Skip to content

AI Usage Review | Advisory

AI usage review before you write the policy

An AI usage review gives Australian organisations a structured picture of the tools and practices staff report using. The review turns that reported picture into a policy draft and action plan.

Describe the problem in a sentence or two. Please do not send credentials or sensitive records.

Not sure if you need this yet? Take the free self check for an indicative risk score first.

Best fit
Teams with informal AI use and no reliable policy baseline
Main deliverable
Reported usage findings, policy draft and action plan
Client effort
One sponsor and a representative staff interview sample
Commercial model
Fixed price based on organisation size and the staff sample
Delivery ownership
  1. Scope
  2. Review
  3. Findings
  4. Walkthrough

The accountable team stays involved from scoping through the final walkthrough. Specialist capability is added where the evidence needs it, with responsibilities agreed before work starts.

Deliverable status

A reported usage picture, draft policy and action plan

We agree a fixed price quote before work starts, based on the staff sample and organisation size. See the Pricing page for the difference between fixed scope advisory and ongoing support.

Interview evidence

Written usage review

Findings from interviews, clearly identified as reported evidence rather than technical verification.
  • Findings by area
  • Risk rated issues
  • Recommendations
  • Owners indicated
Draft, not legal sign off

Draft AI usage policy

A practical first draft based on actual work patterns, ready for HR and legal review.
  • Acceptable use
  • Data handling
  • Approval and review
  • Ready to adapt
Confidential decision session

Leadership walkthrough

A private session to agree priorities and discuss sensitive findings.
  • Leadership walkthrough
  • Stakeholder questions
  • Priority agreement
  • Confidential delivery
The staff sample, evidence boundary and fixed price are agreed before interviews begin.

Scope

The six areas we cover

Tool inventory

Which sanctioned, paid, free and personal account tools are in use, for what tasks and how often.

Data exposure

What information staff report entering or uploading, including client, health, support, financial and commercial data.

Awareness and practice

What guidance exists, where staff are confused and which practical support would change behaviour.

Visibility going forward

How to keep an eye on this without locking everything down, including what to ask the IT provider to configure.

Recommendations and owners

Low, medium or high risk ratings, with practical actions that show who does it and by when.

Recent work

A policy first adoption path for an Australian health services business

We surveyed the team on how they used AI, mapped the platforms in use and handed leadership a practical policy first path.

Method

How the engagement runs

The review depends on reported staff behaviour. It does not independently verify usage through Microsoft 365, devices or network telemetry.
  1. Kick off

    Confirm scope and framing

    The sponsor confirms priorities, interview participants and how the review will be introduced.
  2. Interviews

    Talk to a sample of staff

    Short, non judgemental interviews with a representative slice of the team prioritise honesty over enforcement.
  3. Policy

    Draft the AI usage policy

    We prepare a policy outline that reflects how staff work in practice and can be adapted by the organisation.
  4. Draft

    Risk rated draft report

    We rate findings low, medium or high and pair them with recommendations and owners.
  5. Walkthrough

    Final report and plan

    Leadership reviews the findings, clarifies sensitive points and receives the final report and policy outline.

The picture AI arrived through the side door, no one wrote it down

Staff started using ChatGPT to draft emails. Someone tried Copilot. Another team uses Gemini through a personal Google account. Much of it does not appear in a central IT inventory.

The review can surface personal accounts and informal workflows that a licence list misses, but it cannot prove that every use has been disclosed. The OAIC's Notifiable Data Breaches reports consistently identify human error and access failures among important breach causes.

That makes current exposure hard to describe, and a policy written in a vacuum easy to ignore. The review creates an honest picture in plain language, handled so staff do not feel investigated.

Choose the right starting point

Readiness, usage, DLP or privacy advisory

Whole organisation

AI Readiness Audit

Use this when leadership needs to understand opportunities, operating gaps and the order of work.
Read about AI Readiness Audit
Staff behaviourCurrent service

AI Usage Review

Use this when the immediate question is which tools and data practices staff report using now.
One platform

Data and Privacy Advisory

Use this when a nominated CRM or platform needs an independent review of hosting, access, retention and response.
Read about Data and Privacy Advisory

Boundaries

What this engagement is not

Separate evidence

Technical verification or penetration testing

We do not scan Microsoft 365, devices or networks, or test whether systems can be broken into. Those require separate technical evidence.
Supportive framing

A staff investigation

The review is not disciplinary and does not exist to catch people out.
Advisory

A formal compliance audit

We point to standards and gaps but do not issue compliance certification.
Not legal advice

A legal review

The policy draft should be reviewed by HR and legal before final sign off.

Triggers

When to call us in

Scale unknown

Suspect AI is everywhere

Leadership knows usage is happening but cannot describe the scale or data involved.
Recent incident

Something happened

A staff action prompted a closer look and leadership wants a structured picture, not a witch hunt.
Policy in draft

Writing the policy

The business wants policy grounded in reality rather than copied from a generic template.
External question

How are you managing AI risk?

A board, funder, auditor or insurer expects a confident answer.
Copilot rollout

About to roll out Copilot

A sanctioned tool is launching and the executive wants to understand existing behaviour first.
Sensitive sector

Sensitive data needs clear controls

The organisation works in disability, aged care, health, education, legal, finance or not for profit services.

Practical details

Questions about AI Usage Review

What is assessed, what you receive and where advisory responsibility stops.

A technical audit can verify activity and configuration inside systems it can inspect. Interviews can reveal reported use of personal accounts, privately purchased subscriptions and informal work that those logs may miss. Neither method proves the whole picture alone. We state the evidence boundary in the report and recommend technical checks where they are justified.

Start here

Get a structured picture before writing policy

We will confirm whether interviews can answer the question before scoping the review.Enquiries get a reply within one business day.