AI That Works  ·  AI6 Guidance
AI6-T05.3
Protocol Document — Pillar 05
Data Governance & Cybersecurity Protocols
Document No.AI6-T05.3Version[1.0]
Document Owner[Name / Role]Date[DD/MM/YYYY]
Review Date[DD/MM/YYYY]Status[ Draft / In Review / Approved ]
Organisation[Organisation Name]
Complete one section per AI system or adapt this document as an organisation-wide protocol covering all systems. Legal review is recommended for sections covering intellectual property, privacy, and data residency obligations.
1. Data Inventory
Data TypeSourceContains Personal Information?Sensitivity LevelRetention Period
[e.g. Employee timesheets][e.g. HRIS system]YesSensitive[e.g. 7 years]
     
     
2. Data Provenance & Quality
Training data source and provenance assessment
[Describe where the model's training data came from, whether it has been assessed for bias or quality issues, and any known provenance gaps.]
Ongoing data quality assurance measures
[Describe how input data quality is monitored — e.g. automated validation rules; manual spot-checking; vendor-provided data quality reports.]
3. Privacy Controls
  • All personal information processed by AI systems is governed by [Organisation Name]'s Privacy Policy and the Privacy Act 1988.
  • Personal information is not input into AI systems with third-party cloud processing without Privacy Impact Assessment approval.
  • Generative AI systems must not be used with client or employee personal data unless approved by the Privacy Officer.
4. Intellectual Property Controls
IP rules for generative AI use
[Define what types of content (client proposals, confidential designs, proprietary cost data) must not be submitted to generative AI systems. Reference any approved tools and their data handling terms.]
5. Cybersecurity Measures
  • All AI API integrations are protected by [authentication method — OAuth 2.0 / API key management / other].
  • Access to AI systems is role-based and reviewed quarterly.
  • Prompt injection testing is conducted on all publicly-facing or high-risk Generative AI deployments before go-live.
  • AI system security events are logged and monitored within the organisation's SIEM or equivalent.