I have read a lot of AI risk frameworks that map everything and diagnose nothing.
The principles are there. The policies are there. There is a table that reconciles them — fairness, privacy, accountability, contestability, transparency, safety down one side; policies, committees, reviews, owners, evidence stores across the top. The cells are filled and the colours are calm. Nobody who built it was being careless. Then a real use case presses on the map, and the question that should have an answer doesn’t.
Which control actually discharges this obligation?
Not which policy mentions it. Not which committee receives an update. Which operational control, in this use case, reduces the risk, creates the evidence, gives the affected person a path, or changes the deployment decision? The room usually knows where the documents live. It often does not know whether the documents can diagnose a live AI system under pressure.
That is the work of D7, Ethical AI, Risk and Regulatory Compliance, in the framework. This dimension is easy to flatten into an ethics poster or a compliance inventory. Both are useful at the edge and weak at the centre. The harder question is whether the organisation can trace the obligation, control, evidence, owner, and decision consequence without rebuilding the story from meeting papers.
The differentiator is D7.2, the obligation-to-control map. A static crosswalk says that a principle or regime has been considered. A live diagnostic map says which control carries it, where the evidence sits, which use cases are affected by a legal-watch update, and what changed when the control failed. AI risk does not arrive as a neat legal category. It arrives as a hiring screen with weak fairness evidence, a customer chatbot that makes claims the business cannot substantiate, a claims triage model that uses personal information, a vendor agent with unclear redress, or an internal tool that quietly becomes operationally critical.
D7.1, the AI Impact Assessment protocol, is the front door into that map. The AIA should not be a late-stage form completed after the project has momentum. It should trigger by use-case class, drawing from D2.3 criticality, D1.6 strategic posture, D5 autonomy and blast radius, personal-information use, protected-attribute relevance, stakeholder impact, safety impact, financial impact, and vendor dependency. Risk tier is criticality plus harm assessment, turned into a review path before deployment or material change.
Maturity shows up when the AIA changes something. A low-risk internal productivity assistant should not carry the same evidence burden as an automated credit-impacting decision or employment-screening workflow. A refreshed AIA after a provider change, incident, legal update, or drift should be able to alter design, monitoring, approval, rejection, or redress.
Australia makes this discipline especially important because there is no single AI Act that absorbs the whole question. The Privacy Act 1988, as amended by the Privacy and Other Legislation Amendment Act 2024, is LOCKED as the base privacy regime, while specific amendments remain in phased commencement. The new APPs 1.7–1.9 substantially-automated-decision transparency provisions commence on 10 December 2026; they should not be misdescribed as a general per-interaction explanation right. Privacy counsel determines the specific status and pathway. The operating-model obligation is to know which use cases involve personal information, which APP intersections have been mapped, and which evidence would let privacy counsel decide before the system is live.
APRA CPS 230 is also LOCKED, in force from 1 July 2025 for APRA-regulated entities. It is an operational risk and resilience standard, not a general AI law and not an information-security standard. Where an AI system affects critical operations, material service-provider risk, disruption tolerance, or operational risk controls, the D7 map should connect the use case to CPS 230 operating evidence. Specialist regulatory counsel determines applicability and notification timing. The operating model should make the facts visible before project files become the only memory.
Other anchors sit differently. The Australian Voluntary AI Safety Standard is, as its name says, voluntary. The DISR AI Ethics Principles are voluntary and interpretive. Proposed mandatory guardrails for high-risk AI remain under consultation as at 2026 and are not in force. They should shape controls, review questions, assurance evidence, and future readiness without being written as if Parliament has already turned every principle into binding law.
ASIC and the ACCC matter where AI touches consumer-facing conduct, financial services, credit, market disclosure, misleading claims, unfair practices, or substantiation. ASIC does not regulate AI as a free-standing category; it acts through existing corporations, licensing, market integrity, and consumer financial protection regimes. The ACCC applies competition and consumer law where AI-generated content, automated decisioning, or product claims may mislead consumers. Corporate, licensing, competition and consumer counsel determine the legal application. The operating-model question is whether evidence was captured at the time of the AI-driven decision.
D7.3 brings the ethical layer back from abstraction. The DISR AI Ethics Principles name Fairness; Accountability; Contestability; Transparency and Explainability; Privacy Protection and Security; Reliability and safety; Human-Centred Values; and Human, societal and environmental wellbeing. A weak organisation pastes those words into a policy. A stronger one maps each applicable principle to a design requirement, acceptance criterion, evidence artefact, monitoring signal, owner, exception pathway, and refresh trigger.
The obligation-to-control map is where that translation becomes visible. Fairness may require specialist-determined assessment for a hiring or credit decision. Contestability may connect to the D6.4 redress workflow. Privacy Protection and Security may connect to APP 11 evidence and D9 enforcement. Reliability and safety may connect to D5 evaluation and D10 production monitoring. The point is not that every use case receives the same checklist. The point is that the principle has a control strong enough to change the system.
D7.4 is where many organisations overreach, often with good intentions. Bias, fairness, and explainability methods depend on model type, data, use case, harm pathway, legal context, and the lawfulness of using protected-attribute information. Discrimination law specialists determine the applicable federal or state Act and protected-attribute analysis. Statistical, model-risk, and domain specialists determine methodology. The operating-model question is whether evidence is captured in a form those specialists can use, and whether it follows the same decision class into production.
Explainability is also not one artefact. A board risk report, an internal operator explanation, an affected-customer explanation, and an assurance-review record do different jobs. The D7 map should show which audience needs which explanation, what supports it, who maintains it, and how it changes.
D7.5 gives the work a forum, but the forum is not the work. An AI ethics committee that only receives updates is theatre with minutes. A useful governance forum has a charter, authority, cadence, quorum, evidence standards, escalation rights, disposition tracking, and integration with D6 decision rights. It can be legal/privacy-led, risk-led, product-led under second-line challenge, or part of a regulated three-lines model. The accountable path could run through a CAIO, an extended CIO/CDO/CTO mandate, a legal or risk executive forum, or CEO-direct accountability. The framework requires named accountability and evidence, not a prescribed title.
The forum should review AIAs, exceptions, high-risk use cases, excluded-use-case escalations, material changes, incidents, and unresolved ethical trade-offs. Its maturity is not meeting count. It is whether the forum changed design, blocked deployment, required redress, refreshed controls, or closed remediation after a failed fairness or explainability test. Workforce and People representation matters only if D11 has given that seat enough AI literacy to challenge the work.
The L4 buyer question for D7 is deliberately hard: show same-quarter evidence reconciling the AIA, live deployment log, legal-watch update, fairness or explainability result, governance forum minute, and remediation closure for the same decision class. That prevents a beautiful answer assembled from unrelated artefacts. It asks whether risk, ethics, legal posture, technical evidence, and decision authority touched the same system while it was still alive.
This is where the Responsible and Agentic AI Governance pillar connects back to strategy. A risk control that never changes a decision is not a control in any operating-model sense. It is commentary. A compliance map that cannot diagnose affected use cases after a regulatory update is a catalogue. A principle that cannot be traced to design, evidence, owner, and consequence is a value statement waiting for a harder room.
The practical test is quiet and unforgiving. Pick one material AI use case. Sort its obligations into three states: in force now, enacted but not yet commenced, and proposed but still under consultation. Then ask which specialist must decide the interpretation, which controls carry the obligation, which evidence proves they work, and which decision would change if they do not.
If that line can be traced, D7 is doing its job. If it cannot, the organisation does not yet have ethical AI governance. It has well-organised hope.