Case study · A federal government agency (policy + compliance team)
A 4-week AI Governance Review for an APS agency, followed by a small RAG pilot for the agency's policy team. Voluntary AI Safety Standard aligned.
Quantified outcomes
Outcome metrics for this engagement are pending partner sign-off and will publish here once verified.
The problem
The agency had multiple AI tools in early use across teams with no consolidated governance posture, no published policy, and no risk register. The audit committee had asked management for an AI risk briefing at the next quarterly meeting; existing documentation was insufficient to provide one. Separately, the policy team had identified internal RAG over the agency's policy and case archive as a high-value use case but didn't have the architecture or governance frame to deploy it.
The approach
A 4-week AI Governance Review (the productised offer) running in parallel with a 3-week RAG pilot for the policy team. Governance review week 1: AI usage audit across the agency, risk surface mapping. Week 2: policy + risk-register drafting in collaboration with the CIO + General Counsel offices. Week 3: control framework + board-pack development. Week 4: governance committee readout. The RAG pilot was scoped tightly — a single policy domain, RAG against the agency's public policy corpus + a defined internal subset, deployed in the agency's own AWS environment (Bedrock + AU region). The pilot's deployment governance was the first test of the new governance framework — useful validation that the framework was practically implementable, not just documented.
The outcome
The governance review was approved at the first committee round with the policy and risk-register adopted as the agency's official AI governance posture, mapped explicitly to the Voluntary AI Safety Standard's 10 guardrails plus the AU Government AI Assurance Framework. The RAG pilot was running for the policy team at the end of week 6 with explicit feedback loops back into the governance framework. The agency has since engaged on a follow-up scope to extend the framework to two adjacent departments.
Stack used
Similar situation?
30 minutes, conversational, no commitment. We’ll come ready with questions specific to your industry and situation.