The Naveniem AI Transformation Methodology, re-cut with the NSW AI Assessment Framework as the load-bearing compliance spine. Five phases · Five gates · Eight mechanically enforced artefact controls · 24 dimensions · 120 rubrics · One obligation ledger with eighteen entries. The Commonwealth Compliance Cliff machinery from V2.0 is retained in full as the AU-CTH jurisdiction profile.
V2.1 does not change the phase-and-gate skeleton — it changes what the gates are allowed to ignore. For a NSW Government engagement, the AIAF is not one compliance row among five: it is the mandate the client is measured against, so it becomes the spine the methodology walks along. Everything in V2.0 that worked is retained: the 70% resourcing ratio, scale-or-kill, Buy-Partner-Build, the workforce safeguards, the Sector Intelligence Register.
| Band | ▲ G0 · Diagnose | ▲ G1 · Govern & Build | ▲ G2 · Prove (per use case) | ▲ G3 · Reshape | ▲ G4 · Sustain (recurring) |
|---|---|---|---|---|---|
| Phase label | Tipping Point Diagnostic | Foundations & Governance | Deploy Horizon | Scale Horizon | Agentic Horizon |
| AIAF spine (AU-NSW) | Obligation ledger baselined · self-ratings validated | Assurance actions to closure · trigger register armed · cross-agency annex signed | Per-use-case AIAF current before charter | AIRC packs · audit-ready registers · records filed | Attestation pack · re-score · trigger telemetry |
| Benefits realisation | Baseline defined | Benefit hypothesis design | Tracked vs. pre-agreed threshold | Tracked at scale | Annual re-assessment vs. baseline |
| Monitoring (continuous from Phase 1) | ← AIMS risk register · FinOps · Workforce protocol · 70% ratio · Buy-Partner-Build log · Obligation ledger status · Trigger register (control #8) → | ||||
Compliance means satisfying the chain, not filling in the workbook. Every NAIM V2.1 artefact traces to one of these instruments.
| Instrument | What it obliges | NAIM V2.1 artefact home |
|---|---|---|
| DCS-2024-04 | AI Ethics Policy + AIAF mandatory for all NSW agencies, all AI systems and components, full lifecycle, no project-size floor | OB-01, OB-02 · Phase 0 ledger baseline |
| AI Ethics Policy | Community Benefit · Fairness · Privacy & Security · Transparency · Accountability — every workbook question traces to one | Dimension mapping in MaturityOne V2.1 gov variant |
| AIAF Workbook (Feb 2026) | S1 expertise + responsible officer · S2 16 auto-scored questions → tier · S3 deep dive → risk register · S4 sign-off, records, register, referral, re-run | OB-03, OB-04, OB-05, OB-11, OB-12, OB-13 · Rating Validation workspace |
| Assurance activities | PIA, HRIA, cybersecurity review, legal advice, community engagement, appeal mechanism — as scored | OB-06–OB-10 · Phase 1 assurance-to-closure swimlane |
| AIRC + AI Secretariat | High/Critical residual-risk systems referred; advice returned; agency response owed | OB-14 · Phase 3 AIRC referral pack |
| Digital Assurance Framework | $5M+ or Digital Restart Fund projects: central gate oversight confirming AIAF compliance | OB-16 · Gate calendar in Engagement Hub |
| Lifecycle obligation | Re-run on change to features, datasets, purposes, decision contexts; periodic review proportionate to harm | OB-15 · Trigger Register — artefact control #8 |
| AI Agents Guide (Oct 2025) | Named agent owner, unique identity, observability, escalation, human-intervention points — the incoming assessable standard | OB-18 · Dimension 24 · Phase 4 agentic operating model |
Three-tier assurance: universal self-assessment, central review by exception (self-nominated), financial-threshold oversight. The weakness sits between tiers one and two — the agency's own rating decides whether the centre ever sees the system. That discretion point is where an assurance failure becomes a headline, and where an independent second line earns its fee. When the system-based AIAF ships central telemetry, agencies that built this machinery onboard cleanly; agencies that didn't are exposed on day one.
This ledger replaces V2.0's single AIAF row. Each entry names the source instrument, the evidence artefact an auditor would ask for, and its home in the phase structure. The ledger is baselined at Phase 0, worked to closure through Phases 1–3, and reported in the Gate 4 attestation pack.
| Ref | Obligation | Source | Evidence artefact | Phase home |
|---|---|---|---|---|
| OB-01 | Complete AI inventory, including shadow AI — mandate covers any AI system or component, whether or not part of a formal project | DCS-2024-04 | Maintained inventory: projects, COTS-embedded AI, vendor tools, staff use; owner per entry | P0 discovery · Unsanctioned AI Footprint dimension |
| OB-02 | Current-version AIAF per system — legacy 2022-framework assessments use a different tier scale and do not discharge the obligation | Circular · Workbook S2 | Completed workbooks, version-controlled | P0 stocktake · P1 assessment factory |
| OB-03 | Right expertise at the table — technical, legal, privacy, domain | Workbook S1 | Named participants and roles per assessment | P1 panel design |
| OB-04 | Named responsible officer per system — accountable for the assessment and the decisions the system influences | Workbook S1 · Accountability | Officer named in S1, reflected in register, briefed | P1 accountability mapping · orphan-system flag |
| OB-05 | Risk rating defensibly derived — the Medium/High boundary decides whether the centre ever sees the system | Workbook S2 | Answer rationale surviving independent challenge | P0/P1 Rating Validation — standing rule applies |
| OB-06 | Privacy Impact Assessment where personal information is involved | Assurance · PPIP Act | Completed PIA, privacy sign-off, actions closed | P1 assurance orchestration |
| OB-07 | Human Rights Impact Assessment for rights-affecting consequences — enforcement, eligibility, liberty | Assurance | HRIA proportionate to consequence, findings actioned | P1 assurance orchestration |
| OB-08 | Cybersecurity review; NSW CSP compliance — model endpoints, training stores, prompt injection, agent credentials in scope | Assurance · Cyber Security Policy | Review report, mapped controls, remediation plan | P1 with CISO function |
| OB-09 | Legal-basis advice — statutory authority per automated decision class; the Revenue NSW garnishee finding is the cautionary precedent | Assurance | Legal-basis register: decision class → enabling power | P1 legal-basis register |
| OB-10 | Transparency and appeal path — affected people can understand the factors and access cost-effective review | Transparency principle | Disclosure, explanation capability, review path with volumes | P2 contestability design per use case |
| OB-11 | Audit Record sign-off at seniority proportionate to tier | Workbook S4 | Signed record per delegations matrix | P1 sign-off protocol |
| OB-12 | Records filed under the State Records Act 1998 — shared-drive copies do not discharge the obligation | Workbook S4 · SRA | Records-system entries with retention schedules | P1 records pathway |
| OB-13 | Agency AI register — High/Critical mandatory; better practice registers everything | Workbook S4 | Current register reconciled to inventory | P1 register build · P3 audit-ready |
| OB-14 | AIRC referral for High/Critical residual risk via the AI Secretariat; tracked response to advice | Workbook S4 | Submission record, AIRC advice, agency response | P3 referral pack |
| OB-15 | Re-assessment on material change — features, datasets, purposes, decision contexts; the most-missed obligation in the chain | Lifecycle obligation | Trigger log per system; re-assessment history | Control #8 — Trigger Register, continuous |
| OB-16 | DAF alignment at $5M / Digital Restart Fund thresholds | Digital Assurance Framework | DAF registration; gate submissions citing current AIAF status | P1–P3 gate calendar |
| OB-17 | Supplier obligations in contract — model-change notification, audit rights, data-use limits | Procurement question · buy.nsw | AI schedule in supplier agreements; legacy remediation at renewal | P1 contract-clause audit · feeds control #8 |
| OB-18 | Agentic ownership, identity, observability — named owner, unique identity, audit logs, intervention points | AI Agents Guide | Agent register with fields populated | P4 agentic model · Dimension 24 |
A vendor model retrain is a feature/dataset change under OB-15 — but without a contractual notification clause the trigger fires silently and the agency's AIAF is stale without anyone knowing. Naveniem treats the vendor notification clause as a mandatory remediation in every engagement, actioned at the next contract event.
Only the deltas are shown — everything in the V2.0 phase definitions stands. New deliverable numbering continues the V2.0 sequence.
| Governance Activity | For AU-NSW engagements the 0.7 profile loads the full OB-01–OB-18 ledger, each obligation status-assessed (Evidenced / Partial / Gap / Not applicable) with gate treatment. AIAF stocktake: which systems have current-version assessments; legacy 2022 assessments flagged for migration |
| Validation Activity ✦ | Rating Validation intake: the agency's completed AIAF self-assessments are imported and second-line reviewed. Standing rule applies — Medium self-ratings on penalty/licence/entitlement/safety systems treated as High pending validation |
| Deliverable | 0.7 Regulatory Compliance Exposure Profile (jurisdiction-loaded) · 0.8 AIAF Rating Validation Report ✦ · 0.9 Obligation Ledger Baseline ✦ |
| Assurance Activity ✦ | Triggered assurance to closure: PIA (OB-06), HRIA (OB-07), cyber review (OB-08), legal-basis register (OB-09) — commissioned, tracked, and closed in the Engagement Hub, not just scoped |
| Accountability ✦ | Where any automated decision chain spans agencies (e.g. operator → adjudicator → enforcement), the Cross-Agency Accountability Annex names one end-to-end accountable officer, co-signed by each agency — the direct answer to the administrative-law gap the Ombudsman identified |
| Trigger Activity ✦ | Trigger Register armed (control #8): every consequential system's plausible change events pre-mapped to the four trigger classes with named watchers; vendor notification clauses scheduled into contract events (OB-17) |
| Deliverable | 1.8 Compliance Cliff / Obligation Workstream Plan · 1.9 Shadow-AI Register & AUP · 1.10 Cross-Agency Accountability Annex ✦ · 1.11 Trigger Register (armed) ✦ · 1.12 Delegations Matrix & Records Pathway ✦ |
| Governance Activity ✦ | No use case is chartered without a current AIAF at the correct tier for the system it touches; contestability design (OB-10) is a charter requirement for any citizen-affecting use case, with the appeal path defined before go-live |
| Lockdown ✦ | A use case whose underlying system fires a trigger mid-pilot pauses at the next checkpoint until re-assessment completes — pilots do not outrun their assessments |
| Governance Activity ✦ | AIRC referral packs prepared for all High/Critical residual systems: submission-quality dossiers, anticipated-question briefings, tracked response plans (OB-14). Agency AI register moves to audit-ready: reconciled to inventory monthly, extract producible on demand (OB-13) |
| Deliverable | 3.7 ADM Compliance Evidence Record (AU-CTH) · 3.8 AIRC Referral Pack(s) ✦ · 3.9 Audit-Ready Register Extract ✦ |
| Attestation Activity ✦ | Deliverable 4.6 Executive Attestation Pack: the Gate 4 named output. Weakest-link headline with constraining dimension; obligation ledger status per OB code; validation summary; trigger telemetry (armed / fired / mean time to re-assessment); recommendations carried and closed; signature block for the accountable executive. Every claim traces to an artefact — no free-text assertions |
| Sector Intelligence ✦ | Register extended: jurisdiction profile, constraining dimension, obligation-ledger gap profile, trigger-fire counts — anonymised, sector + size band only, Naveniem principal access |
What it is: second-line review of the agency's own AIAF self-assessments — verdict per system (Confirmed / Uplift recommended / Downgrade recommended / Insufficient evidence) with evidenced rationale.
The standing rule, enforced mechanically: any Medium self-rating on a system flagged penalty, licence, entitlement or safety is auto-flagged treat-as-High pending validation and cannot be confirmed without a recorded rationale addressing the flag.
Why it exists: the framework's most-cited structural weakness is rating discretion at the Medium/High boundary. This control converts that weakness into Naveniem's core assurance product. Exceptions report feeds Gate 0 and the attestation pack.
What it is: per-system pre-mapping of plausible change events to the four AIAF trigger classes — features, datasets, purposes, decision contexts — each with a named watcher and a detection source (vendor notification, release notes, internal change record, data-pipeline event).
Mechanics: firing a trigger requires a date and evidence citation, creates a re-assessment task with a due date, and marks the system AIAF-stale until closed. Vendor model-change log linked to OB-17 contract clauses. Telemetry — armed count, fired-in-period, mean time to re-assessment — reports quarterly and at Gate 4.
Why it exists: OB-15 is the most-missed obligation in the chain because nothing detects the trigger. V2.0 re-assessed by calendar; V2.1 re-assesses by event, with the calendar as the floor.
What it is: where an automated decision chain spans agencies — capture in one, adjudication in another, enforcement in a third — a joint schedule naming a single end-to-end accountable officer, co-signed by each agency, with a shared RACI over the AIAF obligations.
Why it exists: the AIAF assesses at single-agency level; nobody assures the join. The NSW Ombudsman's machine-technology findings make this the administrative-law gap most likely to produce the next headline. The annex is the artefact an agency can adopt in a week.
One change to the instrument set — Dimension 24: Agentic AI Readiness joins Governance & Risk — and one change to the scoring doctrine: the headline maturity score is the minimum across dimensions, with the constraining dimension named. An agency with excellent registers and no trigger detection is not "mostly compliant"; it is exposed, and the headline says so. The mean is reported alongside for trend context. The gov framework variant additionally maps every dimension to an AIAF ethics principle and its OB references.
Pillar: Governance & Risk · Gate linkage: scored at Gate 0; L3 minimum before any agentic scope is funded at Gate 3; L4 target at Gate 4. Ledger linkage: OB-18. Benchmarks: NSW AI Agents Guide (Oct 2025), Singapore IMDA Agentic AI MGF (Jan 2026), IDC AI-Fueled Organization 2.0. L2→L3 artefact test: produce the agent register with named owners and intervention points — or the score is L2.
Anchoring to the AIAF is the defensible position; the crosswalk is what makes it portable. Each gov dimension maps to the AIAF principle it serves, the National Framework cornerstone, the NIST AI RMF function, and the ISO/IEC 42001 clause family — so a QLD (FAIRA/ISO 38507), Commonwealth (DTA v2.0) or regulated-private (VAISS/ISO 42001) engagement is a re-mapping exercise, not a rebuild.
| AIAF principle | Ledger refs | National Framework cornerstone | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|---|
| Community benefit | OB-01, OB-02, OB-09 | AI governance | Map | Context & impact assessment (42005) |
| Fairness | OB-05, OB-06, OB-07 | Risk-based approach | Measure | Annex A data & impact controls |
| Privacy & security | OB-06, OB-08, OB-12 | Data governance | Manage | Annex A security · ISO 27001 bridge |
| Transparency | OB-10, OB-13, OB-14 | Standards | Govern | Documentation & communication clauses |
| Accountability | OB-03, OB-04, OB-11, OB-15–OB-18 | Procurement & assurance | Govern | Leadership, roles, supplier (A.10) |
1. NSW agencies (mandatory AIAF, clearest pain, Excel-era exposure live) → 2. QLD/VIC/Commonwealth via the National Framework crosswalk → 3. Regulated private sector via ISO 42001 + VAISS alignment. Trigger to accelerate: passage of economy-wide mandatory guardrails.
The ten V2.0 rows stand. Three are added — each a documented NSW public-sector failure pattern, not a hypothetical.
Rating discretion: the agency's own Medium rating keeps a consequential system out of central review forever — until an assurance failure makes it a headline
Independent Rating Validation with the mechanically enforced Medium→High-pending rule on penalty/licence/entitlement/safety systems; exceptions report at Gate 0 and in the attestation pack
Silent triggers: a vendor retrains the model, the dataset changes, the AIAF is stale — and nothing in the agency detects that the re-assessment obligation has fired
Trigger Register (artefact control #8) with named watchers and contracted vendor notification (OB-17); fired trigger = re-assessment task with a due date, system marked stale until closed
The unowned join: an automated decision spans three agencies and no single officer is accountable end-to-end — the precise gap behind the Revenue NSW garnishee finding
Cross-Agency Accountability Annex (1.10): one named officer, co-signed joint schedule, shared RACI over the obligation ledger — required at Gate 1 wherever a chain crosses an agency boundary
The methodology and the MaturityOne platform carry the same motion: the Health Check lands the client, the Programme delivers the ledger to closure, the Retainer operates the machinery — and the annual re-score locks the relationship, because Year 2 is only meaningful from the same instrument.
The system-based AIAF is in development. Agencies that build compliance telemetry now onboard cleanly; agencies that don't are exposed the day central visibility switches on. That sentence opens every Secretary conversation this quarter.