Most AI initiatives don't fail in the lab — they fail at the moment of public exposure, when a deployment that worked technically turns out to be one the agency can't defend. The SPRITE Check asks the question that precedes scale: can you stand behind this deployment — to citizens, staff, ministers and oversight bodies?
One honest rating per question. Be specific to this deployment, not your organisation in general.
The deployment is only as trustworthy as its weakest test — the verdict is not an average. Security and Privacy reds are treated as absolute stops, and Ethics and Transparency reds as institutional risk, because a deployment that is insecure, invasive, unaccountable or unexplainable cannot be defended publicly regardless of how it scores elsewhere. This is a deliberate FGI stance, not a neutral calculation — your governance body may weigh Resilience or Inclusion harms more heavily for a given service, and should say so on the record.
Every amber or red leaves the room with an owner, a fix and a date — and the Check is re-run when the re-check date falls due. Fill this in, then print or save as PDF.
The full picture sits at organisation level — the complete 45-indicator FGX baseline, including the full Trust / SPRITE pillar (Q31–Q45) scored G0–G4, with a prioritised roadmap.
The six tests are designed to be defensible against the assurance frameworks an agency's risk, security and privacy teams already use.
| SPRITE test | International | Australian Government |
|---|---|---|
| Security | NIST AI RMF (Govern, Manage); ISO/IEC 42001 | PSPF; ISM and Essential Eight; IRAP assessment where applicable |
| Privacy | ISO/IEC 42001; OECD privacy guidelines | Privacy Act 1988 (APPs); OAIC privacy impact assessment guidance |
| Resilience | NIST AI RMF (Measure, Manage); ISO 22301 | ISM continuity controls; APS AI Plan safe-deployment guidance |
| Inclusion | NIST AI RMF (Map — fairness and context) | WCAG 2.2 AA; Digital Service Standard inclusion criteria |
| Transparency | NIST AI RMF (Govern — transparency); algorithmic impact assessment practice | AI transparency statements under the Commonwealth policy for responsible AI in government |
| Ethics | OECD AI Principles; ISO/IEC 42001 governance clauses | Australia's AI Ethics Principles; Commonwealth AI assurance framework |
A full clause-level mapping (FGX45 ↔ ISO/IEC 42001 ↔ NIST AI RMF) is maintained under the FGX standards alignment programme.