← Apex Delivery|Delivery SignalCIO AIICT PMOEnterprise PMOICT TOMISO GovernanceAI MaturityCybersecurityNAIM V2.1
NAVENIEM · NAIM · V2.1 · AUGUST 2026 · ICT PMO BLUEPRINTS 2026 · CONFIDENTIAL

NAIM V2.1 — NSW Government Jurisdiction Core

The Naveniem AI Transformation Methodology, re-cut with the NSW AI Assessment Framework as the load-bearing compliance spine. Five phases · Five gates · Eight mechanically enforced artefact controls · 24 dimensions · 120 rubrics · One obligation ledger with eighteen entries. The Commonwealth Compliance Cliff machinery from V2.0 is retained in full as the AU-CTH jurisdiction profile.

What changed in V2.1 from V2.0
  • Jurisdiction model — obligations now load per jurisdiction. AU-NSW (this document's core): the AIAF mandate chain and 18-obligation ledger. AU-CTH: the V2.0 five-obligation Compliance Cliff set, unchanged NEW
  • AIAF depth — the single "AIAF: not started / in progress / complete" row in V2.0's 0.7 profile is replaced by the OB-01–OB-18 evidence ledger with per-obligation gate treatment NEW
  • Artefact control #8 — the Trigger Register: the AIAF's event-driven re-assessment obligation operated, not remembered NEW
  • Independent Rating Validation — second-line review of agency AIAF self-ratings, with the Medium→High-pending rule for penalty, licence, entitlement and safety systems NEW
  • Deliverable 1.10 — Cross-Agency Accountability Annex: one named officer for any automated decision chain spanning agencies NEW
  • Dimension 24 — Agentic AI Readiness (Governance & Risk): 24 dimensions / 120 rubrics, resolving the V2.0 doc–product divergence NEW
  • Weakest-link headline — the reported overall maturity is the minimum across dimensions, with the constraining dimension named NEW
  • Deliverable 4.6 — Executive Attestation Pack as the named Gate 4 output; Sector Intelligence Register extended with jurisdiction and constraining-dimension fields NEW
1.0 · Structure at a Glance
Five phases · Five gates · Eight artefact controls · Two jurisdiction profiles

V2.1 does not change the phase-and-gate skeleton — it changes what the gates are allowed to ignore. For a NSW Government engagement, the AIAF is not one compliance row among five: it is the mandate the client is measured against, so it becomes the spine the methodology walks along. Everything in V2.0 that worked is retained: the 70% resourcing ratio, scale-or-kill, Buy-Partner-Build, the workforce safeguards, the Sector Intelligence Register.

Band▲ G0 · Diagnose▲ G1 · Govern & Build▲ G2 · Prove (per use case)▲ G3 · Reshape▲ G4 · Sustain (recurring)
Phase labelTipping Point DiagnosticFoundations & GovernanceDeploy HorizonScale HorizonAgentic Horizon
AIAF spine (AU-NSW)Obligation ledger baselined · self-ratings validatedAssurance actions to closure · trigger register armed · cross-agency annex signedPer-use-case AIAF current before charterAIRC packs · audit-ready registers · records filedAttestation pack · re-score · trigger telemetry
Benefits realisationBaseline definedBenefit hypothesis designTracked vs. pre-agreed thresholdTracked at scaleAnnual re-assessment vs. baseline
Monitoring (continuous from Phase 1)← AIMS risk register · FinOps · Workforce protocol · 70% ratio · Buy-Partner-Build log · Obligation ledger status · Trigger register (control #8)
  • G0–G3 remain sequential; G2 runs per use case; kill and pause remain first-class decisions at G0, G2, G3 and G4.
  • Jurisdiction is selected at engagement creation and loads the obligation catalogue: AU-NSW loads OB-01–OB-18; AU-CTH loads the V2.0 Compliance Cliff set (Privacy Act ADM, DTA Policy v2.0, APRA CPS 230, ASIC s912A). Mixed estates carry both.
  • The self-assessment gap is the business. The AIAF is mandatory but self-assessed with no central verification until the system-based version ships. NAIM V2.1 positions Naveniem as the independent second line the framework lacks — every control below serves that position.
  • Standing rule (applies at every gate): any AI system self-rated Medium that influences a penalty, licence, entitlement or safety outcome is treated as High pending independent validation. No exceptions without a documented waiver.
2.0 · The NSW Mandate Core
The chain the engagement walks along

Compliance means satisfying the chain, not filling in the workbook. Every NAIM V2.1 artefact traces to one of these instruments.

LowMediumHighCritical
InstrumentWhat it obligesNAIM V2.1 artefact home
DCS-2024-04AI Ethics Policy + AIAF mandatory for all NSW agencies, all AI systems and components, full lifecycle, no project-size floorOB-01, OB-02 · Phase 0 ledger baseline
AI Ethics PolicyCommunity Benefit · Fairness · Privacy & Security · Transparency · Accountability — every workbook question traces to oneDimension mapping in MaturityOne V2.1 gov variant
AIAF Workbook (Feb 2026)S1 expertise + responsible officer · S2 16 auto-scored questions → tier · S3 deep dive → risk register · S4 sign-off, records, register, referral, re-runOB-03, OB-04, OB-05, OB-11, OB-12, OB-13 · Rating Validation workspace
Assurance activitiesPIA, HRIA, cybersecurity review, legal advice, community engagement, appeal mechanism — as scoredOB-06–OB-10 · Phase 1 assurance-to-closure swimlane
AIRC + AI SecretariatHigh/Critical residual-risk systems referred; advice returned; agency response owedOB-14 · Phase 3 AIRC referral pack
Digital Assurance Framework$5M+ or Digital Restart Fund projects: central gate oversight confirming AIAF complianceOB-16 · Gate calendar in Engagement Hub
Lifecycle obligationRe-run on change to features, datasets, purposes, decision contexts; periodic review proportionate to harmOB-15 · Trigger Register — artefact control #8
AI Agents Guide (Oct 2025)Named agent owner, unique identity, observability, escalation, human-intervention points — the incoming assessable standardOB-18 · Dimension 24 · Phase 4 agentic operating model
The structural read — why this is Naveniem's ground

Three-tier assurance: universal self-assessment, central review by exception (self-nominated), financial-threshold oversight. The weakness sits between tiers one and two — the agency's own rating decides whether the centre ever sees the system. That discretion point is where an assurance failure becomes a headline, and where an independent second line earns its fee. When the system-based AIAF ships central telemetry, agencies that built this machinery onboard cleanly; agencies that didn't are exposed on day one.

3.0 · The Obligation Ledger — AU-NSW
Eighteen things an agency must evidence

This ledger replaces V2.0's single AIAF row. Each entry names the source instrument, the evidence artefact an auditor would ask for, and its home in the phase structure. The ledger is baselined at Phase 0, worked to closure through Phases 1–3, and reported in the Gate 4 attestation pack.

RefObligationSourceEvidence artefactPhase home
OB-01Complete AI inventory, including shadow AI — mandate covers any AI system or component, whether or not part of a formal projectDCS-2024-04Maintained inventory: projects, COTS-embedded AI, vendor tools, staff use; owner per entryP0 discovery · Unsanctioned AI Footprint dimension
OB-02Current-version AIAF per system — legacy 2022-framework assessments use a different tier scale and do not discharge the obligationCircular · Workbook S2Completed workbooks, version-controlledP0 stocktake · P1 assessment factory
OB-03Right expertise at the table — technical, legal, privacy, domainWorkbook S1Named participants and roles per assessmentP1 panel design
OB-04Named responsible officer per system — accountable for the assessment and the decisions the system influencesWorkbook S1 · AccountabilityOfficer named in S1, reflected in register, briefedP1 accountability mapping · orphan-system flag
OB-05Risk rating defensibly derived — the Medium/High boundary decides whether the centre ever sees the systemWorkbook S2Answer rationale surviving independent challengeP0/P1 Rating Validation — standing rule applies
OB-06Privacy Impact Assessment where personal information is involvedAssurance · PPIP ActCompleted PIA, privacy sign-off, actions closedP1 assurance orchestration
OB-07Human Rights Impact Assessment for rights-affecting consequences — enforcement, eligibility, libertyAssuranceHRIA proportionate to consequence, findings actionedP1 assurance orchestration
OB-08Cybersecurity review; NSW CSP compliance — model endpoints, training stores, prompt injection, agent credentials in scopeAssurance · Cyber Security PolicyReview report, mapped controls, remediation planP1 with CISO function
OB-09Legal-basis advice — statutory authority per automated decision class; the Revenue NSW garnishee finding is the cautionary precedentAssuranceLegal-basis register: decision class → enabling powerP1 legal-basis register
OB-10Transparency and appeal path — affected people can understand the factors and access cost-effective reviewTransparency principleDisclosure, explanation capability, review path with volumesP2 contestability design per use case
OB-11Audit Record sign-off at seniority proportionate to tierWorkbook S4Signed record per delegations matrixP1 sign-off protocol
OB-12Records filed under the State Records Act 1998 — shared-drive copies do not discharge the obligationWorkbook S4 · SRARecords-system entries with retention schedulesP1 records pathway
OB-13Agency AI register — High/Critical mandatory; better practice registers everythingWorkbook S4Current register reconciled to inventoryP1 register build · P3 audit-ready
OB-14AIRC referral for High/Critical residual risk via the AI Secretariat; tracked response to adviceWorkbook S4Submission record, AIRC advice, agency responseP3 referral pack
OB-15Re-assessment on material change — features, datasets, purposes, decision contexts; the most-missed obligation in the chainLifecycle obligationTrigger log per system; re-assessment historyControl #8 — Trigger Register, continuous
OB-16DAF alignment at $5M / Digital Restart Fund thresholdsDigital Assurance FrameworkDAF registration; gate submissions citing current AIAF statusP1–P3 gate calendar
OB-17Supplier obligations in contract — model-change notification, audit rights, data-use limitsProcurement question · buy.nswAI schedule in supplier agreements; legacy remediation at renewalP1 contract-clause audit · feeds control #8
OB-18Agentic ownership, identity, observability — named owner, unique identity, audit logs, intervention pointsAI Agents GuideAgent register with fields populatedP4 agentic model · Dimension 24
Practice note — OB-17 is where procured AI fails quietly

A vendor model retrain is a feature/dataset change under OB-15 — but without a contractual notification clause the trigger fires silently and the agency's AIAF is stale without anyone knowing. Naveniem treats the vendor notification clause as a mandatory remediation in every engagement, actioned at the next contract event.

4.0 · Phase Deltas
What each phase gains in V2.1

Only the deltas are shown — everything in the V2.0 phase definitions stands. New deliverable numbering continues the V2.0 sequence.

4.1 · Phase 0 — Diagnose
Governance ActivityFor AU-NSW engagements the 0.7 profile loads the full OB-01–OB-18 ledger, each obligation status-assessed (Evidenced / Partial / Gap / Not applicable) with gate treatment. AIAF stocktake: which systems have current-version assessments; legacy 2022 assessments flagged for migration
Validation Activity ✦Rating Validation intake: the agency's completed AIAF self-assessments are imported and second-line reviewed. Standing rule applies — Medium self-ratings on penalty/licence/entitlement/safety systems treated as High pending validation
Deliverable0.7 Regulatory Compliance Exposure Profile (jurisdiction-loaded) · 0.8 AIAF Rating Validation Report ✦ · 0.9 Obligation Ledger Baseline ✦

Gate 0 — additional exit criteria (AU-NSW)

  • Obligation ledger baselined across all 18 entries; every Gap has a named phase home
  • Rating Validation Report accepted; all standing-rule flags dispositioned or carried as Phase 1 priorities
  • Any system with no current-version AIAF and a consequence flag: Phase 0 remediation item — engagement does not pass G0 with an unassessed penalty/licence/safety system on the books
4.2 · Phase 1 — Govern & Build
Assurance Activity ✦Triggered assurance to closure: PIA (OB-06), HRIA (OB-07), cyber review (OB-08), legal-basis register (OB-09) — commissioned, tracked, and closed in the Engagement Hub, not just scoped
Accountability ✦Where any automated decision chain spans agencies (e.g. operator → adjudicator → enforcement), the Cross-Agency Accountability Annex names one end-to-end accountable officer, co-signed by each agency — the direct answer to the administrative-law gap the Ombudsman identified
Trigger Activity ✦Trigger Register armed (control #8): every consequential system's plausible change events pre-mapped to the four trigger classes with named watchers; vendor notification clauses scheduled into contract events (OB-17)
Deliverable1.8 Compliance Cliff / Obligation Workstream Plan · 1.9 Shadow-AI Register & AUP · 1.10 Cross-Agency Accountability Annex ✦ · 1.11 Trigger Register (armed) ✦ · 1.12 Delegations Matrix & Records Pathway ✦

Gate 1 — additional exit criteria (AU-NSW)

  • All triggered assurance activities closed or on a dated closure plan with named owners
  • Trigger Register armed for every High/Critical and every consequence-flagged system
  • Cross-Agency Accountability Annex signed where any decision chain crosses an agency boundary
  • Audit Records signed per delegations matrix; assessments filed under the State Records Act
4.3 · Phase 2 — Prove
Governance Activity ✦No use case is chartered without a current AIAF at the correct tier for the system it touches; contestability design (OB-10) is a charter requirement for any citizen-affecting use case, with the appeal path defined before go-live
Lockdown ✦A use case whose underlying system fires a trigger mid-pilot pauses at the next checkpoint until re-assessment completes — pilots do not outrun their assessments
4.4 · Phase 3 — Reshape
Governance Activity ✦AIRC referral packs prepared for all High/Critical residual systems: submission-quality dossiers, anticipated-question briefings, tracked response plans (OB-14). Agency AI register moves to audit-ready: reconciled to inventory monthly, extract producible on demand (OB-13)
Deliverable3.7 ADM Compliance Evidence Record (AU-CTH) · 3.8 AIRC Referral Pack(s) ✦ · 3.9 Audit-Ready Register Extract ✦

Gate 3 — additional exit criteria (AU-NSW)

  • Every High/Critical system referred (OB-14) with agency response to AIRC advice on record
  • Register, records and audit trail would survive an Audit Office performance audit without remediation scramble
  • Regulatory Compliance Readiness at L4 minimum; Lifecycle control (trigger register) demonstrably operating
4.5 · Phase 4 — Sustain & Invent
Attestation Activity ✦Deliverable 4.6 Executive Attestation Pack: the Gate 4 named output. Weakest-link headline with constraining dimension; obligation ledger status per OB code; validation summary; trigger telemetry (armed / fired / mean time to re-assessment); recommendations carried and closed; signature block for the accountable executive. Every claim traces to an artefact — no free-text assertions
Sector Intelligence ✦Register extended: jurisdiction profile, constraining dimension, obligation-ledger gap profile, trigger-fire counts — anonymised, sector + size band only, Naveniem principal access

Gate 4 — recurring annual review (V2.1 additions)

  • Attestation pack issued and signed; re-score linked to baseline lineage with deltas reported
  • Trigger register telemetry current; all fired triggers closed or on dated plans
  • Agentic AI Readiness re-scored; agent register current per the AI Agents Guide ahead of the AIAF agentic module
5.0 · New Governance Controls
The three mechanisms that carry the V2.1 position
✦ Control A — Independent Rating Validation

What it is: second-line review of the agency's own AIAF self-assessments — verdict per system (Confirmed / Uplift recommended / Downgrade recommended / Insufficient evidence) with evidenced rationale.

The standing rule, enforced mechanically: any Medium self-rating on a system flagged penalty, licence, entitlement or safety is auto-flagged treat-as-High pending validation and cannot be confirmed without a recorded rationale addressing the flag.

Why it exists: the framework's most-cited structural weakness is rating discretion at the Medium/High boundary. This control converts that weakness into Naveniem's core assurance product. Exceptions report feeds Gate 0 and the attestation pack.

✦ Control B — The Trigger Register (artefact control #8)

What it is: per-system pre-mapping of plausible change events to the four AIAF trigger classes — features, datasets, purposes, decision contexts — each with a named watcher and a detection source (vendor notification, release notes, internal change record, data-pipeline event).

Mechanics: firing a trigger requires a date and evidence citation, creates a re-assessment task with a due date, and marks the system AIAF-stale until closed. Vendor model-change log linked to OB-17 contract clauses. Telemetry — armed count, fired-in-period, mean time to re-assessment — reports quarterly and at Gate 4.

Why it exists: OB-15 is the most-missed obligation in the chain because nothing detects the trigger. V2.0 re-assessed by calendar; V2.1 re-assesses by event, with the calendar as the floor.

✦ Control C — Cross-Agency Accountability Annex (deliverable 1.10)

What it is: where an automated decision chain spans agencies — capture in one, adjudication in another, enforcement in a third — a joint schedule naming a single end-to-end accountable officer, co-signed by each agency, with a shared RACI over the AIAF obligations.

Why it exists: the AIAF assesses at single-agency level; nobody assures the join. The NSW Ombudsman's machine-technology findings make this the administrative-law gap most likely to produce the next headline. The annex is the artefact an agency can adopt in a week.

6.0 · MaturityOne Diagnostic Instrument — V2.1
24 dimensions · 120 rubrics · weakest-link headline

One change to the instrument set — Dimension 24: Agentic AI Readiness joins Governance & Risk — and one change to the scoring doctrine: the headline maturity score is the minimum across dimensions, with the constraining dimension named. An agency with excellent registers and no trigger detection is not "mostly compliant"; it is exposed, and the headline says so. The mean is reported alongside for trend context. The gov framework variant additionally maps every dimension to an AIAF ethics principle and its OB references.

Strategy & Vision
3 dimensions · 15 rubrics
No change from V2.0
Data & Technology
3 dimensions · 15 rubrics
No change from V2.0
Governance & Risk
5 dimensions · 25 rubrics
+1: Agentic AI Readiness ✦ (joins Regulatory Compliance Readiness from V2.0)
People & Culture
4 dimensions · 20 rubrics
Unsanctioned AI Footprint retained from V2.0
Process & Operations
3 dimensions · 15 rubrics
No change from V2.0
Value & Outcomes
3 dimensions · 15 rubrics
No change from V2.0
Leadership & Engagement
3 dimensions · 15 rubrics
No change from V2.0
6.1 · New Dimension — Agentic AI Readiness

Pillar: Governance & Risk · Gate linkage: scored at Gate 0; L3 minimum before any agentic scope is funded at Gate 3; L4 target at Gate 4. Ledger linkage: OB-18. Benchmarks: NSW AI Agents Guide (Oct 2025), Singapore IMDA Agentic AI MGF (Jan 2026), IDC AI-Fueled Organization 2.0. L2→L3 artefact test: produce the agent register with named owners and intervention points — or the score is L2.

L1
No Visibility
Agents not distinguished from other software. No agent inventory. Shared credentials. Autonomous actions untraceable to an accountable human.
L2
Reactive
Agentic pilots underway with informal ownership. No unique agent identities, no observability or audit logging. Escalation paths undefined.
L3
Governed
Agent register operating: named owner, unique agent identity, audit logging, defined human-intervention points per the AI Agents Guide. Escalation paths documented and communicated.
L4
Managed
Non-human identity lifecycle operated — issuance, entitlement review, revocation. Agent actions observable and reviewed on cadence. Autonomy levels documented per workflow with teaming ratios set deliberately.
L5
Continuous Assurance
Behavioural monitoring live. Autonomy-change events wired to the Trigger Register as re-assessment triggers. Board receives agentic risk metric. Ready for the AIAF agentic module on release.
7.0 · Crosswalks
The jurisdiction-expansion asset, held as data

Anchoring to the AIAF is the defensible position; the crosswalk is what makes it portable. Each gov dimension maps to the AIAF principle it serves, the National Framework cornerstone, the NIST AI RMF function, and the ISO/IEC 42001 clause family — so a QLD (FAIRA/ISO 38507), Commonwealth (DTA v2.0) or regulated-private (VAISS/ISO 42001) engagement is a re-mapping exercise, not a rebuild.

AIAF principleLedger refsNational Framework cornerstoneNIST AI RMFISO/IEC 42001
Community benefitOB-01, OB-02, OB-09AI governanceMapContext & impact assessment (42005)
FairnessOB-05, OB-06, OB-07Risk-based approachMeasureAnnex A data & impact controls
Privacy & securityOB-06, OB-08, OB-12Data governanceManageAnnex A security · ISO 27001 bridge
TransparencyOB-10, OB-13, OB-14StandardsGovernDocumentation & communication clauses
AccountabilityOB-03, OB-04, OB-11, OB-15–OB-18Procurement & assuranceGovernLeadership, roles, supplier (A.10)
Expansion sequence

1. NSW agencies (mandatory AIAF, clearest pain, Excel-era exposure live) → 2. QLD/VIC/Commonwealth via the National Framework crosswalk → 3. Regulated private sector via ISO 42001 + VAISS alignment. Trigger to accelerate: passage of economy-wide mandatory guardrails.

8.0 · Design Traceability
V2.1 failure-mode countermeasures

The ten V2.0 rows stand. Three are added — each a documented NSW public-sector failure pattern, not a hypothetical.

✦ New V2.1 — Failure mode

Rating discretion: the agency's own Medium rating keeps a consequential system out of central review forever — until an assurance failure makes it a headline

✦ New V2.1 — Countermeasure

Independent Rating Validation with the mechanically enforced Medium→High-pending rule on penalty/licence/entitlement/safety systems; exceptions report at Gate 0 and in the attestation pack

✦ New V2.1 — Failure mode

Silent triggers: a vendor retrains the model, the dataset changes, the AIAF is stale — and nothing in the agency detects that the re-assessment obligation has fired

✦ New V2.1 — Countermeasure

Trigger Register (artefact control #8) with named watchers and contracted vendor notification (OB-17); fired trigger = re-assessment task with a due date, system marked stale until closed

✦ New V2.1 — Failure mode

The unowned join: an automated decision spans three agencies and no single officer is accountable end-to-end — the precise gap behind the Revenue NSW garnishee finding

✦ New V2.1 — Countermeasure

Cross-Agency Accountability Annex (1.10): one named officer, co-signed joint schedule, shared RACI over the obligation ledger — required at Gate 1 wherever a chain crosses an agency boundary

9.0 · Commercial Model
Three ways in, one compounding instrument

The methodology and the MaturityOne platform carry the same motion: the Health Check lands the client, the Programme delivers the ledger to closure, the Retainer operates the machinery — and the annual re-score locks the relationship, because Year 2 is only meaningful from the same instrument.

AIAF Health Check

Offer 1 · 3 weeks · fixed fee
  • MaturityOne baseline — reduced gov dimension set
  • Obligation ledger rapid status (18 entries)
  • Rating Validation sample with exceptions
  • Top-10 exposure register + executive readout
  • Non-attestable; converts to full baseline

Compliance Programme

Offer 2 · 12–16 weeks · core engagement
  • Phases 0–1 in full: ledger to closure
  • Assessment factory + full Rating Validation
  • Assurance orchestration (PIA/HRIA/cyber/legal)
  • Trigger Register armed · Cross-agency annex
  • AIRC packs · registers · records pathway

Assurance Retainer

Offer 3 · annual · the moat
  • Trigger Register watch + quarterly telemetry
  • Scheduled re-scores with lineage deltas
  • Annual attestation pack (deliverable 4.6)
  • Sector Intelligence benchmarking
  • System-based AIAF onboarding when it ships
The one-sentence urgency case

The system-based AIAF is in development. Agencies that build compliance telemetry now onboard cleanly; agencies that don't are exposed the day central visibility switches on. That sentence opens every Secretary conversation this quarter.

  • Congruence note: NAIM V2.1 and the MaturityOne product board are now aligned — the jurisdiction model, obligation ledger, Rating Validation, Trigger Register, Dimension 24, lineage/attestation and Health Check mode correspond to EPIC 12 (MAT-87–94) and EPIC 13 (MAT-95–101).
  • Instrument counts: 7 pillars · 24 dimensions · 120 rubrics · 5 phases · 5 gates · 8 artefact controls · 18-entry AU-NSW obligation ledger · 2 jurisdiction profiles.