On July 13, 2025, Australian cybersecurity consultancy vCISO.One announced the launch of its new AI Readiness Assessment service to help organizations take stock of their risk posture ahead of adopting artificial intelligence (AI) solutions. The consultancy will use the service to help Australian businesses and public sector entities identify where they stand in readiness for governing AI in a safe and responsible way, through a maturity assessment and action plan aligned to international best practice standards like ISO/IEC 42001, the NIST AI Risk Management Framework, and Australia’s own AI Ethics Principles.
Bridging the Gap Between Innovation and Governance
Artificial intelligence has been gathering pace in the private and public sectors over recent years, with organizations of all sizes racing to adopt AI tools to help streamline workflow, generate new insights, and drive growth.
The risks posed by misuse of AI systems, biases that could skew decision-making, algorithmic transparency, privacy, or simply non-compliance with new regulations are becoming a mounting concern. The AI Readiness Assessment is vCISO.One’s solution to help bridge this widening gap between AI enthusiasm and governance to deploy AI in a way that minimises harm.
The last 18 months has seen generative AI tooling adoption accelerate beyond large enterprises into small to mid-sized businesses (SMEs), not-for-profits, local councils, and more. The problem is, many of these organizations lack internal governance or oversight teams to provide guidance and assurance that generative AI is being used ethically, legally, and securely. With this service, vCISO.One aims to address that gap.
The AM AI SAFE Framework
At the heart of the new readiness assessment is vCISO.One’s internally developed AM AI SAFE framework, designed to help clients assess their AI maturity and risk posture across 11 critical themes and domains, including:
- Transparency
- Fairness & bias mitigation
- Explainability
- Accountability
- Security
- Privacy
- Sustainability
- Risk Management
- Lifecycle governance
- Data integrity
- Legal/regulatory alignment
Many of these domains overlap with those in the world’s most prominent global models (NIST AI Risk Management Framework, OECD AI Principles, ISO/IEC 42001, and the EU AI Act, among others). Domains like Transparency, Fairness, Explainability, Accountability, Security, Privacy, Risk Management, and Legal/Regulatory Alignment are foundational to nearly every major AI governance model being developed and deployed around the world, and are widely understood to be key elements of trust, risk mitigation, and compliance.
Where AM AI SAFE differentiates itself is in the two areas that are increasingly taking a seat at the table but are often overlooked in governance and risk models: Sustainability and Lifecycle Governance. Sustainability, while often baked into many of these other models, has rarely been called out as a stand-alone domain of focus, but AM AI SAFE highlights and centralizes this, as critical to aligning AI risk, innovation, and enterprise-wide ESG and SDG efforts with Environmental and Social impact targets. Lifecycle Governance is, similarly, baked into other models but not necessarily identified as a stand-alone focus area. AM AI SAFE focuses on governance across the entire lifecycle of AI development — from design to training to deployment and eventual decommissioning, to help ensure continuous governance and long-term accountability.
Another key strength of the AM AI SAFE framework is its nature as a holistic model, providing not only a list of standards or principles to follow, but a scalable, industry-aligned model that can be adapted to different client and organizational needs. It takes both technical and non-technical requirements and implementations into consideration, helping to identify and address risk, ensure and demonstrate compliance, and address concerns around enabling responsible innovation.
A Hands-on Approach
As part of the service, the assessment is delivered through a combination of a remote or in-person 60- to 90-minute guided workshop, which vCISO.One consultants will conduct alongside key stakeholders to help identify areas of strength, blind spots and what needs to be done to move forward.
This is then followed up with a detailed report that provides:
- Current maturity and risk ratings for the 11 framework domains
- Gaps and weaknesses identified during the assessment process
- Recommended next steps with guidance on priority setting
- Tailored roadmap and remediation plan for recommended changes
- Tailored for SMEs, councils, and NFPs
Specifically targeting the SME, council and NFP sectors, this new offering is built around an understanding that many organizations outside of the large enterprise sphere won’t have a dedicated cybersecurity, legal or risk compliance teams with the capacity to fully assess readiness and either do this in house or pay for a service from one of the big consulting firms. This is where vCISO.One aims to come in.
For example, a small to medium business that wants to use AI-powered tools for content generation will want to assess things like appropriate vendor selection, licensing arrangements, and governance; a regional council that is keen to experiment with generative AI to summarise citizen feedback from local surveys may not be aware of privacy considerations in terms of what datasets are being used to train algorithms, or the potential for discriminatory bias that could have significant legal or reputational impact. The readiness assessment aims to help SMEs, councils and NFPs understand where their ethical and legal responsibility starts and ends when it comes to responsible AI use.
Proactive Compliance, Risk Mitigation and More
With the EU AI Act now in force, the UK government publishing their own AI Regulation Roadmap in early 2023, and more countries and international standards organizations like the International Organization for Standardization (ISO) moving on their own standards around AI governance and risk frameworks, 2025 is a pivotal year in making sure Australian organizations are prepared to not just get with the program but future proof risk mitigation efforts.
In short, AI governance is no longer optional. It’s a compliance and business continuity necessity that most businesses and organizations have to factor in one way or another, with failure to carry out an AI readiness assessment now risking potential exposure to data breaches, privacy complaints, reputational damage, fines and regulatory penalties or class action lawsuits down the track around algorithmic discrimination or misuse of AI.
Beyond the Checklist: Building a Culture of Responsible AI
Noting that while an AI Readiness Assessment is a great way to identify gaps and develop plans, it’s not the final solution, Egoroff emphasises that the firm believes that AI governance should go beyond box ticking.
“We’re no longer asking if we need AI governance, but how fast we can embed it into our DNA,” mentioned Michille Lee, Founder/CEO of Obsidian Strategies.
To that end, in addition to training and resource materials for client teams and organizations, vCISO.One is also working with existing clients to help them benchmark their readiness against sector peers, as well as subscribing to regular updates about new AI policy changes and standards as they’re released.
Early Traction and Interest
The AI Readiness Assessment service has already picked up some early interest from education sector organizations, local government, public health bodies and fintech startups interested in gaining rapid, in-depth visibility into how they are faring in their current AI governance strategy or lack thereof.
Looking Ahead
The deployment of AI technologies is an essential and inevitable part of every organization’s digital transformation strategy. In a compliance and risk environment that is gearing up to be just as heavy hitting and detailed as cybersecurity, tools like AI readiness assessments are going to be moving from “nice-to-have” to critical.
From safeguarding against AI ethics and risks, preparing for audits, to just getting the foundational work around AI policy in place for successful scaling, readiness assessment is fast becoming the new baseline.
For those Australian firms that do it now, the AI Readiness Assessment will not only help with that audit preparedness but can build real differentiation through trust, innovation and operational resilience.