← Back to marketing site
BM
Bob Millward
Governance Lead

UC-001_M365_Copilot_AIAF_workpaper_v3.2_signed.pdf

EV-2026-0148 · Workpaper · linked to Microsoft 365 Copilot — staff rollout

← Back to vault
Artefact ID
EV-2026-0148
Type
Workpaper
Linked use case
Uploaded by
Bob Millward
Uploaded at
2026-05-20 14:22
Size
894 KB
SHA-256
a3f9…c2b1 (truncated for display)
Hash chain
Verified · chained to previous entry
Summary

Final signed NSW AIAF workpaper for the Council-wide M365 Copilot rollout (~280 licensed staff). Approved at AIRC on 2026-05-07 with two conditions, both closed before this version.

Chain of custody

Auto-generated from AIG Sentinel intake on 2026-04-18. Signed digitally via M365 Entra. Hash chained at upload; immutable thereafter.

Sections

Section 1 · Use case definition

Signed
James O'Connor (ICT)
2026-04-22

Council-wide deployment of Microsoft 365 Copilot for staff document drafting, email summarisation, and meeting transcription within Teams. Scope: 280 licensed staff across all departments. Out of scope: resident-facing systems.

Section 2 · Risk tier (confirmed)

Signed
Risk Manager
2026-04-30

Medium. Reasoning: Copilot processes internal-only data (no resident PII), AI outputs always reviewed by staff before use or external send, no automated decisions. Initial provisional High downgraded after architecture review confirmed tenant isolation.

Section 3 · Data — sources, sensitivity, retention

Signed
Records Officer
2026-05-08

Internal documents in M365 tenant, staff email, Teams meeting transcripts. No resident PII enters Copilot prompts. Retention: Copilot operates on existing M365 data with existing GA28 retention. No additional retention.

Section 4 · Privacy Impact Assessment

Signed
Privacy Officer
2026-05-10

PIA confirms no PPIPA or HRIPA collection beyond what M365 already collects. Staff training mandatory before Copilot enable. PIA artefact EV-2026-0136 referenced.

Section 5 · AIRC briefing note & decision

Signed
Bob Millward (Governance Lead)
2026-05-20

AIRC 2026-05-07 approved with two conditions: (1) mandatory training before per-user enable; (2) quarterly review of Microsoft compliance position re: Copilot data handling. Both conditions met for v3.2.