An important note on Privacy

This tool does not store anything. If you choose to download a copy, then that's your private copy.
You may choose to upload a copy to Governance Works, but you don't have to, and we don't get a copy if you choose not to provide it. Our Privacy Policy covers anything you do choose to upload.
Exiting the browser deletes the session, the 'Delete Everything' button is there if you want to start over, and isn't strictly necessary if you're leaving the site.

Are you allowed to run that AI?

A five-minute self-check for organisations delivering services under a deed or contract with the Department of Employment and Workplace Relations. Put each AI tool you can think of through the checks, up to ten of them, and see where each one lands, both against the Department's rules and as a risk in its own right.

Nothing you type leaves your browser unless you choose to send us your register at the end. There is no account and no sign-up. Your entries are kept in this browser only, so you can close the tab and come back.

Start from the right default

The Third-Party AI Assessment Framework, published in September 2025, says organisations must not use AI to directly deliver services on the Department's behalf.

AI may proceed only where the technology is not banned, the contract or deed including any guidelines explicitly permits it, a formal application has been lodged, and the Department has given written approval. One application per use case.

A system that is not directly related to service delivery still has to be fully isolated from service delivery systems and their data. Sharing a tenant, a data store, an identity provider or an integration is not isolation. Where isolation cannot be guaranteed, the Framework says the AI must not be used and the Application Form says you must complete it, so treat unconfirmed isolation as in scope until someone can show otherwise.

Approval can be withdrawn if the technology becomes prohibited, if you fail to meet the conditions set out in your application or approval, or if you have not identified an AI Lead or AI Accountable Officer.

Test one tool, or ten

Answer for a single system or feature, add it to the register, then test the next. Copilot across your tenant is one entry. A note-taker in appointments is another. The register holds ten, which is as far as a self-check usefully goes.

Start
Gate 1 Does this AI relate to delivering services on behalf of the Department? Includes anything touching participants, their data, their decisions, or the work your staff do to deliver the contract. If you are not sure, the honest answer is Not sure.
Gate 3 Is the technology prohibited for government use? Check the Department of Home Affairs Protect Security Directions. The Framework applies this check to service delivery use. We apply it to everything, because the Directions do.
Approval Do you hold written approval from the Department for this use case? Written approval for this specific use case. A general conversation, a favourable email about something else, or approval of a different tool does not count.
Context
Where it lands

Answer the questions above

The first gate that fails decides the RFFR outcome, so work down in order.

Your register 0 of 10

Kept in this browser only. Up to ten tools, including the ones a vendor switched on and the ones staff found themselves. If you have more than ten, that is a conversation rather than a self-check.

RFFR outcomes

0 Stop now
0 Apply first
0 Investigate
0 No action

Nothing added yet. Test a tool on the left and it appears here.

The hard part is what comes after

Finding the tools is the easy half. Stopping the ones that have to stop, deciding what to tell the Department, and building an application it can approve is the work that follows.

Governance Works can carry out an exposure assessment across your tenant, your systems and your people, help you work out what to ask of your subcontractors, and assist you in preparing applications for the use cases worth keeping. Lodging them, and deciding what you tell the Department, stays with you. Scoped to what you need, module by module.

Book a conversation  ·  hello@governanceworks.com.au

What this tool is not

  • It is an indicative triage, not an assessment. It tells you where to look, not what the Department will decide.
  • It does not construe your deed, which may impose obligations beyond the Framework.
  • It is not legal advice.
  • Prohibited technology lists and the Framework itself change. Re-check rather than relying on an old answer.

Governance Works · Liability limited by a scheme approved under Professional Standards Legislation. Built against the Third-Party AI Assessment Framework, September 2025.


What the four outcomes mean

Stop now. The tool is either prohibited technology, or it is being used in service delivery without written approval. Neither is curable by an application made after the fact. The action is to cease use, record the period it ran, and decide what to disclose.

Apply first. The use case looks capable of approval, but approval has to come before implementation. Check first that your deed or contract, including any guidelines, explicitly permits AI use. Then build the evidence and lodge one application for this use case.

Investigate. Something is unresolved: whether the technology is on the prohibited list, whether the use touches service delivery, or whether the isolation you are relying on is real. Unconfirmed is not the same as clear, and it should not be recorded as clear.

No action. Either the use is genuinely isolated from service delivery, or you already hold written approval. Both need maintaining. Isolation has to be re-tested when the environment changes, and approval carries conditions and notification obligations.

Outcome and exposure are two different questions

The tool returns two ratings against every entry, and they move independently. The same explanation sits inside the widget, but it needs to exist here as indexable text as well, because this is the part of the page search engines read and the part people quote to a colleague.

RFFR Outcome. Where the Department’s rules land, based on their approvals and on whether the system is genuinely isolated. A tool can meet the AI Assessment guidelines here and still fail in other areas.

AI Governance and Privacy Exposure. The inherent risk of the system, meaning the risk before any controls are counted, regardless of whether it meets the Framework. It does not assess whether your privacy and security controls exist or whether they work. A High or Critical rating means that use needs managing carefully, with real controls around it.

So a use case the Department has approved in writing can read No action and Critical at the same time. Permission is not the same thing as safety. Your Australian Privacy Principle obligations, your ISMS controls under Right Fit for Risk, and whatever your board expects of a system that shapes decisions about people all apply alongside the Framework, not instead of it. It runs the other way too, because a tool can be Stop now on Low exposure where the technology itself is not approved by the Department.

Where this sits relative to an assessment

This is triage, not assessment. It sorts a list you already have into an order of urgency. It cannot tell you what the Department will decide, it does not read your deed, and it will not find the AI you have not thought of, which in most environments is the majority of it.

A full exposure assessment works the other way around. It starts from your tenant, your integrations, your vendor release notes and your subcontractors, and produces the list rather than assuming you have one. Where an application is worth making, the assessment produces the evidence the application form asks for.

Book a conversation

 

Back to the full Third-Party AI Assessment service.