⚡ Quick Summary
Published by the Digital Transformation Agency (DTA), this guidance supports Australian Government agencies in completing the AI impact assessment tool. It is written for teams working on an AI use case, to help them identify, assess and manage impacts and risks against Australia's AI Ethics Principles and to fulfil impact assessment requirements under the Policy for the responsible use of AI in government (the AI policy). The document mirrors the tool's 12-section structure, so each section number can be read alongside the corresponding tool section.
The guidance explains how to record basic use case information, including the AI policy scope criteria, roles and responsibilities, and expert contributions; how to describe purpose and expected benefits against non-AI alternatives; and how to conduct an inherent risk assessment by determining likelihood and consequence and applying the tool's risk matrix. If all risks are low, the assessing officer may recommend that a full assessment is not required; if any risk is medium or higher, they must either complete a full assessment, amend the scope or function until the threshold result is low, or decide not to proceed.
Later sections cover fairness definitions and measurement, data suitability, Indigenous data, procured models, testing, pilots, monitoring and disengagement, operator training, Australian Privacy Principles compliance, security, transparency and disclosure, contestability, human-centred values and accountability. An appendix provides a risk consequence guidance table for the risks in sections 3.1 to 3.8.
🧩 What’s Covered
The guidance follows the tool's twelve sections, with an appendix of consequence descriptors.
- Basic information (1.1–1.11): use case name, lead agency, assessing and approving officers, other roles and responsibilities, in-scope criteria under Appendix C of the AI policy, type of AI technology, usage pattern, administrative decisions, domain, expert contributions and the impact assessment review log.
- Purpose and expected benefits (2): problem definition, use case purpose, non-AI alternatives, stakeholder mapping, and expected benefits supported by quantitative metrics or qualitative analysis.
- Inherent risk assessment and threshold outcome (3–4): definitions of inherent and residual risk, steps for determining likelihood and consequence, the rule that the highest rating becomes the overall rating, and the options open to assessing and approving officers when risks are low or medium and above.
- Fairness (5): individual versus group fairness, bias in training data, accessibility, anti-discrimination legislation, quantitative and qualitative measurement, consultation, user testing and expert review.
- Reliability and safety (6): data suitability, provenance, lineage and volume, Indigenous data and the Framework for Governance of Indigenous Data, procured model checks, acceptance criteria and testing, pilots, monitoring for data and concept drift, disengagement, avoiding overreliance, and operator training.
- Privacy protection and security (7): APPs 1, 3, 5, 6, 10 and 11 applied to AI inputs and outputs, privacy enhancing technologies, privacy threshold and impact assessments, the PSPF, the ISM and ASD guidance.
- Transparency, explainability, contestability, human-centred values and accountability (8–11): consultation, public visibility, transparency statements, model cards, datasheets and decision registries, disclosure mechanisms including C2PA provenance, explanation principles, review of AI-influenced administrative actions, diversity, human rights and lifecycle accountability.
- Use case review and next steps (12) and appendix: legal framework alignment, legal advice and privilege, the risk summary table, the residual risk rating, governance body review for high-risk use cases, and consequence descriptors from insignificant to severe.
💡 Why it matters?
The guidance gives agencies a repeatable way to decide how much scrutiny an AI use case needs. Its threshold logic ties assessment effort to risk: low ratings can be endorsed without a full assessment, while medium or higher ratings force a full assessment, rescoping or abandonment. It also supplies practical checks that outlive the assessment itself, covering procurement conditions, testing and acceptance criteria, monitoring for drift, ways to reduce overreliance on outputs, and operator training. Sections connect this to instruments the document names, including the Privacy Act 1988, the PSPF and ISM, and anti-discrimination legislation.
❓ What’s Missing
The guidance is subordinate to other documents: it repeatedly defers to the AI policy, the impact assessment tool, the Standard for accountability, the Standard for transparency statements and the Classification systems for AI use for definitions, criteria and mandatory actions. The likelihood descriptors and the risk matrix sit in the tool rather than here, and no worked example of a completed assessment is provided. The content is bound to Australian Government agencies and Australian law, and the document states it will be updated periodically, so version currency needs checking. It also states that it is not legal advice and does not authorise AI use.
👥 Best For
Assessing officers and accountable use case owners in Australian Government agencies completing an AI impact assessment; governance, risk and privacy specialists reviewing ratings and privacy thresholds; procurement and legal teams drafting contractual controls; and technical teams designing testing, monitoring and disengagement arrangements for government AI systems.
📄 Source Details
Guidance for the artificial intelligence impact assessment tool, published by the Digital Transformation Agency (DTA), Commonwealth of Australia, version v1.0, published 01/12/2025, 48 pages. No individual authors are named; the document is maintained by the DTA under a Creative Commons Attribution 4.0 International Licence. It is supporting guidance to the AI impact assessment tool and to the Policy for the responsible use of AI in government, which it links to as https://digital.gov.au/ai/ai-in-government-policy. Text extraction covered all 48 pages.