Skip to Content


Privacy Act AI Audit for Australian Businesses.

10 December 2026.


Australia's Privacy Act introduces new obligations for organisations using AI in decisions that affect people.

The ADM (Automated Decision-Making) Readiness Audit tells you where you stand before the deadline.

Book your Audit Today.


Start With a Conversation

Who needs this audit?


Your organisation is directly in scope

Turnover above $3M · Health services · Financial services · Government contractors

The Privacy Act's automated decision-making provisions apply to you if your annual turnover exceeds $3 million, or if you operate in health services, financial services, or as a contractor to an Australian Government agency, regardless of turnover.

If your organisation also uses AI or automated tools to process personal information in decisions that affect employment, credit, housing, benefits, or service access, the new disclosure and accountability obligations commence on 10 December 2026. Non-compliance carries regulatory exposure under the Office of the Australian Information Commissioner.

Your stakeholders are already asking

Many organisations below the statutory threshold are facing the same questions through a different door. Enterprise clients are adding AI transparency requirements to supplier agreements. Professional indemnity and cyber insurers are asking about automated decision-making systems at renewal. Government tenders are beginning to include AI governance conditions.

The audit addresses these pressures with the same rigour as a mandatory compliance engagement. It produces documentation you can put in front of a client, an insurer, or a procurement panel.



If you are uncertain whether the obligation applies to you directly, the pre-engagement call will confirm it.

There is no cost to that conversation.

What the audit covers


A four-week engagement with a fixed scope, a fixed fee, and a clear output at the end of each week. The total time commitment from your team is four to six hours across the full engagement. We work around you.

Every audit produces five documents your organisation keeps, plus a presentation session with your leadership team. These are working assets, not a report that sits in a drawer.




Week 1 

System inventory

We identify every software tool, algorithm, or automated process your organisation uses that touches personal information. We record the system name, owner, purpose, data inputs, and decision outputs across all business functions. You keep the inventory as a permanent compliance asset, updated at each review cycle.


   Structured system inventory

A complete register of every AI and automated system in your organisation that processes personal information. Formatted for ongoing compliance review cycles so it remains useful well beyond December 2026.



Week 2 

Threshold analysis

For each system in the inventory, we apply the two-part test the Privacy Act requires: does the system substantially assist a decision, and does that decision significantly affect an individual's rights or interests? Each determination is written up with its reasoning. This produces your in-scope list.


  Written threshold determination for each system

Written reasoning for each in-scope finding, structured to support a future regulatory inquiry, an internal governance review, or a response to a client or insurer asking how you handle automated decisions.



Week 3 

Gap assessment

For each in-scope system, we review your privacy policy disclosures, contestability mechanisms, vendor contracts, and audit logging against the APP 1.7 to 1.9 requirements. Every gap is rated High, Medium, or Low by risk level, with a direct reference to the provision it engages.


  Scored gap register

A prioritised list of compliance gaps, scored by risk level, with direct references to the Privacy Act provisions each gap engages. High, Medium, and Low ratings give your team a clear sequence for remediation.



Week 4 

Remediation roadmap

A prioritised action plan written for your operations team and your board, with timelines mapped against the 10 December commencement date. Items that require legal advice beyond the audit's scope are flagged explicitly. The roadmap is presented in a one-hour session with your leadership team.


  Written roadmap and presentation session

A plain-language action plan for your operations team and board. Timelines are mapped to the December commencement date. Items requiring legal input are flagged so nothing falls through the gap between advisory and legal scope.

  Executive summary

A one-page document suitable for board presentation. It summarises your risk exposure, the findings, and the actions being taken. Written to be understood by a director with no technical background.

  Presentation session

A one-hour session with your leadership team at the close of week four. We walk through the findings, answer questions, and confirm the next steps together.

The audit does not constitute legal advice. Where a finding requires legal review, we say so clearly and can refer you to a qualified privacy practitioner.

Fixed fees, no surprises.


Tricore Tech ADM Readiness Audit is a fixed-fee engagement.
The fee is confirmed before the engagement starts, based on a short scoping call at no charge.


What you receive for your investment


Fees start from $4,500 ex. GST for Perth metropolitan area engagements. That covers the full four-week process, all six written deliverables, and the closing presentation session with your leadership team.

The scoping call determines where your engagement sits. Most Perth SMEs with AI tools deployed across one or two business functions, a single legal entity, and up to ten systems fall within that figure. Organisations with a larger system footprint, group structures, or sector-specific obligations under health, financial services, or government contracting regulation are scoped and priced accordingly in the same call.

There are no hourly rates, no scope creep, and no invoice surprises. You know what you are paying before the engagement begins.

For clients beyond the Perth metropolitan area, travel and accommodation costs are invoiced separately at actual cost at the close of the engagement. These are passed through at cost with no margin applied.



Contact Us

What we bring to this engagement.


The ADM Readiness Audit is delivered by a practitioner with a background in law, regulatory frameworks, and AI deployment across Australian businesses. The audit follows the READY methodology, Tricore Tech's structured five-phase framework for AI governance, which means every finding is documented consistently and every recommendation is grounded in your actual operating environment, not a generic template.

One principle governs every Tricore Tech engagement. We do not advise a client on the governance of an AI system we supplied. We keep those two activities completely separate. That is not negotiable.

  • We bring a legal and regulatory background to every engagement.
  • We follow a structured methodology, not a generic template.
  • We do not sell the systems we audit.
Tricore Tech

For organisations that see compliance as a foundation.

The December 2026 deadline is a fixed point. What sits beyond it is a regulatory environment that will continue to evolve, and a set of governance questions that do not resolve themselves once the initial obligation is met. New systems get deployed. Existing ones change. The legal framework around AI in Australia is still being written.

Organisations that treat the ADM Readiness Audit as the beginning of a governance practice, rather than a one-time compliance exercise, are the ones that avoid being caught out by what comes next.

Tricore Tech's AI Director on Demand service is built for that longer view. A fractional Chief AI Officer working alongside your leadership team on a retained basis, covering regulatory developments, governance decisions, and AI risk as a standing agenda item rather than a crisis response.

If the audit opens that conversation, it is one we are ready to have.

 Find out more about the AI Director on Demand



AI Director On Demand

Book your scoping call.


The call takes thirty minutes. It confirms whether your organisation is in scope, establishes your fee, and agrees a start date. There is no charge for the call and no obligation to proceed.


The audit takes four weeks to complete. Starting early gives your team time to act on the findings before the deadline.


We are based in Perth and work across Australia. The first conversation is a conversation, not a pitch.


Book a Conversation