For the Board of Northbeam Pay Holdings Pty Ltd. Tabled by the Chief Executive, drawn from Statement 000142, which the company commissioned. Four questions arrive at board level about AI and rarely come back answered on evidence. This page answers them. The pages that follow carry the evidence.
It is adopting. Work is automated at a Systematic level, 58 on the 0–100 scale, and the tools deployed hold in production at a Systematic level, 71. Three deployments operate today: fraud detection, merchant onboarding KYC, and an internal product-analytics LLM.
Workflow automation rate 58 · Systematic · AI tool deployment 71 · SystematicOn governance, no. The largest divergence this Audit measured between what management believes and what the evidence shows sits on governance: the documented posture is over-read by 18 points. Two deployments reported as governed carry no formal governance in evidence. The gap is the start of the Accountable Person's reasonable-steps record, not an indictment; the cure is commissioned at page 5.
CEO visibility gap −18 · governance over-read · largest measured on this AuditWhat is spent is tracked. Outcome tracking reads Systematic, 63; the investment itself reads Early-stage, 42. The company measures its AI better than it funds it.
AI investment spend 42 · Early-stage · Outcome tracking 63 · SystematicIn governance, and it is priced. Two of the three deployments operate without formal governance, the documented posture is over-read by 18 points, and A$747K of annual productivity is carried while the gap stays open. Three Required Actions are commissioned with named owners, deadlines, and verification criteria: page 5 of this pack.
Governance and oversight 34 · Early-stage · CEO visibility gap −18 · recoverable basis: Statement, p16Every figure on this page renders verbatim from the issued Statement. Readings and bands are absolute measures under the kn0w methodology.
For the Board of Northbeam Pay Holdings Pty Ltd. Drawn from Statement 000142, issued 23 May 2026. The Statement governs; this pack carries what the board needs to discharge its oversight of AI accountability.
The company's documented governance posture is over-read by 18 points, the largest visibility gap on this Audit, concentrated on the two AI deployments operating without formal governance: the merchant onboarding KYC automation and the internal product-analytics LLM. The fraud detection regime is governed, and is the exception. Bringing the other two into governance is the Accountable Person's clearest reasonable-steps action under APRA FAR.
The gap is the starting point of the reasonable-steps record, not an indictment. This pack and the Statement's evidence ledger stand as the contemporaneous record that the gap was identified and the cure commissioned. Under FAR, that record is the Accountable Person's evidence of steps taken; whether it satisfies the obligation is a determination for counsel, APRA, or a court.
The reading (Systematic · 51) places the company on the 0–100 scale. The recoverable figure is a structural measurement of annual productivity carried while the governance gap stays open, not a forecast; its full basis is stated at Statement, page 16.
Six readings on a 0–100 scale, each against a fixed dimension construct, weighted to one composite.
| Code | Dimension | Reading | Band |
|---|---|---|---|
| D1 | Workflow automation rateThe share of real work moved from manual effort to AI-assisted or automated execution. Higher means more of the business runs on it. | 58 | Systematic |
| D2 | AI tool deploymentWhich AI tools are deployed and hold in production, rather than piloted and abandoned. | 71 | Systematic |
| D3 | AI literacy levelWhether the people using and buying AI can evaluate it independently of what vendors tell them. | 38 | Early-stage |
| D4 | Governance and oversightWhether AI use is documented, owned, reviewed and auditable, or merely happening. | 34 | Early-stage |
| D5 | AI investment spendWhether investment in AI is deliberate and directed, rather than incidental. | 42 | Early-stage |
| D6 | Outcome trackingWhether AI spend and deployment are tracked to measured business outcomes, or reported as activity. | 63 | Systematic |
| · | Composite | 51 | Systematic |
The composite is bifurcated: three readings sit in the Systematic band and carry it upward; three sit in the Early-stage band and pull it downward. The bifurcation is concentrated by deployment. The fraud detection regime carries the strong readings; the merchant onboarding KYC and internal product-analytics LLM deployments carry the weak ones. The company deploys at a Systematic level and governs at an Early-stage one.
Methodology. Readings are produced under the kn0w methodology from evidence collected across seven structured sessions during the engagement window; the same evidence, evaluated under the same methodology version, always produces the same readings. Full methodology, evidence ledger, and verification status: Statement, pages 18–21.
The company's readings routed to the regulatory instruments its footprint answers to, stamped on documented control evidence. None of these stamps is a legal compliance determination.
Evidenced documented control evidence materially present and operating · Amber evidence partial, non-systematic, or undocumented as a control · Red evidence absent or materially insufficient
| Obligation area | Instrument | Status |
|---|---|---|
| Accountable-person accountability and reasonable steps for AI-affected operations | FAR s21(1)(c), s21(1)(d) | Amber |
| Operational risk management · in-house AI systems | CPS 230 ¶23–32 | Evidenced / Red |
| Service provider management · vendor AI systems | CPS 230 ¶46–61 | Red |
| Efficient, honest and fair provision of financial services where AI supports decisions | s912A · ASIC REP 798 | Amber |
| Privacy governance of AI inputs | Privacy Act 1988, APP 1.2 | Amber |
| AI incident response and monitoring | CPS 230 ¶31–32 | Amber |
Statuses are the Issuer's reading of the documented posture against publicly stated obligations and supervisory expectations; they are not legal compliance determinations. Each Red stamp maps to a Required Action at page 5 of this pack. Stamp status, Red and Amber alike, is re-read at each Quarterly Review and re-issued at the Annual Statement: the cure path is part of the record. Per-deployment evidence positions: Statement, pages 14–15.
Exactly three required actions issue with every Statement. These are required actions, not recommendations. Function ownership is named; individual ownership is the company's to assign under its accountability framework.
Model card, monthly performance review, incident log, decision-rights matrix, and a contractual right-to-audit clause negotiated into the vendor agreement at the next renewal cycle. Resolves CPS 230 ¶46–61 Red.
Recoverable ~A$188,000 p.a. · attributable to the KYC deployment in OperationsThe KYC deployment carries the five governance artefacts operative on the fraud detection regime, plus the right-to-audit clause, and each has operated for one review cycle. CPS 230 ¶46–61 then re-stamps from Red at the next Quarterly Review.
Formal governance review; accountability ownership transfer from Growth & Revenue to the Head of Risk; model card; testing regime; incident log. Resolves CPS 230 ¶23–32 Red.
Recoverable ~A$309,000 p.a. · the largest single shareThe internal product-analytics LLM carries the same five governance artefacts under named ownership reporting to the Head of Risk, and each has operated for one review cycle. CPS 230 ¶23–32 then re-stamps from Red at the next Quarterly Review.
A structured capability programme covering vendor model evaluation, failure-mode identification, and adoption-stage decision-making independent of vendor representations. Actions 1 and 2 depend on this capability in operation.
Recoverable ~A$118,000 p.a. · across Compliance & Risk and FinanceCompliance & Risk and Finance demonstrate, on evidence, the capability to evaluate a vendor or general-purpose model against independent benchmarks and reach adoption decisions without reliance on vendor representations. The D3 reading re-reads at the next issuance.
Together the three actions are attributed ~A$615,000 of the recoverable A$747,000; the balance (~A$132,000, Customer Success) is in scope on its own governance reading and is closed by no single action: it lifts with the general governance programme. If any action is incomplete at its deadline, the Accountable Person notifies the Board at its next scheduled meeting, the delay is recorded in the evidence ledger, and the relevant obligation is re-stamped as unresolved at the next Quarterly Review. Each closure is recorded in the evidence ledger and forms part of the Accountable Person's reasonable-steps record. The next issuance is a fresh immutable record of whether the work was done, not a repeated opinion.
Four questions, keyed to this Statement's findings by fixed rule. None is answerable from assertion.
The questions render from a fixed bank, selected by rule from the issued findings: one keyed to the weakest dimension, two keyed to the obligations the Required Actions resolve, one keyed to the direction of the visibility gap. No question is authored for this pack. At each Quarterly Review the findings re-read and the questions re-select with them.
Trajectory. This is the company's first Statement; no prior period exists. Trajectory against these readings renders in this pack from the first Quarterly Review onward.