WA Government AI Assurance Framework Logo
  • WA Government Artificial Intelligence Assurance Framework

    Version: 2.0 | April 2025
  • What is the Artificial Intelligence (AI) Assurance Framework?

  • The AI Assurance Framework (the Framework) supports the safe, secure and reliable use of AI in alignment with the WA Government Artificial Intelligence Policy (the Policy).

    The Framework aims to ensure that AI systems are designed, built and used transparently and safely. It highlights potential risks associated with an AI project and assigns a risk level. As you navigate this Framework, reflect on the risk factors associated with your project and consider further mitigation measures where necessary. This Framework is not intended to duplicate existing Information and Communication Technology governance within your entity. Where possible, use existing project documentation to complete the form.

    Self-assessments against the Framework are submitted to the Office of Digital Government (DGov) for inclusion in the WA Government’s AI Register. The AI team at DGov is available to support you with any questions at ai-dgov@dpc.wa.gov.au.

    • Who should use the Framework? 
    • This Framework applies to entities within the scope of the Policy. The AI ‘use case’ or ‘project’ is what you will be assessing against this Framework.

      Completion of a self-assessment within this Framework should be led or reviewed by the team within your entity responsible for AI governance. Your response to this Framework must be approved by an AI Accountable Officer, an executive within your entity responsible for the governance of these technologies. This officer will be required to approve the self-assessment once you have completed it.

    • When to use the Framework? 
    • A re-assessment of the AI system against this Framework should be undertaken at the completion of key milestones:

      • the design and planning of a new use case, which should occur before an investment or public commitment is made;
      • at the end of testing, a proof of concept, or pilot (if applicable);
      • at the end of the build phase, prior to go-live or deployment;
      • following roll-out, once operational; and
      • prior to any major change in the system or its use.
    • The scope of this Framework 
    • This Framework must be applied to non-trivial systems and projects which use AI or automated decision making. This includes the use of large language models, machine learning tools, and generative AI. This Framework should be used whether an AI system is procured, built or otherwise sourced or adapted.

      The following are examples of AI use cases that would be in or out of scope for the use of this Framework:

      In scope Out of scope
      • Development or procurement of a bespoke AI solution
      • AI software trained to detect specific objects in images and videos
      • The procurement of an AI tool to streamline a business process or to support decision-making
      • Procuring or developing a complex machine learning tool
      General-purpose hardware and software with trivial smart features such as:
      • Smart phones and laptops
      • QR code readers
      • Satellite Navigation Systems
      • Predictive text in Microsoft Outlook and Word
      • Online workflows
      • Data entry tools and software
      • Data analytics software

      Some common AI use cases are not required to be assessed via this Framework. Please refer to guidance on these use cases to ensure their safe procurement and implementation.

    • Innovation pathway 
    • Entities are encouraged to explore and innovate with AI and are not required to apply this Framework when experimenting with the technology in a contained testing environment. The following conditions must be met for this to occur:

      • No personal information or sensitive government information is used;
      • The data is held on local servers or tenancy within Australia and is not provided to a third party;
      • Outputs do not inform the basis of any government operations, policy advice, service delivery or decision making; and
      • No external AI software is procured or used in a free trial.
    • The AI Advisory Board 
    • Your project will be progressed for review to the WA Government AI Advisory Board (the Board) if it meets one or more of the following threshold criteria:

      • Residual risk/s (after mitigations) are mid-range or higher; or
      • Funding has been provided through the Digital Capability Fund; or
      • Total cost exceeds $5 million.

      Projects which meet these threshold criteria will have their self-assessment submitted to the board, as well as a number of existing project artifacts. Further information is provided at the end of this form.

      The purpose of the Board is to support your entity’s use of AI and ensure that the WA Government’s use of AI is as robust as possible. The Board brings independent technical and ethical expertise to projects and can recommend further mitigations to balance key risks. You can proceed with your project while it is under Board review. The advice of the Board is non-binding, but we do recommend that you consider it fully to ensure sound risk mitigation.

    • Invisible section collapse to allow for text underneath 
  • AI Assurance Framework

    Ready to start your self-assessment?
  • It may not be possible for projects in the testing or proof of concept phase to answer all questions. In these cases, please answer to the best of your knowledge.

    You can save your responses using the  button at the end of each page.

    DO NOT enter any information classified as OFFICIAL: Sensitive or above in this self-assessment. Such sensitive information includes information that is cabinet-in-confidence, personally identifiable or sensitive, restricted by contractual conditions, or subject to legal professional privilege.

    For more information on assessing the sensitivity of information, please see the WA Government Information Classification Policy.

    * = a response is required

  • Project information

    Please start by telling us about your project.
  • Primary contact

    The primary contact is responsible for ensuring their department or entity aligns with the WA Government AI Policy, including data governance and technical requirements.

    • Add other project members if required 
    • At the end of the form, you will be invited to provide details on the AI Accountable Officer for this AI use case or project.

  • Community benefit and fairness

    Government entities should be able to define and document the benefits and possible harms of the AI use case to the community, environment and organisation.
  • What is the intended benefit of the AI solution?

    In describing the direct and indirect benefits, please consider the potential risk or loss of benefits from not doing the project and how the AI solution is preferable to other alternatives.
  • Privacy, security, transparency, explainability and contestability

    AI solutions must be well understood, documented, explainable and contestable. This is crucial to making AI use transparent and fair. Please provide information that is currently available to you, or indicate what is planned.
  • You may wish to refer to these requirements before filling out the question above:

    • WA Government Information Classification Policy
    • Privacy and Responsible Information Sharing Act 2024 (WA)
  • You may wish to refer to these requirements before filling out the question above:

    • WA's data offshoring position and guidance
  • Controls

    All AI projects should have appropriate controls in place to ensure outputs are safe, secure and reliable.
  • Requirements

  • Your AI use must comply with all of the following:

    • The WA Government AI Policy, and any further policy requirements expected by your entity.
    • The WA Government data offshoring position and guidance.
    • Privacy requirements under the Privacy and Responsible Information Sharing Act 2024 (WA).
    • Cyber security requirements under the WA Government Cyber Security Policy.
    • Australian anti-discrimination laws.
    • Record keeping requirements under the State Records Act 2000 (WA) and Artificial Intelligence and Record Keeping guidance.
    • Other relevant laws and policies.
  • Note that legal advice should be sought where there are necessary compliance concerns, including when sensitive data is used by the AI system.

  • Risk assessment

  • Note that the risk of offshoring non-sensitive personal information and official government information should also be considered and mitigated through security controls per the WA Government data offshoring position and guidance.

  • Step 3: Please complete the below risk assessment in consideration of your previous responses and planned controls. Note that controls can only mitigate, but do not resolve all risks.

  • Risk matrix
  • Assess the following residual risks:

  •  
  •  
  •  
  • Assessment outcome

  • If all residual risks are low, any sensitive or personal data is hosted in Australia and your use case is not in a high risk category: 
    Manage risks within your entity and consider appropriate controls. Seek the advice of the DGov AI team at ai-dgov@dpc.wa.gov.au should you have further questions.

    If there is a medium or high residual risk, you have sensitive or personal data hosted or processed offshore, or your use case is in a high risk category: 
    Your project will be referred to the AI Advisory Board. This will require you to provide further existing project documentation, and a detailed risk-assessment for any elevated risks identified in this assessment. The DGov AI policy team will be in contact with you to provide further information. The Board may recommend further appropriate controls for your project.

  •  
  • Accountable Officer

    It is crucial that someone is always responsible for the implementation and use of AI in functions and decisions of government.
  • Please provide the name of the AI Accountable Officer for this use case within your entity. This should be an executive leader within your entity responsible for the governance of these technologies.

  • Browse Files
    Drag and drop files here
    Choose a file
    Cancelof
  • Review and submit

    Please review your responses before submitting.
  •  
  • Should be Empty: