FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Use of Artificial Intelligence, Generative AI, and Machine Learning — Interim Policy
Version 1.0 — April 2024
OCIO
ndis.gov.au
ndis
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 1
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Policy Summary
The National Disability Insurance Agency (NDIA or the ‘Agency’) requires all staff (including contractors and partner staff) to implement and adhere to the Agency Policies and Procedures. This document establishes the policy for Use of Artificial Intelligence, Generative AI, and Machine Learning in the Agency.
Document Control
| Document Name | Use of Artificial Intelligence, Generative AI, and Machine Learning – Interim Policy |
| HPE Document No or SharePoint Link | Use of AI Interim Policy Draft 0.1.docx |
| Date | April 2024 |
| Status | Final |
| Version | 1.0 |
| Owner | Branch Manager, Enterprise Architecture and Governance Branch |
Approval Status Log
| Version | 1.0 |
| Reviewed by | BM Enterprise Architecture and Governance |
| Publication date | April 2024 |
| Approved by | Ajay Satyan, Chief Information Officer |
| Approval date | April 2024 |
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 2
Page 94 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Table of Contents
Use of Artificial Intelligence, Generative AI, and Machine Learning – Interim Policy………………………………………………………………………………………………………..1
Policy Summary……………………………………………………………………………………………………………………………………………………………………………………………..2
-
Introduction……………………………………………………………………………………………………………………………………………………………………………………………..4
-
Purpose……………………………………………………………………………………………………………………………………………………………………………………………..4
-
Applicability……………………………………………………………………………………………………………………………………………………………………………………………..4
3.1. Policy exclusions………………………………………………………………………………………………………………………………………………………………………………4
3.2. Policy exemptions………………………………………………………………………………………………………………………………………………………………………………5
-
Policy Principles……………………………………………………………………………………………………………………………………………………………………………………………..5
-
Roles and responsibilities……………………………………………………………………………………………………………………………………………………………………………………………..6
5.1. Chief Information Officer (CIO)……………………………………………………………………………………………………………………………………………………………………………….6
5.2. AI Working Group……………………………………………………………………………………………………………………………………………………………………………….6
5.3. Project Team……………………………………………………………………………………………………………………………………………………………………………….6
5.4. Copilot trial members……………………………………………………………………………………………………………………………………………………………………………….7
-
Non-compliance……………………………………………………………………………………………………………………………………………………………………………………………..7
-
Authority and review……………………………………………………………………………………………………………………………………………………………………………………………..7
Appendix A – Glossary of terms and abbreviations……………………………………………………………………………………………………………………………………………………………………………………………..8
Appendix B – References, legislation, and standards……………………………………………………………………………………………………………………………………………………………………………………………..9
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 3
Page 95 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
1. Introduction
The National Disability Insurance Agency (Agency) is participating in a trial of Copilot for Microsoft 365 (the trial) along with other Federal Government Agencies. The trial is sponsored by the Prime Minister and is supported by the Digital Transformation Agency (DTA). The use of Copilot as part of a trial aligns with interim Government guidance on the use of generative AI tools.
Copilot by Microsoft brings the power of generative AI to professional settings while offering protection from unauthorised data sharing and unregulated internet access.
The aim of the trial is to help to shape the future use of Artificial Intelligence (AI) by Government staff. Copilot is built on top of advanced AI tools to provide intelligent assistance to users to potentially enhance productivity and collaboration.
Copilot is not a mechanism for making independent decisions.
During the trial, emphasis will be placed on protecting Agency data and personal privacy.
Finally, the trial will explore the benefits and any potential impacts of integrating Copilot within the Agency and the wider APS.
2. Purpose
This policy outlines expectations in the use of AI functionality provided by Copilot within the trial.
The policy establishes a framework for the ethical, legal, secure, and effective use of Artificial Intelligence (AI), Generative AI, and Machine Learning (ML) within the Agency. The policy ensures the safety and security of our staff, critical data, and the National Disability Insurance Scheme (the Scheme) information.
The policy aims to harness the benefits of generative AI services to enhance business outcomes and administrative efficiencies for Agency staff.
This policy is written within the context of the Agency ICT Policy Framework.
3. Applicability
This policy applies to all Agency staff, including labour hire workers, participating in the DTA trial of Copilot and the use of AI-products and related activities within the agency during the Microsoft Copilot trial period.
3.1. Policy exclusions
There are NO exclusions to this policy.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 4
Page 96 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
3.2. Policy exemptions
Unless specified in this policy, there are NO exemptions, unless approved by the CIO and recommended by the Agency AI Working Group.
4. Policy Principles
AI tools offer transformative possibilities for public sector services, particularly in enhancing the efficiency and effectiveness of administrative and operational functions. To ensure confidence in the Agency’s processes and alignment with the operational and strategic goals, users of Copilot must ensure that the following policy principles are met:
- Accountability: Users must be able to explain, justify and take ownership of any advice or decisions made when using AI. Users are responsible for the outcomes of AI generated artefacts. Exercising due diligence when using AI tools is required to ensure the highest standards of quality and ethical responsibilities are met.
- Transparency: Decisions made by Agency staff utilising AI within Microsoft productivity software must be understandable and explainable and provide a clear auditable trail of how the decision was made. AI must not be used for automated independent decision making which may impact participants or the strategic direction of the Agency.
- Accessibility and Inclusion: Any AI tool used by the Agency must adhere to and actively support accessibility standards such as the Web Content Accessibility Guidelines (WCAG).
- Privacy: All Agency staff have a responsibility to protect classified, personal, or otherwise sensitive information held by the Agency. Acceptable use of AI tools compliments existing use of data and information expectations and must protect the privacy of Participants, Partners, and other stakeholders. The use of AI must adhere to the requirements of the Privacy Act 1998 (Cth). The recommendations in the privacy assurance advice in respect of Copilot must be implemented.
- Use of Scheme data: Any recording, use or disclosure of protected Agency information by the AI tools must comply with the secrecy provisions in the National Disability Insurance Scheme Act 2013 (Cth) (NDIS Act). Unless otherwise expressly [authorised by the CIO and] authorised under the NDIS Act, AI tools must not access participant records in PACE, store protected Agency information outside of Australia, disclose protected Agency information to any third parties, or use any protected Agency information for any purposes other than provision of services to the NDIA.
- Compliance: Use of AI tools must comply with existing Agency and ICT specific policies including but not limited to the Acceptable Use Policy, the Digital Collaboration policy, and ICT Security Policy. The use of AI tools must also take into consideration and comply with the APS Code of Conduct and other relevant legislation.
- Training: All users of AI tools must have familiarised themselves with Agency supplied information and training on the responsibilities and ethical use of AI tools within the Agency.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 5
Page 97 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
- Governance: The establishment of a dedicated AI Governance function via the Agency AI Working Group will oversee this trial. The governance body will include representatives with expertise in accessibility, technology, ethics, and legal compliance.
- Human Intervention and Review Processes: Procedural guidelines will ensure that human oversight and input is integral to any continued use of AI tools after the trial.
This policy, supported by procedural documents and information, reflects our commitment to ethical AI usage across the Australian Government.
5. Roles and responsibilities
5.1. Chief Information Officer (CIO)
The CIO is responsible for ensuring that, as far as reasonably possible, effective controls are in place during the trial period to ensure that Copilot is being used as per the requirements of this policy. The CIO is responsible for resourcing the Copilot trial.
5.2. AI Working Group
The AI Working Group are the responsible governance body for the trial. They are responsible for monitoring the use of AI, ensuring that users have access to training and resources that provides clear guidance on the use of AI during the trial. The body will review the outcomes of the Microsoft Copilot trial when it concludes on the 30th of June 2024. The body is also responsible for informing the DTA and other agencies of any insights that will assist the government in implementing and guiding the use of AI tools throughout the APS. The feedback collated from the AI Working Group will be incorporated when developing the permanent Use of AI Policy, should the Copilot trial be embedded further into the agency.
The AI Working Group is not responsible for individual quality control of artefacts produced as part of the trial.
5.3. Project Team
The project team for the trial are responsible for monitoring the use of Copilot and ensuring that, throughout the trial users are informed of their responsibilities and the need to comply with this policy. The project team are accountable for undertaking a review of the trial and providing feedback to DTA. The project team are responsible for working with the Information Law and Privacy team in Legal Services Group to facilitate the privacy assurance advice for the Copilot trial.
The project team will be responsible for reporting the outcomes of the trial to the Agency Senior Leadership Team (SLT) and the Board in the form of a decision paper on the future use of AI within the Agency in alignment with the approach of the Australian Government. The project team will engage with DTA during the trial period, to socialise and review the policy, to ensure consistency with DTA’s expectations of the Copilot trial.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 6
Page 98 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
5.4. Copilot trial members
The members of the Copilot trial are responsible for ensuring that they understand and comply with the requirements of this policy and that they provide unbiased and factual feedback in a timely manner regarding their experience using Copilot.
6. Non-compliance
Any intentional, repeated, or negligent breach of this policy or any other ICT policy by Agency personnel may be considered a breach of the APS Code of Conduct which could give rise to a range of possible sanctions including termination.
Breaches will be managed in line with Agency Human Resource policies.
7. Authority and review
This policy was approved by the CIO on April 2024 and will be reviewed at the completion of the trial pending recommendations from DTA.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 7
Page 99 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Appendix A – Glossary of terms and abbreviations
The Glossary contains definitions for all key terms used in this document and contain specific meaning in the context of this policy.
| Term or Abbreviation | Definition |
|---|---|
| Artificial Intelligence (AI) | Systems performing tasks requiring human intelligence. For the Agency, this could include AI-assisted communication tools for clients with speech or hearing impairments. |
| Machine Learning (ML) | A subset of AI where systems learn from data and improve results over a period. In the Agency context, this could involve using ML to analyse data indicating software use to inform decisions around the purchase of additional licences. |
| Generative AI | AI tools that generate new content based on data. For the Agency, this can include summarising documents, providing meeting notes from a recorded transcript, or creating a PowerPoint presentation from a reading. |
| Copilot for Microsoft 365 Trial | A government initiative using AI in public sector operations. The Agency may leverage this for automated reporting and administration tasks, reducing the workload on staff and enhancing service delivery. |
| Copilot for Microsoft 365 | Copilot is an AI-powered productivity tool that coordinates large language models (LLMs), available and appropriate Agency data, and the Microsoft 365 apps such as Word, Excel, PowerPoint, Outlook, and Teams. This integration provides real-time quasi-intelligent assistance, enabling users to enhance their creativity, productivity, and skills. |
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 8
Page 100 of 189
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Appendix B – References, legislation, and standards
Legal Frameworks and Acts
The Privacy Act
Disability Discrimination Act 1992
National Disability Insurance Scheme Act 2013
National Disability Insurance Scheme (Protection and Disclosure of Information) Rules 2013
Ethical Guidelines and Standards
Australia’s Artificial Intelligence Ethics Framework
European Unions Ethics guidelines for Trustworthy AI
Australian Government AI Resources
Digital Transformation Agency’s AI resources and guidelines
Australia’s Tech Future policy document
Engaging with Artificial Intelligence
International AI Guidelines
OECD Principles on AI
IEEE Standards on AI and Autonomous Systems
Best Practice Guidelines for AI in Public Sector
World Economic Forum’s Guidelines on AI Governance
United Nations Guidelines on AI and Public Service Delivery
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 9
Page 101 of 189
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
S42 - legal professional privilege
FOI 24/25-1356 - DISCLOSURE LOG OFFICIAL
OCIO Artificial Intelligence Working Group — Terms of Reference March 2024
Artificial Intelligence Working Group
Terms of Reference — Office of the Chief Information Officer
Purpose
In the wake of rapid advancements in Artificial Intelligence (AI) technologies, our Agency recognises the potential of AI to transform public service delivery, enhance operational efficiency, and foster innovation. To this end, the Agency has embarked on a trial of Copilot for Microsoft 365 alongside numerous Australian Government Agencies and Departments, aiming to explore the utility and implications of AI-assisted work processes.
Concurrently, there is a pressing need to establish a robust governance framework to navigate the ethical, legal, and practical challenges associated with any future AI deployment.
This necessitates the formulation of an Interim Use of AI Policy, aligned with the principles and standards advocated by the Digital Transformation Agency (DTA) and the broader mandates of the Australian Government regarding ethical AI use.
The AI Working Group is thus constituted to steer this pivotal initiative, ensuring that the exploration of AI technologies is conducted responsibly, transparently, and in harmony with public interest and the expectations of the NDIA.
Objectives
The primary objectives of the AI Working Group are as follows:
- Governance Oversight: To provide strategic oversight of the Copilot for Microsoft 365 trial, ensuring it aligns with the Agency’s objectives, ethical standards, and regulatory requirements.
- Policy Development and Approval: To spearhead the drafting, refinement, and eventual approval of the Interim Use of AI Policy. This policy will serve as the cornerstone for the Agency’s AI governance framework, encapsulating guidelines on ethical AI use, data privacy, and security.
- Feedback Analysis and Decision Making: To systematically evaluate feedback from the Copilot for Microsoft 365 trial, alongside insights from the DTA and other stakeholders. Based on this analysis, the Working Group will formulate recommendations on the strategic incorporation of AI technologies within the Agency’s operational and service delivery paradigms.
Scope
The AI Working Group’s scope of activities encompasses the following areas:
- Trial Monitoring and Evaluation: Overseeing the execution of the Copilot for Microsoft 365 trial, including monitoring performance metrics, user satisfaction, and compliance with ethical guidelines.
- Policy Formulation: Leading the development of the Interim Use of AI Policy, ensuring it reflects the Agency’s commitment to ethical AI use, safeguards privacy, and promotes transparency.
Delivered by the
National Disability Insurance Agency
Page 143 of 189
1
FOI 24/25-1356 - DISCLOSURE LOG OFFICIAL
OCIO Artificial Intelligence Working Group – Terms of Reference March 2024
- Stakeholder Engagement and Feedback Synthesis: Engaging with a broad spectrum of stakeholders, including trial participants, the DTA, and the public, to garner diverse perspectives on AI deployment. This engagement will inform the Group’s recommendations on the future direction of AI initiatives within the Agency.
Membership
The AI Working Group shall comprise Directors and Branch Managers from various business areas within the Agency to ensure a diverse range of perspectives and expertise. The composition is as follows:
- Chair: Phil Bergersen, Branch Manager of the OCIO Enterprise Architecture and Governance Branch, will serve as the Chair of the Working Group, responsible for leading discussions, setting agendas, and ensuring the Group’s objectives are met.
- Deputy Chair: Cathy
redacted: s47F - personal privacy, Director of the OCIO Portfolio Management Directorate, will support the Chair and act in their stead as required. - Additional members will include Directors and Branch Managers from Legal, Procurement, Human Resources, and Accessibility and Inclusion each bringing unique insights into how AI can serve their area’s objectives and challenges.
Member Responsibilities
Members of the AI Working Group are entrusted with the following responsibilities:
- Strategic Oversight: Ensure that the AI initiatives, particularly the Copilot for Microsoft 365 trial and the development of the Interim Use of AI Policy, align with the Agency’s strategic goals and comply with Australian Government standards for ethical AI use.
- Collaboration and Communication: Facilitate effective communication and collaboration across departments and with external stakeholders to ensure a comprehensive understanding and integration of AI technologies.
- Policy Development: Lead the creation, refinement, and approval process of the Interim Use of AI Policy, ensuring it is comprehensive, practical, and reflective of stakeholder feedback.
- Evaluation and Reporting: Assess the outcomes of the Copilot trial and synthesise feedback from all relevant sources to inform policy development and future AI strategy.
Operations
The AI Working Group will convene every fortnight via Microsoft Teams to ensure regular monitoring and progress on its objectives. These meetings will:
- Discuss Progress: Review the status of the Copilot trial and policy development efforts.
- Resolve Issues: Identify and address any challenges or concerns arising from the trial or policy formulation process.
- Strategic Decisions: Make decisions regarding the direction of AI initiatives and policy adjustments as required.
Special meetings may be called by the Chair or upon request by any member if urgent issues or decisions arise.
March 2023
Page 144 of 189
2
FOI 24/25-1356 - DISCLOSURE LOG OFFICIAL
OCIO Artificial Intelligence Working Group – Terms of Reference March 2024
Reporting and Review
- Reporting Structure: The AI Working Group will report directly to the Chief Information Officer (CIO), the Chief Operating Officer (COO) and the Agency’s Senior Leadership Team, providing regular updates on the progress, findings, and recommendations regarding the Copilot trial and AI policy development.
- Review Process: The ToR will be subject to an annual review or as needed to ensure it remains relevant and effective in guiding the Working Group’s activities. Feedback from members and stakeholders will be integral to this review process.
Approval and Amendment Process
- The initial ToR is to be approved by the Chief Information Officer following consultation with the AI Working Group members.
- Amendments to the ToR can be proposed by any member of the Working Group but must be ratified by a majority vote within the Group before submission for final approval by the Senior Leadership Team.
March 2023
Page 145 of 189
3
FOI 24/25-1356 - DISCLOSURE LOG OFFICIAL:
Risk & Issue Review Process
The following process steps need to be included in Risk Register for consistency:
Project teams should follow the below steps to determine the applicable risk rating for each of the identified project risks and/or issues:
- Open Project Risk Register
- Refer to the NDIA Risk Rating Matrix (Below)
- Consider the Likelihood of the risk or issue being realised (percentage-based assessment), taking account for any existing controls in place to manage/mitigate the risk
- Consider the most material Consequence to the project if the risk is realised using the Project Consequence matrix (for project delivery risks) or the Strategic & Operational Consequence matrix (for delivered risks)
- Document both Likelihood (numeric) and Consequence (alphanumeric) rating outcomes in the Risk Register
- Applicable risk rating (Low/Medium/High/Critical) will be calculated based on the intersection of the Likelihood and Consequence ratings determined in steps 3. and 4. (e.g., 3D = High).
Assessments under points 3 and 4 above are to be based on the current / prevailing project environment. Risk assessments should be conducted on a regular basis (weekly is preferred, with alignment to reporting timeframes being the minimum).
All high and critical rated risks should referred to the SES project lead for confirmation and reported to the Program Management Office as appropriate.
NDIA Risk Rating Matrix
The Agency has a risk assessment criteria which includes a risk matrix (below) to support the process of applying a severity rating to each identified risk.
The matrix contains consequence assessment criteria for both strategic and operating risks (left hand side of matrix) and project risks (right hand side of matrix), with the same likelihood ratings and severity matrix used for all risks categories (centre of matrix).
| Project Consequences | Likelihood One - Rare | Likelihood Two - Unlikley | Likelihood Three - Possible | Likelihood Four - Likely | Likelihood Five - Almost Certain | Strategic Consequence | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| Schedule (critical path) | Cost (Budget) | Outcomes / Benefits | < 5 percent likelihood of the risk occurring in the next year | 5 percent - 20 percent likelihood of the risk occurring in the next year | 20 percent - 50 percent likelihood of the risk occurring in the next year | 50 percent - 80 percent likelihood of the risk occurring in the next year | >80 percent likelihood of the risk occurring in the next year | Participant Outcomes | Scheme Sustainability1 | |
| E - Extreme | >3 months or >30% of schedule whichever is the greater | >$3M or >30% of budget whichever is the greater | Fundamental impact on business case & benefit (requiring immediate assessment of project viability) | M | H | H | C | C | Significantly below target levels across most regions for:\ | |
| • Participant intake levels for > 2 quarters\ | ||||||||||
| • Participant satisfaction levels for > 3 quarters\ | ||||||||||
| • Participant outcomes for > 1 year | • Scheme support costs >20% over target\ | |||||||||
| • Agency costs >20% over budget\ | ||||||||||
| • Divisional underspend >60% | • Significant shortages in availability of critical service supply across most regions for > 2 quarters, requiring significant NDIA intervention\ | |||||||||
| • Significant and sustained impact on provider sentiment across most regions for > 2 quarters | • Long term (e.g. 1 year) significant deficiencies in workforce capacity, quality and engagement across most of the agency\ | |||||||||
| • Single or multiple fatalities or serious sustained health impacts for a large number of people | Complete loss of public confidence and trust for the agency’s management of the scheme leading to significant Government intervention and/or inquiry. Board and/or CEO removed. |
Page 146 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Project Consequences | Likelihood One - Rare | Likelihood Two - Unlikley | Likelihood Three - Possible | Likelihood Four - Likely | Likelihood Five - Almost Certain | Strategic Consequence | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| Schedule (critical path) | Cost (Budget) | Outcomes / Benefits | < 5 percent likelihood of the risk occurring in the next year | 5 percent - 20 percent likelihood of the risk occurring in the next year | 20 percent - 50 percent likelihood of the risk occurring in the next year | 50 percent - 80 percent likelihood of the risk occurring in the next year | >80 percent likelihood of the risk occurring in the next year | Participant Outcomes | Scheme Sustainability1 | |
| D - Major | >1 month & < 3 months or <30% of schedule whichever is the greater | >$1M & <=$3M or <30% of budget whichever is the greater | Tangible impact on business case & benefit (requiring immediate reporting to Steering Committee) | M | M | H | H | C | Significantly below target levels across multiple regions for:\ | |
| • Participant intake levels for > 1 quarter\ | ||||||||||
| • Participant satisfaction levels for > 2 quarters\ | ||||||||||
| • Participant outcomes for 6-12 months | • Scheme support costs 10-20% over target\ | |||||||||
| • Agency costs 10-20% over budget\ | ||||||||||
| • Divisional operating costs >25% over budget\ | ||||||||||
| • Divisional underspend 40-60% | • Significant shortages in availability of some critical service supply across regions for > 1 quarter requiring some NDIA intervention\ | |||||||||
| • Significant and lengthy impact on provider sentiment across multiple regions for > 1 quarter | • Significant deficiencies in workforce capacity, quality and engagement across most divisions for the agency for > 2 quarters\ | |||||||||
| • Potentially serious or life threatening consequences for a person or with systemic health effects across large parts of the workforce | Significant loss of public confidence and trust relating to multiple aspirations over > 1 quarter. Increased scrutiny at ministerial level. | |||||||||
| C - Moderate | >10 days & <1 month or <20% of schedule whichever is the greater | >$250k & <=$1M or <20% of budget whichever is the greater | Minor impact on business case & benefit | M | M | M | H | H | Moderately below target levels across 1 or more regions for:\ | |
| • Participant intake levels for 1 month\ | ||||||||||
| • Participant satisfaction levels for 1 quarter\ | ||||||||||
| • Participant outcomes for 6 months | • Scheme support costs 5-10% over target\ | |||||||||
| • Agency costs 5-10% over budget\ | ||||||||||
| • Divisional operating costs 20-30% over budget\ | ||||||||||
| • Divisional underspend 25-40% | • Moderate shortages in availability of some service supply across 1 or more regions\ | |||||||||
| • Moderate impact on provider sentiment across 1 or more regions for > 1 month | • Moderate deficiencies in workforce capacity, quality and engagement across 1 or more divisions and/or multiple regions for > 1 month\ | |||||||||
| • Significant injury or health effects to a person or cohort | Moderate loss of public confidence and trust on 1 or more issues for > 1 month | |||||||||
| B - Minor | >5 & <10 days or <10% of schedule which ever is the greater | >$50k & <=$250k or <10% of budget whichever is the greater | No impact to business case & benefit | L | L | M | M | M | Slightly below target levels across 1 or more regions for:\ | |
| • Participant intake levels for < 1 month\ | ||||||||||
| • Participant satisfaction levels for < 1 quarter\ | ||||||||||
| • Participant outcomes for < 1 quarter | • Scheme support costs 2-5% over target\ | |||||||||
| • Divisional operating costs 10-20% over budget\ | ||||||||||
| • Divisional underspend 10-25% | • Delay in availability of few non-critical services across 1 or more regions for < 1 month\ | |||||||||
| • Minor impact on provider sentiment across 1 or more regions for < 1 month | • Minor deficiencies in workforce capacity, quality and engagement within 1 division for < 1 month\ | |||||||||
| • Minor impact on a person’s health | Some loss of public confidence and trust on a single issue for < 1 month | |||||||||
| A - Insignificant | Up to <5 days or <5% of schedule which ever is the greater | Up to $50k or <5% of budget whichever is the greater | No impact to business case & benefit | L | L | L | L | L | Below target levels within 1 region for:\ | |
| • Participant intake levels for < 1 week\ | ||||||||||
| • Participant satisfaction levels for <1 month\ | ||||||||||
| • Participant outcomes for < 1 quarter | • Scheme support costs <2% over target\ | |||||||||
| • Divisional operating costs 5-10% over budget\ | ||||||||||
| • Divisional underspend <10% | • Minor delay for < 1 week in availability of non-critical services within 1 region\ | |||||||||
| • Minor impact for < 1 week on provider sentiment within 1 region | • Temporary minor shortfall in workforce capacity, quality and engagement within 1 region | Minor and isolated damage to public confidence and trust within 1 region or issue. |
Page 147 of 189
FOI 24/25-1356 - DISCLOSURE LOG
The content of this document is OFFICIAL: SENSITIVE.
RISK & ISSUE REGISTER
Project Name
Copilot Project Risk Register
| Number | Project Risk Owner | Project Risk Manager | Project Risk Name | Project Risk Description | Project Risk Type |
|---|---|---|---|---|---|
| Risk number | Surname, First name | Surname, First name | i.e. One line summary/title | i.e. Detailed description | Select Risk Type |
| R.1 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Data Privacy Concerns | Data Privacy Concerns: AI systems often require large amounts of data, which can raise concerns about user privacy and data protection. | Project Risk |
| R.2 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Copilot training | Lack of training for users could lead to inefficient, incorrect, or inappropriate use of Copilot tool and raise further concerns & confusion. | Project Risk |
| R.3 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Security Vulnerabilities: | AI systems can be susceptible to cyberattacks, including ransomware, which have recently increased quite significantly. | Project Risk |
| R.4 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Agency Staff access to Copilot without permission | There is a risk that, if the Agency decides to not proceed with the Copilot Program, that the Agency might not be able to effectively prevent staff from accessing Copilot on Agency systems | Project Risk |
| R.5 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Change Management Activities | There is risk that the change management approach won’t be adaptive enough to incorporate both technical information and practical training on the use of CoPilot. | Project Risk |
| R.6 | Chief Information Officer | redacted: s47F - personal privacy Josiph |
Current controls not effective to manage Copilot risks | There is a risk that the current operational controls may not be effective enough to manage the risks of Copilot. | Both |
* The fields can be used interchangeably between Risk and Issues
Risk Control
Risk controls are a part of the risk management process in which methods for neutralising or reduction of identified risks are implemented. Controlled risks remain potential threats, but the probability of an associated incident or the consequences thereof have been significantly reduced.
Risk control measures are actions taken to eliminate, prevent or reduce the occurrence of a hazard that you have identified.
Risk Treatment
Risk treatment involves working through options to treat unacceptable risks to your business. Unacceptable risks range in severity; some require immediate treatment, others can be monitored and treated later.
Specify the treatment plan - outline the approach to be used to treat the risk. Any relationships or interdependencies with other risks should also be highlighted.
Page 148 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Project Risk Status | Causes | Impacts | Current Consequence Rating | Current Likelihood Rating |
|---|---|---|---|---|
| Select status | i.e. List each Cause as a bullet point | i.e. List each Impact as a bullet point | Select Consequence Rating | Select Liklehood rating |
| Active | There could be configuration issues leading to data breaches where Copilot retrieved sensitive information that the user should not have had permissions for. Broader concerns regarding data governance in terms of how data is stored and who has access to it. | • Inappropriate access of information by Copilot tool.\ | ||
| • Breach of data governance & agency process.\ | ||||
| • Risks to data and information security.\ | ||||
| • Impact to participants privacy\ | ||||
| • Sensitive information compromised | B - Minor | Two - Unlikley | ||
| Active | CoPilot implementation has lack of appropriate training for users\ | |||
| • Inadequate and short of timing by agency to train staff\ | ||||
| • Agency more focussed on reducing costs and funds are not spent on training | • Inefficient use of the tool\ | |||
| • Confusion and errors\ | ||||
| • Retraining and further agency costs\ | ||||
| • More time consuming\ | ||||
| • Inadvertant data breaches and private and confidential data is released\ | ||||
| • Participants data used within the tool to help arrive on decisions | C - Moderate | Three - Possible | ||
| Active | People not updating patches (live updates on PC, software updates, windown updates)\ | |||
| • Phishing email\ | ||||
| • Likelihood of phishing incidents due to the high volume of links present in Copilot output.\ | ||||
| • Adversarial Attacks: These are deliberate attempts to confuse or mislead AI systems, such as feeding them untrustworthy data to induce malfunctions. | • The introduction and outputs from Copilot will bring with it increased risks and channels for threats, i.e, Copilot can often provide external agency links. Sometimes these links may contain and bring with them increased cyber threats.\ | |||
| • Ransom demand from cyber criminals against the agency and the individuals\ | ||||
| • Reputational damage, credibility and loss of public trust\ | ||||
| • Lawsuits, damages and further regulatory fines for the agency | D - Major | Two - Unlikley | ||
| Active | Microsoft updates having updates on Copilot which hasn’t been patched\ | |||
| • Reset of settings in Microsoft to access Copilot\ | ||||
| • Lack of monitoring by agency on use of Copilot | • Unintended access to Copilot by Agency staff\ | |||
| • Data breaches, participant data breaches and confidentialty breaches\ | ||||
| • Reputational damage, credibility and loss of public trust\ | ||||
| • Lawsuits, damages and further regulatory fines for the agency | B - Minor | Three - Possible | ||
| Active | Change resistance culture\ | |||
| • Lack of planning and ineffective change management process\ | ||||
| • Leadership not supportive the change management activities | • Staff confusion and ineffective use of the tool\ | |||
| • Costs of AI in license is under utilised\ | ||||
| • Likelihood of data breaches and information security | B - Minor | Three - Possible | ||
| Active | Copilot is a new project, process, and technology which will have new risks posing to the agency. | Benefits of Copilot won’t be realised | C - Moderate | Three - Possible |
Page 149 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Current Risk rating | Current Risk Rating Rationale | Control Name |
|---|---|---|
| Based on the Likelihood/Consequence fields | Rationale for the Current Risk Rating, including justification for the Current Likelihood and Consequence rating. | i.e. One line summary/title |
| Low | Agency to ensure their information management and security processes are prepared for Copilot i.e. actively manage their permissions and IT infrastructure to address data storage and access issues and to provide enhanced data governance to maintain appropriate oversight on data and information assets. Without the appropriate infrastructure and governance in place, there are risks to data and information security. | Existing ICT policies\ |
| Interim policy for the trial\ | ||
| Authority to Operate\ | ||
| Microsoft agreement on Data Protection with DTA to allow Copilot access only to files based on user identity. | ||
| Medium | Training needs to incorporate both technical information and practical training on the use of Copilot. Agency need to provide both technical information on practical training on how to use Copilot, such as how to author prompts. In addition, there is also a need for tailored training that reflected participants’ role and use of Copilot. | Training: All users of AI tools must have familiarised themselves with Agency supplied information and training on the responsibilities and ethical use of AI tools within the Agency.\ |
| Better communication plan\ | ||
| Effective change impact assessment\ | ||
| Awareness of Copilot risks | ||
| Medium | Valuable data on vulnerable participants\ | |
| • Lack of security within agency firewalls\ | ||
| • Increase threats on cyber threats due to evolving technology and more sophisticated scams been developed | Awareness to staff n scams and cyber threats\ | |
| • Increase number of staff to manage security\ | ||
| • Strengthened monitoring controls to capture when participants data or confidential data is entered into AI tool.\ | ||
| • Continuous improvement in IT controls\ | ||
| • Copilot does not access CRM or Protected Enclave | ||
| Medium | Possibility of microsoft embedding Copilot links in their existing product suites that is available to staff within the agency. | Policy inplace restricting staff from unitionally accessing Copilot\ |
| • Stronger monitoring in place, more staff reconfiguring settings and applying patches | ||
| Medium | Effective communication plan & strategy followed by Project team\ | |
| • Staff training and awareness\ | ||
| • High Staff competency level | Comms plan drafted by Internal Communications\ | |
| • Effective transition plan for the agency & government\ | ||
| • Learning from other government agencies\ | ||
| • Conduct Surveys | ||
| Medium | Lack of controls within Insight for Cyber Security\ | |
| • Unknown knowledge about AI technology\ | ||
| • Ability to enforce breaches is limited | New controls for AI technology\ | |
| • Strengthen control assurance program\ | ||
| • Stronger enforcement where policy breaches occur |
Page 150 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Control Description | Control Owner | Control Manager | Status | Primary Control Category |
|---|---|---|---|---|
| i.e. Detailed description | SES accountable for the Control\ | |||
| \ | ||||
| Surname, First name | Responsible for day to day management of the Control\ | |||
| \ | ||||
| Surname, First name | Select status\ | |||
| (For approved status please ensure Control has been approved by Control Owner) | Refer to Controls taxonomy sheet | |||
| Copilot accesses files based on the user’s identity and current level of permission\ | ||||
| Copilot does not access CRM or Protected Enclave | Active | ICT_and_Physical_Security | ||
Page 151 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Control Sub-Category | Control Type | Control Automation | Frequency | Is this control linked to a risk and/or a Regulatory Obligation? | How does the control mitigate the risk | Control documented within a process? | Is there an assurance process behind this control? | What is the assurance/review schedule of the control? |
|---|---|---|---|---|---|---|---|---|
| Refer to Controls taxonomy sheet (aligned with primary control) | Refer to List data sheet | Refer to Definitions sheet | Refer to Definitions sheet | Risk or Regulatory obligation or both? | Describe the effect of the control on the cause(s) and how it mitigates the risk(s) | Yes or No | Yes or No | Frequency (refer to drop down options) |
| Digital Access & Cyber Security | Preventative | Manual with quality assurance | Ad-hoc | Risk | The Windows and Microsoft 365 identity controls provide effective measures to restrict access to Agency data. Microsoft has quarrantined Agency data in line with the Copilot trial agreement made with the Digital Transformation Agency. | Yes | No | N/A |
Page 152 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Treatment Name | Treatment Description | Treatment/Action Plan Owner | Treatment/Action Plan Manager |
|---|---|---|---|
| i.e. One line summary/title | i.e. Detailed description | Surname, First name | Surname, First name |
| What additional actions are required/underway | |||
| Will be reviewed if there is a decision to move Copilot into production and make it available beyond the trial. | |||
Page 153 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Original Due Date (DD/MM/YYYY) | Status |
|---|---|
| i.e. 01/01/2021 | Select status |
| In Progress | |
| In Progress | |
| In Progress | |
| In Progress | |
| In Progress | |
| In Progress |
Page 154 of 189
FOI 24/25-1356 - DISCLOSURE LOG
Controls Taxonomy
A controls taxonomy is a controlled vocabulary of terms used to categorise and organise the Controls library. The Taxonomy ensures:
- A consistent standard of controls for the Agency
- The ability to effectively manage a more sustainable Controls Library
- Reduces duplication of controls
- Supports a more mature risk environment
| Primary Control Category | Definition | Control Sub-Category | Examples |
|---|---|---|---|
| Standards & Documentation | Documents that govern the design, operations, specifications & regulations of the Agency & the Scheme. | Legislation | NDIS Act, PGPA Act, Privacy Act, NDIS Rules |
| Policy & Frameworks | Fleet Vehicle Policy, Risk Management Framework | ||
| Standard Operating Procedures | Standard Operating Procedures | ||
| Practise Guidance & Knowledge Management | Guidance materials | ||
| Templates & Checklists | Medium Term Accommodation Checklist, Off-System Planning, Severity Tools | ||
| Enterprise Agreements & Employment Policies | Enterprise Agreements, Policies | ||
| Validation & Reviews | The monitoring, assessment & validation of data to ensure we are a high performing NDIA. | Formal Compliance & Assurance Processes | Controls Assurance, Compliance Checks |
| Fraud & Risk Detection Profiles | Typologies, Reviews, Assessments | ||
| Reconciliation | Validating expenditure | ||
| On - System Verification | Payment Validations, mandatory & structured data fields | ||
| System Alerts | Pace Alerts, Geolocating, payment flags | ||
| Data Extraction & Validation | BI Reports, Data Collation for reporting, Survey Results | ||
| Organisational Governance | The tasks associated with the daily running of business. | Defined Roles & Responsibilities | Documented Roles and Responsibilities, Span of Control |
| Segregation of Duties | Separate review/ sign-off / approval processes | ||
| Instruments of Delegation | HR Delegations, Financial Authorities, Board Attestation, CEO/ELT Representation letters | ||
| Reporting | Financial Reporting, Incident Reporting, Declarations, Risk Reporting, ELT Reporting, Attestations | ||
| Operational Management | Procurement & Contract Management, On-Boarding & Off-Boarding Process, Action Logs, Comms Plans | ||
| Resource Management | Building staff capability & supporting a high performing NDIA. | Discretionary Training (E-Learning & Facilitated) | Conferences, technical training |
| Mandatory Training | Legislative, Agency Assigned | ||
| Probation Procedure | Probation | ||
| Performance Management | Annual Performance Plans & Performance Support | ||
| ICT & Physical Security | Managing the systems & physical assets of the Agency. | Building Security & Safety | Building Passes, Fire Alarms, Locked Doors |
| Digital Access & Cyber Security | System Access and protecting data | ||
| Records Management | Recording and Storage of documents | ||
| Asset Management | Phones, Laptops, Fleet Vehicles, Key Registers | ||
| Business Continuity | Crisis Communications System, | ||
| Incident Management | Incident & Emergency Reporting & Response (ICT, Cyber, Media, WHS), Speak Up | ||
| System Operations | ICT Maintenance, ICT Upgrades, New ICT Programs | ||
| Work Health & Safety | Protecting the health & safety of staff & participants. | Workplace Supports | Ergonomic Workstations, Disability Adjustments, EAP |
| Health, Safety & Wellbeing | Personal Emergency & Evacuation Plans, Wellbeing Programs, |
Page 155 of 189
FOI 24/25-1356 - DISCLOSURE LOG
-
Control Type
- Preventative controls are designed to reduce the likelihood of risks occurring or reduce the consequences of a risk event.
- Detective controls seek to uncover circumstances that could lead to a risk or detect the occurrence of a risk event.
- Corrective controls are implemented after a risk event, and focus on mitigating the impact of a risk.
- Directive Controls are instructional controls that direct the work undertaken. They direct the work to be undertaken.
-
Control Automation Control Automation refers to how the control functionally operates
- Automated refers to a control that is completely automated within the system such as plan approval delegation
- Automated with Intervention refers to a control within the system that requires some manual intervention, such as alerts on a participant file
- Manual refers to controls that are manual or off-system in nature, such as verification of identity when a participant contacts the Agency
- Manual with Quality Assurance refers to manual or off-system controls that have quality checking activities to ensure accuracy
-
Frequency how often the control functions, or takes place. Some controls are only implemented once or twice a year, some are implemented daily.
-
Is there an assurance process behind this control? Assurance is the process of testing controls to ensure they are adequately mitigating a risk.
-
What is the assurance/review schedule of the control? How often is the control tested to ensure it is working correctly?
Page 156 of 189
FOI 24/25-1356 - DISCLOSURE LOG
| Primary Control Category | Control Sub-Category
(please note: sub-categories aligned with specific primary control. Refer to control taxonomy tab for mappings) | Control Type: | Control Evaluation | Frequency | Linked to risk or obligation | Control documented within a process? | What is the assurance/review schedule of this control? |
| — | — | — | — | — | — | — | — |
| Standards & Documentation | Legislation | Corrective | Automated with Intervention | Ad-hoc | Risk | Yes | Daily |
| Validation & Reviews | Policy & Frameworks | Detective | Fully Automated | Daily | Regulatory Obligation | No | Weekly |
| Organisational Governance | Standard Operating Procedures | Directive | Manual | Weekly | Both | | Monthly |
| Resource Management | Practise Guidance & Knowledge Management | Preventative | Manual with quality assurance | Monthly | | | Quarterly |
| ICT & Physical Security | Templates & Checklists | | | Quarterly | | | Annually |
| Work Health & Safety | Enterprise Agreements & Employment Policies | | | Bi-Annually | | | N/A |
| | Formal Compliance & Assurance Processes | | | Annually | | | |
| | Fraud & Risk Detection Profiles | | | | | | |
| | Reconciliation | | | | | | |
| | On - System Verification | | | | | | |
| | System Alerts | | | | | | |
| | Data Extraction & Validation | | | | | | |
| | Defined Roles & Responsibilities | | | | | | |
| | Segregation of Duties | | | | | | |
| | Instruments of Delegation | | | | | | |
| | Reporting | | | | | | |
| | Operational Management | | | | | | |
| | Discretionary Training (E-Learning & Facilitated) | | | | | | |
| | Mandatory Training | | | | | | |
| | Probation Procedure | | | | | | |
| | Performance Management | | | | | | |
| | Building Security & Safety | | | | | | |
| | Digital Access & Cyber Security | | | | | | |
| | Records Management | | | | | | |
| | Asset Management | | | | | | |
| | Business Continuity | | | | | | |
| | Incident Management | | | | | | |
| | System Operations | | | | | | |
| | Workplace Supports | | | | | | |
| | Health, Safety & Wellbeing | | | | | | |
Page 157 of 189