Three engagements. Each one ends in a document.
Work is scoped against a single obligation: the automated decision-making transparency requirement in APP 1.7, which commences 10 December 2026. Start with the review. Most businesses need nothing else for a while.
Exposure review
Before anyone writes a policy, you need to know whether you have an obligation at all, and where it sits. Most businesses genuinely do not know how many of their systems make automated decisions.
What happens
- Interview the people who run your key systems
- Sweep your software stack, including modules you may not know are active
- Identify where personal information feeds a decision
- Apply the significance test to each one and record the reasoning
- Rank what actually carries risk
What you receive
- Written findings, system by system
- A clear position on whether APP 1.7 applies to you
- A risk ranking, so you know what to deal with first
- A recommendation, including “you do not need step two”
Fixed fee, quoted before we start. About one week, and credited against a build if you proceed within sixty days.
Compliance build
The artefacts that make you defensible. Written so they hold up when someone asks how a decision about them was made, not so they look good in a folder.
Automated decision register
Every system, the personal information it uses, the decision it touches, and its significance position.
Privacy policy disclosure
APP 1.7 wording in plain English, drafted against what your systems actually do.
Significance assessments
A reasoned written position per decision — the record showing you considered the question properly.
Human review pathway
Who reviews a challenged decision, in what time, and how the outcome is recorded.
Collection notices
Updated wording at the points where you actually collect the information.
Staff briefing
A working session so the people operating these systems know what they can and cannot do with the output.
Fixed fee, quoted before we start. Four to six weeks.
Assurance
The obligation does not end on 10 December. New systems arrive, staff turn over, and the Commonwealth is expected to legislate broader AI requirements from 2027.
What it covers
- Triage of any new system before it goes live
- Register and policy kept current as things change
- Monitoring of OAIC guidance and regulatory change
- An annual written review of your position
- A named person to call when something looks uncertain
Why it matters
The common failure is not getting compliant. It is going out of date six months later because a vendor switched on a scoring feature and nobody assessed it.
Monthly retainer. Cancel any time. No lock-in contract.
What this is and isn’t
This is compliance documentation work
Registers, assessments, policy wording, process design and the training that makes them stick.
This is not legal advice
We draft; a lawyer advises. Where you need a legal opinion or a signed-off policy, we say so and work alongside your solicitor.
This is not an AI build service
We are not here to sell you models, agents or automation. If the answer is that a system should be switched off, that is the answer.
This is not an audit you can fail
The review is diagnostic. Finding exposure early is the point of doing it before December rather than after.
Start with the review
One week, a fixed fee, and a clear answer on whether you have anything to fix.