A generative AI compliance officer at a TEQSA-regulated provider needs six things in operation: a policy set, an assessment audit, a staff training record, published student guidance, an integrity case-handling procedure, and a board reporting line. Those six are the evidence that the action plan TEQSA asked every provider to lodge by 3 July 2024 has been carried out rather than filed.
This article is operational. It describes each of the six components and the record it should leave, so that an evidence file can be built from things that happened. It draws on fifteen years of TEQSA registration and renewal work.
What TEQSA has asked a generative AI compliance officer to show
In June 2024 TEQSA issued a request for information requiring every provider to lodge, by 3 July 2024, a credible institutional action plan overseen by governance to address the risk generative AI poses to award integrity. That request was made under the existing standards, principally Standard 1.4 on assessment and Standard 5.2 on academic integrity.
TEQSA's substantive guidance is in two publications: the 2023 Assessment reform for the age of artificial intelligence, which favours process, secured assessment points and program-level design, and the 2025 Enacting assessment reform in a time of artificial intelligence, which moves from principle to practice. Both are guidance, not Threshold Standards. Our overview of TEQSA's framework and toolkit for generative AI summarises them.
Component one: the policy set
The policy set is three documents, not one. An academic integrity policy that defines unauthorised use of generative AI as a breach in terms specific enough to apply. An assessment policy that requires each course to identify its secured assessment points and to state, unit by unit, what AI use is permitted. And a staff and student use policy covering data, privacy and disclosure. Each should be approved by the academic board, and the file should hold the approval minute.
What the file should not hold is a single omnibus AI policy adopted in mid-2024 and untouched since. TEQSA reads dates, and revision in response to the 2025 guidance or the provider's own case data is evidence of a system operating.
Component two: the assessment audit
The assessment audit is the document a generative AI compliance officer will be asked for first. It lists every unit and assessment task and records whether each is secured, meaning completed under conditions where AI assistance is controlled, or open. It then shows that each course has enough secured points to assure its learning outcomes.
In my experience this audit is where most providers discover the real gap: a course in which every task is a take-home essay has no secured points, whatever the policy says. The audit should be reviewed by the academic board annually. Our companion piece on using AI in higher education covers what assessors look for in it.
Component three: the staff training record
Standard 3.2 requires staff to be qualified and supported to teach. In the generative AI context that means a register showing which staff have completed which training on AI in assessment design, detection limitations and case handling, with dates. It must include sessional staff, who mark most assessments at most private providers and are the group most often left out. An assessor who samples the register will look for the sessional marker who has never been trained.
Component four: student guidance
Students must know what is permitted before they submit work. That means published guidance, in the unit outline or an equivalent that the student receives, stating for each assessment task whether and how generative AI may be used, how any use must be disclosed, and what the consequences of unauthorised use are. General guidance on a website does not satisfy this.
The file should hold the template unit outline with the AI statement, a sample of completed outlines showing it in use, and the orientation material that introduces the policy.
Component five: integrity case handling
The integrity case procedure is where the policy meets reality. It should describe how a suspected case is identified, who investigates, what evidence is gathered, how the student is heard, who decides, what outcomes are available and how appeals work. It should say explicitly that detection software output is not sufficient evidence on its own, because TEQSA does not endorse detection tools as sufficient.
The file should hold the procedure, the case register and a few anonymised case files showing the procedure being followed. An empty case register is not evidence that there are no cases; it is evidence that none are being found. Our article on achieving academic integrity compliance under TEQSA guidelines covers the wider integrity framework.
Component six: board reporting
The last component closes the loop. TEQSA's 2024 request asked for a plan overseen by governance, and the evidence of oversight is a reporting line from the compliance officer to the academic board and from the academic board to the corporate board. I recommend a twice-yearly report covering the audit, training completion, case outcomes and policy changes, with minutes recording discussion rather than receipt.
Assembled together, these six components are the evidence checklist: a policy set with approval minutes and revision history, an assessment audit with secured points per course, a training register including sessional staff, task-specific student guidance in unit outlines, a case procedure with register and sample files, and board reports with minutes showing oversight. A generative AI compliance officer who can produce all six from the file, with dates, has answered the question TEQSA is asking.
What I tell compliance officers
Do not build this for the regulator. Build it because the alternative is a set of awards whose integrity you cannot vouch for. The toolkit above is unglamorous, and that is its virtue: every component is a record of something that happened, and that is the only evidence TEQSA has ever accepted.
Download the Darlo AI Governance Checklist
— a one-page checklist of the six evidence components and the records each should leave, drawn from our TEQSA registration and governance work with private providers. Get the checklist
Want the full article?
Enter your email for free access to the rest of this guide and our TEQSA resource library.
Frequently asked questions
Does TEQSA require a specific generative AI policy?
No. It asked every provider in June 2024 for a credible institutional action plan overseen by governance, assessed under existing standards on assessment and academic integrity. The form of the policy set is the provider's choice; its operation is what is examined.
Is AI detection software enough to prove misconduct?
No. TEQSA does not endorse detection tools as sufficient evidence, and a case procedure should require corroborating evidence such as a viva, drafts or process records before a finding is made.
What is a secured assessment point?
An assessment task completed under conditions where the use of generative AI is controlled, such as a supervised examination, an oral assessment or a practical demonstration, so that the learning outcome it assesses can be assured at program level.
How often should the academic board see AI compliance reports?
At least twice a year in my experience, covering the assessment audit, training completion, integrity cases and policy changes, with minutes that record discussion and decisions rather than receipt.
Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.
