Australia Guidance for AI Adoption (2025)
Practice 5: Test and monitor – Australia Guidance for AI Adoption (2025)

Australia Guidance for AI Adoption (2025) 5.4.2: 5.4.2 Apply data and security controls per AI use case

For each AI use case: (a) define and document data quality, data and model provenance and data preparation requirements; (b) understand and document the data sources and collection processes the model or system relies on, including personal and sensitive data, and manage and document training, test and inference data; (c) for developers, define and document how models and systems are protected against emerging cybersecurity and privacy risks; (d) where appropriate, report data, model and system provenance to stakeholders; (e) document how the Australian Privacy Principles were applied, including in third-party models and systems; (f) document data usage rights including intellectual property and copyright, Indigenous data sovereignty, privacy, confidentiality and contract; and (g) monitor for and detect leakage of personal and sensitive information from models and systems.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 3.3 3.3 Ensure quality of data and design
  • 4.2 4.2 Minimise and protect personal information
  • 4.3 4.3 Secure systems and data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Practice 5: Test and monitor – Australia Guidance for AI Adoption (2025)

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.