Privacy Act AI Audit for Australian Businesses.
10 December 2026.
Australia's Privacy Act introduces new obligations for organisations using AI in decisions that affect people.
The ADM (Automated Decision-Making) Readiness Audit tells you where you stand before the deadline.
Book your Audit Today.
Start With a Conversation
Who needs this audit?
Your organisation is directly in scope
The Privacy Act's automated decision-making provisions apply to you if your annual turnover exceeds $3 million, or if you operate in health services, financial services, or as a contractor to an Australian Government agency, regardless of turnover.
If your organisation also uses AI or automated tools to process personal information in decisions that affect employment, credit, housing, benefits, or service access, the new disclosure and accountability obligations commence on 10 December 2026. Non-compliance carries regulatory exposure under the Office of the Australian Information Commissioner.
Your stakeholders are already asking
The audit addresses these pressures with the same rigour as a mandatory compliance engagement. It produces documentation you can put in front of a client, an insurer, or a procurement panel.
If you are uncertain whether the obligation applies to you directly, the pre-engagement call will confirm it.
There is no cost to that conversation.
What the audit covers
A four-week engagement with a fixed scope, a fixed fee, and a clear output at the end of each week. The total time commitment from your team is four to six hours across the full engagement. We work around you.
Every audit produces five documents your organisation keeps, plus a presentation session with your leadership team. These are working assets, not a report that sits in a drawer.
Week 1
System inventory
We identify every software tool, algorithm, or automated process your organisation uses that touches personal information. We record the system name, owner, purpose, data inputs, and decision outputs across all business functions. You keep the inventory as a permanent compliance asset, updated at each review cycle.
Structured system inventory
A complete register of every AI and automated system in your organisation that processes personal information. Formatted for ongoing compliance review cycles so it remains useful well beyond December 2026.
Week 2
Threshold analysis
For each system in the inventory, we apply the two-part test the Privacy Act requires: does the system substantially assist a decision, and does that decision significantly affect an individual's rights or interests? Each determination is written up with its reasoning. This produces your in-scope list.
Written threshold determination for each system
Written reasoning for each in-scope finding, structured to support a future regulatory inquiry, an internal governance review, or a response to a client or insurer asking how you handle automated decisions.
Week 3
Gap assessment
For each in-scope system, we review your privacy policy disclosures, contestability mechanisms, vendor contracts, and audit logging against the APP 1.7 to 1.9 requirements. Every gap is rated High, Medium, or Low by risk level, with a direct reference to the provision it engages.
Scored gap register
A prioritised list of compliance gaps, scored by risk level, with direct references to the Privacy Act provisions each gap engages. High, Medium, and Low ratings give your team a clear sequence for remediation.
Week 4
Remediation roadmap
A prioritised action plan written for your operations team and your board, with timelines mapped against the 10 December commencement date. Items that require legal advice beyond the audit's scope are flagged explicitly. The roadmap is presented in a one-hour session with your leadership team.
Written roadmap and presentation session
A plain-language action plan for your operations team and board. Timelines are mapped to the December commencement date. Items requiring legal input are flagged so nothing falls through the gap between advisory and legal scope.
Executive summary
A one-page document suitable for board presentation. It summarises your risk exposure, the findings, and the actions being taken. Written to be understood by a director with no technical background.
Presentation session
A one-hour session with your leadership team at the close of week four. We walk through the findings, answer questions, and confirm the next steps together.
The audit does not constitute legal advice. Where a finding requires legal review, we say so clearly and can refer you to a qualified privacy practitioner.
Fixed fees, no surprises.
Tricore Tech ADM Readiness Audit is a fixed-fee engagement.
The fee is confirmed before the engagement starts, based on a short scoping call at no charge.
What you receive for your investment
The scoping call determines where your engagement sits. Most Perth SMEs with AI tools deployed across one or two business functions, a single legal entity, and up to ten systems fall within that figure. Organisations with a larger system footprint, group structures, or sector-specific obligations under health, financial services, or government contracting regulation are scoped and priced accordingly in the same call.
There are no hourly rates, no scope creep, and no invoice surprises. You know what you are paying before the engagement begins.
For clients beyond the Perth metropolitan area, travel and accommodation costs are invoiced separately at actual cost at the close of the engagement. These are passed through at cost with no margin applied.
What we bring to this engagement.
One principle governs every Tricore Tech engagement. We do not advise a client on the governance of an AI system we supplied. We keep those two activities completely separate. That is not negotiable.
- We bring a legal and regulatory background to every engagement.
- We follow a structured methodology, not a generic template.
- We do not sell the systems we audit.

For organisations that see compliance as a foundation.
If the audit opens that conversation, it is one we are ready to have.
Find out more about the AI Director on Demand
Book your scoping call.
The call takes thirty minutes. It confirms whether your organisation is in scope, establishes your fee, and agrees a start date. There is no charge for the call and no obligation to proceed.
The audit takes four weeks to complete. Starting early gives your team time to act on the findings before the deadline.
We are based in Perth and work across Australia. The first conversation is a conversation, not a pitch.
