Written usage review
- Findings by area
- Risk rated issues
- Recommendations
- Owners indicated
AI Usage Review | Advisory
An AI usage review gives Australian organisations a structured picture of the tools and practices staff report using. The review turns that reported picture into a policy draft and action plan.
Describe the problem in a sentence or two. Please do not send credentials or sensitive records.
Not sure if you need this yet? Take the free self check for an indicative risk score first.
The accountable team stays involved from scoping through the final walkthrough. Specialist capability is added where the evidence needs it, with responsibilities agreed before work starts.
Deliverable status
We agree a fixed price quote before work starts, based on the staff sample and organisation size. See the Pricing page for the difference between fixed scope advisory and ongoing support.
Scope
A usable policy starting point grounded in observed work, with the Privacy Act 2026 compliance guide providing regulatory context.
Recent work
Method
Kick off
Interviews
Policy
Draft
Walkthrough
Staff started using ChatGPT to draft emails. Someone tried Copilot. Another team uses Gemini through a personal Google account. Much of it does not appear in a central IT inventory.
The review can surface personal accounts and informal workflows that a licence list misses, but it cannot prove that every use has been disclosed. The OAIC's Notifiable Data Breaches reports consistently identify human error and access failures among important breach causes.
That makes current exposure hard to describe, and a policy written in a vacuum easy to ignore. The review creates an honest picture in plain language, handled so staff do not feel investigated.
Choose the right starting point
Boundaries
Triggers
Practical details
A technical audit can verify activity and configuration inside systems it can inspect. Interviews can reveal reported use of personal accounts, privately purchased subscriptions and informal work that those logs may miss. Neither method proves the whole picture alone. We state the evidence boundary in the report and recommend technical checks where they are justified.
Start here