AI policy your board can sign, and your teams will actually use.
Governance, policy, board sessions and ISO/IEC 42001 readiness for
Australian companies. Sydney-based, built on fifteen years running the commercial
functions this work has to fit.
All three are Australian, and two of them reach companies that have never
thought of themselves as AI businesses.
This monthNational CabinetConsiders the mandatory AI standards framework, after the July
reversal from voluntary standards.10 Dec 2026Automated decisions, disclosedPrivacy policies must set out the personal information used in
significant automated decisions. APP 1.Early 2027LegislationData-centre energy and water obligations flagged. No
text-and-data-mining copyright exemption.
45 minutes. What you're using, what's exposed, and whether there's
anything here worth doing.
02
Discovery
Where AI is genuinely in use, including the tools nobody
registered, and which of it is regulated.
03
The session
A working session with the board, risk committee or exec team.
Decisions get made in the room.
04
Deliverables
Policy for your category, with the register, decision trail and
review cadence that hold it up.
05
Ongoing
Standing advisory as the rules move and your use of AI changes,
at whatever cadence you need.
ISO/IEC 42001 readiness
The international standard for an AI management system, and it certifies. It
shares its structure with ISO 27001, so if you already hold 27001 the risk,
incident and audit machinery largely carries across. The policy, register and
review cadence from steps 04 and 05 are the same evidence a readiness
assessment asks for. If certification turns into a procurement requirement,
you aren't starting again.
Where the work warrants it
Training modules built for the specific teams the policy constrains, using
your scenarios rather than generic ones. And custom AI tooling built with your
people, inside the guardrails you've just set.
03 — QUESTIONS THAT COME UP
What boards actually ask first.
We don't build AI. Does any of this apply to us?
If you use AI to make or materially inform decisions about people —
hiring, credit, pricing, claims, rostering — then yes. From 10 December 2026,
Australian privacy policies must set out the kinds of personal information used in
substantially automated decisions that significantly affect a person's rights or
interests. That obligation attaches to the decision, not to whether you consider
yourself a technology company.
Who should own AI risk on the board?
In most companies it lands with audit and risk because nobody named an
owner. That's a workable answer, but it should be a decision with a date against it
rather than a gap. Naming the owner and setting the reporting cadence is usually the
first thing a session settles.
Is ISO/IEC 42001 certification worth it yet?
It depends on whether you sell to anyone who will ask for it. Readiness
is inexpensive and useful either way, because the policy, risk register and review
cadence are the same evidence a readiness assessment wants. Certification itself is a
real programme, usually nine to twelve months. If you already hold ISO 27001, much of
the risk, incident and audit machinery carries across.
We already wrote an AI policy. Isn't that done?
Policies written in 2024 tend to restrict tools that have since shipped
inside Microsoft 365, Google Workspace and the browser by default. A policy that bans
what people already have open isn't governance, it's a document. The test is whether
it survives contact with a commercial team at quarter-end.
04 — BACKGROUND
Roger Hanney.
$150M
HOKA ANZ omnichannel business, grown from $0
$1.6B
ASX-listed retail group, senior commercial role
15+
Years scaling global brands across ANZ and APAC
MBA
With Distinction, University of Wollongong
I've run pricing, distribution, marketing and supply, and I've built
AI into all of them. That's the useful part: I know which clauses a commercial team
will work around when the quarter gets tight, and I can write around that before
anyone signs.
Worked withHOKAAccent Group
“The passion, the commitment, the values, the professionalism you
showed are extremely rare.”
Jean-Luc Diard — Co-founder, HOKA