Using AI in Higher Education: What TEQSA Compliance Assessors Want to See

📕
Free planner
Download the Darlo AI Governance Checklist

— a one-page list of the seven AI evidence elements with the standard each one serves, drawn from our TEQSA registration and governance work with private providers. Get the checklist

An evidence folder labelled with an assessment map and board minutes, representing AI TEQSA compliance evidence
Updated: 2026-09-20

The AI TEQSA compliance evidence an assessor wants to see is a set of seven documents: a generative AI action plan approved and monitored by the governing bodies with the minutes to prove it, an assessment map showing secured assessment points across each course, the policies that govern AI use by staff and students, a staff training record, student-facing guidance, academic integrity data that shows detection and response, and a register of where the provider itself uses AI in its operations. Nothing in that set is exotic, and a provider that holds all seven will find the AI conversation with TEQSA short.

This article describes each element, what it needs to contain and why assessors ask for it. It draws on fifteen years of TEQSA registration and compliance work, including the period since mid-2024 in which generative AI has been an explicit line of inquiry in nearly every assessment I have been involved with.

Where the AI TEQSA compliance expectations come from

There is no AI standard in the Threshold Standards. What there is instead is a sequence of TEQSA publications and one regulatory request that together tell providers what the regulator expects. The 2023 paper Assessment reform for the age of artificial intelligence set out two principles: that assessment should equip students for a society in which AI is pervasive, and that trustworthy judgments about learning require multiple, inclusive and contextualised approaches. Its propositions favoured assessing process, securing selected assessment points, and designing at program level rather than task by task.

In June 2024 TEQSA issued a request for information requiring every registered provider to lodge, by 3 July 2024, a credible institutional action plan, overseen by governance, to address the risk generative AI poses to award integrity. TEQSA said it would follow up plans that were insufficient or absent and would consider its regulatory tools where needed. The 2025 paper Enacting assessment reform in a time of artificial intelligence then moved from principle to practice. None of these documents is a Threshold Standard, but the standards they connect to, principally 1.4 on assessment, 5.2 on academic integrity and 6.3 on academic governance, are binding, and TEQSA reads the AI evidence as evidence against them.

Element 1: the action plan and the minutes behind it

The action plan lodged in 2024 is the anchor document, and assessors now read it against what has happened since. Two things matter. The first is that the plan is credible: specific to the provider, with named actions, owners and dates, rather than a generic statement of intent. The second is that it is governed. The request for information asked for a plan overseen by governance, and the evidence of oversight is the academic board minute that approved it, the subsequent minutes that received progress reports, and the corporate board minute that noted the risk.

In my experience the weakest plans are the ones that were lodged to meet the deadline and never returned to. A plan with no progress report against it two years later is evidence that governance did not oversee it, and that is a Standard 6.3 finding as much as an integrity one. I have written about the wider set of AI considerations in higher education elsewhere.

Element 2: the assessment map with secured points

This is the document assessors spend longest on. For each course, the map lists every assessment task, identifies which learning outcomes it serves, and marks the tasks that are secured, meaning that the provider can be confident the student's own work is being assessed: supervised examinations, vivas, in-class tasks, authenticated practicals, or staged work with observed process. The sector calls this a two-lane approach; TEQSA does not use that label, but the pattern it describes is what the 2023 and 2025 papers point to.

What assessors check is that every course learning outcome is demonstrated at least once at a secured point, that the secured points are distributed sensibly across the program rather than clustered in one unit, and that the map reflects what is actually delivered. A map that exists only for the application, with unit outlines that still describe unsupervised essays as the sole assessment, will be found out. I have described the design side in the TEQSA framework and toolkit for generative AI.

Element 3: the policies

Three policies or policy sections are needed. An academic integrity policy that defines unauthorised AI use as misconduct, sets out the investigation procedure and the penalties, and explains how allegations are decided on evidence rather than on a detection score. An assessment policy that permits, restricts or prohibits AI use at task level and requires that permission to be stated on each task. And a staff-facing policy on the use of AI in teaching, marking and feedback, including what may not be entered into an external tool.

Assessors read policies for operation, not existence. They look for the version history, the academic board approval date, and evidence that students were told. A policy that prohibits something the assessment map plainly permits is a consistency failure that assessors notice quickly.

Element 4: staff training

The action plan almost certainly promised staff training, and the training record is how the promise is evidenced. Assessors look for a dated log of who attended sessions on the integrity policy, on assessment redesign and on the provider's rules for AI use in marking, and for evidence that sessional staff were included. Standard 3.2 requires that staff receive the development needed for their roles, and in the AI context that requirement has a concrete content.

Element 5: student guidance

Standard 5.2 requires that students are informed about academic integrity. For AI, that means guidance that tells students what is permitted in each task, how to acknowledge AI assistance, what happens if they breach the rules, and where to get help. Assessors look for the guidance itself, the point at which students receive it, typically orientation and the learning management system, and evidence of use such as completion of an integrity module or a student survey response.

Element 6: integrity data

This is the element that separates a provider that manages AI risk from one that has written about it. Assessors ask for the number of academic misconduct allegations by period, the proportion involving AI, the outcomes, the time taken to resolve, and the report to the academic board that discussed the trend. A provider with no AI-related allegations at all in two years is not read as a provider with no problem; it is read as a provider that is not looking.

The data should connect back to the assessment map. If a unit generates repeated allegations, the map should show it being redesigned. That loop, from data to governance to design, is the operational evidence that the action plan is working, and it is what TEQSA's self-assurance model is built to reward.

Element 7: the operational-use register

The final element is the one most providers have not thought about. Providers use AI themselves: in admissions triage, in marketing, in student communications, in drafting policies and, increasingly, in drafting TEQSA applications. Assessors are alert to the last of these, because generic AI-drafted applications have become a recognisable pattern since the move from Confirmed Evidence Tables to self-assurance, and they draw more scrutiny rather than less.

A register of where the provider uses AI operationally, what data is entered, who is accountable and how outputs are checked serves two purposes. It satisfies Standard 7.3 on information management and privacy where student data is involved, and it shows the governing body knows what the institution is doing. I have set out a practical version in a toolkit on generative AI for TEQSA-regulated providers.

Assembling the AI TEQSA compliance file

Put the seven elements in one indexed file, owned by the academic board, reviewed annually, and referenced in the self-assurance report at renewal. In my experience the assembly takes a small provider a few months if the underlying work has been done and cannot be done at all if it has not. TEQSA does not endorse detection software as sufficient, and it does not accept a policy as proof of practice. What it accepts is a record that shows the provider deciding, acting, measuring and adjusting, which is the same thing it accepts everywhere else in the framework.

Free download

Download the Darlo AI Governance Checklist

— a one-page list of the seven AI evidence elements with the standard each one serves, drawn from our TEQSA registration and governance work with private providers. Get the checklist

Keep reading — free

Want the full article?

Enter your email for free access to the rest of this guide and our TEQSA resource library.

Frequently asked questions

Is there a TEQSA standard on artificial intelligence?

No. TEQSA's expectations come from its 2023 and 2025 assessment reform papers and its June 2024 request for information, read against binding Standards 1.4, 5.2 and 6.3. The papers are guidance, not Threshold Standards, but the standards they connect to are enforceable.

What did the 2024 request for information require?

Every registered provider had to lodge, by 3 July 2024, a credible institutional action plan overseen by governance to address the risk generative AI poses to award integrity. TEQSA said it would follow up insufficient or absent plans.

Does TEQSA accept AI detection software as evidence of integrity?

Not on its own. TEQSA has not endorsed detection tools as sufficient, and assessors look for secured assessment points, an investigation procedure based on evidence, and integrity data showing detection and response.

What is a secured assessment point?

A task where the provider can be confident it is assessing the student's own work, such as a supervised examination, a viva, an in-class task or an authenticated practical. TEQSA's guidance favours program-level design in which every learning outcome is demonstrated at least once at such a point.

BM
Dr Brendan MoloneyCEO, Darlo Higher Education

Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.

Not sure where to start? Talk to us.

A short conversation tells you where you stand and what it takes — no cost, no obligation.

Talk to us →