AI Governance for Australian Aged Care & Healthcare

Say yes to AI with confidence.

Most organisations don't have an AI problem — they have a visibility problem. We bring the guardrails, evidence, and decision ownership that turn AI from a risk conversation into a confident yes.

Aligned to: Aged Care Act 2024 · Strengthened Quality Standards · OAIC AI guidance · AS ISO/IEC 42001:2023 · NIST AI RMF · OWASP LLM Top 10 (2026)
The problem

Between fear and chaos

Staff are already using AI — often invisibly. Boards are asked to approve AI they can't assess. Regulators are moving: enforcement is up, new obligations have fixed dates, and health information sits at the centre of it. Blanket bans push usage underground; blind adoption creates the incidents that end up in penalty proceedings.

Governance is not the brake. Done properly, it's the reason you can move: every AI use case visible, every decision owned, every claim evidenced.

From fear and chaos → clarity, control, confident action.

Services

Three ways we make AI defensible

Inspect-based · MedHELM-informed

AI Assurance Evals

Independent evaluation of your AI systems — does the tool actually do what the vendor claims, safely, on your population?

  • Built on the UK AI Security Institute's Inspect framework
  • Clinical task coverage informed by Stanford's MedHELM taxonomy
  • Audit-grade logs — every finding carries a verifiable receipt
OWASP-mapped · Layered testing

AI Security Assessment

Structured adversarial testing of AI applications before your residents' data depends on them.

  • Baseline vulnerability scanning and application red-teaming
  • Bespoke multi-turn adversarial scenarios
  • Findings mapped to OWASP LLM Top 10 (2026) and the Agentic Top 10
AI6 practices · ISO/IEC 42001 readiness

Governance Advisory

The frameworks, policies, and decision rights that let leadership approve AI — and prove it to an auditor.

  • Implementation of the National AI Centre's 6 essential practices
  • ADM transparency readiness before the 10 Dec 2026 deadline
  • AI management systems certifiable against AS ISO/IEC 42001:2023
Start with the AI Risk Assessment — $2,500

Your facility scored across 8 governance dimensions in 5 business days. Guaranteed to reveal gaps you didn't know you had, or your money back.

Get your score
Why now

The regulatory clock is running

Verified against the Australian landscape as at August 2026 — what's in force, what has a fixed date, and what's coming.

10 Jun 2025

Statutory privacy tort In force

Individuals can now sue directly for serious invasions of privacy — raising the stakes of any AI misuse of resident data.

1 Nov 2025

Aged Care Act 2024 + Strengthened Quality Standards In force

Rights-based Act and seven strengthened Standards. Standard 2 (governance & information systems) and Standard 5 (clinical care) are where AI deployments meet your accreditation.

Ongoing

OAIC enforcement-first posture Active

Civil penalty proceedings live against major providers; a $5.8M penalty in the health sector for security failures. Health information is the enforcement epicentre.

10 Dec 2026

Automated decision-making transparency Commencing

Privacy policies must disclose automated decisions that significantly affect individuals. If AI touches admissions, care planning, or rostering decisions — you have a deadline.

Announced

Legislated "Australian Standards for AI" Forthcoming

Announced July 2026 with a new Office of AI — legislation expected from 2027. Providers who implement the National AI Centre's 6 essential practices now will already be positioned.

Data residency

Your residents' data has a postcode

Where AI processing happens is a legal question, not a technical detail. We design AI architectures that keep Australian health data where it belongs.

My Health Records Act s 77

My Health Record data must not be held, processed, or handled outside Australia. Any AI touching MHR-derived data must be onshore. No exceptions worth testing.

State health records law

Victoria (HPP 9) and NSW (HPP 14) restrict sending health information outside the jurisdiction without equivalent protections — plus APP 8 accountability for cross-border disclosure.

Onshore AI inference

Frontier models can now run with inference pinned to Sydney (e.g. Claude on AWS Bedrock ap-southeast-2). Enterprise-grade, in-country AI is achievable — consumer AI tools with identifiable health data are not defensible.

Sovereign hosting

For government-adjacent workloads: IRAP-assessed environments and the Hosting Certification Framework. We architect to the standard your data classification demands.

Method

Evidence over adjectives

We apply our own governance to our own AI. Every assessment is framework-mapped, every claim carries a receipt, and escalation logic is deterministic — the model can add a warning, never remove one.

01

See

AI usage inventory — including the shadow AI nobody put on a register.

02

Score

Risk assessment across 8 governance dimensions, mapped to the frameworks your auditors recognise.

03

Secure

Guardrails, policies, and decision ownership — governance designed to enable, not block.

04

Sustain

Evals, monitoring, and review cadence so approval isn't a one-off event.

Who you work with

Built by someone who ships governed AI, not just slides about it

GVRN-AI is led by Nathan Bhasker — a healthcare ICT professional with 10+ years across clinical systems, aged-care telehealth operations, and enterprise AI delivery. Everything we recommend, we've built and evaluated ourselves: clinical triage systems with deterministic safety gates, agent systems with published eval results, and governance frameworks running in production.

See the work in the open →

Credentials

  • PMP & PRINCE2 certified
  • Certified Scrum Master
  • IBM AI Product Management
  • IAPP AIGP (in progress)
  • Mastering Agentic AI — certified, The Gen Academy
Questions

Straight answers, plain English

What is AI governance?

AI governance is the set of rules, checks, and responsibilities that let an organisation use AI safely. It answers three questions: what AI is being used, who is accountable for it, and how do we know it is working safely. It is not about blocking AI — it is about being able to say yes with evidence.

We have banned AI tools. Do we still need governance?

Yes. Bans rarely work — staff use AI on personal devices instead, which is harder to see and riskier. Sector surveys consistently find a majority of care staff have used AI tools at work. Governance makes usage visible and safe rather than hidden.

What does the $2,500 AI Risk Assessment include?

A scored assessment of your facility across 8 governance dimensions, a prioritised list of gaps, a board-ready summary, and a 45-minute debrief — delivered within 5 business days. If it reveals nothing you didn't already know, you get your money back.

Is our residents' data safe with AI? Where is it processed?

It depends on the tool. My Health Record data must never leave Australia by law (My Health Records Act s 77). Consumer AI tools generally process data offshore and are not defensible for identifiable health information. Enterprise AI can now run entirely in Sydney — we design architectures that keep Australian health data onshore.

Which regulations apply to AI in aged care right now?

In force today: the Aged Care Act 2024 and strengthened Quality Standards (from 1 November 2025), the Privacy Act including the new statutory privacy tort, and state health records laws. Coming: automated decision-making transparency in privacy policies from 10 December 2026, and legislated Australian Standards for AI expected from 2027.

How long does an engagement take?

The AI Risk Assessment takes 5 business days. Governance implementation typically runs 4–8 weeks depending on facility size. Advisory support is ongoing month-to-month — no lock-in contracts.

Know exactly where you stand

A 30-minute discovery call. No pitch — just an honest conversation about your AI exposure and what visibility would take.

Book a discovery call