What's in this pack?
The RACGP tells practice owners to "Develop a policy on using AI scribes in the practice" and publishes no template for one: its policy and procedure templates page (last updated 19 May 2025) lists no AI policy template. This pack is that policy, plus the documents it needs to work: an assessment record per scribe, a vendor questionnaire, an AI register with an update log, a monitoring file with a note audit and incident log, and an F11 evidence map. It is built to RACGP criterion F11, the RACGP's AI scribes fact sheet, Avant's AI scribe checklist, MDA National's AI governance guidance, the ACSQHC AI Clinical Use Guide, ACRRM and GPSA. About 35 pages across six documents, each starting on a new page so it can be printed alone; the registers and logs are landscape.
- Cover and how to use this pack. Practice details, the named AI scribe lead, a six-step how-to and the boundary table.
- Document 1, AI Scribe Policy. Permitted scribes, contractor and tenant GP and registrar rules, note review and sign-off, labelling, MBS suggestions, updates, errors and breaches, outages, training and roles, with a contractor declaration and a registrar checklist as appendices.
- Document 2, AI Scribe Assessment Record. One per scribe: our assessment guide's eight steps as a fill-in record, with a signed decision block.
- Document 3, AI Vendor Due-Diligence Questionnaire. Sent to the vendor: 13 sections with a clause-and-date column per answer, for any AI tool.
- Document 4, AI Register and Monitoring Log. The register (same columns as the AI Acceptable Use Policy's), an update log, and quarterly use counts including the clinician-only rate.
- Document 5, AI Monitoring File. An annual review record, a note accuracy audit sheet, and an AI incident and correction log with a "how detected" column.
- Document 6, F11 Evidence Map. Each F11 indicator against the document that evidences it, where it is filed and when updated.
Editable placeholder fields
Yellow-highlighted {{placeholder}} fields cover the practice details, the AI scribe lead, the permitted scribes, the contractor and registrar rules, the note review deadline, the MBS suggestion setting, the update check timeframe, the audit sample and frequency, and where the evidence is filed. The pack assumes the free AI Acceptable Use Policy and AI Scribe Patient Information and Consent Form are already in place, and repeats neither.
A governance pack, not a patient form or a general AI policy
The pack sits between the document that approves an AI tool and the documents that govern the practice generally. It replaces none of them.
| Document | The question it answers |
|---|---|
| AI Scribe Governance Pack (this pack) | How an approved AI scribe is run day to day, how a tool is assessed and questioned in writing, how its use is monitored, how errors are corrected, and where the F11 evidence is |
| AI Acceptable Use Policy (free) | Which AI tools may be used at all, on which plan and settings, what may never be entered into any AI tool, and the practice-wide rules: consent, withdrawal, labelling, identified data, training |
| AI Scribe Patient Information and Consent Form (free) | What patients are told, and how consent is asked for, recorded, declined and withdrawn |
| Privacy Policy | The public APP 1 document, including the AI scribe paragraph and, from 10 December 2026, any automated decision-making statements |
| Privacy Impact Assessment | Whether a tool's data flows are acceptable at all |
| Clinical Risk Management Policy (the clinical incident register) | Every significant clinical incident and near miss. AI incidents are logged in the pack first and copied here when they meet its threshold |
| Data Breach Response Plan | What happens when an AI incident is, or may be, an eligible data breach |
| Digital Health Technology Governance Policy | The lifecycle of any digital health technology, AI or not: assess, cost, implement, support, retire |
| Patient Access and Correction Procedure | A patient's request to access or correct a record, including an AI-drafted note |
A worked example. A contractor GP brings their own scribe subscription, and the vendor pushes a silent update that turns on "suggested investigations". The AI Acceptable Use Policy says only registered tools may be used. It does not say what the contractor must sign, who checks the update, or how anyone would notice the new lines in the notes. This pack is where those three answers live: Appendix 1.1, the update log, and the note audit sheet.
In short: approve the tool under the AI acceptable use policy, tell and ask patients with the consent form, then run, monitor and evidence it with this pack.
What the RACGP, the insurers and the regulators expect
The RACGP asks owners for a written AI scribe policy
The RACGP's AI scribes fact sheet (first published August 2024, last updated October 2025) says plainly: "If you are an owner responsible for running a general practice, you will need to: Develop a policy on using AI scribes in the practice". The policy "could include: details of which AI scribes are permitted" and "details on how to report privacy breaches, cybersecurity incidents or errors in recording caused by the AI scribe."
Most have not. A Healthed/HSD survey of 1,535 GPs, reported by Health Services Daily on 14 May 2026, found "Only 25.0% of respondents said their practice had an AI governance policy", while 18.7% said they personally use an AI scribe. MDA National, in AI governance in clinical practice (21 September 2026), says it is "important to have an officially documented and internally approved policy for the use of an AI". Its own AI governance template is for members only.
What F11 asks a practice to show
RACGP criterion F11 (published 26 August 2026) opens with F11.A: "Where the practice uses artificial intelligence, it does so safely and securely and consistent with existing standards." Its indicators require the practice to establish "governance processes for AI use, including accountability and compliance with legislation", to document "processes that support clinical oversight of AI outputs", and to ensure "identified patient data is not used by AI tools unless its use is clinically necessary, explicitly authorised, and supported by documented governance and consent processes". F11.B, "The practice assesses and evaluates its use of artificial intelligence", asks for a "process to assess and evaluate the use of AI, including risk mitigation, prior to implementation" and "processes for monitoring, review, and quality improvement".
| F11 indicator (short) | Document in the pack |
|---|---|
| Governance, accountability, legislative compliance | Document 1, AI Scribe Policy |
| Clinical oversight of AI outputs | Document 1 (review and sign-off) and Document 5 (note audit) |
| Identified data used only when necessary, authorised, governed | Document 2, Assessment Record, with the consent form |
| Assessment and risk mitigation before implementation | Document 2, with Document 3 answers |
| Monitoring, review and quality improvement | Document 4 (register and update log) and Document 5 |
On status: accreditation under the NGPA Scheme "currently uses the 5th edition of the Standards. Information about arrangements for the 6th edition of the Standards will be provided in due course" (ACSQHC, last updated 26 August 2026). F11 applies only to practices that use AI. What a surveyor will accept as F11 evidence is not yet known, because F11 is not yet assessed; the evidence map is our suggestion, not a guarantee.
Contractor GPs, tenant GPs and registrars
The RACGP fact sheet puts tenant GPs inside the owner's policy: owners "will need to create a policy and inform all tenant GPs and staff of this decision." F11 adds that "When AI tools are provided by third parties, practices remain responsible for their safe and appropriate use." The ACSQHC AI Clinical Use Guide (Version 1.0, August 2025) says "Only use AI tools that are authorised and/or supplied by your organisation", which "applies to clinicians that have both clinical and managerial responsibilities in sole-trader or smaller organisations." ACRRM's checklist (June 2025) agrees: "Only use tools approved by your organisation".
Registrars are a separate question. GPSA's AI scribes resource (dated 14 August 2025, reviewed 19 July 2026) states: "Recent RACGP guidance strongly discourages the use of AI scribes by GPT1 registrars." Its framework is "Ask, Assess, Advise", and supervisors "should regularly review and assess AI scribe-assisted registrar medical records over the course of the placement and give feedback." Appendix 1.2 is a supervision checklist on that framework.
Reviewing the note, and MBS item suggestions
The RACGP fact sheet says to "Remember to review all notes generated by your AI scribe as soon as possible after consultations" and to "verify any suggested item numbers and ensure the consultation meets any specific Medicare requirements." Avant's checklist (13 February 2026) says to review output "before including it in the medical record, sending it to a third party or using it for Medicare billing purposes." MDA National's Lost in transcription (current as at July 2026) puts it this way: "the notes are deemed to have been reviewed and approved by the clinician, regardless of whether the clinician has checked them or not." Ahpra (reviewed 22 August 2024) says "Practitioners must apply human judgment to any output of AI."
The billing risk sits with the practitioner. The Department's Medicare billing assurance toolkit says "Practitioners are responsible for all Medicare billing claims made under their Medicare provider number or name, even if the practice software was used to facilitate the process". The ANAO reported on 21 September 2026 that "approximately one-fifth" of listed software websites "refer to using AI, particularly AI scribes".
Vendor updates and scope creep
The TGA's digital scribes page (last updated 30 January 2026) says a scribe generating "a diagnosis, differential diagnosis or treatment recommendation not explicitly stated by the healthcare practitioner" is a medical device, and that health professionals should regularly assess whether "software updates have introduced new functionality that may change the intended purpose". MDA National's AI governance in clinical practice (21 September 2026) gives the case: a scribe "set to auto-update" introduced "new features, enabled by default, including 'suggested investigations'", and "MDA advises you to audit all your clinical notes, from the date of update up until the present". CG7 lists "unexpected changes in AI behaviour after updates to the software" among AI-related incidents, and F11's monitoring examples include reviewing "updates and changes to AI systems to confirm they are not introducing new risks or reducing effectiveness."
The clinical decision support software exemption is also amended from 1 November 2026 (F2026L01167): qualifying software must not be intended to make a clinical diagnosis or treatment decision, and must display the logic behind recommendations. See our post on the TGA clinical decision support changes from 1 November 2026.
Finding AI errors before a patient complains
CG7's guidance on "AI-related incidents" says the practice's "incident management process needs to include steps for identifying, documenting, and responding to AI-related issues. Identifying AI-related issues must not rely solely on feedback or complaints." Its examples: "incorrect or misleading outputs; system failures or outages; breaches of privacy or data handling protocols; clinician or patient concerns about safety or appropriateness; unexpected changes in AI behaviour after updates to the software."
That is why Document 5 exists in this form. The note accuracy audit sheet finds incorrect outputs before anyone outside the practice sees them. The incident log's "how detected" column is the evidence that identification does not rely solely on complaints. CG7 gives no audit method, sample size or frequency, so the pack leaves those as your choices (Audit sample size{{audit_sample_size}}, Audit frequency{{audit_frequency}}).
How to customise this pack
- Adopt the AI Acceptable Use Policy and the consent form first.
- Name the AI scribe lead (AI scribe lead{{ai_scribe_lead}}), per Avant's advice to "appoint a person in your practice to be responsible for monitoring use of the AI scribe and ensuring all updates have been actioned."
- Send Document 3 to each vendor and get answers back with clauses and dates.
- Complete Document 2 for each scribe from those answers, following our assessment guide.
- Enter each tool in Document 4, using the same columns as the AI Acceptable Use Policy's register so you keep one, not two.
- Choose the rules in Document 1: permitted scribes, contractor subscriptions, registrars, the review deadline, MBS suggestions and the update check. Collect Appendix 1.1 from every contractor or tenant GP who uses a scribe.
- Set the audit sample and frequency and run Document 5.
- Keep Document 6 current. Review annually, or whenever a vendor update adds a clinical feature.
Related templates and tools
- AI Acceptable Use Policy: approves tools and sets the rules this pack assumes.
- AI Scribe Patient Information and Consent Form: the patient-facing half.
- How to assess an AI scribe for privacy compliance: the eight steps Document 2 turns into a record.
- Digital Health Technology Governance Policy: the wider technology framework AI sits inside.
- Clinical Risk Management Policy: the clinical risk framework AI incidents feed into.
- Data Breach Response Plan: for AI incidents that are also data breaches.
- Privacy Impact Assessment: for privacy risk before a tool goes live.
- Privacy Policy: the practice's privacy commitments to patients.
- AI scribe (glossary): what counts as an AI scribe for scoping.
- Automated decision-making (glossary): the boundary between a scribe and a decision tool.
- TGA clinical decision support changes from 1 November 2026: the exemption and what it means for scribes.
- AI billing software and the ANAO audit: the ANAO's findings on AI in billing software.
Frequently asked questions
Does my practice need an AI scribe policy?
Yes, if any scribe is used or could be. The RACGP fact sheet says owners "will need to: Develop a policy on using AI scribes in the practice." Only 25.0% of respondents to a Healthed/HSD survey of 1,535 GPs said their practice had one, and the RACGP publishes no template.
How is this different from the free AI acceptable use policy?
The AI Acceptable Use Policy approves tools and sets rules for all AI use. This pack runs, assesses, monitors and evidences an approved scribe: assessment record, vendor questionnaire, register, monitoring file and F11 evidence map. Document 4's register shares the AUP's columns, so you keep one, not two.
Can contractor or tenant GPs use their own AI scribe?
Only if the practice's policy permits it. The RACGP says owners must "create a policy and inform all tenant GPs and staff of this decision", and F11 says "practices remain responsible for their safe and appropriate use." Appendix 1.1 is the declaration each signs. Who must notify a breach of data in a contractor's own scribe account depends on the contracts; ask a lawyer or MDO.
Can GP registrars use AI scribes?
That is the practice's rule to set (Registrar rule{{registrar_rule}}). GPSA states that "Recent RACGP guidance strongly discourages the use of AI scribes by GPT1 registrars", with supervision run on its "Ask, Assess, Advise" framework and registrar records reviewed over the placement. Appendix 1.2 is that checklist.
Who should be responsible for AI scribes in our practice?
One named person. Avant's checklist says to "appoint a person in your practice to be responsible for monitoring use of the AI scribe and ensuring all updates have been actioned", and F11 requires governance "including accountability and compliance with legislation." Often the privacy officer or digital governance lead: the pack names them AI scribe lead{{ai_scribe_lead}}.
Does every AI scribe note have to be checked?
Yes. The RACGP says to "review all notes generated by your AI scribe as soon as possible after consultations." Avant says to review output "before including it in the medical record, sending it to a third party or using it for Medicare billing purposes." MDA National is plain that the notes "are deemed to have been reviewed and approved by the clinician, regardless of whether the clinician has checked them or not."
What should we do when the scribe vendor pushes an update?
Recheck the tool. The TGA says to regularly assess whether "software updates have introduced new functionality that may change the intended purpose", and MDA National advises auditing "all your clinical notes, from the date of update up until the present." Switch off any new clinical feature until you have confirmed the tool has not become a medical device, and log the update in Document 4.
Will this pack make us compliant with RACGP F11?
No one can say yet. F11 is not assessable until arrangements for the 6th edition are announced, and it applies only where the practice uses AI. Document 6 maps each indicator to the document that answers it, as our suggestion for what a surveyor will want to see.