. That gap is where most AI engagements in New South Wales come unstuck.
What the framework actually asks.
The NSW AI Assessment Framework is the New South Wales Government's mandatory process for assessing artificial intelligence systems across their lifecycle. Under NSW Government circular DCS-2024-04, agencies must apply it to AI they build, buy or inherit inside a vendor product. It is risk-tiered: lower-risk uses are assessed and documented by the agency itself, while high-risk and critical-risk systems are referred to the NSW AI Review Committee for independent review.
Strip away the templates and it asks four questions. What does this system do, in terms a non-specialist can check? What data does it use, and where did that data come from? Who is accountable for it, by name and by role? And what happens when it is wrong — who notices, how fast, and what stops the error reaching a citizen?
None of those are modelling questions. All four are provenance and accountability questions, which is why agencies with capable data science teams still stall.
Why the assessment lands on your supplier.
The legal obligation belongs to the agency. It cannot be contracted away and no consultancy can accept it. But an agency cannot describe the lineage of a dataset it did not assemble, the fallback behaviour of a model it did not train, or the retention policy of logs it does not hold. In practice the AI consulting firm that built the system writes most of the assessment content, and the agency signs it.
That has a blunt procurement consequence. If the firm cannot produce that material as a by-product of delivery — because lineage, ownership and guardrails were designed in rather than reconstructed afterwards — the assessment becomes a separate project, funded separately, months after go-live, using memory instead of records. A supplier in that position is a risk to the assessment, not a help with it.
This is the practical difference between artificial intelligence consulting companies that deliver a demo and those that deliver a system somebody else has to defend. Both look identical in a pitch.
Five questions to ask before you engage.
01
Provenance
Where does every input dataset come from, who owns it, and is our intended use lawful under the collection notice it arrived with?
02
Uncertainty
What does the system do when it does not know? Show us the abstain path and the point where a human decides.
03
Evidence
What is logged, how long is it kept, and can we reconstruct a specific decision in twelve months' time?
04
Handover
Who is accountable after your team leaves? If the answer needs your team, we have bought a dependency, not a capability.
05
Independence
What software do you resell? A recommendation from a reseller is a quote wearing a strategy's clothes.
Ask for an artefact against each one, not an answer. A firm that has done this before has a lineage diagram, a guardrail spec and a log schema from a previous engagement, redacted. A firm that has not will offer a slide describing its methodology.
The evidence gap, and why it is a data problem.
The failure mode is consistent. Governance is treated as a document produced after delivery, so the artefacts the framework asks for were never captured while they were cheap to capture. Six months later, nobody can say with confidence which extract fed the training set, whether it was the version before or after the field mapping was fixed, or who approved its use.
That is not an AI control gap. It is an ownership gap in the data layer underneath, and it is the same gap we describe in asserted versus observed compliance: a policy that asserts a control exists is a weaker artefact than a signal showing it operating. Assessments are survivable when compliance is instrumented. They are painful when it is narrated.
The fix is unglamorous and it starts before the model. Pick the one data domain the AI use case depends on. Name an accountable owner. Map it end to end — source system, pipeline, dataset, consumer. Write down the quality and access rules, then instrument them so they emit a signal. That is ordinary data governance consulting work, and it is what converts an assessment from an archaeology exercise into a report.
If you are not a NSW agency.
Two reasons this still applies. If you supply NSW Government, the framework reaches you through your contract — the same mechanism by which the Victorian Protective Data Security Standards reach Victorian government suppliers who are not themselves public sector bodies. Your customer's obligation becomes your clause.
And if you are APRA-regulated, CPS 230 and CPS 234 ask structurally similar questions about accountability, critical operations, data and resilience. The wording differs. The evidence does not. An organisation that can answer the NSW framework can largely answer APRA's expectations, and vice versa, because both are asking whether you can prove what you assert.
A ninety-day path.
Days 1-30: scope and own
Classify the use case against the framework's risk tiers before design starts, not after build. Name the accountable owner for the AI system and for each dataset it consumes. If a dataset has no owner, that is the first finding.
Days 31-60: map and instrument
Trace lineage end to end for the domains in scope. Define the quality rules and access rules that matter, and wire them to emit a live signal rather than a quarterly attestation. Specify the guardrails and the human decision point in writing.
Days 61-90: evidence and rehearse
Assemble the assessment pack from what the system already emits. Then rehearse: pick one decision the system made and reconstruct it from logs alone. If you cannot, you have found the gap while it is still cheap.
After: keep it live
Frameworks apply across the lifecycle, so an assessment passed at go-live and never revisited is a snapshot, not a control. Review on change: new data source, new population, new decision the model influences.
Common questions.
Does the framework apply to AI embedded in software we already bought?
Generally yes — the framework is concerned with AI an agency uses, not only AI it builds. Features switched on inside an existing platform are the most commonly missed category, because nobody procured them as AI.
Who is accountable if the consultant got it wrong?
The agency remains accountable to the framework. Contractual recourse against a supplier is a separate matter and does not repair a failed assessment, which is why the evidence question belongs in procurement rather than in the post-mortem.
How much of this can be done before a vendor is chosen?
Most of it. Ownership, lineage and quality rules for the underlying data domain are vendor-independent, and doing them first is what lets you evaluate AI consulting firms in Sydney on evidence instead of on their deck.
For where this sits in our wider practice, see AI governance consulting and AI consulting in Australia. If you want a fast read on where you stand before committing to any of it, the free AI readiness check takes a few minutes and covers the data foundation questions first.
General information only, not legal or regulatory advice. Current as at August 2026. Confirm current NSW Government requirements with the Department of Customer Service before relying on them.