Before deploying any AI system, identify who could be harmed, how, and how severely. Establish formal mechanisms for redress before a harm occurs — not in response to one.
AI systems do not operate in a vacuum. They affect real people — workers whose shifts are assigned by an algorithm, subcontractors whose prequalification scores are AI-generated, site communities whose complaints may be triaged by an AI tool. This pillar requires you to identify those people before you deploy, assess the potential for harm, and put formal mechanisms in place for redress.
The Stakeholder Impact Assessment (SIA) is the central artefact. It is not a risk register entry. It is a structured assessment of who is affected by an AI system, in what ways, with what severity, and what your organisation will do if the system causes harm or produces discriminatory outputs.
Contestability is the other requirement. Stakeholders — including your own workers — must have an accessible, real pathway to challenge an AI-influenced decision. A general grievance form is not sufficient. The pathway must be specific to AI-generated outcomes and must connect to someone with authority to act on it.
Your workforce management platform uses AI to generate rosters. Over three months, the algorithm consistently assigns older workers to less desirable shifts due to patterns in historical scheduling data. A union delegate raises a concern. If you cannot produce a Stakeholder Impact Assessment that considered this risk before deployment — and a documented redress process — you are exposed under both the Fair Work Act and AI6 Pillar 02.
An AI-assisted prequalification system assigns risk scores to prospective subcontractors. A small First Nations business is consistently scored as higher-risk due to lack of historical data — not due to actual capability. They are excluded from tendering. Without a documented SIA and a formal contestability mechanism, this outcome is both an ethical failure and a potential breach of procurement obligations.
Impact assessment and redress require coordination across project delivery, legal, HR, and risk functions. This matrix defines who owns each activity.
| Function / Activity | Executive Accountable Official | Project / Business Unit Lead | Legal & Ethics | Risk & Compliance | People & Culture / HR |
|---|---|---|---|---|---|
| Stakeholder identification | C | R | C | C | A |
| Stakeholder Impact Assessment (SIA) | I | R | A | C | C |
| Redress protocol design | A | C | R | I | C |
| Feedback channel monitoring | I | R | C | A | C |
| Systemic issue review | A | I | C | R | I |
These artefacts must exist for every AI system you deploy. Generic HR or risk documents do not satisfy the AI6 requirement — each document must be system-specific.
A structured assessment completed before deployment. Identifies all affected parties, evaluates potential harms (bias, discrimination, privacy, safety, employment), classifies the system as lower-risk or higher-risk, and documents planned mitigations. One SIA per AI system.
A documented process — not a suggestion box — that gives affected stakeholders a specific, accessible pathway to challenge AI-influenced decisions. Must name who reviews challenges, within what timeframe, with what authority to reverse or modify outcomes. Must be communicated to workers in plain language.
A register that tracks every stakeholder contest or feedback item received about an AI system over time. Must be reviewed periodically to identify patterns — repeated challenges about the same type of decision indicate a systemic problem, not a one-off. Pattern thresholds must trigger formal escalation.
An inventory of stakeholder groups with elevated risk of harm from AI outputs — labour hire and casual workers, CALD workers with language barriers, older workers, workers on remote sites, small subcontractors with limited digital access. Must document specific mitigations for each group and be updated when site demographics change.
Work through these items against your current documentation. Your progress is saved automatically and persists between sessions.
Tick each item when you have the required documentation in place.
These are the findings that appear most frequently when heavy industry contractors are assessed against Pillar 02.
Organisations conduct a Stakeholder Impact Assessment as part of a compliance remediation process — after an incident has already occurred. The SIA is a pre-deployment requirement. If the system is already live when you conduct the assessment, you are already non-compliant for the period it operated without one.
A feedback form, a general complaints email, or a reference to the standard HR grievance process is not a contestability mechanism under AI6. The pathway must be named, specific to AI outputs, accessible to the affected party, and connected to someone with authority to modify or reverse the AI-influenced decision.
Contractors typically assess impact on clients and regulators. They rarely treat their own workforce — particularly labour hire, CALD, or casual workers — as a primary stakeholder group requiring specific assessment. The SIA must address internal as well as external impacts, and vulnerable worker groups must be explicitly addressed.
Individual contestation events are recorded but never aggregated. This means systemic algorithmic failures — repeated bias in the same type of decision, for example — are invisible. The Systemic Issue Review Log exists specifically to surface these patterns. Without it, the organisation is governed reactively, not proactively.
The full AI Governance Compliance App includes completed SIA templates, a redress protocol framework, and a systemic issue review log — pre-configured for Australian heavy industry contractor contexts and ready for submission on request.