Policy is not proof. AURA defines the path to proof.

AI governance you can operate — and prove.

AURA 3.0 — AI Use, Risk and Assurance — is an Australian-developed operating model for the safe, governed, evidenced and auditable use of artificial intelligence. Six layers. One spine. Evidence from strategy to external assurance.

Explore the method Get the publications
What is AURA 3.0

An operating model, not another policy

Most organisations already have AI policies, ethical statements, risk frameworks and regulatory obligations. What they often lack is an integrated operating model: clear ownership, delivery controls, approval gates, runtime monitoring and ongoing assurance. AURA closes that gap.

Identify what AI is used

A common use-case identity follows every AI capability across portfolio, delivery, vendor, runtime and assurance systems — so nothing gets lost between disciplines.

Decide what risk it creates

Proportionate risk tiering means low-risk internal assistance doesn't carry the same control burden as autonomous systems that change records or affect rights.

Prove it stays controlled

Evidence is produced by the work itself, not reconstructed for audits — connected from governance requirement through to independent assurance.

Why it's different

Many patches. One coat.

Like the calamanco cat that gives our consultancy its name, AURA blends many distinct patches into one coherent whole. It does not compete with the disciplines you already run — GRC, PMO, Agile, DevSecOps, architecture, procurement, audit. It connects their AI-specific decisions, controls, evidence and handoffs into one operating path.

Underpin, connect and strengthen. Do not duplicate or replace.

Connection without displacement

Specialist methods stay intact and keep their authority. AURA defines where the AI-specific risk decision, control, evidence and assurance handoff must appear.

Start with work, not hype

The five-pass opportunity method begins with the work, the pain and the evidence burden — not with an AI demo hunting for somewhere to be deployed.

Lowest sufficient authority

The right design is the lowest level of AI authority that reliably delivers the outcome. Maximum autonomy is never the default destination.

See the six-layer architecture

Publications

Learn the method in depth

The complete AURA 3.0 publication family — from the full operating model guide with fourteen epics and seventy-nine stories, to focused e-books on the core method and its differentiation.

Full guide

AURA 3.0 AI Op Model Guide

The authoritative reference: six layers, the operating spine, core templates, companion operating models, epics and stories.

Get it on Payhip
E-book

Core Method and Practices

The repeatable nine-step operating method and the essential practices that make it real — condensed for fast application.

Get it on Payhip
E-book

Why AURA Is Differentiated

Connection, depth and proof: how AURA completes the operating system rather than competing with the disciplines around it.

Get it on Payhip
Work with us

Consulting built on AURA

Calamanco Consulting helps boards, executives and governance teams put AURA 3.0 to work — from first briefing to minimum viable governance and beyond.

View services Start a conversation