A top-down working model of how artificial intelligence changes the operation of an aged care business: where value is created across people, roles, process and money, what it does to risk and compliance, and how to score, validate and measure any proposed application or data idea against the organisation's process framework.
Aged care is a labour-intensive, heavily regulated, information-rich business whose economics are set largely by government funding rules and whose licence to operate depends on demonstrable quality and safety. Those three characteristics make it unusually exposed to AI, in both directions. Well-applied AI returns time to care, improves funding integrity and turns compliance from a periodic scramble into a continuous state. Poorly applied AI creates clinical, privacy and regulatory exposure faster than any other technology the sector has adopted.
The value is not in "an AI tool" but in embedding seven repeatable capability patterns (perceive, understand, forecast, optimise, generate, automate, monitor) into the 323 processes the organisation already runs. Every idea should be expressed as a change to a named process, owned by a named role.
Back-office and workforce processes (rostering, payroll, accounts payable, claims) offer low-risk, fast, measurable gains. The largest value pools (care minutes, AN-ACC funding integrity, avoidable hospital transfers, agency spend, documentation burden) sit closer to care and carry higher risk, so they need the governance built first.
Classify every use case into one of four risk tiers with pre-agreed controls. Tier 1 ideas can be piloted in weeks with light governance. Tier 4 (clinical decision, resident-facing) ideas require a clinical safety case, privacy impact assessment and clinical governance sign-off. The tier, not enthusiasm, dictates the validation path.
For the reference organisation in this library (7 residential facilities, 8 independent living complexes, a home care service, roughly 370 to 580 residents and clients, CEO plus six executives including a Chief Risk Officer), the model identifies six value pools. They are ordered by how much they are worth relative to how hard they are to capture. Indicative magnitudes are deliberately not quoted here; the measurement framework in section 9 exists so that every figure used in a business case is the organisation's own baseline, not a vendor's.
| Value pool | What AI changes | Primary lens | Typical risk tier |
|---|---|---|---|
| Documentation and administrative burden on care staff | Ambient and voice capture of progress notes, handover summaries, incident narratives, care plan drafting. Returns minutes per shift to direct care and lifts the quality and completeness of the record that funding and accreditation depend on. | Care, Workforce | Tier 4 Tier 3 |
| Workforce supply, rostering and agency spend | Demand forecasting by acuity and care-minute targets, roster optimisation within award and fatigue rules, automated vacancy fill, attendance anomaly detection. Directly moves agency hours, overtime and unfilled shifts. | Workforce, Financial, Compliance | Tier 2 |
| Funding and revenue integrity | AN-ACC classification currency and reassessment triggers, leave and respite day accuracy, means-tested fee and RAD/DAP calculation assurance, Support at Home claim integrity. This is where "cash leakage" typically hides. | Financial, Compliance | Tier 3 |
| Clinical risk and avoidable harm | Deterioration and falls risk stratification, medication safety monitoring, infection and pressure injury early warning, incident trend analysis. Moves the Quality Indicators and Star Ratings that shape reputation and occupancy. | Care, Compliance | Tier 4 |
| Continuous compliance | Obligation registers mapped to controls and evidence, regulatory change monitoring, SIRS classification support, accreditation self-assessment assembly, control monitoring for finance and access. Converts audit preparation from an event to a by-product. | Compliance, Capability | Tier 2 |
| Back-office throughput | Invoice capture and matching, reconciliation, month-end acceleration, procurement forecasting, helpdesk triage, policy Q&A. Lowest risk, fastest payback, and the place to build organisational muscle. | Financial, Capability | Tier 1 |
The model is a stack. Each layer constrains the one below it. An idea that cannot be traced upward to a value lens and downward to a validated metric is not ready for investment. The layers correspond to the sections of this page.
Every use case cites the L3 process IDs it changes (for example ROS-001.2.2). This keeps AI ideas inside the existing accountability structure and lets the role-process matrix answer "who owns this".
AI changes who does the work, not who is accountable for it. The role that owns a process in the matrix remains accountable for outputs produced with AI assistance, and the risk tier defines the minimum human involvement.
No pilot starts without a measured baseline for its primary metric. This is the single most common failure in AI programs: value that cannot be demonstrated because the "before" was never recorded.
The seven patterns map to shared components (document ingestion, speech capture, a retrieval layer over policies and records, forecasting services, workflow orchestration, monitoring). Buying or building these once, with governance built in, is cheaper and safer than 30 disconnected vendor tools each holding resident data.
Aged care value is multi-dimensional and the dimensions trade off. A roster optimiser that cuts agency spend but breaches care-minute targets destroys value. Scoring every idea across all five lenses, with explicit weights, forces those trade-offs into the open. The weights below are defaults for a medium not-for-profit or mission-led operator; a for-profit operator with funding pressure might raise Financial, and an operator under a Commission notice would raise Risk & compliance.
Quality of life, safety, dignity, choice and continuity for residents and clients, and the experience of families. Measured through Quality Indicators, incidents, hospital transfers, complaints, satisfaction and care-minute delivery.
Capacity, retention, wellbeing and time returned to direct care. Measured through documentation time, vacancy fill, turnover, agency reliance, overtime, fatigue and engagement.
Revenue integrity (funding classification, claims, fees), cost to serve, cash conversion and leakage. Measured through claim variance, DSO, agency and overtime cost, invoice cost and cycle time, and EBITDA per bed or client.
Regulatory standing, audit outcomes, timeliness of mandatory reporting, privacy and security posture. AI can score positively here (continuous compliance) or negatively (new exposure), so the scorecard captures both.
Decision quality, data maturity, speed of learning, reuse of platform components. Small in weight but decisive in sequencing: foundational work scores here.
Classifying by pattern does three things: it makes very different ideas comparable, it exposes which shared platform components are needed, and it sets a default risk posture (generation and autonomous action carry more inherent risk than monitoring or forecasting used as a signal).
| Pattern | What it does | Typical technology | Inherent risk notes |
|---|---|---|---|
| P · Perceive & capture | Turns speech, documents, images and sensor signals into structured data. | Speech-to-text and ambient scribing, OCR and document AI, computer vision, IoT event interpretation. | Consent and dignity where residents are recorded or observed; accuracy of transcription into the clinical record. |
| U · Understand & retrieve | Classifies, extracts, summarises and answers questions over the organisation's own information. | Large language models with retrieval over policies, contracts, care records; entity extraction; semantic search. | Hallucination and staleness; access control must be enforced at retrieval, not just at the user interface. |
| F · Forecast & predict | Estimates future demand, risk or events from historical patterns. | Time-series forecasting, risk stratification models, survival and deterioration models, churn and attrition models. | Bias and calibration drift; predictions about individual residents or staff need fairness review and human interpretation. |
| O · Optimise & decide | Chooses the best option under constraints. | Constraint solvers for rostering and routing, matching algorithms, recommendation engines. | Constraints must encode award, care-minute and skill-mix rules explicitly; objective functions must reflect all five lenses. |
| G · Generate & communicate | Drafts text, plans, reports and communications for human review. | Generative language models with templates and grounding. | Over-reliance and automation bias; drafts entering the clinical or legal record need explicit human sign-off and provenance. |
| A · Automate & act | Executes multi-step workflows and system actions, increasingly with agentic tool use. | Workflow orchestration, robotic process automation, agent frameworks with tool access and approval steps. | Blast radius of errors; needs idempotent actions, approval gates by tier, full audit logging and a kill switch. |
| M · Monitor & assure | Continuously watches data for anomalies, exceptions and control breaches. | Rules plus anomaly detection over transactions, records, access logs, clinical data. | Alert fatigue; thresholds need tuning against baseline and false-positive rates must be measured. |
Each cell counts the catalogued use cases in that functional area that use that pattern. Darker cells are denser opportunity clusters. The right-hand columns summarise the area's dominant value lens and typical risk tier, which together indicate sequencing: dense, low-tier areas are where to start.
This is the reference layer. Each entry is a hypothesis, not a recommendation: it names the processes it would change, the accountable roles from the role-process matrix, the value lenses it should score on, the risk tier that determines its validation path, the roadmap horizon it naturally belongs to, and the primary metric that a pilot would have to move. Use it to locate a new idea among its neighbours, to check the process and role it must attach to, and to borrow the metric.
The organisation design in this library has around 75 distinct roles across three service lines and five back-office functions. They collapse into ten archetypes for the purpose of AI impact. For each, the model distinguishes work that AI takes off the plate, work it adds (mostly oversight and exception handling), the decisions that must remain human by tier, and the capability the role needs to build.
| Archetype (roles in matrix) | Work AI absorbs | Work AI adds | Decisions that stay human | Capability to build |
|---|---|---|---|---|
| Frontline care worker Personal care workers, home care workers, lifestyle staff | Progress note typing, handover recall, locating procedures, form filling, shift-swap logistics. | Reviewing and confirming AI drafts, flagging errors, using voice capture correctly and with consent. | Every observation about a resident's condition; escalation. | Digital confidence, "read before you sign" discipline, knowing when the AI is wrong. |
| Registered nurse / Nursing Unit Manager | Assessment and care plan first drafts, medication chart reconciliation checks, QI data assembly, incident write-ups, care-minute tracking. | Clinical review of risk flags, override and rationale recording, supervising delegated AI-assisted documentation. | All clinical judgements, medication decisions, care plan approval, SIRS determinations. | Interpreting risk scores and calibration, clinical safety reporting for AI, delegation under AI assistance. |
| Facility Director / Site Coordinator / Homecare Team Lead | Roster building, vacancy chasing, agency booking, family update drafting, maintenance triage, occupancy and admission admin. | Approving optimised rosters, managing exceptions, monitoring adoption and staff wellbeing during change. | Roster publication, admissions, staff performance actions, family escalations. | Reading forecasts and constraints, running a facility on exception dashboards rather than spreadsheets. |
| Clinical Lead / Quality & Compliance Manager | Chart audit sampling, evidence mapping to the strengthened Quality Standards, incident trend analysis, policy currency checks. | Owning the clinical safety case for every Tier 3 and 4 use case; validating models against local data; investigating AI-related incidents. | Accreditation attestations, clinical governance decisions, restrictive practice decisions. | Clinical AI safety (a new discipline), evaluation design, bias and drift review. |
| Finance, Payroll, Accounting Officers | Invoice coding and matching, reconciliations, accruals, subsidy claim preparation, fee calculations, collections letters, variance commentary. | Exception queues, control monitoring review, claim variance investigation. | Payment release, claim lodgement sign-off, write-offs, journal approvals. | Control design for automated processes, data literacy for anomaly review. |
| HR, Recruiter, Learning Coordinator | Screening, verification chasing, onboarding content, training compliance reporting, award interpretation lookups. | Fairness review of screening outputs, candidate communication oversight, learning-path curation. | Hiring, discipline, grievance outcomes, pay decisions. | Employment-law implications of automated decision-making, bias testing. |
| Scheduling & Rostering Officers | Manual roster construction, callout rounds, timesheet chasing, travel route planning for home care. | Tuning constraints and preferences, handling the residual unfillable shifts, validating solver output against award rules. | Publishing rosters, overriding solver for human reasons. | Constraint thinking, understanding the objective function they are asked to approve. |
| Risk, Compliance, Internal Audit | Regulatory change reading, obligation mapping, evidence collection, audit sampling, breach assessment drafting. | Owning the AI risk framework, AI register and tiering decisions; second-line assurance over models and vendors. | Risk acceptance, breach notification decisions, audit opinions. | AI risk management (ISO/IEC 42001 style), model and vendor assurance, privacy impact assessment for AI. |
| IT & Data (CIO, IT Manager, Clinical Systems Coordinator, Data & Security Officer) | Helpdesk first-line, access reviews, monitoring triage, release notes. | Running the AI platform, retrieval layer and evaluation harness; data quality engineering; security of AI supply chain. | Production changes, vendor selection, incident declaration. | MLOps and LLMOps, data platform engineering, prompt and retrieval security. |
| Executives and Board | Board pack narrative assembly, KPI commentary, scenario modelling mechanics, regulatory horizon scanning. | Directing AI strategy, setting lens weights and risk appetite, attesting to AI governance under Standard 2 (The Organisation). | Strategy, risk appetite, investment, regulatory attestations. | AI literacy sufficient to challenge, not just approve. |
AI may complete the task. A human reviews samples and exceptions after the fact. Administrative, no consequential decision about a person.
AI prepares or recommends; a named role approves before effect. Personal data involved or financial or compliance consequence.
AI output is one input to a human decision that affects a resident, client or staff member. Rationale for the decision is recorded, including when AI was overridden.
Output touches clinical care or the clinical record. Clinician sign-off, clinical safety case, validation on local data, and incident pathway. May be a regulated medical device.
A standing sub-committee of the existing Technology Steering Committee with clinical governance representation. Chaired by the CRO (risk owner) with the CIO (platform owner) and CCO (clinical safety owner). Approves tiering, pilots, scaling decisions and the AI register. Reports to the board quarterly.
Sits under the CCO, typically an extension of the Quality & Compliance Manager (Clinical). Owns clinical safety cases, local validation and AI-related incident review for Tier 3 and 4 use cases.
Under the CIO, likely evolving from the Clinical Systems Coordinator or a new hire. Owns the platform components, evaluation harness, monitoring and vendor technical assurance.
One accountable manager per functional area (for example the Finance Manager for FIN use cases, the Regional RAC Manager for RAC) who owns the benefits case; data stewards per data domain who own quality. These are additions to existing roles, not new headcount, in a medium operator.
In aged care, AI risk is not a separate category; it is a new way of failing existing obligations. The framework therefore starts from the obligations the organisation already carries and asks how each use case could breach or strengthen them.
| Instrument | Relevance to AI use | Model touchpoints |
|---|---|---|
| Aged Care Act 2024 and Rules (commenced 1 November 2025) and the Statement of Rights | Provider registration and obligations, the duty of care, rights to privacy, information and to be treated with dignity and to make decisions. AI that records, observes or makes recommendations about an individual engages these rights directly. | Consent design for Perceive patterns; supported decision-making; provider governance attestations. |
| Strengthened Aged Care Quality Standards (seven standards under the new Act) | Standard 2 (The Organisation) covers governance, information management and risk systems; Standard 3 (Care and Services) covers assessment, planning and communication; Standard 5 (Clinical Care) covers clinical governance, medication and deterioration; Standard 6 covers food and nutrition. AI in care processes must show it supports, not undermines, these outcomes, and AI governance itself is evidence under Standard 2. | Accreditation evidence mapping; clinical safety case; AI register as governance evidence. |
| Serious Incident Response Scheme (SIRS) | Priority 1 incidents reportable within 24 hours, Priority 2 within 30 days. AI can improve classification and timeliness but an incorrect AI classification that delays a report is a breach. | Tier 3 classification-support use cases; timeliness metrics. |
| Quality Indicator Program, Star Ratings, care minutes and 24/7 RN requirements | Quarterly QI reporting, care-minute targets (sector average 215 minutes including 44 RN minutes per resident per day, facility targets vary by AN-ACC case mix), and reporting via the Quarterly Financial Report and Government Provider Management System. AI-assembled data must be auditable back to source. | Monitor-pattern use cases; rostering constraints; data lineage requirement. |
| AN-ACC funding model; Support at Home program (from 1 November 2025) | Classification and reassessment rules, respite and leave, means testing, RAD/DAP and Support at Home classifications, budgets and co-contributions. AI that influences claims must be demonstrably accurate; over-claiming exposes the provider to recovery and compliance action. | Tier 3 funding-integrity use cases; claim variance metrics. |
| Privacy Act 1988 and the Australian Privacy Principles; Notifiable Data Breaches scheme; 2024 amendments | Health information is sensitive information. The 2024 amendments introduce transparency obligations for automated decision-making in privacy policies (commencing December 2026) and a statutory tort for serious invasions of privacy. Sending resident data to an AI vendor is a disclosure that needs a lawful basis and vendor controls. | Privacy impact assessment per use case; vendor data terms; ADM disclosure register. |
| My Health Record, state health records legislation, retirement villages legislation | Additional obligations for clinical records and for ILU residents' contracts and personal information. | Data classification; ILU lease use cases. |
| Therapeutic Goods Administration: software as a medical device | Software that provides diagnosis, prognosis, monitoring or treatment recommendations for an individual may be a regulated medical device unless an exemption applies. Deterioration prediction and medication decision support can fall in scope. | Tier 4 gate: SaMD determination before pilot. |
| Commonwealth AI policy: Voluntary AI Safety Standard (10 guardrails), AI Ethics Principles, and health-sector guidance from the Australian Commission on Safety and Quality in Health Care | Not yet mandatory for providers, but they define what "reasonable steps" look like and will be the yardstick regulators and insurers apply. The guardrails (accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply chain, records, stakeholder engagement) map directly to the controls table below. | Controls design; board reporting. |
| ISO/IEC 42001 (AI management systems), ISO 27001, ACSC Essential Eight, NIST AI Risk Management Framework | Management-system standards that give structure to the AI register, risk process and security baseline. Certification is optional; using the structure is the practical path to defensible governance. | Governance operating model in section 12. |
| Fair Work Act, Aged Care Award, Nurses Award, enterprise agreements, WHS and workplace surveillance laws | Rostering and time-and-attendance AI must encode award rules; consultation is required for major change; monitoring of staff is regulated. | Rostering constraints; people section warnings. |
Wrong or missed risk flags, erroneous transcription into notes, drafted plans accepted unread, model drift as case mix changes. Controls: clinical safety case, local validation, sign-off, incident pathway integrated with existing clinical incident process.
Disclosure to vendors, data used to train third-party models, cross-resident leakage through retrieval, offshore processing, retention. Controls: PIA, Australian data residency, contractual no-training clauses, retrieval-time access control, minimisation.
Screening or attrition models disadvantaging groups; risk models under-calibrated for culturally and linguistically diverse residents or First Nations residents. Controls: fairness testing on local cohorts, human decision at Tier 3+, review of overrides.
Fabricated policy citations, wrong award interpretations, invented figures in board narratives. Controls: grounding on approved sources, citations required, evaluation harness with accuracy thresholds, sampling audits.
Staff stop checking; junior staff never learn the underlying judgement. Controls: sampling review, periodic "AI-off" checks, training that includes failure modes, adoption metrics that track override rates.
Residents with cognitive impairment, substitute decision-makers, staff subject to monitoring. Controls: plain-language notices, consent recorded, a route to question or contest an AI-informed decision.
Prompt injection via documents, data exfiltration through agents with tool access, over-privileged integrations, shadow AI on personal devices. Controls: least privilege for agents, allow-listed tools, input filtering, approved-tool policy, monitoring.
Lock-in, sudden model changes altering behaviour, vendor failure, unclear liability. Controls: exit provisions, version pinning and change notification, evaluation re-run on model change, insurance review.
Deploying a de facto medical device without determination; inability to reproduce what the AI said at the time of a decision. Controls: SaMD determination step, immutable logs of prompts, outputs and versions for the record's retention period.
The tier is assigned at intake by the Risk & Compliance Manager and confirmed by the AI Governance Committee. Assign the highest tier triggered by any criterion.
| Tier | Criteria (any one triggers) | Mandatory controls before pilot | Approval |
|---|---|---|---|
| Tier 1 Administrative | No health or sensitive personal information; no consequential decision about an individual; reversible actions; internal users only. | Approved tool and vendor; data classification confirmed; basic usage guidance; audit logging; baseline metric recorded. | Functional product owner + IT. |
| Tier 2 Operational | Personal or financial data involved; output has financial, employment-administrative or compliance consequence; human approves before effect. | All Tier 1 plus: privacy impact assessment (short form); role-based access enforced at retrieval; accuracy threshold agreed and tested on local sample; exception and override process; staff notice; vendor data terms (residency, no training, deletion). | Product owner + Risk & Compliance Manager; noted at AI Governance Committee. |
| Tier 3 Care-adjacent or people-affecting | Influences a decision about a resident, client or staff member (allocation, funding, screening, incident classification, wellbeing); or processes health information at scale; or involves monitoring of people. | All Tier 2 plus: full PIA; fairness and bias testing on local cohorts; documented human decision rationale including overrides; consultation with staff or residents and families as applicable; contestability route; monitoring plan with drift and false-positive metrics; incident pathway defined. | AI Governance Committee, with CCO input where care-adjacent and CPO where staff-affecting. |
| Tier 4 Clinical | Enters the clinical record, informs clinical assessment or treatment, predicts individual clinical risk, or observes residents (vision, sensors). | All Tier 3 plus: clinical safety case owned by the Clinical AI Safety Lead; TGA software-as-a-medical-device determination; validation study on local data with pre-agreed sensitivity and specificity or accuracy thresholds; clinician sign-off workflow; resident and substitute decision-maker consent process; shadow-mode period before any live use; clinical governance committee endorsement; immutable prompt and output logging for the record retention period. | Clinical Governance Committee and AI Governance Committee; CEO informed. |
Every use case names one primary metric and up to three secondary metrics from this library, each with a baseline measured before the pilot, a target, a measurement window and an owner. Prefer metrics the organisation already reports (QI Program, QFR, board KPIs) so that AI benefits are visible in existing governance rather than in a separate dashboard.
| Lens | Outcome metrics (lagging) | Process and adoption metrics (leading) |
|---|---|---|
| Care & experience | QI Program indicators (pressure injuries, restrictive practices, unplanned weight loss, falls and major injury, medication management, activities of daily living, incontinence care, hospitalisation, workforce, consumer experience, quality of life); unplanned hospital transfers per 1,000 bed-days; complaints per 100 residents; satisfaction and experience scores; care minutes delivered vs target. | Documentation minutes per shift; note completeness and timeliness; care plan review currency; time from risk flag to clinical review; family update frequency. |
| Workforce | Turnover and 12-month retention; vacancy rate; agency hours as % of total; overtime hours as %; unfilled shift rate; engagement score; WHS incidents per 100 FTE; absenteeism rate. | Time to fill a vacant shift; roster build hours; roster changes after publication; time to shortlist; training compliance %; AI adoption and override rates by role. |
| Financial | Revenue per bed-day vs case-mix expectation; AN-ACC reassessment uplift captured; claim variance and rejection rate; billing adjustments and credit memos; days sales outstanding; bad debt; cost per invoice; labour cost as % revenue; EBITDA per bed or client. | Touchless invoice %; month-end close days; reconciliation exceptions cleared per day; forecast accuracy; consumables stock-outs and waste. |
| Risk & compliance | Accreditation findings and non-compliance notices; SIRS reports lodged within timeframe %; audit findings open beyond due date; privacy incidents and notifiable breaches; control failures detected internally vs externally; policy currency %. | Days from regulatory change to mapped action; evidence items auto-collected %; AI register completeness; model monitoring alerts actioned within SLA; PIA and safety-case cycle time. |
| Capability | Data quality score by domain; share of processes with a system of record; reuse of platform components across use cases; time from idea to validated pilot; benefits realised vs business case. | Staff AI literacy completion; number of active data stewards; evaluation harness coverage; incidents attributable to AI per quarter. |
Gates are pass or fail on documented criteria. The tier sets which controls must be evidenced at G2 and how long shadow mode runs at G3. Nothing skips a gate; Tier 1 items simply pass quickly.
| Pattern | How to validate before trusting it | Typical acceptance evidence |
|---|---|---|
| Perceive | Word error rate and field-level extraction accuracy on a local sample; clinician review of transcribed notes; consent audit. | Accuracy above threshold on 200+ local samples; zero unconsented capture in audit. |
| Understand | Question set with known answers drawn from your own policies; citation correctness; access-control red-team (can a carer retrieve another facility's records?). | Answer accuracy and citation rate; zero access-control failures. |
| Forecast | Back-testing on historical data; calibration by subgroup; comparison with current practice (for example NUM judgement) in shadow mode. | Lift over baseline; calibration plots; subgroup parity within agreed bounds. |
| Optimise | Constraint tests (award, care minutes, skills) as automated test suite; side-by-side with human roster; staff acceptance. | Zero hard-constraint breaches; measurable improvement in objective; change rate after publication. |
| Generate | Blind review of drafts by domain experts against rubric; sampling of signed-off outputs for errors; over-reliance checks. | Rubric scores; edit distance trends; error rate in sampled records. |
| Automate | Dry runs with actions logged not executed; reconciliation of automated vs manual outcomes; failure injection. | Match rate to manual; correct handling of exceptions; rollback proven. |
| Monitor | Precision and recall against known past events; alert volume and actionability review with operators. | False-positive rate acceptable to operators; known past events detected. |
The scorecard turns the idea template into two comparable numbers. Value index is the weighted sum of the five lens scores. Ease index combines feasibility, effort and risk tier. Together they place the idea in a quadrant that suggests how to treat it. Adjust the lens weights to your organisation's priorities; the defaults match section 3.
| Idea | Lens scores C/W/F/R/K | Feasibility D/I/P/C | Effort | Tier | Value | Ease | Quadrant |
|---|---|---|---|---|---|---|---|
| Invoice capture and three-way match (FIN-001.3.1) | 1/3/4/3/4 | 4/4/4/4 | 2 | 1 | 54 | 67 | Quick win |
| Roster optimisation with care-minute and award constraints (ROS-001.2.2) | 3/5/4/4/3 | 3/3/4/3 | 3 | 2 | 76 | 39 | Strategic bet |
| Ambient clinical documentation (CLIN-001.2.2) | 4/5/2/3/3 | 3/2/3/3 | 3 | 4 | 70 | 22 | Strategic bet, needs foundations first |
| AN-ACC reassessment trigger monitoring (RAC-003.2.1) | 2/1/5/4/2 | 3/3/3/4 | 2 | 3 | 56 | 41 | Strategic bet, close to quick win |
| Helpdesk triage assistant (IT-004.1.1) | 0/1/1/1/3 | 4/4/4/4 | 1 | 1 | 18 | 80 | Fill-in |
Most catalogue items fail at G2 for the same reason: the data they need is either not captured, not trusted or not reachable. The foundations below are scored on the Capability lens and belong in Horizon 1 whether or not any specific use case is chosen.
| Data domain | System of record (typical) | Key entities | Steward (role in matrix) |
|---|---|---|---|
| Person (resident, client, family, decision-maker) | Clinical and care management system; CRM for enquiries | Identity, consent, preferences, representatives, funding status | Resident Services Manager; Clinical Lead |
| Care and clinical | Care management system; medication management; assessment tools | Assessments, care plans, progress notes, medications, incidents, observations | Clinical Lead per service line |
| Workforce | HRIS; rostering and time-and-attendance; learning management | Employees, competencies, registrations, availability, shifts, timesheets, training | HR Manager; Scheduling & Operations Officer |
| Financial | Finance or ERP; payroll; billing; government claims portals (GPMS, B2G integration) | GL, AP, AR, claims, fees, budgets, assets | Finance Manager |
| Facility and assets | Maintenance and asset management; building systems | Work orders, assets, compliance schedules, utilities | Facility Manager |
| Compliance and risk | Risk and compliance platform; policy library; audit tool | Obligations, controls, evidence, risks, audits, incidents, breaches | Risk & Compliance Manager |
A governed store that joins the six domains with stable identifiers and records lineage back to source. Required for any Forecast or Monitor use case and for auditable regulatory reporting.
APIs or FHIR-based exchange with the care system, My Health Record where applicable, GPMS and B2G reporting, payroll and finance. Vendor selection should weight open integration heavily.
Document AI and speech capture as shared services with consent and classification built in, rather than per-tool features.
A single retrieval index over policies, procedures, contracts and (for Tier 3+) records, enforcing role-based access at query time. This is what makes "ask the policy" and "summarise this resident" safe.
Workflow engine with approval gates, idempotent actions, audit logs and kill switches, used by every Automate pattern.
Inventory of every AI system with tier, owner, model version and metrics; automated evaluation suites re-run on every model or prompt change; drift and quality dashboards feeding the AI Governance Committee.
Score each domain on completeness, accuracy, timeliness and consistency (0 to 5). A use case whose primary domain scores below 3 should be paired with a data-quality remediation item and not proceed past G2 alone. This single rule prevents most failed AI pilots.
| Forum or role | Accountability | Cadence |
|---|---|---|
| Board (via Risk and Clinical Governance sub-committees) | AI risk appetite, lens weights, attestation under Standard 2, oversight of Tier 4. | Quarterly |
| AI Governance Committee (sub-committee of Technology Steering; CRO chair, CIO, CCO, CFO, CPO, COO) | Approve tiering, gates G2 and G5, AI register, vendor standards; review incidents and benefits. | Monthly |
| Clinical Governance Committee | Endorse Tier 4 safety cases and pilots; review AI-related clinical incidents. | Bi-weekly (existing) |
| Functional product owners | Benefits case, baseline, adoption and metrics for their area's use cases. | Monthly service line reviews (existing) |
| Clinical AI Safety Lead; Data & AI Platform Lead; Data stewards | Safety cases and validation; platform, evaluation and monitoring; domain data quality. | Continuous |
| Project Transformation Officer | Runs the portfolio through the gates; owns the idea intake and catalogue currency. | Weekly |
The Project Transformation Officer owns catalogue currency. The CRO owns the regulatory table and the tiering criteria. The model is reviewed annually alongside the strategic planning cycle (EXEC-001.1.1) and the process framework itself, and whenever the Commission, the Department or the Privacy Commissioner issues material guidance on AI.