This tool does not store anything. If you choose to download a copy, then that's your private copy.
You may choose to upload a copy to Governance Works, but you don't have to, and we don't get a copy if you choose not to provide it. Our Privacy Policy covers anything you do choose to upload.
Exiting the browser deletes the session, the 'Delete Everything' button is there if you want to start over, and isn't strictly necessary if you're leaving the site.
A five-minute self-check for organisations delivering services under a deed or contract with the Department of Employment and Workplace Relations. Put each AI tool you can think of through the checks, up to ten of them, and see where each one lands, both against the Department's rules and as a risk in its own right.
Nothing you type leaves your browser unless you choose to send us your register at the end. There is no account and no sign-up. Your entries are kept in this browser only, so you can close the tab and come back.
The Third-Party AI Assessment Framework, published in September 2025, says organisations must not use AI to directly deliver services on the Department's behalf.
AI may proceed only where the technology is not banned, the contract or deed including any guidelines explicitly permits it, a formal application has been lodged, and the Department has given written approval. One application per use case.
A system that is not directly related to service delivery still has to be fully isolated from service delivery systems and their data. Sharing a tenant, a data store, an identity provider or an integration is not isolation. Where isolation cannot be guaranteed, the Framework says the AI must not be used and the Application Form says you must complete it, so treat unconfirmed isolation as in scope until someone can show otherwise.
Approval can be withdrawn if the technology becomes prohibited, if you fail to meet the conditions set out in your application or approval, or if you have not identified an AI Lead or AI Accountable Officer.
Answer for a single system or feature, add it to the register, then test the next. Copilot across your tenant is one entry. A note-taker in appointments is another. The register holds ten, which is as far as a self-check usefully goes.
Your register is full. Ten is the limit. Delete a row from the register to make space for another tool, or book a conversation if there are more than ten to work through.
Kept in this browser only. Up to ten tools, including the ones a vendor switched on and the ones staff found themselves. If you have more than ten, that is a conversation rather than a self-check.
RFFR outcomes
| Tool | RFFR Outcome |
AI Governance/ |
Remove |
|---|
Nothing added yet. Test a tool on the left and it appears here.
RFFR Outcome tells you where the Department's rules land, based on their approvals and on whether the system is genuinely isolated. A tool can meet the AI Assessment guidelines here and still fail in other areas.
AI Governance/Privacy Exposure tells you the inherent risk of the system, regardless of whether it meets the Framework. It does not assess whether your privacy and security controls exist or whether they work. A High or Critical rating means this one needs managing carefully, with real controls around it.
Because the two columns answer different questions. A use case the Department has already approved in writing is No action under the Framework. That same use case can be Critical exposure because it touches sensitive information and shapes decisions about participants. Permission is not the same thing as safety.
Exposure is inherent risk, meaning the risk before any controls are counted. This tool does not look at your controls at all, so it cannot tell you whether that risk is being managed. It tells you how much there is to manage. Your Australian Privacy Principle obligations, your ISMS controls under Right Fit for Risk, and whatever your board expects of a system that shapes decisions about people all apply alongside the Framework, not instead of it.
So a High or Critical rating on an approved use case is not a problem with the approval. It is a signal about where your privacy and security controls, your monitoring and your human review need to be strongest.
It runs the other way as well. A tool can be Stop now on Low exposure, because prohibited technology has to stop whatever it happens to touch.
That is ten, which is as many as this tool takes. If there are more, the honest answer is that you are past what a five-minute self-check can tell you. Book a conversation and we will work through the rest properly.
Optional, and nothing above depends on it. This sends your register to Paul Berryman at Governance Works, who will read it and may follow up once. Keep your own copy with Print or save as PDF above. You can unsubscribe from any message.
Form not loading? Open it in a new tab.
Finding the tools is the easy half. Stopping the ones that have to stop, deciding what to tell the Department, and building an application it can approve is the work that follows.
Governance Works can carry out an exposure assessment across your tenant, your systems and your people, help you work out what to ask of your subcontractors, and assist you in preparing applications for the use cases worth keeping. Lodging them, and deciding what you tell the Department, stays with you. Scoped to what you need, module by module.
Governance Works · Liability limited by a scheme approved under Professional Standards Legislation. Built against the Third-Party AI Assessment Framework, September 2025.
Stop now. The tool is either prohibited technology, or it is being used in service delivery without written approval. Neither is curable by an application made after the fact. The action is to cease use, record the period it ran, and decide what to disclose.
Apply first. The use case looks capable of approval, but approval has to come before implementation. Check first that your deed or contract, including any guidelines, explicitly permits AI use. Then build the evidence and lodge one application for this use case.
Investigate. Something is unresolved: whether the technology is on the prohibited list, whether the use touches service delivery, or whether the isolation you are relying on is real. Unconfirmed is not the same as clear, and it should not be recorded as clear.
No action. Either the use is genuinely isolated from service delivery, or you already hold written approval. Both need maintaining. Isolation has to be re-tested when the environment changes, and approval carries conditions and notification obligations.
The tool returns two ratings against every entry, and they move independently. The same explanation sits inside the widget, but it needs to exist here as indexable text as well, because this is the part of the page search engines read and the part people quote to a colleague.
RFFR Outcome. Where the Department’s rules land, based on their approvals and on whether the system is genuinely isolated. A tool can meet the AI Assessment guidelines here and still fail in other areas.
AI Governance and Privacy Exposure. The inherent risk of the system, meaning the risk before any controls are counted, regardless of whether it meets the Framework. It does not assess whether your privacy and security controls exist or whether they work. A High or Critical rating means that use needs managing carefully, with real controls around it.
So a use case the Department has approved in writing can read No action and Critical at the same time. Permission is not the same thing as safety. Your Australian Privacy Principle obligations, your ISMS controls under Right Fit for Risk, and whatever your board expects of a system that shapes decisions about people all apply alongside the Framework, not instead of it. It runs the other way too, because a tool can be Stop now on Low exposure where the technology itself is not approved by the Department.
This is triage, not assessment. It sorts a list you already have into an order of urgency. It cannot tell you what the Department will decide, it does not read your deed, and it will not find the AI you have not thought of, which in most environments is the majority of it.
A full exposure assessment works the other way around. It starts from your tenant, your integrations, your vendor release notes and your subcontractors, and produces the list rather than assuming you have one. Where an application is worth making, the assessment produces the evidence the application form asks for.
Back to the full Third-Party AI Assessment service.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
ZOHO is a comprehensive suite of cloud-based applications for business management, collaboration, and productivity.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
GoDaddy's visitor traffic tracking, added automatically to sites hosted with GoDaddy and to sites built with GoDaddy Website Builder. It records page views, clicks, and page timing, and sends them to GoDaddy to measure traffic and site performance.
Service URL: www.godaddy.com (opens in a new window)
You can find more information in our Privacy Policy and .