Future Government Institute SPRITE™ AI Deployment Check
v1.0 · June 2026
Trust / SPRITE pillar
20 minutes · One deployment · Six tests

Can you stand behind
this AI deployment?

Most AI initiatives don't fail in the lab — they fail at the moment of public exposure, when a deployment that worked technically turns out to be one the agency can't defend. The SPRITE Check asks the question that precedes scale: can you stand behind this deployment — to citizens, staff, ministers and oversight bodies?

01
Score one deployment — a chatbot, a decision-support tool, a pipeline. Not your whole organisation.
02
Get the right people in the room: business owner, technical lead, and someone who speaks for affected users.
03
Rate 19 questions across six tests — Security, Privacy, Resilience, Inclusion, Transparency, Ethics.
04
Get a scale / don't-scale verdict and a remediation log you can take away.
Green — confident yes, and we could show the evidence tomorrow.
Amber — partly, in progress, or true on paper but untested.
Red — no, or we don't know. If no one in the room can answer, that is the answer — score it red.
N/A — this risk genuinely doesn't apply to this deployment (e.g. no citizen-facing surface). Use sparingly — "we haven't done it" is a red, not an N/A. N/A questions are excluded from the verdict.

Rate the deployment

One honest rating per question. Be specific to this deployment, not your organisation in general.

0 / 19 rated
0 0 0 0
Unrated questions count as 🔴 red.
SPRITE VERDICT

The six tests

Reading your results

The deployment is only as trustworthy as its weakest test — the verdict is not an average. Security and Privacy reds are treated as absolute stops, and Ethics and Transparency reds as institutional risk, because a deployment that is insecure, invasive, unaccountable or unexplainable cannot be defended publicly regardless of how it scores elsewhere. This is a deliberate FGI stance, not a neutral calculation — your governance body may weigh Resilience or Inclusion harms more heavily for a given service, and should say so on the record.

Remediation log

Every amber or red leaves the room with an owner, a fix and a date — and the Check is re-run when the re-check date falls due. Fill this in, then print or save as PDF.

Go deeper

The Check is a rapid read on one deployment.

The full picture sits at organisation level — the complete 45-indicator FGX baseline, including the full Trust / SPRITE pillar (Q31–Q45) scored G0–G4, with a prioritised roadmap.

Appendix — Standards alignment

The six tests are designed to be defensible against the assurance frameworks an agency's risk, security and privacy teams already use.

SPRITE testInternationalAustralian Government
SecurityNIST AI RMF (Govern, Manage); ISO/IEC 42001PSPF; ISM and Essential Eight; IRAP assessment where applicable
PrivacyISO/IEC 42001; OECD privacy guidelinesPrivacy Act 1988 (APPs); OAIC privacy impact assessment guidance
ResilienceNIST AI RMF (Measure, Manage); ISO 22301ISM continuity controls; APS AI Plan safe-deployment guidance
InclusionNIST AI RMF (Map — fairness and context)WCAG 2.2 AA; Digital Service Standard inclusion criteria
TransparencyNIST AI RMF (Govern — transparency); algorithmic impact assessment practiceAI transparency statements under the Commonwealth policy for responsible AI in government
EthicsOECD AI Principles; ISO/IEC 42001 governance clausesAustralia's AI Ethics Principles; Commonwealth AI assurance framework

A full clause-level mapping (FGX45 ↔ ISO/IEC 42001 ↔ NIST AI RMF) is maintained under the FGX standards alignment programme.