Skip to content

AI Usage Review · Advisory

AI usage review, find out first

An AI usage review is an interview-based engagement for Australian organisations that want to know what AI tools their staff are actually using and what data is going into them. Most tools arrived through the side door. The OAIC's Notifiable Data Breaches reports consistently identify human error and compromised or misconfigured access among important breach causes. Before writing policy, we surface actual usage and produce a risk picture leadership can act on.

Not sure if you need this yet? Take the free self-check for an indicative risk score first.

The picture

AI arrived through the side door, no one wrote it down

Staff started using ChatGPT to draft emails. Someone tried Copilot. Another team uses Gemini through a personal Google account. Much of it does not appear in a central IT inventory.

That makes current exposure hard to describe, and a policy written in a vacuum easy to ignore. The review creates an honest picture in plain language, handled so staff do not feel investigated.

Scope

The six areas we cover

Tool inventory

Which sanctioned, paid, free and personal account tools are in use, for what tasks and how often.

Data exposure

What information staff report entering or uploading, including client, health, support, financial and commercial data.

Awareness and practice

What guidance exists, where staff are confused and which practical support would change behaviour.

Visibility going forward

How to keep an eye on this without locking everything down, including what to ask the IT provider to configure.

Recommendations and owners

Low, medium or high risk ratings, with practical actions that show who does it and by when.

Method

How the engagement runs

The review depends on reported staff behaviour. It does not independently verify usage through Microsoft 365, devices or network telemetry.
  1. Kick-off

    Confirm scope and framing

    The sponsor confirms priorities, interview participants and how the review will be introduced.
  2. Interviews

    Talk to a sample of staff

    Short, non-judgemental interviews with a representative slice of the team prioritise honesty over enforcement.
  3. Policy

    Draft the AI usage policy

    A policy outline reflects how staff actually work and is prepared for organisational adaptation.
  4. Draft

    Risk rated draft report

    Findings are rated low, medium or high and paired with recommendations and owners.
  5. Walkthrough

    Final report and plan

    Leadership reviews the findings, clarifies sensitive points and receives the final report and policy outline.

Deliverable status

What you walk away with

A fixed price quote is agreed before work starts.
Interview evidence

Written usage review

Findings from interviews, clearly identified as reported evidence rather than technical verification.
  • Findings by area
  • Risk rated issues
  • Recommendations
  • Owners indicated
Draft, not legal sign off

Draft AI usage policy

A practical first draft based on actual work patterns, ready for HR and legal review.
  • Acceptable use
  • Data handling
  • Approval and review
  • Ready to adapt
Confidential decision session

Leadership walkthrough

A private session to agree priorities and discuss sensitive findings.
  • Leadership walkthrough
  • Stakeholder questions
  • Priority agreement
  • Confidential delivery

Boundaries

What this engagement is not

Not verified

A technical audit

We do not scan Microsoft 365, devices or networks to verify usage.
Separate service

A penetration test

Technical security testing addresses different questions and evidence.
Supportive framing

A staff investigation

The review is not disciplinary and does not exist to catch people out.
Advisory

A formal compliance audit

We point to standards and gaps but do not issue compliance certification.
Not legal advice

A legal review

The policy draft should be reviewed by HR and legal before final sign off.

Triggers

When to call us in

Scale unknown

Suspect AI is everywhere

Leadership knows usage is happening but cannot describe the scale or data involved.
Recent incident

Something happened

A staff action prompted a closer look and leadership wants a structured picture, not a witch hunt.
Policy in draft

Writing the policy

The business wants policy grounded in reality rather than copied from a generic template.
External question

How are you managing AI risk?

A board, funder, auditor or insurer expects a confident answer.
Copilot rollout

About to roll out Copilot

A sanctioned tool is launching and the executive wants to understand existing behaviour first.
Sensitive sector

Sensitive data, real consequences

The organisation works in disability, aged care, health, education, legal, finance or not for profit services.

Recent work

A policy first adoption path for an Australian health services business

We surveyed the team on how they used AI, mapped the platforms in use and handed leadership a practical policy first path.

Practical details

Questions about AI Usage Review

What is assessed, what you receive and where advisory responsibility stops.

Start here

Want to know what your team is actually doing? Start with a 30 minute scoping call

We will tell you whether this engagement is the right fit. No pitch deck.