Foundational artificial intelligence risk assessment guideline

Document type:
Guideline
Version:
v2.0.0
Status:
CurrentNon-mandated
Effective:
August 2026–current
Security classification:
OFFICIAL-Public
Category:
Artificial intelligence

Purpose

A Queensland Government Enterprise Architecture (QGEA) guideline provides information for Queensland Government agencies on the recommended practices for a given topic area. Guidelines are generally for information only and agencies are not required to comply. They are intended to help agencies understand the appropriate approach to addressing a particular issue or doing a particular task.

This document provides guidance to agencies on the considerations and issues to be addressed when assessing risks across the artificial intelligence (AI) lifecycle in a Queensland Government context. The purpose of the Foundational AI risk assessment (FAIRA) and FAIRA LITE presented in this guideline is to promote a consistent approach to identifying, evaluating, communicating, and managing risks associated with AI during trials and across its lifecycle.

The FAIRA framework is a mandated requirement to maintain a comprehensive, consistent and evidence-based process to evaluate AI under the AI governance policy. For further information on what agencies must do regarding the governance of AI, please see the AI governance policy.

Audience

This document is intended for:

  • senior executives
  • chief information officers (CIO)
  • risk managers
  • project team members
  • business users
  • procurement officers.

Scope

This document sets out the considerations for identifying and documenting risks specific to AI solutions. It is intended to complement (rather than replace) any risk management frameworks currently being used by agencies. The use of AI products and services for Queensland Government is governed by the same responsibilities, obligations, and policies for the use of other digital products or services.

This document is provided as guidance to support the AI governance policy including FAIRA and FAIRA LITE benefits.

The benefits of conducting a FAIRA include:

  • Promotes a common understanding of AI risk: Identifies risk features to establish common controls to AI solutions in line with existing Queensland Government legislation, values, polices, requirements, processes, and frameworks.
  • Supports sector-specific frameworks: Provides the basis for more detailed application- or domain-specific criteria evaluation for specific government sectors.
  • Supports initial risk assessment: Provides a foundational understanding of AI risk and relevant controls that can be incorporated into broader agency risk assessment frameworks.
  • Supports ongoing risk management: Helps risk owners to update risk assessments when risks of an AI solution change or become known through new evidence including changes to the technologies themselves and how they are used in an operational context. Helps related work on mitigation, compliance, and enforcement throughout the AI solutions lifecycle, including actions for ongoing evaluation and monitoring and responding to feedback.
  • Supports documentation and communication: Helps product owners communicate responsible use of AI solutions to stakeholders including CIOs, business owners, users, and those impacted by use of the AI solution or system.
  • Ensures transparency and accountability of decisions to use AI by Queensland Government.

Background

The FAIRA framework is a transparency, accountability, and risk identification tool for Queensland Government agencies involved in the approval, development, procurement, management, use, monitoring or evaluation of artificial intelligence (AI) solutions. The FAIRA aims to help stakeholders identify risks and potential mitigation actions across the AI lifecycle. FAIRA is ‘foundational’ because stakeholders can use it to systematically describe an AI solution in terms of technical, system, business, values and governance components and their associated impacts as a foundation for action in existing compliance and risk management processes.

The FAIRA LITE framework, aligned to the FAIRA, enables agencies to trial low-risk AI solutions to inform a FAIRA for deployed systems. The FAIRA LITE framework is suitable for Limited, Informed, Tested, and use of AI that Excludes high risk. It enables agencies to govern, and risk manage a low-risk AI proof of concept, trial or explore the use of an AI system to inform a decision to deploy it operationally.

Agencies can use the FAIRA as the basis for communicating AI risks and mitigations with stakeholders and to strengthen other existing impact evaluation frameworks such as privacy or human rights. FAIRA can clarify the requirements, implementation, and operation of an AI solution and in doing so strengthen public trust in how government manages AI.

What is AI

Given the broad range of definitions of AI, the suggestions below provide additional guidance to agencies when identifying an AI solution.

A technology is an AI system if it meets one or more of the following criteria:

  • It meets the Organisation for Economic Co-operation and Development (OECD) definition of an AI system found in the National Framework for the Assurance of AI in Government:
    ‘A machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.’
  • It is classified as AI under ISO 22989 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology.
  • It is classified as AI under the QGEA technology classification framework V.5.0 August 2024 when:
    • a project, product, or service uses AI
    • a vendor describes its product or service as using AI
    • users, the public or other stakeholders believe the project, product or service uses AI.

Lack of agreement on definitions of AI should not prevent the identification of risks or the ability to communicate risk to stakeholders through FAIRA. Agencies may wish to adopt a specific AI definition that describes their classification of AI solutions. Products that carry some ambiguity as to whether AI is integrated can still be assessed by FAIRA to identify risks surrounding the human-machine interface, as many of these risks may overlap with risks relating to non-AI automated ICT and decision-making software. See the definitions section for further clarification on key terms. If an agency is unsure whether their project, solution, or service includes AI then they may wish to seek guidance from Data and Digital Group within the Department of Customer Service, Open Data, and Small and Family Business (dai@chde.qld.gov.au).

When to use FAIRA

Agencies apply the FAIRA or FAIRA LITE if an IT Solution meets the definition of AI - see Is a FAIRA or FAIRA LITE needed?

An agency prepares or updates a FAIRA when an AI system commences a new phase in the AI lifecycle. Agencies should also include each business process incorporating AI functions for reasoning or decision-making.

The risk assessment should be proportionate to the risk inherent in a business process and the type of AI functions involved. An agency should develop detailed assessment criteria and risk profiles within the FAIRA framework suitable to the subject matter and commensurate to the level of complexity of the reasoning or decision making evaluated.

See ISO 22989 for further information on the AI lifecycle and its functions.

Monitoring, feedback and evaluation mechanisms must be implemented to enhance risk assessments across the AI lifecycle. A FAIRA should be reviewed and updated when: a risk is realised via identified hazard, harm or incident; the likelihood or consequence of an identified risk changes; when new risks are identified; or when organisational values or priorities change. Examples of changes that could trigger a review could include any of the following:

Change type and affect

Technology or application asset

  • Data, model, system architecture or integration
  • Cloud infrastructure, software application layer
  • AI System design, features, functionality, UI/UX
  • Data storage and access.

Business processes

  • Strategic obligations
  • Functions, processes, workflows, decision and data architecture
  • Users
  • Context of use
  • Those impacted by use of the system

Risk controls

  • Governance including policy, guidance, and best practice
  • Risk management practices
  • Feedback and Impact assessments
  • Test, evaluation, monitoring and decision assurance
  • Human factors including training and oversight
  • Communication, transparency and accountability

and existing agency risk management processes and obligations.[1]

AI risk management include both periodic and circumstantial risk reviews.

Periodic risk reviews (scheduled re-evaluations) should be completed across the AI lifecycle such as recurrent conformity assessments and quarterly deep dives into bias, drift, and accuracy metrics. Critical ICT systems should be reviewed at least annually to confirm all documented attributes, including risks and security controls, remain current. For AI systems deemed at risk and high risk, and high residual risk systems need a continuous, scheduled collection of performance data and biannual reviews. Quarterly business reviews for platform-based AI systems provide agency awareness of how systems and their use is changing in the organisation that may affect risk. The cadence of periodic risk reviews should be determined by agencies based on risks identified in the FAIRA over the AI lifecycle See also the DTA AI Technical Standard.

Circumstantial reviews (trigger-based assessments) should be completed when significant changes are made that affect risk. These changes could be to the technology layer, the organisation’s strategic priorities, shifting governance obligations, changed use of an AI system by an agency that affect end users and those impacted by use of an AI system.

Under the Financial Accountability Act 2009, agencies are required to establish and maintain appropriate systems of internal control and risk management and should already have well established risk management frameworks in place. The Australian Standard AS/NZS ISO 31000:2009: Risk Management – Principles and Guidelines typically form the basis for agency risk management frameworks. The figure below depicts the key process steps.


Key process steps for agency risk management frameworksFigure 1: Overview of the risk assessment framework

It is important to involve a wide range of stakeholders, from different disciplines within the agency, such as business, finance, security, business continuity planning, legal and IT, and ensure that the business owners of the information assets, application, and associated technologies are included during the process and at final sign-off on conclusion.

The FAIRA should assist agencies when considering AI use during their risk identification processes. It outlines the AI considerations and risks that agencies should address as part of their existing risk management framework processes.

Establish the context

The purpose of this phase of the risk assessment framework (Figure 1) is to define the parameters within which risks will be managed and set the scope for the rest of the process. This phase is concerned with developing an understanding of the internal and external context where the department or business area operates and the factors that may influence the achievement of objectives. It also establishes the risk management context (i.e. the organisation and parameters of the risk management task itself) and scope of the target system being assessed.

Understand the internal and external environment

Understanding the internal and external environment is part of a broader scanning activity and provides the platform for building strategic, business, and operational objectives and understanding how the agency operates.

Influences on the internal environment may include:

  • the agencies governance and accountability structures
  • policies, standards, and guidelines
  • resources availability with the agency (for example, information systems, staffing and funding)
  • organisational readiness
  • nature and extent of contractual relationships
  • the agency culture, including the security culture
  • existing risk management expertise and practices
  • budget/financial/timing constraints
  • ICT architecture and technical constraints.

The primary influences on the external environment relate to the social, cultural, political, legal, regulatory, financial, technological, and economic environments where the agency operates. Agencies should consider what external factors are relevant to their situation, and factor these into their risk assessment process. Some examples include:

  • Queensland Government policies/standards/frameworks
  • State/Federal Statutory/legislative requirements e.g. Public Records Act 2002, Information Privacy Act 2009
  • National frameworks and best practice:
  • The National Framework for the Assurance of AI in Government (2024),
    • Digital Transformation Agency’s AI Technical Standard (2025) and AI Policies (2025),
    • Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide (2025),
    • National AI Centre (2025). Guidance for AI Adoption,
    • National Archives, Information Management for records created using Artificial Intelligence (AI) technologies (2025)
    • OAIC Artificial Intelligence and privacy
    • ASD Artificial Intelligence
  • International frameworks:
    • OECD (2025). Governing with Artificial Intelligence: The State of Play and Way Forward in Core Government Functions
    • OECD (2025) Towards a common reporting framework for AI incidents
  • foreign laws and potential jurisdictional access to information, and
  • The expectations and strategic direction of the Queensland Government
  • community and industry expectations
  • product roadmaps and the stability of the vendor marketplace and offerings.

Risk management context

The risk management context refers to the organisation and parameters of the risk management task itself. Key considerations include:

  • risk appetite
  • risk tolerance
  • risk impact and likelihood
  • risk matrix and responsibilities
  • risk rating responses
  • risk management maturity

The agency’s risk management framework will outline the preferred treatment/tools in these areas.

Other considerations

Information assets

AI can assist agencies create and acquire information assets. AI’s involvement in the creation or acquisition of an information asset can also raise a range of data management, data quality, and security risks that ought to be addressed consistent with Open data, information sharing, access and use policy and an agency’s application of relevant policies. Agencies should classify their information and information assets according to business impact and implement appropriate controls according to the classification (see the Information security classification framework).

For further information on the challenges of using AI solutions see the Use of Generative AI in Queensland Government guideline.

Automated decision making

AI is a form of automated decision making defined in the Commonwealth Ombudsman’s Automated Decision Making Better Practice Guide (2025). This guide outlines important considerations to determine whether the use of an AI solution qualifies as engaging in automated decision making (from p. 7 below).

“Automated systems range from traditional rules-based systems (for example a system which calculates a rate of payment in accordance with a formula set out in legislation) through to more specialised systems which use automated tools to predict and deliberate, including through the use of machine learning. The term automated system is used in this guide to describe a computer system that automates part or all of an administrative decision-making process. Automated systems can be used in different ways in administrative decision-making processes.”

For example they can:

  • make a decision.
  • recommend a decision to a decision-maker.
  • include decision-support systems, such as commentary about relevant legislation, case law and policy, for the decision-maker at relevant points in the decision-making process.
  • provide summaries or preliminary assessments for individuals or internal decision-makers.
  • automate aspects of the fact-finding process which may influence subsequent decisions, for example by applying data:
    • from other sources (e.g. data matching information)
    • directly entered or uploaded to the system by an individual.

Agencies need to consider whether their use of AI constitutes automated decision-making and manage any associated risks. This guide provides a checklist for agencies on pages 49-58.

AI risk identification framework

Under the AI governance policy, government agencies managing the lifecycle of an AI solution are required to apply the FAIRA or, for a low-risk proof of concept, trial, or exploratory activity, a FAIRA LITE to communicate risk with stakeholders. The FAIRA framework includes an AI component analysis (Part A), a values assessment (Part B), and a list of common controls (Part C) to assist responsible officers with identification of actions that could be taken to reduce risks identified using the FAIRA. Stakeholder consultation should be conducted and answers to any gaps should be sought from relevant experts to assist with clarification and confirmation (refer to Domains of AI Risk in FAIRA framework [link]. Through analysis and consultation an agency should identify the boundaries/scope of an AI solution/system, for example, what it contains and what it entails, integration points with associated upstream and downstream systems and what is NOT part of the scope of the evaluation. Agencies should communicate responsible use of an AI system to stakeholders including authorised uses, limits, and prohibitions as well as safety guardrails informed by the FAIRA.

Action

A responsible officer should ensure risks identified during a FAIRA are communicated to appropriate stakeholders for evaluation and management through the existing risk management processes in their agency. The responsible officer can draw from the general controls listed in the framework to mitigate risks during an AI lifecycle. If an AI solution changes, is deployed for a different purpose, in a different domain, or in a different context of use, a responsible officer should review the FAIRA as required—see section ‘When to use a FAIRA’. Risk analysis should proceed within an agency’s risk management framework with similar processes to those listed below.

Risk analysis, evaluation and treatment

The risk analysis, evaluation and treatment steps are not typically considered separately. They are interrelated processes which need to be considered by the agency simultaneously.

Risk analysis

Risk analysis (as shown in Figure 1) is about developing an understanding of the risk to determine the level of risk and make decisions about how the risk should be treated. Risk analysis will result in determining the risk level or risk rating for each identified risk. It involves developing an understanding of each risk, its consequences and the likelihood of the risk occurring. The risk analysis will inform the evaluation of risks, whether risks need to be treated and the selection of the most appropriate risk treatment strategy.

Agencies will need to assess the likelihood and consequence of each risk occurring (taking existing controls into account). The process for analysing risk will differ from agency to agency. All agencies will use some sort of risk matrix mapping and ‘dashboard’ representation, for example, the ICT risk matrix.

Agencies may use different categories for likelihood and consequence or have differing criteria and thresholds for each category or even have different risk ratings. These variations do not matter. The point is that agencies will arrive at a per risk assessment.

Agencies will often expand the variation in likelihood and consequence based on inherent risk versus residual risk (refer to your agency’s risk management framework to determine if this approach is applicable). To assign a residual risk rating to an AI system see Assigning a residual risk rating to an AI system.

Risk evaluation and treatment

The purpose of risk evaluation is to make decisions based on the outcomes of risk analysis about which risks are acceptable, which risks need treatment and the treatment priorities. The highest priority should be given to those risks that are evaluated as being the least acceptable. To treat unacceptable risks, agencies may improve existing controls or develop and implement new controls. The risk evaluation stage involves the following key steps to determine:

  • treatment actions using risk rating responses (refer to your agency risk management framework for details)
  • the risk target (refer to your agency risk management framework for details)
  • the treatment decision.

The decision about how to treat a risk is based on the relationship between their current risk rating and the target risk rating where the current risk rating is:

  • higher than the target risk rating, risk treatment options should be undertaken to reduce the risk to the required target.
  • the same or lower than the target risk rating, the risk can be accepted and monitored.

It is important risks are treated appropriately to reduce the risk to a level that is tolerable to the agency. It is also important that mitigation efforts are focussed on priority risk areas. In some instances, the risk target may be high despite the risk tolerance of the agency. This could occur in situations where no amount of reasonable mitigation treatment will effectively reduce the risk to a normally tolerable level.

When determining the treatment decision consider the:

  • causes of the risk and whether they are within the agency’s ability to manage
  • effectiveness of existing controls to manage the causes of the risk
  • resources required to implement treatment actions and the expected change to risk level
  • cost of implementing each treatment option against the benefits derived from it
  • impact should the risk still occur despite the treatments applied
  • gap between the current risk rating and the risk target.

The following treatment options are possible:

Reduce

The agency can apply risk treatment or mitigations to reduce either likelihood or consequence of the risk occurring.

Avoid

The agency makes an informed decision not to proceed with deployment of a particular solution or architecture to not be exposed to a particular risk.

There are numerous possible avoid scenarios depending on the context and outcome of the evaluation.

Note – in practice, agencies may undertake a risk analysis for several potential options simultaneously as part of an overall options analysis (as opposed to doing risk assessment for one option at a time, finding out it was unsuitable and starting over).

Share and transfer

The agency distributes risk with other parties. Potential options include:

  • In certain circumstances, and for certain risk types, sharing risk at a whole-of-government level may be acceptable in cases where doing so at the agency level has been deemed unacceptable
  • Shifting or sharing risk with the service provider may be an option for certain risk types. However, it is more likely that this approach would be to reduce risk only since government agencies cannot ‘outsource’ risk for their regulatory or statutory requirements. Agencies are still ultimately responsible.

Accept

Determine the agency can tolerate the risk introduced by the solution.

There may be a mixture of risk treatments applied – for example a combination of reduce, share and accept treatments could be applied across the range of individual risks to achieve an overall acceptable level of risk for an AI solution.

To assign a residual risk to an AI system, see Assigning a residual risk rating to an AI system.

Reporting requirements

An agency’s AI investments and risks are relevant to several of its reporting obligations, for example:

  • ICT Profiling
  • Assurance reviews
  • Privacy
  • Cybersecurity
  • Risk.

ICT profiling

Annual ICT profile reporting includes reporting on AI use for Queensland Government agencies included in the AI Governance Policy’s Applicability Statement.

Assurance

Any initiatives that use AI submitted for review under the Digital Investment Governance Framework should include a FAIRA in their submission.

Privacy

Agencies should manage and report AI risks to their adherence to the Queensland Privacy Principles through their standard information privacy management processes.

Cyber security

Agencies should manage and report AI risks related to cybersecurity through their standard cybersecurity risk management processes.

Risk

Agencies should manage and report AI risks through their standard risk management processes.

Advice

Agencies should ensure existing governance frameworks and bodies (such as an audit and risk committees) are aware of initiatives that use AI technology and that related initiatives have been assessed and documented against the FAIRA framework or a suitable alternative framework.

Alignment

FAIRA contributes to compliance with 6.1.2 AI Risk Assessment in ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system as a repeatable method to ensure that risk assessments are valid, consistent, and comparable. FAIRA aligns with the National Framework for the Assurance of AI in Government and the National AI Centre’s Guidance for AI Adoption.

Conducting a FAIRA will help those involved in development or procurement identify the objectives of the AI solution to identify risks of AI being unable to achieve its objectives. Completing a FAIRA enables an assessment of the potential consequences to Queensland Government stakeholders if risks were realised.

A FAIRA is completed in addition to Queensland Government AI guidelines[1] and ICT risk management[2].

Definitions

Term

Meaning

AI solution

An AI solution integrates an AI system into a broader context to solve specific problems or meet needs. An AI solution implies application, incorporating the AI system into a functional setup that addresses a real-world issue or requirement, often including user interfaces, integration with other technologies or systems, and consideration of operational and ethical aspects.

The FAIRA is focussed on AI solution risks.

AI lifecycle

The AI system life cycle model describes the evolution of an AI system from inception through retirement. This document does not prescribe a specific life cycle model but underlines some processes that are specific to AI systems that can occur during the system life cycle. Specific processes and timelines can occur during one or more of the life cycle stages and individual stages of the life cycle can be repeated during the system's existence. For example, it can be decided to repeat the "design and development" and "deployment" stages many times to develop and implement bug fixes and updates to the system. (ISO 22989)

Artificial intelligence system

A technology is an AI system if it meets one or more of the following criteria:

1) It meets the OECD definition of an AI System found in the National Framework for the Assurance of AI in Government:

‘A machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.’

2) It is classified as AI under ISO 22989 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology

3) It classified as AI under the QGEA technology classification framework V.5.0 August 2024 when:

a project, product, or service uses AI

a vendor describes its product or service as using AI

users, the public or other stakeholders believe the project, product or service uses AI.

For further information on AI concepts refer to ISO 22989

IT solution

An IT solution in this document is any combination of hardware, software, network components and digital services to address specific operational or organisational needs and objectives.

Machine learning

Machine learning is a process using computational techniques to enable systems to learn from data or experience. It employs a set of statistical methods to find patterns in existing data and to then use patterns to make predictions on production data. In traditional computer programming, a programmer specifies the logic to solve a given problem by specifying exact computational steps using a programming language. In contrast, the logic of a machine learning model is in part dependent on the data used to train the model. Thus, the computations, or steps, needed to solve the problem are not determined a priori. Also, in contrast to traditional computer programming, machine learning models can improve over time without being re-written by being re-trained on new, additional data and by using techniques to optimize model parameters and data features. (ISO 22989)

Resources

AI policies

International

National government

Appendices


[1] Generic (i.e. non-cloud) content in this section is extracted, for the most part, from Risk Management Guideline and A Guide to Risk Management developed by Queensland Treasury

[2] Under the Financial Accountability Act 2009