AI Risk Management: A Practical Guide for Australian Executives
AI risk management for Australian CISOs and executives. Governance frameworks, scam threats, deepfakes, and how to build controls that actually work.
Key takeaways
AI risk is real, material, and growing faster than most governance frameworks can keep pace with. Australian organisations face regulatory pressure, reputational exposure, and operational vulnerabilities that did not exist three years ago.
Governance gaps are common. Many enterprises have deployed AI tools before establishing clear policies on data use, model oversight, or accountability. That sequence creates compounding risk.
AI-powered scams and deepfakes are the sharpest near-term threat for most organisations. Voice cloning, synthetic video, and hyper-personalised phishing have moved from theoretical concern to documented incident.
Workforce training is a governance control, not a soft skill. An employee who can identify a deepfake or recognise an AI-generated phishing email reduces your attack surface more directly than most technical controls acting alone.
Prioritisation matters. CISOs and executives cannot address every AI risk simultaneously. A clear framework for assessing likelihood, impact, and control effectiveness is the difference between a managed programme and a reactive one.
What does AI risk management actually cover?
AI risk management is the discipline of identifying, assessing, and controlling the harms that can arise from building, deploying, or simply being exposed to artificial intelligence systems. It sits at the intersection of technology risk, operational risk, and compliance, and it is broader than most executives initially expect.
The clearest way to understand the scope is to break it into five distinct categories.
Operational risk covers the ways AI can fail in day-to-day use. A model produces incorrect outputs that get acted on. An automated workflow makes a decision no human reviewed. A system trained on historical data performs poorly when conditions shift. These are not hypothetical edge cases; they are recurring failure modes in any organisation that uses AI in a consequential process, from credit approvals to supply chain forecasting.
Security risk is what happens when AI becomes an attack surface. AI systems rely on data pipelines, APIs, and model infrastructure, each of which can be compromised. Beyond the infrastructure itself, AI can be manipulated through techniques like prompt injection (feeding a model malicious instructions disguised as normal input) or model poisoning (corrupting training data to alter how a model behaves).
Reputational risk is often underweighted until something goes wrong publicly. An AI system that produces biased, offensive, or factually wrong outputs at scale can cause serious brand damage quickly, faster than any human communication error because AI systems operate at volume.
Compliance risk spans privacy law, consumer protection obligations, sector-specific regulation, and, increasingly, emerging AI-specific rules. In Australia, the Privacy Act, the Notifiable Data Breaches scheme, and sector regulators like APRA and ASIC all create obligations that AI use can easily violate if governance is absent.
AI-enabled fraud and scams is the fifth category, and the fastest-growing one. This is distinct from the others because the threat comes from outside the organisation, not from your own AI systems. Generative AI has dramatically lowered the cost of producing convincing phishing emails, synthetic voice calls, and deepfake video. A scammer who previously needed skill and time to impersonate a CFO in a written message can now do it cheaply and at scale. For Australian organisations, this is an immediate, practical threat that sits squarely in the AI risk portfolio, even for businesses that have not yet deployed any AI themselves.
These five categories do not operate in isolation. A security breach of an AI system can trigger compliance obligations and reputational damage simultaneously. An AI-powered scam that succeeds against your staff is also an operational failure and a training gap. Effective AI risk management treats the categories as interconnected, not as separate checklists.
Why is AI risk accelerating for Australian organisations?
Australian enterprises are adopting AI tools faster than most have developed the governance structures to manage them. That gap is the core problem.
The pace of adoption is real. Microsoft 365 Copilot, Google Gemini, and a growing range of third-party AI tools are being deployed across finance, legal, HR, and customer-facing teams. Many of these deployments are driven by productivity goals, with security and compliance reviews following after the fact, if at all. The result is an expanding attack surface that most organisations have not yet mapped.
The scam infrastructure is maturing
Offshore criminal networks have invested heavily in AI tooling. Deepfake voice and video generation, once requiring specialist capability, is now accessible through low-cost platforms. Australian organisations have already seen incidents involving synthetic voice fraud targeting finance teams, fabricated executive video used to authorise transfers, and AI-generated phishing content that bypasses traditional detection because it contains no spelling errors, no suspicious links, and no obvious tells.
The financial losses from business email compromise in Australia run into hundreds of millions of dollars annually, according to the Australian Federal Police. AI is making this category of fraud cheaper to execute and harder to detect.
The regulatory environment is tightening
Australia's Privacy Act is undergoing its most significant reform in decades. The proposed changes, drawn from the Government's response to the Privacy Act Review, would strengthen obligations around automated decision-making, consent, and data minimisation. Organisations using AI to process personal data, which includes most enterprise AI deployments, will face new accountability requirements.
The Australian Signals Directorate (ASD) has published guidance on AI security considerations, and the Australian Cyber Security Centre (ACSC) has flagged AI-enabled social engineering as an escalating threat in its annual cyber threat reports. Regulatory expectation is rising, and the window between "best practice" and "minimum required" is narrowing.
The skills gap is widening the exposure
Most employees using AI tools today received no formal training before they started. They do not know how the tools handle data, what prompts are risky, or how to verify whether a piece of AI-generated content is legitimate. This is not a criticism of those employees. It reflects how quickly these tools were deployed relative to any structured onboarding.
That gap matters for risk because human behaviour is now a primary attack vector. An employee who cannot recognise a deepfake video call, or who does not understand that pasting customer data into a public AI tool may breach privacy obligations, represents genuine organisational exposure regardless of how well-configured the technical controls are.
The combination of rapid adoption, sophisticated threat actors, a tightening regulatory environment, and undertrained workforces means Australian organisations are managing AI risk in conditions that are genuinely more demanding than they were two years ago.
What governance frameworks apply to AI risk in Australia?
No single framework currently covers AI risk end-to-end for Australian organisations. What exists is a patchwork: some global standards with genuine depth, some local guidance that is still maturing, and a handful of sector-specific expectations that carry real teeth. Understanding what each one does (and does not) require is more useful than treating any of them as a complete answer.
NIST AI Risk Management Framework (AI RMF)
The US National Institute of Standards and Technology released its AI RMF in 2023. It is voluntary, not a regulation, but it has become the most widely cited structured approach to AI risk globally. The framework organises AI risk work into four functions: Govern, Map, Measure, and Manage. That structure is genuinely practical. It pushes organisations to identify who is accountable for AI decisions, document where AI is being used, and build repeatable processes for evaluating harm before and after deployment.
Australian organisations, particularly those with US-linked supply chains or multinational operations, are increasingly using the NIST AI RMF as a baseline. Its weakness is that it requires significant internal effort to operationalise. The framework tells you what to do, not how to do it for your specific context.
ISO/IEC 42001
ISO 42001, published in late 2023, is the international standard for AI management systems. If your organisation already runs ISO 27001 for information security, the structure will feel familiar: policies, risk assessments, objectives, internal audits, continual improvement. ISO 42001 can be independently certified, which gives it weight in procurement and vendor assurance contexts.
For Australian organisations that need to demonstrate AI governance to clients, regulators, or boards, ISO 42001 certification is becoming a credible signal. The standard is still early in adoption, and there are not yet many Australian-certified assessors, but that is changing. Pursuing alignment with ISO 42001, even without formal certification, is a reasonable starting point for building a defensible AI governance program.
Australia's Voluntary AI Safety Standard
In early 2024, the Australian Government's Department of Industry, Science and Resources (DISR) released a voluntary AI Safety Standard built around ten guardrails. These cover accountability, transparency, human oversight, data governance, and testing. The standard is explicitly designed to be consistent with international frameworks, and the government has flagged that mandatory obligations may follow for high-risk applications, though firm legislative timelines remain uncertain.
The voluntary nature is a genuine limitation. Without a compliance mechanism, the standard functions more as a signal of government intent and a benchmark for self-assessment than a hard obligation. That said, organisations in regulated industries, or those supplying to government, would be unwise to ignore it. Procurement criteria and grant conditions are realistic levers through which voluntary standards can become effectively mandatory in practice.
APRA guidance on AI and model risk
For organisations regulated by the Australian Prudential Regulation Authority (banks, insurers, superannuation funds), AI risk sits inside existing obligations rather than a new AI-specific regime. APRA's Prudential Standard CPS 234 on information security and its guidance on model risk management both apply to AI systems. APRA has also signalled through supervisory letters and industry briefings that it expects boards and senior management to have clear oversight of material AI use.
The APRA lens tends to focus on model explainability, data integrity, and concentration risk in third-party AI providers. If your organisation is APRA-regulated and relies on a single large AI vendor for material decisions (credit scoring, claims assessment, investment recommendations), that dependency is a risk APRA expects you to have mapped and governed.
Honest gaps
Across all of these frameworks, a few gaps are consistent. None of them deal adequately with AI-generated misinformation or social engineering as an organisational risk. They focus heavily on AI systems your organisation deploys, and less on AI tools that external threat actors use against you. For a CISO thinking about the full AI risk surface, that gap matters, and it is covered in the next section.
How are AI-powered scams and deepfakes changing the threat landscape?
AI has handed fraudsters capabilities that, until recently, required nation-state resources. The result is a category of threat that moves faster than most corporate security controls were designed to handle, and that specifically targets human judgement rather than technical vulnerabilities.
Voice cloning and CEO fraud
Traditional business email compromise relied on an attacker impersonating an executive through text. The recipient had at least a fighting chance of pausing, checking the sender address, or calling to verify. Voice cloning removes that pause.
Using publicly available audio, a credible voice clone can now be produced in minutes. For Australian executives with media appearances, conference recordings, or even LinkedIn video posts, the raw material is already online. A convincing call from the "CEO" authorising an urgent wire transfer, or instructing the finance team to bypass a payment approval, requires no access to corporate systems whatsoever.
A useful illustrative scenario: a mid-market company's CFO receives a call that sounds exactly like the managing director, referencing a real acquisition the MD mentioned publicly the week before. The call requests an urgent transfer to a new account before the deal closes. No malware. No phishing link. Just a human decision made under pressure with imperfect information.
Deepfake video in enterprise contexts
Deepfake video extends the same principle to visual confirmation. If a caller asking your team to take an unusual action also appears on a video call as the face they expect to see, the cognitive barrier to compliance drops sharply.
This is no longer a theoretical risk. Publicly reported cases have involved attackers using deepfake video in live calls to impersonate executives and, in one widely cited case in Hong Kong, to conduct a group video call with a finance employee before authorising a large fraudulent transaction. The employee saw familiar faces and heard familiar voices. The entire call was fabricated.
For Australian organisations, board meetings and all-hands calls are now part of the attack surface.
Hyper-personalised phishing
Generic phishing is losing effectiveness as awareness grows. AI-generated spear phishing is doing the opposite. Large language models can now scrape an individual's LinkedIn activity, recent company announcements, public calendar data, and social media presence, then produce a phishing email that references their actual project, their actual manager's name, and a plausible context for a request.
The cognitive load on the recipient is very different when an email says "following up on the Sydney workshop last Thursday" rather than "Dear Valued Customer." Most people are not trained to interrogate that kind of specificity, because historically specificity was a signal of legitimacy.
Synthetic identity fraud
Beyond targeted attacks on known individuals, AI is enabling synthetic identity creation at scale. This involves combining real and fabricated personal data to create identities that pass standard verification checks. For Australian financial institutions, fintechs, and any organisation running digital onboarding, this presents a direct fraud risk that sits partially outside traditional cybersecurity scope and inside the identity and access management problem.
The identity documents look real. The face in the verification selfie, generated by a model, matches the document. The fraud is often only visible in aggregate, when patterns across many applications are analysed together.
Why traditional awareness training is no longer sufficient
Most staff are trained to spot the signals that AI has now removed: poor spelling, unusual sender addresses, generic greetings, implausible scenarios. AI-generated attacks are well-written, contextually accurate, technically delivered from legitimate-looking addresses, and increasingly delivered as voice or video rather than text.
The controls that worked in 2019 were designed for a different threat. Staff who trust their own judgement, because they have not been updated on what a realistic AI-enabled attack looks and sounds like, are the most exposed.
Better People's AI Scam and Deepfake Awareness workshop is designed specifically for this gap. It walks teams through what current AI-enabled fraud actually looks and sounds like in practice, so that the human firewall functions on accurate assumptions rather than outdated ones.
Which internal controls reduce AI risk most effectively?
Five controls consistently make the biggest difference: an acceptable use policy, data classification, access governance, vendor due diligence, and an AI-specific incident response plan. Organisations that have all five in place are not immune to AI risk, but they have defined boundaries, clear ownership, and a path to recovery when something goes wrong.
Acceptable use policy
An acceptable use policy (AUP) for AI tells employees exactly what they can and cannot do with AI tools. Without one, staff make individual judgement calls, and those calls will vary widely. A marketing coordinator may paste a customer list into a public AI chatbot without realising that constitutes a data breach. A finance analyst may use an AI tool to draft board commentary without knowing the output requires human review before circulation.
A useful AUP names the specific tools that are approved, specifies which data classifications may and may not be processed by each tool, and sets out who is accountable for outputs. It is a short document. Three to five pages is enough. The goal is clarity, not comprehensiveness.
Data classification
AI tools need data to be useful, and that is precisely the problem. Employees who would never email a customer record to a personal address will paste the same record into a chat interface without a second thought, because the interaction feels conversational rather than transactional.
A working data classification scheme labels information by sensitivity before the question of AI access arises. Typical tiers are public, internal, confidential, and restricted. Once data is labelled, the AUP can map each tier to permitted tools cleanly. Restricted data does not go to external AI services. Full stop. Classification also feeds directly into access governance and makes vendor due diligence conversations sharper, because you can ask vendors exactly how they handle confidential-tier data rather than asking in the abstract.
Access governance
AI tools should follow the same least-privilege principles that apply to any system. In practice, many organisations grant broad access during pilots and never tighten it. A team of ten tries a new AI tool, the pilot succeeds, and the tool becomes permanent with the same open permissions that were convenient during testing.
Minimum-viable access means users can reach the data they need to do their job and nothing more. For AI systems that process documents, this means connecting them only to the repositories relevant to each role. For AI agents that can take actions such as sending emails or executing transactions, it means defining the exact scope of permitted actions in advance and logging every action taken. Reviewing access quarterly, rather than annually, catches drift before it becomes exposure.
Vendor due diligence
Every AI tool your organisation uses is also a data pipeline. Before any vendor is approved, the security and legal teams should be asking four things: where is our data stored and processed, is it used to train the vendor's model, who has access to it within the vendor's organisation, and what happens to it when we terminate the contract.
Vendors with enterprise-grade offerings generally answer these questions clearly in their data processing agreements. Vendors who cannot or will not answer them clearly are a risk signal regardless of how useful the product appears. Australian organisations also need to satisfy themselves that vendor data handling is compatible with the Privacy Act 1988 and, where applicable, sector-specific obligations such as the Australian Privacy Principles or APRA CPS 234. A vendor hosted in a jurisdiction with conflicting data access laws deserves additional scrutiny.
AI-specific incident response
Standard incident response playbooks assume the threat is external and the compromise is a breach of stored data. AI introduces scenarios those playbooks were not written for: a deepfake voice call that authorises a fraudulent transfer, a model that begins returning systematically biased outputs, a prompt injection attack that causes an internal AI agent to exfiltrate data through a legitimate-looking API call.
An AI-specific incident response plan identifies the new failure modes, assigns ownership, and defines escalation paths before an incident occurs. At minimum it should cover: who decides when an AI system is suspended during investigation, how outputs are preserved as evidence, how affected parties are notified, and how the root cause is communicated internally. Tabletop exercises that walk through an AI-specific scenario once a year are far more useful than a document that no one has read.
Why is workforce training a governance control, not a soft skill?
Technical controls catch a lot. They do not catch everything. A well-configured email gateway will block known phishing domains, but it will not stop an employee who has been socially engineered into wiring funds to a fraudulent account by a voice that sounds exactly like the CFO. At that point, the only control left is the judgement of the person receiving the call.
That is why workforce training belongs in the same governance conversation as access controls, incident response plans, and data classification policies. It is not a cultural initiative or a HR checkbox. It is a risk reduction measure with a measurable attack surface: the number of people in your organisation who, under pressure, would make the wrong call.
Training reduces risk in proportion to coverage
The maths are straightforward. If one in ten staff members would fall for a well-crafted AI-generated phishing email, and your workforce is five hundred people, you have roughly fifty active vulnerabilities walking around. Targeted awareness training on how AI-generated content looks and feels, how voice cloning works, and what to do when something seems off, reduces that number. It does not eliminate it, but it shifts the probability in your favour in a way that no software alone can.
This is the same logic applied to financial controls: you do not just install accounting software, you train your finance team on fraud red flags. AI risk deserves the same treatment.
What good training actually covers
Generic cybersecurity awareness training is not sufficient for the current threat environment. The scenarios have changed too quickly. Effective AI risk training covers at minimum:
How generative AI is being used to create convincing phishing emails, fake invoices, and impersonation audio
The specific tells that distinguish AI-generated content from human-created content, and why those tells are narrowing
Internal verification procedures to follow when an unusual request arrives, regardless of how legitimate the requester sounds
The organisation's own AI use policies, so staff understand both what is permitted and what creates liability
The last point matters more than it is usually given credit for. Many employees using AI tools in their daily work do not know whether they are permitted to paste a client contract into a public AI assistant. That uncertainty either leads to risky behaviour or, just as problematically, to staff avoiding tools entirely and falling behind on productivity. Neither outcome serves the organisation.
The link between fluency and governance
There is a direct connection between AI fluency across the workforce and an organisation's overall risk posture. Staff who understand how AI systems work are better equipped to recognise when they are being manipulated by one. They ask better questions. They are more likely to pause before acting on an unusual instruction, and less likely to be paralysed by every edge case.
Fluency training and governance training are not the same program, but they reinforce each other. A workforce that has genuinely engaged with AI tools in a structured setting, rather than one that has only read a policy document, will apply that knowledge in higher-stakes situations.
The same is true at the implementation level. Organisations that approach AI implementation with governance built in from the start, rather than bolted on after, tend to have clearer internal policies, better-defined use cases, and staff who understand the boundaries of the tools they are using. Training is easier to deliver, and it lands with more context.
Why executives often underinvest here
The reluctance to treat training as a formal governance control usually comes from one of two places. Either it is seen as intangible ("how do you measure a prevented incident?") or it is assumed to be covered by existing cybersecurity awareness programs.
On the first point: incident reduction is measurable. Simulated phishing exercise results, help desk call volumes around suspicious messages, and the frequency with which staff follow verification procedures on high-value transactions are all trackable metrics. They are imperfect, but they are no more imperfect than penetration test results or patch compliance rates.
On the second point: legacy cybersecurity awareness training was built for a different threat model. It was designed around recognising bad links and suspicious attachments. An employee who passed that training with flying colours may still wire money to the wrong account because a deepfake of their manager asked them to with exactly the right tone of voice and the right level of urgency. The threat has evolved. The training has to evolve with it.
How should a CISO prioritise AI risk management investments?
Start with likelihood multiplied by impact. It is a simple filter, but it cuts through the noise quickly when budgets are tight and the threat list is long.
For most Australian mid-market organisations right now, that calculation points to two areas above everything else: AI-enabled social engineering (high likelihood, high impact) and ungoverned AI tool use by staff (high likelihood, moderate-to-high impact depending on what data employees are pasting into consumer AI tools). Both are immediate. Both are addressable without a multi-year program.
Quick wins versus structural fixes
Not every control requires a capital investment or a procurement cycle. Some of the highest-return actions are procedural.
Quick wins (weeks, not months):
Publish a one-page AI acceptable use policy. It does not need to be perfect; it needs to exist so staff have a reference point and the organisation has a documented position.
Add AI-generated content and voice-cloning scenarios to your existing phishing simulation program. Most simulation vendors now support this; it is a configuration change, not a new vendor.
Brief the finance team and executive assistants on deepfake voice and video fraud. These two groups are the most targeted. A 90-minute session materially reduces risk.
Audit which consumer AI tools are already in use across the organisation. Shadow AI is almost certainly present. Knowing the scope is the first step to managing it.
Structural fixes (quarters, not weeks):
Establish an AI governance policy with named ownership, a review cadence, and a process for approving new AI tools before deployment.
Integrate AI risk into your existing enterprise risk register rather than treating it as a separate workstream. This is how boards start taking it seriously.
Build a vendor AI risk assessment into procurement. Any supplier deploying AI in a product or service you use should be able to answer basic questions about data handling, model governance, and incident response.
Define data classification rules that explicitly address what can and cannot be processed by external AI systems. Many organisations have classification schemes that predate generative AI entirely.
The honest reality for mid-market CISOs is that you are unlikely to do all of this at once. Sequence matters. Get the quick wins in place first because they reduce the most immediate exposure and they build organisational credibility for the structural work that follows.
Where training sits in the investment stack
Training is not the last line of defence in AI risk. For social engineering threats specifically, it is close to the first, because the attack vector is human judgment. No firewall catches a CFO who genuinely believes they are on a video call with their CEO.
This is worth stating plainly because training budgets are often the first thing cut when security programs face pressure. The calculus changes when you frame workforce awareness as a preventive control with a measurable cost-per-incident-avoided. A single successful AI-enabled business email compromise in Australia commonly results in losses well into six figures. A half-day scam awareness workshop for your finance team costs a fraction of that.
The prioritisation, broadly:
Targeted awareness training for high-risk roles (finance, executive assistants, procurement, HR)
Acceptable use policy and shadow AI audit
AI risk integrated into enterprise risk governance
Vendor and third-party AI risk assessment
Broader workforce fluency training to reduce ungoverned tool use
Mid-market CISOs working without a dedicated AI security function should treat items one and two as non-negotiable this financial year. They require modest investment and address the threats most likely to cause material harm in the near term. The rest of the list builds on that foundation.
Frequently asked questions
Is there an Australian AI law yet?
There is no single, dedicated Australian AI law in force as of mid-2025, but the regulatory picture is more active than it was two years ago. The federal government has signalled a risk-based approach modelled partly on the EU AI Act, and mandatory guardrails for high-risk AI use cases are under active consultation. In the meantime, existing obligations under the Privacy Act 1988, the Security of Critical Infrastructure Act 2018, and the Australian Consumer Law already apply to many AI deployments. Organisations that wait for a dedicated statute before building governance structures will find themselves well behind when legislation does land.
What is the biggest AI risk for Australian organisations right now?
The most acute near-term risk is social engineering, specifically AI-generated phishing, voice cloning, and deepfake impersonation used to initiate fraud. These attacks require no technical compromise of your systems; they exploit people. Beyond that, the slower-burning risks are data leakage through unsanctioned AI tool use and model outputs that create legal or reputational exposure. Organisations with mature perimeter security but thin AI governance policies are often more exposed than they realise, because the threat surface has shifted from infrastructure to human behaviour.
How do deepfakes get used in financial fraud?
A typical deepfake fraud follows a short sequence: an attacker clones the voice or video likeness of a senior executive using publicly available audio or footage, then contacts a finance team member with an urgent, time-pressured instruction to transfer funds or share credentials. Because the voice or face matches someone the target trusts, normal scepticism is bypressed. Reported cases internationally have involved losses running to millions of dollars, and the technology required to execute this kind of attack has become cheap and widely accessible. Australian organisations are not immune. The control is not purely technical; it involves staff knowing that any out-of-channel financial instruction, regardless of how convincing it sounds, must be verified through a separate, pre-established channel.
Does AI governance need its own policy, or can it sit inside existing frameworks?
AI governance works best as its own policy, at least in terms of a dedicated document, even when it references and connects to your existing information security, privacy, and acceptable-use frameworks. The reason is specificity. A general acceptable-use policy rarely covers model selection criteria, data classification rules for AI inputs, approval pathways for new AI tools, or how the organisation handles AI-generated content in customer-facing contexts. Without a dedicated policy, those gaps stay invisible until something goes wrong. The policy does not need to be long; a clear, well-scoped document that staff can actually find and read is more valuable than a comprehensive one buried in a governance repository.
How do I get my board to take AI risk seriously?
Boards respond to materiality, so connect AI risk to financial exposure, regulatory liability, and reputational harm in concrete terms rather than technical abstractions. A useful approach is to present two or three scenarios with plausible loss estimates, for example the cost of a deepfake-enabled payment fraud, the regulatory exposure from a privacy breach caused by unsanctioned AI tool use, or the reputational fallout from a publicly attributed AI governance failure. Pair those scenarios with a short gap analysis showing what controls exist today and what is missing. Directors who would glaze over at a discussion of model governance tend to focus quickly when the conversation is framed around dollar figures and named regulatory obligations.
How often should an organisation review its AI risk posture?
AI risk posture should be reviewed at least every six months, because the underlying threat environment and the internal AI tool landscape both change faster than annual cycles can accommodate. Trigger-based reviews are equally important: a significant new AI deployment, a major vendor update to a tool already in use, a security incident involving AI, or a material change in the regulatory environment should each prompt an out-of-cycle assessment. The review does not need to be exhaustive every time; a standing AI risk register that is actively maintained is more useful than an annual deep-dive that sits on a shelf for eleven months.
Take the next step on AI risk
AI risk management is not a project with a finish line. The threat surface shifts as models improve, scam tactics evolve, and regulators sharpen their expectations. What matters now is having the foundations in place: clear governance, tested controls, and a workforce that knows how to respond when something looks wrong.
A practical place to start is with the people most likely to be targeted. Social engineering and AI-generated fraud do not wait for your policy framework to be finalised. If your teams cannot recognise a deepfake call or a suspiciously convincing supplier email, the technical controls behind them are carrying more weight than they should.
Better People's AI Scam and Deepfake Awareness workshop is designed for exactly that gap. It gives employees, including those in finance, procurement, and executive support, the vocabulary and instincts to spot AI-assisted fraud before it causes harm. The session is practical, scenario-based, and can be run on-site for Australian organisations across sectors.
If you are working through a broader AI governance challenge, including how to structure acceptable-use policy, build a risk register, or roll out AI fluency programs that reach the whole organisation, we are happy to talk through what that looks like for your context. Better People works with enterprise and government clients across Australia on programs that connect AI implementation to the governance and risk disciplines that sit alongside it.
Get in touch to discuss where AI risk sits on your current agenda, or explore the workshop directly.
Last updated: 2026-08-19
Ijan Kruizinga
Co-founder of Better People. 20+ years across technology and marketing leadership. Previously CEO of Crucial, CEO/COO of OMG and Jaywing.