AI Governance for Australian Aged Care & Healthcare

GOVERN AI — Automate Trust.

Independent AI audits, guardrails and governed automation for Australian healthcare & aged care — so your board can say yes with evidence.

Aligned to: Aged Care Act 2024 · Strengthened Quality Standards · OAIC AI guidance · AS ISO/IEC 42001:2023 · NIST AI RMF · OWASP LLM Top 10 (2026)
The problem

Between fear and chaos

Your teams already use AI. Your board is already accountable for it. Bans push it underground; blind adoption creates the incidents.

79%of leaders use AI weekly
2%of boards have an AI framework
+40%unannounced ACQSC visits since 2024
AI in use today untracked, unowned The same AI, governed visible, owned, evidenced

Governance is not the brake. Done properly, it's the reason you can move: every AI use case visible, every decision owned, every claim evidenced.

From fear and chaos → clarity, control, confident action.

Services

Three ways we make AI defensible

Inspect-based · MedHELM-informed

AI Assurance Evals

Does the vendor's AI actually work — on your population?

  • Inspect framework · MedHELM-informed task coverage
  • Audit-grade logs — every finding has a receipt
OWASP-mapped · Layered testing

AI Security Assessment

Break it before your residents' data depends on it.

  • Red-teaming + multi-turn adversarial scenarios
  • Mapped to OWASP LLM Top 10 & Agentic Top 10
AI6 practices · ISO/IEC 42001 readiness

Governance Advisory

Policies and decision rights an auditor will accept.

  • NAIC 6 essential practices · ISO/IEC 42001 readiness
  • ADM disclosure before the 10 Dec 2026 deadline
The Board AI Assurance Pack — $4,900

One engagement answers "are we safe with AI?"

  • Scored across 8 governance dimensions
  • Shadow-AI inventory — what your register misses
  • ADM disclosure drafted for 10 Dec 2026
  • Board-ready report + 30-min briefing
  • 90 days of email follow-up
  • Delivered in 5 business days — or it's free

Full path: Pack + 90-day Uplift Roadmap — $9,500. Maximum 4 engagements per month.

Book the assessment
Why now

The regulatory clock is running

Verified against the Australian landscape as at August 2026 — what's in force, what has a fixed date, and what's coming.

10 Jun 2025

Statutory privacy tort In force

Individuals can now sue directly for serious invasions of privacy — raising the stakes of any AI misuse of resident data.

1 Nov 2025

Aged Care Act 2024 + Strengthened Quality Standards In force

Rights-based Act and seven strengthened Standards. Standard 2 (governance & information systems) and Standard 5 (clinical care) are where AI deployments meet your accreditation.

Ongoing

OAIC enforcement-first posture Active

Civil penalty proceedings live against major providers; a $5.8M penalty in the health sector for security failures. Health information is the enforcement epicentre.

10 Dec 2026

Automated decision-making transparency Commencing

Privacy policies must disclose automated decisions that significantly affect individuals. If AI touches admissions, care planning, or rostering decisions — you have a deadline.

Announced

Legislated "Australian Standards for AI" Forthcoming

Announced July 2026 with a new Office of AI — legislation expected from 2027. Providers who implement the National AI Centre's 6 essential practices now will already be positioned.

Data residency

Your residents' data has a postcode

Where AI processing happens is a legal question, not a technical detail. We design AI architectures that keep Australian health data where it belongs.

My Health Records Act s 77

My Health Record data must not be held, processed, or handled outside Australia. Any AI touching MHR-derived data must be onshore. No exceptions worth testing.

State health records law

Victoria (HPP 9) and NSW (HPP 14) restrict sending health information outside the jurisdiction without equivalent protections — plus APP 8 accountability for cross-border disclosure.

Onshore AI inference

Frontier models can now run with inference pinned to Sydney (e.g. Claude on AWS Bedrock ap-southeast-2). Enterprise-grade, in-country AI is achievable — consumer AI tools with identifiable health data are not defensible.

Sovereign hosting

For government-adjacent workloads: IRAP-assessed environments and the Hosting Certification Framework. We architect to the standard your data classification demands.

Method

Evidence over adjectives

We apply our own governance to our own AI. Every assessment is framework-mapped, every claim carries a receipt, and escalation logic is deterministic — the model can add a warning, never remove one.

Your AI tools & use cases Guardrails · policies · decision ownership Evidence: evals, logs, framework mapping The board says yes, with confidence
01

See

AI usage inventory — including the shadow AI nobody put on a register.

02

Score

Risk assessment across 8 governance dimensions, mapped to the frameworks your auditors recognise.

03

Secure

Guardrails, policies, and decision ownership — governance designed to enable, not block.

04

Sustain

Evals, monitoring, and review cadence so approval isn't a one-off event.

Who you work with

Built by someone who ships governed AI, not just slides about it

Led by Nathan Bhasker — 10+ years in healthcare ICT and enterprise AI delivery. Everything we recommend, we've built and evaluated ourselves, with published results.

See the work in the open →

Credentials

  • PMP & PRINCE2 certified
  • Certified Scrum Master
  • IBM AI Product Management
  • IAPP AIGP (in progress)
  • Mastering Agentic AI — certified, The Gen Academy
How we handle your data

We hold ourselves to the standard we assess you against

No consumer AI tools

Your documents, policies, and data never enter public chatbots. Enterprise-grade, access-controlled tooling only.

Australian-hosted where it matters

Engagements touching health or resident information run on Australian-hosted infrastructure, consistent with My Health Records Act s 77 and state health records law.

Confidential by default

NDA standard on every engagement. Nothing from your organisation appears in our marketing or case studies without written consent.

Aligned, not badge-washed

We align our own practice to AS ISO/IEC 42001:2023 and the NIST AI RMF — and we say "aligned," not "certified," because words matter in governance. Certification is on our public roadmap.

Questions

Straight answers, plain English

What is AI governance?

AI governance is the set of rules, checks, and responsibilities that let an organisation use AI safely. It answers three questions: what AI is being used, who is accountable for it, and how do we know it is working safely. It is not about blocking AI — it is about being able to say yes with evidence.

We have banned AI tools. Do we still need governance?

Yes. Bans rarely work — staff use AI on personal devices instead, which is harder to see and riskier. Sector surveys consistently find a majority of care staff have used AI tools at work. Governance makes usage visible and safe rather than hidden.

What does the $4,900 Board AI Assurance Pack include?

A scored assessment of your facility across 8 governance dimensions mapped to the strengthened Quality Standards, a prioritised list of gaps, a board-ready assurance report, and a 45-minute debrief — delivered within 5 business days, or it's free. We rework the report until your board rates it decision-ready. A $9,500 tier adds a sequenced 90-day governance uplift roadmap.

Is our residents' data safe with AI? Where is it processed?

It depends on the tool. My Health Record data must never leave Australia by law (My Health Records Act s 77). Consumer AI tools generally process data offshore and are not defensible for identifiable health information. Enterprise AI can now run entirely in Sydney — we design architectures that keep Australian health data onshore.

Which regulations apply to AI in aged care right now?

In force today: the Aged Care Act 2024 and strengthened Quality Standards (from 1 November 2025), the Privacy Act including the new statutory privacy tort, and state health records laws. Coming: automated decision-making transparency in privacy policies from 10 December 2026, and legislated Australian Standards for AI expected from 2027.

How long does an engagement take?

The Board AI Assurance Pack takes 5 business days. Governance implementation typically runs 4–8 weeks depending on facility size. Advisory support is ongoing month-to-month — no lock-in contracts.

Know exactly where you stand

A 30-minute discovery call. No pitch — just an honest conversation about your AI exposure and what visibility would take.

Book a discovery call