Business Strategy

The Board-Ready AI Business Case Template for

The Board-Ready AI Business Case Template for

Board-ready AI business case template for Australian businesses

Boards do not approve "we want to do AI". They approve specific bets.

Most internal AI business cases that land in front of an Australian board get rejected, and almost never because the idea is bad. They get rejected because the case is shaped wrong. It opens with capability ("we want to deploy an AI agent"), it pitches an unbounded ambition, the cost stack stops at year one, the risk register is three lines of hand-waving, and the kill criterion is missing entirely. A board reading that case has no idea what they are approving, what it costs if it fails, or when they are allowed to stop.

This is the companion piece to the seven prior articles in this series on AI agents in Australian businesses. We have already covered the technical and operational reasons a business should not run unsupervised DIY agent builds, what day-two production reality actually looks like, the staffing gap most internal teams underestimate, how to select a vendor without locking yourself in, the ACCC consumer-guarantees exposure you inherit the moment your agent speaks to a customer, the APRA and ASIC overlay for financial services, and the 50-point security checklist you should hold any deployment against.

This article gives you the shape of the document that turns all of that work into a board approval. It is the AU-specific business-case template for an Australian business, including the 24 to 36-month cost stack the Productivity Commission's 2024 report on the application of AI implies most cases are underestimating, the benefit baselines a CFO will actually accept, the risk register a director can defend, and the governance pathway that aligns with the AICD's 2024 AI Governance for Directors guidance and the DISR Voluntary AI Safety Standard.


Part 1: The five sections every AU AI business case needs

A board-grade AI case is a capital-allocation document carrying a regulatory overlay. It runs to five sections, in this order.

1. Strategic alignment: why this, why now, why us

What good looks like: one paragraph that ties the proposed AI bet to a specific strategic objective the board has already endorsed, a sentence on why the timing is now that is more concrete than "AI is the future", and a sentence on why the organisation has a structural reason it can execute this particular use case (data access, existing process maturity, customer relationship). Boards reject AI cases that read as "everyone else is doing it". The CSIRO and the National AI Centre's 2024 AI ecosystem report is useful baseline reading for sector context, but the alignment must be specific to your organisation.

2. The honest 24 to 36-month cost stack

What good looks like: the full economic cost of running the capability, carried well past the year-one licence fee. Boards have been burned often enough on AI pilots that morphed into multi-year cost commitments without a refreshed business case. We covered the operational stack in day-two production reality and the staffing component in the staffing-gap analysis. The cost stack section consolidates both into a single board-readable view, with explicit ranges and citations.

3. The benefit case

What good looks like: four to six benefit lines, each with a credible baseline measured today, a credible target, the source of the target evidence, and a named owner who will be held to the post-deployment number. Productivity gains alone rarely carry a case. Risk reduction and customer-experience proxies materially strengthen it.

4. The risk register

What good looks like: 10 to 12 named risks, each with likelihood, impact, control, control owner, and the cost of the control. The risks must include the ones the board is actually exposed to under Australian law: Australian Consumer Law misleading-conduct exposure, Privacy Act and Notifiable Data Breach liability, model deprecation, vendor concentration, and the staffing and capability gap.

5. Governance and review cadence

What good looks like: a clear answer to four questions a director will ask. Who decides? Who reviews? When do we scale, and when do we kill it? Reference to the DISR Voluntary AI Safety Standard and to ISO/IEC 42001:2023 is increasingly expected in AU board papers; the AICD's director guidance frames the duty of care.


Part 2: The 24 to 36-month cost stack

The single most common reason an AI case is approved at pilot and then rejected at scale is that the pilot case understated the run cost. The McKinsey Global Institute's 2024 State of AI and Gartner's 2024 AI cost guidance both note that organisations consistently underestimate the operating, observability, and governance cost lines once a model is in production. Here is the stack a board will accept for an AU deployment of one bounded agent use case (e.g. reconciliation, customer triage, or quoting).

24 to 36 month cost stack for a single AU agent deployment

Build / integration (one-off, professional services or internal build cost)$60,000 - $180,000
Model licences, tokens, compute (24 months)$24,000 - $120,000
Specialist staffing or managed service (24 months)$180,000 - $480,000
Observability, evals and monitoring stack (24 months)$18,000 - $60,000
Annual privacy impact assessment and security review (x2)$20,000 - $60,000
Insurance review for AI-amplified ACL / cyber exposure$5,000 - $15,000
Exit / contingency reserve (recommended 10-15% of total)$30,000 - $135,000
Indicative 24 to 36 month total range$337,000 - $1,050,000

Ranges are intentional. The lower bound assumes a single bounded use case and a tightly scoped vendor product. The upper bound assumes a custom-built agent with multiple integrations and internal staffing. The Productivity Commission report and the DISR National AI Capability Plan workforce data both indicate AU organisations consistently under-budget the specialist staffing line; the Tech Council of Australia's AI workforce reports put senior AI engineer salaries above $200,000 fully loaded.

Boards expect to see the corresponding offset against existing run-cost lines. That belongs in Part 3.


Part 3: The benefit case

A benefit case lands when every line has a baseline measured today and a target a CFO would accept. Avoid productivity-only cases. The OECD's 2024 AI in Business report finds that risk-reduction and quality benefits frequently exceed pure productivity gains over a 24-month horizon. Use this shape, replacing the metrics with your actual processes.

Benefit baselines and targets a CFO will accept

Metric
Today (baseline, evidence required)
Target (24 months, evidence required)
Improvement
Cycle time on the target process (e.g. quote turnaround)Measured median in current ops report30-50% reduction, time-stamped from the same systemSource: internal ops report, vendor case data
Error or rework rate on the same processAudit sample, last 90 daysDefined post-deployment audit at month 3 and month 12Source: internal audit, NIST AI RMF guidance
Headcount efficiency (FTE redeployed, not removed)Time-tracking baseline by taskHours redirected to higher-value work, named recipient rolesSource: workforce plan, board people committee
Customer experience proxy (NPS, complaint volume, FCR)Trailing 12 months, source namedConservative 5-10 point improvement on chosen proxySource: CX system, ACCC complaint trend data
Risk reduction (incidents avoided, control coverage)Incident register, last 24 monthsDefined control coverage measured against ISO 42001Source: risk register, AICD director guidance
Revenue-side benefit (conversion, retention, recovery)CRM and finance system trailing baselineDefined uplift target with clear attribution methodSource: CRM, finance system, model evals

A credible baseline is one a finance committee can re-derive from a source system. A credible target is one a department head will sign their name against. If either is missing, cut the line rather than soften it. Boards detect "directional" benefit lines and discount the entire case.

For a worked operational example of how risk-reduction and quality benefits accrue in practice, see our Carbonly compliance automation case study and our RootCauseAI investigation tool case study.


Part 4: The risk register

A board paper that ignores the AU regulatory perimeter will be sent back. The register below is the minimum shape for an agent deployment. Each line names a risk, the likelihood and impact, the control, the owner of the control, and the indicative annual cost of operating the control.

AI program risk register, AU deployment

Metric
Risk, likelihood, impact
Control, owner, annual control cost
Improvement
1. ACL ss18 / 29 misleading conduct exposure when the agent speaks to customersLikelihood: Medium. Impact: High (fines, ACCC action, brand)Output review, disclaimers, escalation paths. Owner: GM Customer. Cost: $30,000 - $60,000 p.a.Reference: ACCC Guidance + Moffatt v Air Canada precedent
2. Privacy Act breach or Notifiable Data Breach eventLikelihood: Medium. Impact: High (regulator, reputation)PIA, data minimisation, OAIC-aligned retention. Owner: Privacy Officer. Cost: $25,000 - $50,000 p.a.Reference: OAIC NDB scheme, Privacy Act 1988
3. Model deprecation by vendor (model retired, API end-of-life)Likelihood: High over 24 months. Impact: Medium-HighMulti-model fallback, frozen-version contracts. Owner: CTO. Cost: $15,000 - $40,000 p.a.Reference: OpenAI / Anthropic published deprecation calendars
4. Vendor concentration / lock-inLikelihood: High. Impact: High at exitData portability clauses, exit testing. Owner: Procurement. Cost: $10,000 - $25,000 p.a.Reference: AU vendor selection framework
5. Staffing capability gap (cannot hire or retain operators)Likelihood: High. Impact: HighManaged service or partner cover. Owner: COO. Cost: built into operating stackReference: DISR / Tech Council workforce data
6. Brand / reputation incident (Moffatt, DPD, Chevrolet style)Likelihood: Medium. Impact: HighOutput guardrails, human-in-the-loop on sensitive paths. Owner: CMO. Cost: $20,000 - $40,000 p.a.Reference: Moffatt v Air Canada, DPD chatbot, Chevrolet of Watsonville incidents
7. Inaccurate or hallucinated output on regulated contentLikelihood: Medium. Impact: High (sector-specific)Evals on regulated paths, retrieval grounding. Owner: Head of Compliance. Cost: $20,000 - $50,000 p.a.Reference: NIST AI RMF, ISO 42001
8. Cybersecurity / prompt injection / data exfiltrationLikelihood: Medium. Impact: HighSecurity checklist coverage, red-team cadence. Owner: CISO. Cost: $30,000 - $70,000 p.a.Reference: 50-point AI security checklist
9. Unclear accountability and director duty of careLikelihood: Medium. Impact: High at incidentDocumented decision rights, AICD-aligned register. Owner: Board. Cost: nominalReference: AICD AI governance guidance 2024
10. Regulatory shift (Voluntary Standard moving to mandatory)Likelihood: Medium over 24-36 months. Impact: MediumTrack DISR consultation, build to ISO 42001. Owner: GC. Cost: $10,000 - $20,000 p.a.Reference: DISR Voluntary AI Safety Standard, AU mandatory-guardrails consultation
11. Insurance gap on AI-amplified lossLikelihood: Medium. Impact: High at incidentBroker review, endorsement update. Owner: CFO. Cost: $5,000 - $15,000 p.a.Reference: insurer guidance on generative AI exposure
12. Sunk-cost continuation past the kill criterionLikelihood: Medium. Impact: Medium-HighPre-agreed quarterly scale-or-kill gate. Owner: Sponsor + Board. Cost: nominalReference: governance pathway, Part 5 below

The likelihoods and impacts here are baseline assumptions for a typical AU deployment. Each register should be re-rated against the specific use case. What earns the register its place is that every line has a named control owner sitting in the room when the board approves, which matters more than the precision of any individual score.


Part 5: Governance and the approval pathway

The pathway is what turns "approval of a single agent build" into a defensible program. It also gives the board the option to stop without losing face.

Governance and approval pathway for an AU AI program

1
Month 0
Pilot approval
Board approves bounded pilot with a defined scope, a fixed budget, named owners, a written kill criterion, and a first review date.
2
Month 1 - 3
Build and parallel run
Pilot runs alongside the existing process. Evals, observability and audit logging in place from day one. Privacy impact assessment and security review complete before any production traffic.
3
Month 3
Quarterly review #1
Sponsor reports against pre-agreed KPIs and risk register. Board decides: continue, adjust scope, or trigger the kill criterion. Decision recorded in the AI register.
4
Month 6
Quarterly review #2 + scale gate
If KPIs are met and risk register is green, scale-or-kill decision. ISO 42001-aligned controls reviewed. AICD board-readout cadence formalised.
5
Month 9 - 12
Annual program review
Full benefit verification against finance baseline, refreshed risk register, refreshed cost stack, refreshed insurance position, decision on next-tier expansion or wind-down.
6
Month 12+
Ongoing governance
AI program embedded into normal risk and audit cadence. DISR Voluntary AI Safety Standard mapping refreshed. ISO 42001 control attestation. Annual board briefing.

The pathway has three properties that boards reward. It is reversible (the kill criterion is real and someone will use it). It is observable (every gate produces a report against the original case, with the original numbers still in it). It is regulator-defensible (the artefacts produced at each gate are the artefacts a regulator or court would ask for).

For ongoing program operation, see our managed AI services and AI strategy practice pages.


Part 6: Is this AI bet board-ready?

Before submitting, run the case against the five questions every director will ask.

Is this AI bet board-ready?

Score the case against these five gates. If any answer is no, the case is not board-ready yet.
1. Is the use case bounded? (One named process, one named owner, one named system of record.)
→ If no: rescope before submission. Unbounded cases get rejected.
2. Is the baseline measurable today, from a source system the CFO can re-derive?
→ If no: measure for 4-6 weeks first. Cases without baselines cannot prove benefit.
3. Is the AU regulatory exposure (ACL, Privacy Act, sector regs) mapped to named controls and owners?
→ If no: add the risk register before submission. Director duty of care requires this.
4. Is the kill criterion explicit, with a date, a metric, and a named decision-maker?
→ If no: write it. Boards will not approve unbounded commitments.
5. Is the cost stack 24+ months, with the run cost and the staffing line called out separately?
→ If no: rebuild the stack. Year-one-only cases get rejected at the scale gate.

A case that passes all five gates is one a board can approve in a single sitting. A case that fails any one of them is one the board will defer pending more work, regardless of how strong the underlying idea is.


Part 7: The board readout, in CFO language

The executive summary slide is where most cases are won or lost. It should fit on one page and contain exactly this list, in this order, in this voice.

  1. The bet. One sentence naming the process, the agent's role in it, and the scope boundary. No capability language.
  2. The baseline. One line, from a named source system, dated, with the metric we are improving.
  3. The 24-month cost. Total, with the build line and the run line called out separately.
  4. The 24-month benefit. Total, with the productivity, risk-reduction and revenue lines called out separately.
  5. Net position at 24 months and payback month. Single number, with the worst-case sensitivity (e.g. "$420,000 net at 24 months; payback month 14; worst-case payback month 22").
  6. The top three risks and their controls. One line each, naming the control owner.
  7. The kill criterion. Single sentence. "If by month 6 we have not achieved [metric], the program is wound down with [residual cost]."
  8. The governance cadence. "Quarterly review against this paper, scale-or-kill gate at month 6."
  9. The approval requested. Single line: scope, capex, opex, start date, first review date.
  10. The sponsor and the named owners. Sponsor, control owners, and the executive accountable for the post-deployment benefit number.

That is the slide. Everything else is appendix. The discipline of compressing the case to those 10 lines is what turns a transformation pitch into a capital allocation a board will sign.

For deeper context on the operational and accountability shape this case sits on top of, the AI agent governance, data access and human override article in this series walks through the day-two accountability structure that should be referenced in the readout.


Where to go next

If you are preparing a board paper in the next quarter, the most useful hour you can spend is re-reading the prior seven series articles back-to-back: DIY agent risk, production reality, staffing gap, vendor selection, ACCC exposure, financial services compliance, and the 50-point security checklist. Each feeds a section of the case above.

For a confidential review of your specific board paper before submission, including the cost stack and risk register against AU regulatory expectations, book a 30-minute consultation. We work with AU executive teams who want their AI program approved on the first attempt and defensible at every review thereafter.


Related Reading:


Research synthesised from the Productivity Commission report on the application of AI (2024), the DISR Voluntary AI Safety Standard (2024), AICD AI Governance for Directors guidance (2024), the CSIRO and National AI Centre AI ecosystem reports, the OAIC Notifiable Data Breach scheme, ISO/IEC 42001:2023, NIST AI Risk Management Framework, the McKinsey Global Institute State of AI 2024, Gartner AI cost guidance (2024), and the Tech Council of Australia AI workforce reports.