How-to guides
RACGP & AccreditationHalf a day to set up, then a quarterly monitoring check

How to Meet RACGP F11 (Artificial Intelligence): An Evidence Checklist per Indicator

A seven-step procedure for a general practice that uses AI, administrative AI included, to meet RACGP 6th edition criterion F11: inventory every tool, decide whether F11 applies, write the policy with an explicit authorisation for identified patient data, set up consent and the withdrawal pathway, train the team under F4, add an AI category to the CG7 incident process, and monitor use. Ends with what an assessor could ask to see for each of the nine indicators. F11 is not yet assessed: accreditation still runs on the 5th edition.

F11 is the RACGP 6th edition criteria set on artificial intelligence: two criteria, F11.A and F11.B, with nine requirement lines under them. The 6th edition dropped the 5th edition's numbered indicators, so "indicator" on this page is our word for those nine lines, and the labels A1 to A7, B1 and B2 are ours. It applies only to practices that use AI, and administrative AI counts, so a booking assistant or an AI scribe brings you into scope. It is not yet assessed, because accreditation under the NGPA Scheme still runs on the 5th edition. Meeting it is seven steps, plus a file of evidence for each indicator. This guide is the procedure. What the 6th edition contains overall is in our RACGP 6th edition standards guide; the accreditation picture is on the RACGP accreditation pillar.

Before you begin

The Australian Commission on Safety and Quality in Health Care (ACSQHC) states the current position plainly: "Accreditation under the NGPA Scheme currently uses the 5th edition of the Standards. Information about arrangements for the 6th edition of the Standards will be provided in due course." That page was last updated 26 August 2026, and no transition date has been announced for when F11 becomes assessable. F11 is a required criterion, not an aspirational one, for any practice that uses AI. The 6th edition says "All criteria in the Standards need to be met to achieve accreditation, apart from Aspirational Criterion", and F11.A and F11.B are not marked aspirational.

Have open while you work: the F11 text, your incident register, your training records, your privacy policy and the terms for any AI tool already in use. The general self-assessment method is in our guide to how to run a RACGP self-assessment; this page covers F11 only.

Step 1: Inventory every AI tool, including administrative AI

F11's scope is wider than AI scribes. The criterion's "Why this is important" text says AI tools in general practice "may include clinical decision-support systems, patient engagement platforms, diagnostic aids, administrative automation, and documentation tools, such as AI scribes." The RACGP's AI and the Standards hub article adds systems that may "generate draft clinical notes during consultations", "support triage or administrative processes" and "help identify care gaps or risk factors through data analysis."

So the register has to catch four categories, not one:

  • Dedicated AI tools. An AI scribe, an AI phone or booking assistant, a triage tool.
  • AI capabilities inside software already in use. If your practice software added an AI summarisation or drafting function, that is an entry.
  • Administrative AI. What F11 calls administrative automation.
  • General chatbots used by staff. A team member pasting letter drafts into a general-purpose chatbot is AI use touching patient data if the text is not deidentified.

Record each tool in one AI register: what it does, whether it is clinical or administrative, whether it touches identified patient data, and who approved it. Our AI acceptable use policy template includes this register as Appendix A, with columns for identified-data authorisation, the fallback pathway if a patient declines, a named owner and approval dates.

The evidence for this step is the register itself, dated.

Step 2: Decide whether F11 applies, and write the decision down

The RACGP is explicit about applicability: "The Standards do not require practices to adopt or use AI tools. The AI criteria are only applicable and mandatory for practices who use AI tools." That is from the RACGP's what practices need to know page.

If your register from Step 1 has any entry, F11 applies in full. There is no partial scope for "just admin" use; F11 names administrative automation as an example of AI use. One point is unsettled: indicator A1 speaks of consent when "aspects of care will be delivered using AI", and it is not stated whether that consent indicator reaches purely administrative AI such as a booking assistant. Build the consent pathway from Step 4 anyway, and note the open question in your policy.

If the practice decides not to use AI at all, the RACGP's AI scribes fact sheet still gives you work to do: "If, as a practice owner, you make the decision not to permit the use of AI scribes, or wish to limit use to a particular scribe, you will need to create a policy and inform all tenant GPs and staff of this decision. Consider how you will monitor compliance with this policy."

The evidence for this step is a signed and dated applicability statement: F11 applies, or it does not, with the register attached.

Step 3: Write the policy: authorisation, deidentification and oversight

The hardest phrase in F11 is in the third F11.A indicator: the practice "ensures that identified patient data is not used by AI tools unless its use is clinically necessary, explicitly authorised, and supported by documented governance and consent processes." The Standards do not define "clinically necessary" or "explicitly authorised", and the same words return in the withdrawal steps. Our reading, not the RACGP's: for each tool touching identified patient data, write down (1) why identified data is needed for the clinical purpose rather than deidentified data, (2) who authorised that use and on what date, and (3) which governance and consent documents support it. A tool on the register without that entry is not "explicitly authorised." Who must authorise, the practice principal, a governance lead or the patient, is not stated; say so in your policy and name your own answer.

The rest of the policy covers five areas:

Deidentification (A2). The practice "facilitates data deidentification/anonymisation when using AI tools that process patient data." The Standards give no method. Record, per tool, whether it can operate on deidentified or anonymised data and whether that setting is switched on. The RACGP hub article puts the expectation as "prioritise privacy and data protection, including de-identification where appropriate."

Governance and accountability (A5). The practice "establishes governance processes for AI use, including accountability and compliance with legislation." Name an AI lead. F11 says AI systems used in clinical care "need to operate within a framework that supports clinical supervision of, intervention in, and accountability for any AI output." Ask vendors: "Does the AI vendor confirm compliance with the Privacy Act and APPs?" F11 adds that "Legal advice may be useful", and that "contracts with vendors address data handling, consent, and accountability." Some AI tools "(for example, diagnostic aids, clinical decision support systems, transcription tools) may be classified as medical devices", and need vendor documentation on regulatory status; see the 1 November 2026 change for decision-support software in our post on TGA clinical decision support changes.

Clinical oversight (A6). The practice "documents processes that support clinical oversight of AI outputs." F11 requires "clinical autonomy for practitioners, including the ability to review and override AI outputs using clinical judgement." The RACGP fact sheet's concrete rule: "review all notes generated by your AI scribe as soon as possible after consultations."

Clinician accountability (A7). "Members of the clinical team" "are accountable for care decisions supported by AI tools." The hub article's line is that "clinical decision-making always remains with the practitioner" and "AI outputs are aids, not answers." ACRRM's fact sheet says: "You are responsible for what is in the patient record."

Questioning outputs. F11 asks for "a timely and accessible process for patients, consumers, and the practice team to question or challenge AI outputs" and "transparent processes for responding to AI-related issues." Write the route into the policy: who raises a concern, and what happens next.

F11 also asks practices to be "particularly mindful of the potential disproportionate impact of AI on vulnerable populations", to review "vendor documentation relating to bias mitigation" and to "involve consumer representatives and/or cultural advisors when selecting and evaluating AI tools", and to be "mindful of Indigenous data sovereignty", citing the Maiam Nayri Wingara principles.

Our AI scribe governance pack carries the policy, the register and the monitoring logs in one set of documents.

Indicator A1 requires that the practice "facilitates processes for members of the clinical team to obtain and document informed consent from patients when aspects of care will be delivered using AI." Patients must be told how the tools use their health information: "for example, what information is collected, where it is stored and who has access to it." F11 states plainly: "Patients have the right to withdraw consent for the use of AI tools in their care at any time." The practice must tell patients this and have "a clear and accessible mechanism for patients to opt out."

If a patient withdraws consent, F11 sets out four steps:

  1. "document the withdrawal in the patient's health record"
  2. "stop using AI tools in the patient's care unless clinically necessary and re-authorised"
  3. "provide alternative care pathways that do not rely on AI tools, where feasible"
  4. "communicate any limitations or implications of opting out in a transparent and respectful manner"

Our reading of what those steps need as evidence: a note template or code for "AI consent withdrawn"; a written alternative pathway per tool (for a scribe, the clinician types or dictates the note; for an AI phone line, a human answers); a script line for explaining any limitation; and a rule for who "re-authorises" AI use for that patient and how it is recorded.

The bodies publishing on consent do not agree; the practice's medical defence organisation decides what it needs:

Body and document (date)On consentOn withdrawal
RACGP 6th edition F11 (2026)"obtain and document informed consent from patients when aspects of care will be delivered using AI""document the withdrawal in the patient's health record" and stop "unless clinically necessary and re-authorised"
RACGP AI scribes fact sheet (last significant update October 2025)"Obtain patient consent to use an AI scribe at the beginning of each consultation" and "Ask your MDO if they require written consent"Not addressed
Ahpra and the National Boards (page reviewed 22 August 2024)"Make sure you obtain informed consent from your patient, and ideally note the patient's response in the health record."Not addressed
ACRRM fact sheet (June 2025)"Obtain explicit consent before using the AI scribe before each consultation" and "Avoid relying on implied consent"Not addressed
ACSQHC ambient scribe scenario (version 1.0, August 2025)consent may be documented "on registration forms (paper or electronic), as part of online booking terms and conditions, through privacy collection notices with opt out options or in the healthcare record""If consent is withdrawn, stop the recording and delete any data and outputs."

Note Ahpra's word is "ideally": Ahpra does not require that consent be recorded. Note also the ACSQHC's warning that "The recording of a conversation without consent may also be subject to national and/or jurisdictional device surveillance Acts"; the state detail is on our AI scribe patient consent form page, which includes the withdrawal block with the F11 actions and a consent log.

F11 points to PP4 for telling patients about external providers. PP4's guidance says "It is not acceptable for consent to be sought for the first time in the consulting room." Whether an AI vendor counts as a PP4.B third party is not stated. It is unsettled; ask your MDO.

Step 5: Train the team and record it (F4)

F4 carries the training obligation. If the practice uses AI tools, F4 says training needs to:

  • "include information about the safe and effective use of these systems"
  • "support the practice team to understand the purpose, limitations, and appropriate use of AI tools"
  • "reinforce the importance of clinical oversight and judgement when interacting with AI-generated outputs"

F4 also says "practices need to update their training regularly to reflect new capabilities, risks, and regulatory requirements." No interval is given, so set one and write it down. F4.B adds that the practice "provides ongoing training to address continued competency and adaptation to changes."

Indicator A4 requires that the practice "discusses the implementation and use of AI with members of the practice team to identify practical implications and training needs." That discussion is evidence in itself, if you minute it.

Minutes. Date, attendees, the practical implications raised and the training needs identified.

Training record. Per person: the date, the tool, and the three F4 points covered.

Refresh date. The interval you set, and the next due date.

Tenant and contractor GPs. A note of how they were informed; the RACGP fact sheet expects "all tenant GPs and staff" to be told.

One training topic worth naming is automation bias, which the ACSQHC's AI Clinical Use Guide defines as "the tendency to over-rely on AI tools by prioritising the output of the AI tool over clinician's own independent judgement."

Step 6: Add an AI category to the incident process (CG7)

CG7 says: "If the practice uses artificial intelligence (AI) tools, its incident management process needs to include steps for identifying, documenting, and responding to AI-related issues." And: "Identifying AI-related issues must not rely solely on feedback or complaints."

CG7 gives five examples of AI-related issues:

  • "incorrect or misleading outputs"
  • "system failures or outages"
  • "breaches of privacy or data handling protocols"
  • "clinician or patient concerns about safety or appropriateness"
  • "unexpected changes in AI behaviour after updates to the software"

What does "must not rely solely on feedback or complaints" mean in practice? Our reading: the practice needs at least one detection route it runs itself, recorded. Options include a periodic sample audit of AI-drafted notes, a check after every vendor update, a log of technical support requests, and clinicians flagging corrections they made. An incident log with a "how detected" column shows incidents the practice found itself, not just ones patients reported. The Standards give no method, sample size or frequency; choose one and record it.

CG7 also notes that "If AI tools are provided by third parties, the practice could coordinate with vendors to report issues and track corrective actions." CG7's own registers, CG7.A's "clinical risk register" and CG7.B's "clinical incident or event register", are the natural home for the AI category.

Step 7: Monitor, review and improve (F11.B)

F11.B has two indicators. B1: the practice "has a process to assess and evaluate the use of AI, including risk mitigation, prior to implementation." The assessment procedure itself is our guide on how to assess an AI scribe for privacy compliance. Our suggestion for a tool already in use: a retrospective assessment, dated when it is done.

B2: the practice "has processes for monitoring, review, and quality improvement to ensure AI tools deliver safe, high-quality care, with mitigation of any unintended consequences." F11 lists optional examples of what the practice "could" do: collect team feedback, monitor consumer complaints, track technical support requests, and review software updates for new risk. Two items are worth quoting exactly:

  • "audit outcomes from AI-generated recommendations (for example, checking for over-diagnosis or missed diagnosis when AI tools are used for interpretation or triage)"
  • "collect data on how often AI is used in clinical decision-making or administrative processes, and how often clinician-only approaches are used"

Clinician-only rate. Our suggestion: count consultations or tasks where the AI tool was used and where it was not, including patients who declined or withdrew, per quarter, drawn from the consent log or the software's usage report. The Standards give no target figure, so do not invent one.

Over and missed diagnosis audit. F11 frames this for tools "used for interpretation or triage." A practice whose only AI is a scribe has no AI recommendations to audit in that sense. Our suggestion for a scribe is a note accuracy audit: a sample of AI-drafted notes checked against what the clinician corrected.

F11 also asks for "mechanisms for monitoring and reviewing AI performance, safety, and appropriateness, including regular evaluation against clinical standards and the practice's needs." An annual review record, dated, with the results and any changes made, closes the loop.

What an assessor could ask to see, indicator by indicator

F11 is not yet assessed and no accrediting agency has published F11 evidence expectations, so this table is our suggested mapping, not the RACGP's. The indicator text is quoted exactly; the labels A1 to A7, B1 and B2 are ours, for this page only, as is the count of nine.

IndicatorWhat to have readyStep
A1: The practice "facilitates processes for members of the clinical team to obtain and document informed consent from patients when aspects of care will be delivered using AI"Consent process, consent form or script, sample records with consent noted, withdrawal note template, alternative pathwayStep 4
A2: The practice "facilitates data deidentification/anonymisation when using AI tools that process patient data"Per-tool record of whether deidentified operation is possible and the setting chosenStep 3
A3: The practice "ensures that identified patient data is not used by AI tools unless its use is clinically necessary, explicitly authorised, and supported by documented governance and consent processes"Register entry per tool: why identified data is needed, who authorised it and when, supporting documentsSteps 1 and 3
A4: The practice "discusses the implementation and use of AI with members of the practice team to identify practical implications and training needs"Minutes of the team discussion with training needs identifiedStep 5
A5: The practice "establishes governance processes for AI use, including accountability and compliance with legislation"The AI policy, named AI lead, vendor answers and contract termsStep 3
A6: The practice "documents processes that support clinical oversight of AI outputs."The written note review and override ruleStep 3
A7: "Members of the clinical team" "are accountable for care decisions supported by AI tools."Policy statement that the clinician is accountable, acknowledged by each clinicianStep 3
B1: The practice "has a process to assess and evaluate the use of AI, including risk mitigation, prior to implementation"Dated pre-implementation assessment per tool, retrospective for tools already in useStep 7
B2: The practice "has processes for monitoring, review, and quality improvement to ensure AI tools deliver safe, high-quality care, with mitigation of any unintended consequences."Incident log with "how detected", audit results, clinician-only counts, update review log, annual reviewSteps 6 and 7

Four mistakes show up often:

Leaving administrative AI off the register. F11 names administrative automation as AI use, so the booking assistant and patient engagement platforms belong on the register too.

Treating a patient complaint log as AI monitoring. CG7 says identifying AI-related issues "must not rely solely on feedback or complaints." Without a detection route the practice runs itself, the monitoring indicator has nothing behind it.

Writing "AI is authorised" without saying by whom and why. A3 asks for use that is "explicitly authorised, and supported by documented governance and consent processes." An authorisation with no name and no date behind it is not explicit.

Stopping the scribe on withdrawal but not recording it. The first F11 withdrawal step is to "document the withdrawal in the patient's health record." Stopping without the note leaves the practice unable to show it acted.

The next action is the register: build it this week, including AI capabilities already inside your software, because every later step hangs off it.

Three templates carry this procedure into daily use. The AI acceptable use policy holds the AI register from Step 1, the authorisation column A3 needs and the CG7 incident category. The AI scribe patient consent form covers the patient notice, the consent record and the withdrawal block from Step 4. For a practice running an AI scribe, the AI scribe governance pack adds the monitoring log with the clinician-only count, a note accuracy audit sheet, an incident log with a how-detected column, and an F11 evidence map.

Frequently asked questions

What does RACGP F11 require?

Two criteria: F11.A, "Where the practice uses artificial intelligence, it does so safely and securely and consistent with existing standards", and F11.B, "The practice assesses and evaluates its use of artificial intelligence." By our count that is nine indicators: seven under F11.A, two under F11.B. It applies only to practices using AI tools, administrative AI included.

Is F11 assessed at accreditation yet?

No. The ACSQHC page on the 6th edition, last updated 26 August 2026, says: "Accreditation under the NGPA Scheme currently uses the 5th edition of the Standards. Information about arrangements for the 6th edition of the Standards will be provided in due course." No transition date has been announced.

Does F11 apply if we only use AI for admin tasks?

Yes. F11 names "administrative automation" among the AI tools it covers, and its monitoring text refers to "how often AI is used in clinical decision-making or administrative processes." One point is unsettled: whether A1's consent indicator, which speaks of "aspects of care", reaches purely administrative AI. Build the consent pathway regardless.

What does "clinically necessary, explicitly authorised" mean in F11?

The Standards do not define either term. Our reading: for each tool, record why identified data is needed, who authorised that use and when, and which governance and consent documents support it. Who must authorise, the principal, a governance lead or the patient, is not stated; say so in your policy and name your answer.

What happens when a patient withdraws consent for AI?

F11 sets four steps: document the withdrawal in the patient's health record; stop using AI tools in the patient's care unless clinically necessary and re-authorised; provide alternative care pathways that do not rely on AI tools, where feasible; and communicate any limitations transparently and respectfully. The ACSQHC scenario adds: "If consent is withdrawn, stop the recording and delete any data and outputs."

What counts as AI incident monitoring under CG7?

CG7 requires steps for "identifying, documenting, and responding to AI-related issues", and says identifying them "must not rely solely on feedback or complaints." Our reading: at least one detection route the practice runs itself, recorded, with a "how detected" column in the incident log. The Standards give no method or frequency.

Do we need written consent for an AI scribe under F11?

No. F11 requires the practice to "obtain and document informed consent" but does not specify written consent. The RACGP fact sheet says "Ask your MDO if they require written consent." ACRRM says "Avoid relying on implied consent", and Ahpra says to note the patient's response "ideally". Your MDO decides.

Last reviewed

30-day free trial

Be the practice the assessor compliments.

Choose your frameworks and work through the checklist. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime