Content reviewed and verified by Graham Chee, with FCPA-led practice at Local Knowledge, Mascot NSW. Continuous CPA Australia member since 1986. Prior career at Goldman Sachs, BNP Investment Management and Merrill Lynch.. Last reviewed August 2026. Next review scheduled for November 2026.
Safeguard your organisation: Aligning AI ethics with APES 310 and ASIC expectations for NSW directors.
The rapid proliferation of Large Language Models (LLMs) and other Artificial Intelligence (AI) technologies presents both unprecedented opportunities and complex governance challenges for Australian boards, particularly in New South Wales. While the productivity gains of AI are widely lauded, the ethical 'black box' of these models, their data provenance, and their potential for bias or misrepresentation demand rigorous oversight. For directors, the imperative extends beyond merely adopting AI; it necessitates active governance to ensure regulatory compliance, uphold ethical standards, and manage inherent risks. This article, penned from the perspective of an FCPA-led practice with institutional-grade compliance experience, delves into the specific professional ethical obligations outlined in APES 310: Statement of Assurance Engagements, and how these intersect with the responsible deployment and oversight of AI within your organisation. We will equip NSW boards with a framework to understand and mitigate the ethical and regulatory risks associated with LLMs, moving from theoretical concerns to practical, auditable governance strategies. You will learn how to embed robust data ethics guardrails, understand ASIC's evolving expectations for AI accountability, and leverage the expertise of GRCP/GRCA qualified practitioners to future-proof your board's approach to AI.
The allure of LLMs lies in their capacity to automate tasks, generate insights, and enhance decision-making. However, their opaque nature – often referred to as the 'black box' problem – introduces significant governance complexities. Boards must move beyond superficial adoption strategies to establish robust governance frameworks that address the inherent risks. These risks include data privacy breaches, algorithmic bias leading to discriminatory outcomes, intellectual property infringement, and the potential for LLMs to generate inaccurate or misleading information, a phenomenon known as 'hallucination'. ASIC, for instance, has increasingly signalled its focus on technological risk management, expecting boards to demonstrate clear accountability for the systems and data underpinning their operations [ASIC: CP 368]. For NSW directors, the Corporations Act 2001 (Cth) imposes duties of care and diligence, which extend to understanding and managing the risks posed by emerging technologies like AI. Effective LLM governance is not merely about preventing legal repercussions; it's about preserving reputational integrity, fostering stakeholder trust, and ensuring the long-term sustainability of the enterprise in an AI-driven landscape. This requires a proactive stance, embedding ethical considerations and accountability mechanisms from the outset, rather than reacting to incidents.
APES 310: Statement of Assurance Engagements, issued by the Accounting Professional & Ethical Standards Board (APESB), provides a critical ethical framework that extends directly to the governance of AI. While primarily focused on assurance engagements, its underlying principles of integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour are directly applicable to how boards oversee AI. When an LLM is used to generate reports, analyses, or advice that influences organisational decisions or is presented to external stakeholders, the board must ensure that the output is reliable and ethically sound. This requires scrutinising the data inputs, the model's architecture (to the extent possible), and the validation processes. For example, professional competence and due care demand that directors understand the limitations of LLMs and do not over-rely on their outputs without independent verification. Objectivity dictates that potential biases within the LLM's training data or algorithms are identified and mitigated to prevent skewed or unfair outcomes. Confidentiality is paramount when LLMs process sensitive organisational or client data. Boards must ensure that the use of LLMs aligns with these fundamental ethical tenets, treating AI outputs not as infallible truths but as tools requiring expert oversight and validation [APESB: APES 310].
For NSW directors, the challenge of AI governance is amplified by evolving regulatory landscapes and increasing public scrutiny. Mitigating AI risk requires more than just policy statements; it demands the integration of AI governance into existing corporate governance frameworks. This includes updating board charters, risk management policies, and internal audit functions to specifically address AI. Directors should consider establishing an AI ethics committee or assigning responsibility to a dedicated sub-committee, comprising individuals with diverse expertise in technology, law, ethics, and business. Furthermore, regular training for board members on AI capabilities, limitations, and ethical implications is essential to ensure informed decision-making. ASIC's focus on 'digital trust' and 'responsible innovation' underscores the expectation for boards to proactively manage technological risks [ASIC: Information Sheet 214]. Boards should also consider the implications of the Privacy Act 1988 (Cth) when LLMs process personal information, ensuring appropriate consents, anonymisation, and data security measures are in place. A robust framework will ensure that AI deployment aligns with the organisation's values, legal obligations, and long-term strategic objectives.
Implementing an AI governance audit is a critical step for NSW boards to assess their current state and identify areas for improvement. This audit should be comprehensive, covering technical, ethical, and regulatory dimensions. A structured approach ensures all critical aspects are reviewed. Here is a numbered process for conducting an AI governance audit:
Navigating the complex interplay of AI technology, ethical principles, and regulatory obligations requires specialised expertise. This is where the GRCP (Governance, Risk, and Compliance Professional) and GRCA (Governance, Risk, and Compliance Auditor) certifications become invaluable. Practitioners holding these credentials, like Graham Chee, possess a deep understanding of integrated governance, risk management, and compliance frameworks. They are equipped to design, implement, and audit systems that ensure organisations not only meet their legal and ethical obligations but also achieve strategic objectives responsibly. For AI governance, a GRCP/GRCA qualified practitioner can:
Leveraging GRCP/GRCA expertise provides boards with the assurance that their AI governance strategies are robust, compliant, and future-proofed against evolving regulatory and ethical landscapes.
The landscape of AI ethics and regulation is in constant flux. What constitutes best practice today may be superseded tomorrow. For NSW boards, future-proofing their approach to AI governance involves cultivating a culture of continuous learning, adaptation, and proactive engagement with emerging standards. This includes staying abreast of international AI governance frameworks, such as those proposed by the OECD or the EU AI Act, which may influence Australian policy. It also means actively participating in industry dialogues and contributing to the development of sector-specific AI ethical guidelines. Boards should foster an environment where ethical considerations are embedded throughout the AI lifecycle, from initial concept to ongoing operation and decommissioning. Regular review of AI governance frameworks, at least annually, is crucial to ensure they remain relevant and effective. Engaging with external experts, like GRCP/GRCA certified professionals, can provide valuable external perspectives and help benchmark an organisation's practices against leading standards. Ultimately, future-proofing AI governance is about instilling a mindset of responsible innovation, where the pursuit of technological advantage is inextricably linked with a commitment to ethical conduct and robust accountability.
The primary concern for NSW directors revolves around ensuring accountability and mitigating risks associated with the ethical 'black box' of LLMs. This includes issues like algorithmic bias, data privacy breaches, intellectual property infringement, and the generation of misleading information (hallucinations). Directors are expected to exercise due care and diligence, as per the Corporations Act 2001 (Cth), to understand and govern these risks, aligning with ASIC's expectations for robust technology risk management. Boards must demonstrate that AI systems are used responsibly and ethically, without compromising data integrity or stakeholder trust [ASIC: CP 368].
APES 310, while focused on assurance engagements, provides foundational ethical principles – integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour – that are directly applicable to AI governance. Boards must ensure that any AI-generated outputs, especially those influencing decisions or external reporting, adhere to these principles. For instance, professional competence requires understanding AI limitations, and objectivity demands mitigating algorithmic bias. Confidentiality is crucial for sensitive data processed by LLMs. Adherence to APES 310 ensures that AI use aligns with the highest professional ethical standards [APESB: APES 310].
Data ethics guardrails for LLMs are a set of policies, processes, and controls designed to ensure the ethical and responsible handling of data throughout the AI lifecycle. This includes ensuring data provenance, detecting and mitigating biases in training data, safeguarding data privacy, and ensuring the explainability and fairness of AI outcomes. These guardrails move beyond traditional data governance by specifically addressing the unique ethical challenges posed by LLMs, such as the potential for discriminatory outputs or the misuse of personal information. Robust guardrails are essential for maintaining trust and regulatory compliance [OAIC: Guide to undertaking a DPIA].
GRCP (Governance, Risk, and Compliance Professional) and GRCA (Governance, Risk, and Compliance Auditor) certifications signify expertise in designing, implementing, and auditing integrated governance, risk management, and compliance frameworks. This is highly relevant for AI governance because it requires a holistic approach to managing technological, ethical, and regulatory risks. A GRCP/GRCA qualified practitioner can translate complex regulatory requirements into actionable strategies, develop robust AI governance frameworks, conduct independent audits of AI systems, and ensure alignment with professional ethical standards like APES 310, providing boards with critical assurance and guidance.
ASIC plays a significant role in promoting AI accountability, particularly for financial services entities, but its principles extend broadly to corporate governance. ASIC expects boards to demonstrate clear oversight and accountability for technological risks, including those posed by AI. They focus on 'digital trust' and 'responsible innovation', requiring boards to understand the systems and data underpinning their operations. ASIC's regulatory guidance, such as that found in Information Sheet 214, indicates an expectation for robust risk management frameworks, transparent decision-making, and ethical considerations in the deployment of new technologies. Boards must be prepared to articulate how they are managing AI risks effectively [ASIC: Information Sheet 214].
In principal-led practice, we observe that many boards are enthusiastic about AI's potential but often underestimate the depth of governance required. The 'set and forget' approach to technology is simply not viable with LLMs. Our experience, grounded in FCPA-grade compliance and institutional risk management from years at Goldman Sachs, BNP Investment Management, and Merrill Lynch, highlights that true accountability demands continuous engagement. It's not enough to have a policy; you need auditable processes, clear lines of responsibility, and a culture that questions AI outputs critically. The ethical 'black box' isn't just a technical challenge; it's a fundamental governance challenge that requires the same rigour applied to financial reporting or operational risk. Embedding APES 310 principles into AI oversight is not an optional extra; it's a core fiduciary duty for NSW directors in the AI era.
The integration of LLMs into business operations is no longer a futuristic concept but a present reality. For NSW boards, the responsibility to govern these powerful tools ethically and compliantly is paramount. By leveraging frameworks like APES 310, establishing robust data ethics guardrails, and integrating AI governance into existing corporate oversight, directors can navigate the complexities of AI with confidence. The expertise of GRCP/GRCA qualified practitioners is instrumental in translating these principles into practical, auditable strategies, ensuring that your organisation not only harnesses the power of AI but does so responsibly and sustainably. Proactive governance is not just about avoiding penalties; it's about building enduring trust and future-proofing your enterprise in an increasingly AI-driven world. Speak with our principal to discuss how your board can develop a robust AI governance framework tailored to your organisation's unique needs.

Principal and Founder, Local Knowledge
Graham Chee is the principal and founder of Local Knowledge, an FCPA-led Australian practice that brings institutional-grade compliance, investment-structure and intellectual-property experience directly to owner-managed businesses. Graham is a Fellow of CPA Australia (FCPA since November 2005, continuous CPA member since 1986) and holds the OCEG Governance, Risk & Compliance Professional (GRCP) and Governance, Risk & Compliance Auditor (GRCA) designations. His prior career includes senior roles at Goldman Sachs, BNP Investment Management and Merrill Lynch. Graham was previously portfolio manager of the Asian Masters Fund (IPO December 2007 – 31 December 2009), which returned +29% in AUD terms versus the MSCI Asia Pacific (ex Japan) benchmark. He signs off on 100% of client files personally.
Areas of Expertise:
General information only. Speak to us for advice specific to your situation. Every file is signed off by our principal under CPA Code of Ethics.
Graham Chee FCPA, CPA, GRCP, GRCA · Principal, Local Knowledge · Mascot NSW · CPA-signed files