Approved AI services
List approved services and the uses each approval covers.
One-page preparation guide
Use this sheet to route questions and gather current evidence before completing the scan. It is an organisation aid, not an approval or control assessment.
Document owner
Effective date
Review date
Guide versionPack 0.5.0
Initiative or internal reference
Assessment date
Business owner
AI intake coordinator
Backup coordinator
Exception and escalation path
List approved services and the uses each approval covers.
Record information, decisions, transactions or integrations that need escalation.
Link the AI inventory, risk assessment, security tests, monitoring, fallback and supplier records.
Important: An approved tool or service does not establish that a control is effective for this initiative. Answer the scan for the actual implementation and current evidence.
Purpose, impact and ownershipBusiness owner, system owner, AI governance or riskNamed contact:
Data and affected peoplePrivacy, legal, data governance, conduct and complianceNamed contact:
Security and agent authorityInformation security, identity, engineering and architectureNamed contact:
Critical operations and fallbackOperational resilience, business continuity and operationsNamed contact:
Supplier and CPS 230 treatmentProcurement, third-party risk and the arrangement ownerNamed contact:
Independent assuranceSecond-line risk and internal audit with relevant technical capabilityNamed contact:
The AI intake coordinator should route and track the review. The role should not replace specialist challenge, accountable decision-makers or a backup escalation path.
Complete the scan for the current implementation. Assign owners and dates to material gaps, retain evidence of remediation, then load the saved assessment and rerun it with revised answers.
Avowal AI Prudential Risk Scan: avowal.com.au/assessment | Pack 0.5.0