00 — Overview

Queensland Audit Office (QAO) reference application. This is a demonstration prototype modelled on the Queensland Audit Office's public-facing documentation, reports, guidance and activities. It is not an official QAO system and holds no real audit information — every entity, AI system, assessment, risk and decision in the demo data is fictional and illustrates the data model and workflow only.

What AIGERM is

The AI Governance & Ethical Risk Manager turns AI governance into a structured, evidence-backed register. An AI system isn't "safe to use" because it works — it is assured when its use is justified (necessity and proportionality), its ethical, privacy and legal risks are assessed, effective controls and human oversight are in place, its transparency obligations are met, deployment was approved against evidence, and it is monitored for adverse outcomes and bias — with change and retirement governed. AIGERM holds every one of those links so the state of AI assurance is always demonstrable.

The domain

Public-sector AI attracts scrutiny for fairness, transparency, accountability and privacy — especially where it makes or informs decisions about people. The hard parts are ethical risk (who could be harmed, and how badly?), human oversight (can a person intervene before harm?), and ongoing assurance (does it still behave after deployment and change?). AIGERM models all three, keeping approval and operation honest against evidence and monitoring.

The 22 models by area

AI Register (4) - Entity — the audited organisation. · AISystem — an AI system in scope (lifecycle, risk tier, flags). - AIUseCase — a use of the system (necessity/proportionality). · DataSource — data feeding it.

Assessment & Ethics (4) - RiskAssessment — a lifecycle-stage risk assessment (versioned). · EthicalRisk — an ethical risk (inherent/residual scored). - EthicalPrincipleAssessment — a rating against an ethics principle. · LegalComplianceAssessment — a legal/privacy compliance check.

Controls & Approval (4) - Control — a control mitigating a risk. · HumanOversightControl — a human-in-the-loop intervention point. - TransparencyObligation — a disclosure obligation. · ApprovalGate — a lifecycle approval decision.

Evidence & Monitoring (4) - EvidenceRequirement — what evidence is required. · EvidenceSubmission — the evidence provided. - MonitoringMetric — a metric with thresholds. · MonitoringObservation — an observed value (warning/breach).

Incidents, Change & Retirement (6) - AdverseOutcomeIncident — a harm/near-miss. · FeedbackComplaint — public feedback/complaint (may link an incident). - AIChange — a change (may require reassessment). · TrainingRequirement / TrainingCompletion — required training and its completion. - RetirementPlan — controlled decommission (with a confirmation checklist).

(The source pack's DomainEvent outbox is Phase 2 — see page 03.)

The demo scenario

A QAO-style AI-governance register for the Department of Customer & Digital Services, with two live systems and a retired pilot:

  • Customer Enquiry Assistant (AI-CEA) — public generative chatbot, HIGH tier: grounded-response control, published transparency notice, deployment approved; an adverse-outcome incident (incorrect concession advice) with a linked complaint, both resolved; a model-version change flagged for reassessment.
  • Debt Recovery Prioritisation (AI-DRP)automated decision model, CRITICAL tier: a fairness/bias ethical risk, human oversight before enforcement, a fairness-test evidence, a CONDITIONAL deployment gate, and a disparate-impact monitoring breach (0.79) with reinforced mitigation.
  • Chatbot Pilot v0 (AI-PILOT)retired, with a completed retirement plan.

38 rows across all 22 models — the whole lifecycle across a generative, an automated-decision and a retired system.