ANAO

Australian National Audit Office

Tracked since 11 Nov 2025 · 1 change of substance across 2 captures · last changed 27 June 2026

The story so far

How to read this
  1. Tracking begins. The statement already existed; when Australian National Audit Office first published it is not recorded.

  2. substantive Major rewrite: the ANAO names a Chief AI Officer, adds a fourth AI tool, confirms Copilot's full rollout, and adds DTA use-classification and governance detail.

    read by Claude Opus 5
    • Appoints the Group Executive Director, Systems Assurance and Data Analytics as Chief AI Officer
    • Removed: Chief Digital Officer as an Accountable Official (now COO alone)
    • New tool disclosed: CTM Scout travel booking platform with an AI chatbot
    • Microsoft Copilot moves from trial to adoption across the ANAO, assessed low risk
    • New section classifying AI use under the DTA system (workplace productivity, image processing, analytics; corporate and enabling domain)
    • Oversight moves from the IT Strategic Committee to the Security & Information Technology Committee, with Accountable Officials reporting high-risk use cases
    • New assurance requirements for AI in audit work (documented in audit planning, testing, validation, review)
    • Adds staff avenue to raise AI concerns and a statement that no bespoke AI is developed in-house
    • Removed: explicit claim of no identified legislative breaches, replaced by broader compliance assurance
    • Adds a direct contact line for statement enquiries
    • Added: Chief AI Officer: not mentioned → in place
    • Added: Named tool added: CTM Scout
    • Added: New commitment (human oversight): Document AI use in audit planning, with testing, validation and review of outputs
    • Added: Safeguard added: audit or assurance
    • Added: Safeguard added: human review of outputs
    • Added: Safeguard added: incident or concern reporting
    • Added: Safeguard added: testing or evaluation
    • Added: Usage pattern added: analytics for insights
    • Changed: Stated last-updated date: 2025-07-21 → 2026-06-26
    Show the words that changed ↓

What the statement says

How to read this

The ANAO says it uses AI in vendor-supplied enterprise tools (Nuix image/word recognition, Adobe Acrobat form-filling, Microsoft Copilot across Microsoft 365 and a CTM Scout travel chatbot) for productivity and to explore audit uses, with no AI that interacts directly with the public. Governance sits with the Executive Board of Management and its Security & Information Technology Committee, with an internal AI use register, an Auditor-General-approved AI policy, an Accountable Official and a Chief AI Officer, and mandatory AI fundamentals training. read by Claude Opus 5

What it says AI is used for

  • Workplace productivity
  • Image processing
  • Analytics for insights
  • Corporate and enabling

Named tools: Nuix, Adobe Acrobat, Microsoft 365 Copilot, CTM Scout

Public-facing AI: none

Safeguards named: risk assessment, use-case register, staff training, a governance body, an acceptable-use policy, privacy or security controls, audit or assurance, testing or evaluation, human review of outputs, incident or concern reporting

Against the Standard 8/8

  • Present:Intentions behind AI use
  • Present:Use classified by DTA usage pattern or domain
  • Present:Public-facing use addressed
  • Present:Monitoring and protection measures
  • Present:Compliance with the policy
  • Present:Compliance with legislation
  • Present:Date last updated
  • Present:Public contact

What the policy requiresPolicy v2.0

Accountable official
Chief Operating Officer
Strategic position on AI
not mentioned
AI use-case register
in place
Staff training
mandatory
Policy version referenced
unspecified version

What the AI Plan asksAI Plan

Chief AI Officer
in place (Group Executive Director, Systems Assurance and Data Analytics)

Currency as of 29 Aug 2026

Review cadence
not stated
Says it was last updated
26 Jun 2026
Last change we observed
27 June 2026
Updated since policy 2.0
yes
Annual review
within a year of its own date

Commitments

  • will notDoes not use AI tools that interact directly with the public
  • will notLimits staff use of publicly available generative AI tools under the ANAO AI policy
  • human oversightDocument AI use in audit planning, with testing, validation and review of outputs
  • willRecord any AI application in a register and report it to the IT Strategic Committee
  • willMonitor software changes for new AI functions to identify risks before installation
  • willCarefully consider all AI tools to ensure safe, ethical and beneficial use
  • willImplement mandatory AI fundamentals training for staff

The statement

How to read this

ANAO’s artificial intelligence transparency statement

Please direct enquiries through our contact page.

The policy for responsible use of artificial intelligence (AI) in government includes mandatory requirements to nominate accountable officials and publish AI transparency statements. This statement provides details of the Australian National Audit Office (ANAO) implementation of these policy requirements. (Template language)

ANAO’s approach to AI adoption and use

The ANAO is exploring how AI may be used to improve business operations by enhancing efficiency, while ensuring quality and transparency in decision-making.

In embracing emerging technology — which includes AI — the ANAO will do so thoughtfully while managing risk for responsible and effective adoption.

The ANAO Use of Artificial Intelligence Policy (the policy) outlines the conditions under which ANAO staff and contractors may use AI. This is to ensure the responsible, safe, and ethical use of AI, with the intention of:

  • reducing the risk of using AI to the ANAO;
  • upholding the highest ethical standards when using AI; and
  • enabling transparency in the use of AI at ANAO.

The policy limits the use of publicly available generative AI tools (such as ChatGPT, Bing AI, and other large language models). It outlines staff obligations regarding the use of both publicly available AI and licensed enterprise AI. The policy also sets out expectations for the use of AI in audit-related activities.

The policy is supported by existing ANAO security frameworks, policies and guidance.

The ANAO is exploring how generative AI can enhance the audit process in a profession where human judgment and scepticism are fundamental to auditing standards. This work continues through the adoption of Microsoft Copilot across the ANAO, as well as by monitoring emerging trends and learning from the experiences of others within the APS and the broader public sector audit community, both in Australia and internationally.

The ANAO primarily uses commercial, vendor‑provided AI tools within approved enterprise environments. The ANAO does not currently develop or deploy bespoke AI systems in‑house.

The ANAO uses four enterprise applications that incorporate AI:

  • Nuix — Nuix is an eDiscovery tool used to search large unstructured data sets. One of its features uses AI to identify shapes and words in images. The ANAO has been using Nuix prior to the introduction of this AI function and does not view the AI-powered image search as a risk.
  • Adobe Acrobat — This software includes an automatic form-filling function which cannot be disabled. Given its limited use, this feature is considered low risk.
  • Copilot — Microsoft Copilot is an AI-powered assistant embedded across the Microsoft 365 ecosystem — including Word, Excel, Outlook, PowerPoint, Teams, and other applications. It leverages large language models combined with the Microsoft Graph (which includes data like emails, documents, meetings, chats, and calendar events) to deliver contextually aware productivity support. Copilot is considered low risk as it operates within the ANAO’s secure Microsoft 365 environment, does not use ANAO data to train AI models, and is subject to governance, audit logging and formal evaluation processes.
  • CTM Scout is a third-party platform that facilitates corporate travel bookings and features AI Chat Bot capabilities. Since this activity does not constitute audit work and involves only minimal personal information (such as staff name and date of birth), the associated risks are considered low. Therefore, an assessment under the ANAO Use of Artificial Intelligence Policy is not required.

The ANAO manages AI use cases through structured governance, documentation and continuous evaluation processes. AI use cases are captured in an internal register, with outcomes and feedback used to inform understanding of benefits, risks and effectiveness.

The ANAO actively monitors vendor-proposed changes to installed software within its IT environment — including and specifically for the introduction of new AI vendor-supplied functions — to identify any potential risks before the software update is installed.

Future development or customisation of AI tools is managed through ANAO’s project and change management frameworks and is subject to additional governance, risk assessment, and assurance processes. These processes include consideration of usability, productivity, security, privacy and audit implications.

The ANAO classifies its use of AI in accordance with the DTA classification system for AI use.

Public impact and protection

The ANAO may access personal information during audits and applies robust physical, information and personnel security policies to protect sensitive information and support secure, responsible audit work. The ANAO is committed to the safe and responsible use of AI. All AI tools and their applications will be carefully considered to ensure there is benefit to the technology and can be used safely and ethically.

The ANAO does not use AI tools that interact directly with the public and assesses its current AI use as low impact. Existing security measures and policies are considered sufficient to manage public impact and protection risks.

The Executive Board of Management (EBOM) is the ANAO’s primary governing body and is responsible for overseeing the use of AI. The Auditor‑General has approved the ANAO’s Use of Artificial Intelligence Policy, which establishes the framework for responsible AI use across the organisation.

AI applications are recorded in an internal register and reported to the Security & Information Technology Committee (a sub‑committee of EBOM) which supports ongoing oversight and transparency. The use of AI is also subject to governance by Accountable Officials, who oversee implementation and report high‑risk use cases, including their intended application, risk assessment and sensitivities. (Template language)

For audit‑related activities, AI use must be documented in audit planning and subject to defined assurance processes, including testing, validation and review of outputs. These arrangements ensure that AI use cases are assessed, monitored and implemented with appropriate consideration of risks, impact and benefits.

The ANAO complies with all relevant legislation in its use of AI, including requirements relating to privacy, security and confidentiality. The ANAO’s Use of Artificial Intelligence Policy establishes clear conditions to prevent misuse and ensures AI is applied in a responsible, safe and ethical manner. Ongoing monitoring, risk management and governance oversight supported by the ANAO’s quality and security frameworks provide assurance that AI use remains compliant across both public‑facing and internal operations.

ANAO’s existing management processes provide staff with the ability to raise concerns relating to the use of AI, including security, privacy or data handling issues. These processes support the identification, assessment and management of risks associated with AI use and are supported by the ANAO’s broader incident management, governance and compliance frameworks.

  • implemented mandatory requirements set out in the Digital Transformation Agency policy within the specified timelines;
  • appointed the Chief Operating Officer as the Accountable Official for AI within the ANAO; (Template language)
  • appointed the Group Executive Director, Systems Assurance and Data Analytics, as the Chief AI Officer within the ANAO; and
  • informed all staff of the appropriate use and risks associated with the use of generative AI through an internal communications and training program, including the implementation of mandatory AI fundamentals training.

The ANAO continues to review its approach in line with Australian Government policy, including consideration of mechanisms to enhance transparency and public engagement regarding AI use.

Contact: enquiries about this statement can be submitted to the ANAO via our contact us page

Approved for publication by Dr Caralee McLiesh PSM, Auditor-General for Australia

Statement text © Australian National Audit Office, reproduced for transparency tracking (most agency content is CC BY 4.0 — check the original for specifics).

Every revision

Every capture the daily scrape recorded that differed from the last, including edits with no change of substance. Pick a dot to view the statement as it stood at that capture.

  1. substantive+3708

    Major rewrite: the ANAO names a Chief AI Officer, adds a fourth AI tool, confirms Copilot's full rollout, and adds DTA use-classification and governance detail.

    read by Claude Opus 5
    View diff
    Corporate ## ANAO’s artificial intelligence transparency statement Updated MonFriday 216 Julyne 20256 Contact Please direct enquiries through our [contact page](https://www.anao.gov.au/about/contact-us). The [policy for [responsible use of artificial intelligence (AI) in government](https://www.digital.gov.au/policy/ai/policy) in government includes mandatory requirements to nominate accountable officials and publish AI [ transparency statements](https://www.digital.gov.au/policy/ai/list-of-transparency-statements). This statement provides details of the Australian National Audit Office (ANAO) implementation of these policy requirements. ## ANAO’s approach to AI adoption and use The ANAO is exploring how AI may be used to improve business operations by enhancing efficiency, while ensuring quality and transparency in decision-making. The ANAO willIn embraceing emerging technologies —y — which includinges AI — the ANAO will do so thoughtfully, while managing risk for safresponsible and effective useadoption. The ANAO Use of Artificial Intelligence Policy (the policy) outlines the conditions under which ANAO staff and contractors may use AI. This is to ensure the responsible, safe, and ethical use of AI, with the intention of: - reducing the risk of using AI; - enabl to the ANAO; - upholding the highest ethical standards when using AI; and - increasenabling transparency in the use of AI at the ANAO. The policy limits the use of publicly available generative AI tools (such as ChatGPT, Bing AI, and other large language models). It outlines staff obligations regarding the use of both publicly available AI and licensed enterprise AI. The policy also sets out expectations for the use of AI in audit-related activities. The policy is supported by existing ANAO security frameworks, policies, and guidance. The ANAO is exploring how generative AI can enhance the audit process in a profession where human judgment and scepticism are fundamental to auditing standards. This work will continues through a trialthe adoption of Microsoft Copilot across the ANAO, as well as by monitoring emerging trends and learning from the experiences of others within the APS and the broader public sector audit community, both in Australia and internationally. ## ANAO’s use of AI tools The ANAO uses threeprimarily uses commercial, vendor‑provided AI tools within approved enterprise environments. The ANAO does not currently develop or deploy bespoke AI systems in‑house. The ANAO uses four enterprise applications that incorporate AI: - Nuix — Nuix is an eDiscovery tool used to search large unstructured data sets. One of its features uses AI to identify shapes and words in images. The ANAO has been using Nuix prior to the introduction of this AI function and does not view the AI-powered image search as a risk. - Adobe Acrobat — This software includes an automatic form-filling function which cannot be disabled. Given its limited use, this feature is considered low risk. - Copilot — Microsoft Copilot is an AI-powered assistant embedded across the Microsoft 365 ecosystem — including Word, Excel, Outlook, PowerPoint, Teams, and other applications. It leverages large language models combined with the Microsoft Graph (which includes data like emails, documents, meetings, chats, and calendar events) to deliver contextually aware productivity support. The ANAO is conducting a comprehensive trial of this tool in its environmentCopilot is considered low risk as it operates within the ANAO’s secure Microsoft 365 environment, does not use ANAO data to train AI models, and is subject to governance, audit logging and formal evaluation processes. - CTM Scout is a third-party platform that facilitates corporate travel bookings and features AI Chat Bot capabilities. Since this activity does not constitute audit work and involves only minimal personal information (such as staff name and date of birth), the associated risks are considered low. Therefore, an assessment under the ANAO Use of Artificial Intelligence Policy is not required. The ANAO manages AI use cases through structured governance, documentation and continuous evaluation processes. AI use cases are captured in an internal register, with outcomes and feedback used to inform understanding of benefits, risks and effectiveness. The ANAO actively monitors vendor-proposed changes to installed software within its IT environment — including and specifically for the introduction of new AI vendor-supplied functions — to identify any potential risks before the software update is installed. ## Public impact and protection Future development or customisation of AI tools is managed through ANAO’s project and change management frameworks and is subject to additional governance, risk assessment, and assurance processes. These processes include consideration of usability, productivity, security, privacy and audit implications. ## Classification of AI use The ANAO classifies its use of AI in accordance with the DTA [classification system for AI use](https://www.digital.gov.au/policy/ai/resources/use-classification). ### Usage patterns - Workplace productivity - Image processing - Analytics for insights ### Domains - Corporate and enabling ## Public impact and protection The ANAO may access personal information during audits and applies robust physical, information and personnel security policies to protect sensitive information and support secure, responsible audit work. The ANAO is committed to the safe and responsible use of AI products. All AI tools and their applications will be carefully considered to ensure there is benefit to the technology and it can be used safely and ethically. The ANAO does not use AI tools that interact directly with the public and considerassesses its current use of AI within the organisation to havAI use as low impact on the public. Given this assessment, no additional safeguards have been implemented in relation to. Existing security measures and policies are considered sufficient to manage public impact and protection risks. ## AI governance The Executive Board of Management (EBOM) is the ANAO’s primary governing body and is responsible for overseeing the use of AI. Any AI application identified or implemented is The Auditor‑General has approved the ANAO’s Use of Artificial Intelligence Policy, which establishes the framework for responsible AI use across the organisation. AI applications are recorded in an internal register and reported to the IT StrategicSecurity & Information Technology Committee, (a sub-committee of EBOM. The Auditor-General approved the ANAO’s Use of Artificial Intelligence Policy. ## AI legislative compliance The ANAO complies with all relevant legislation and has not identified any breaches in the use of AI) which supports ongoing oversight and transparency. The use of AI is also subject to governance by Accountable Officials, who oversee implementation and report high‑risk use cases, including their intended application, risk assessment and sensitivities. For audit‑related activities, AI use must be documented in audit planning and subject to defined assurance processes, including testing, validation and review of outputs. These arrangements ensure that AI use cases are assessed, monitored and implemented with appropriate consideration of risks, impact and benefits. ## AI legislative compliance The ANAO complies with all relevant legislation in its use of AI, including requirements relating to privacy, security and confidentiality. The ANAO’s Use of Artificial Intelligence Policy establishes clear conditions to prevent misuse and ensures AI is applied in a responsible, safe and ethical manner. Ongoing monitoring, risk management and governance oversight supported by the ANAO’s quality and security frameworks provide assurance that AI use remains compliant across both public‑facing and internal operations. ANAO’s existing management processes provide staff with the ability to raise concerns relating to the use of AI, including security, privacy or data handling issues. These processes support the identification, assessment and management of risks associated with AI use and are supported by the ANAO’s broader incident management, governance and compliance frameworks. ## AI policy compliance The ANAO has: - implemented all elements ofmandatory requirements set out in the Digital Transformation Agency policy within the specified timelines; - appointed the Chief Operating Officer and Chief Digital Officer as the Accountable Officials for AI within the ANAO; and - a program to - appointed the Group Executive Director, Systems Assurance and Data Analytics, as the Chief AI Officer within the ANAO; and - informed all staff of the appropriate use and risks associated with the use of generative AI through an internal communications and training program, including the implementation of mandatory AI fundamentals training. The ANAO continues to review its approach in line with Australian Government policy, including consideration of mechanisms to enhance transparency and public engagement regarding AI use. **Contact:** enquiries about this statement can be submitted to the ANAO via our [contact us](https://www.anao.gov.au/about/contact) page Approved for publication by Dr Caralee McLiesh PSM, Auditor-General for Australia
    038c946
  2. first tracked+4972

    First tracked revision.

    07278a5