02 / 06

Understand impacts and plan accordingly

Before deploying any AI system, identify who could be harmed, how, and how severely. Establish formal mechanisms for redress before a harm occurs — not in response to one.

Medium priority Ongoing requirement — ethical alignment Accountable parties: Project owners, Legal, Risk, HR
Pillar explained

What this pillar requires from your organisation.

AI systems do not operate in a vacuum. They affect real people — workers whose shifts are assigned by an algorithm, subcontractors whose prequalification scores are AI-generated, site communities whose complaints may be triaged by an AI tool. This pillar requires you to identify those people before you deploy, assess the potential for harm, and put formal mechanisms in place for redress.

The Stakeholder Impact Assessment (SIA) is the central artefact. It is not a risk register entry. It is a structured assessment of who is affected by an AI system, in what ways, with what severity, and what your organisation will do if the system causes harm or produces discriminatory outputs.

Contestability is the other requirement. Stakeholders — including your own workers — must have an accessible, real pathway to challenge an AI-influenced decision. A general grievance form is not sufficient. The pathway must be specific to AI-generated outcomes and must connect to someone with authority to act on it.

Most contractors think about impact on their principal. They rarely think about impact on their own workforce. That is where auditors look first.
Contractor scenario — Workforce

When AI scheduling disadvantages workers

Your workforce management platform uses AI to generate rosters. Over three months, the algorithm consistently assigns older workers to less desirable shifts due to patterns in historical scheduling data. A union delegate raises a concern. If you cannot produce a Stakeholder Impact Assessment that considered this risk before deployment — and a documented redress process — you are exposed under both the Fair Work Act and AI6 Pillar 02.

Contractor scenario — Supply chain

When AI vendor scoring disadvantages subcontractors

An AI-assisted prequalification system assigns risk scores to prospective subcontractors. A small First Nations business is consistently scored as higher-risk due to lack of historical data — not due to actual capability. They are excluded from tendering. Without a documented SIA and a formal contestability mechanism, this outcome is both an ethical failure and a potential breach of procurement obligations.

Accountability mapping

Impact assessment RACI — who does what

Impact assessment and redress require coordination across project delivery, legal, HR, and risk functions. This matrix defines who owns each activity.

AAccountable
RResponsible
CConsulted
IInformed
Function / Activity Executive Accountable Official Project / Business Unit Lead Legal & Ethics Risk & Compliance People & Culture / HR
Stakeholder identification C R C C A
Stakeholder Impact Assessment (SIA) I R A C C
Redress protocol design A C R I C
Feedback channel monitoring I R C A C
Systemic issue review A I C R I
Required audit documentation

The documents an auditor will ask for.

These artefacts must exist for every AI system you deploy. Generic HR or risk documents do not satisfy the AI6 requirement — each document must be system-specific.

Document 01

Stakeholder Impact Assessment (SIA) Form

A structured assessment completed before deployment. Identifies all affected parties, evaluates potential harms (bias, discrimination, privacy, safety, employment), classifies the system as lower-risk or higher-risk, and documents planned mitigations. One SIA per AI system.

Pre-deployment — mandatory Download template — available in full pack
Document 02

Feedback & Redress Protocol

A documented process — not a suggestion box — that gives affected stakeholders a specific, accessible pathway to challenge AI-influenced decisions. Must name who reviews challenges, within what timeframe, with what authority to reverse or modify outcomes. Must be communicated to workers in plain language.

Communicated to all affected parties Download template — available in full pack
Document 03

Systemic Issue Review Log

A register that tracks every stakeholder contest or feedback item received about an AI system over time. Must be reviewed periodically to identify patterns — repeated challenges about the same type of decision indicate a systemic problem, not a one-off. Pattern thresholds must trigger formal escalation.

Reviewed quarterly at minimum Download template — available in full pack
Document 04

Vulnerable Stakeholder Register

An inventory of stakeholder groups with elevated risk of harm from AI outputs — labour hire and casual workers, CALD workers with language barriers, older workers, workers on remote sites, small subcontractors with limited digital access. Must document specific mitigations for each group and be updated when site demographics change.

Project-specific Download template — available in full pack
Audit-ready checklist

Five questions a compliance auditor will ask.

Work through these items against your current documentation. Your progress is saved automatically and persists between sessions.

Pillar 02 — Impacts checklist

Tick each item when you have the required documentation in place.

0 of 5 items complete 0%
Audit risk

Common gaps auditors find in contractor submissions.

These are the findings that appear most frequently when heavy industry contractors are assessed against Pillar 02.

SIA completed after deployment

Organisations conduct a Stakeholder Impact Assessment as part of a compliance remediation process — after an incident has already occurred. The SIA is a pre-deployment requirement. If the system is already live when you conduct the assessment, you are already non-compliant for the period it operated without one.

Passive contestability only

A feedback form, a general complaints email, or a reference to the standard HR grievance process is not a contestability mechanism under AI6. The pathway must be named, specific to AI outputs, accessible to the affected party, and connected to someone with authority to modify or reverse the AI-influenced decision.

Workforce not considered as stakeholders

Contractors typically assess impact on clients and regulators. They rarely treat their own workforce — particularly labour hire, CALD, or casual workers — as a primary stakeholder group requiring specific assessment. The SIA must address internal as well as external impacts, and vulnerable worker groups must be explicitly addressed.

No pattern monitoring across contests

Individual contestation events are recorded but never aggregated. This means systemic algorithmic failures — repeated bias in the same type of decision, for example — are invisible. The Systemic Issue Review Log exists specifically to surface these patterns. Without it, the organisation is governed reactively, not proactively.

Next step

Identify your exposure before a principal does.

The full AI Governance Compliance App includes completed SIA templates, a redress protocol framework, and a systemic issue review log — pre-configured for Australian heavy industry contractor contexts and ready for submission on request.

← Previous 01 — Decide who is accountable Next → 03 — Measure and manage risks