Ten guardrails.
One standard.

Rev 2

September 2026. A named owner, a record and a process for every AI system we build. Full text published.

Most AI governance is written for enterprises with a risk committee. This is the version for a 10 to 500-person Australian business: ten guardrails translated from Australia's Voluntary AI Safety Standard, the Privacy Act and ISO/IEC 42001, built into every engagement rather than bolted on afterwards.

An empty glass-walled boardroom with a long table, ready for a governance meeting
Ask who is accountable when an AI system gets something wrong. The answer should be a name, not a shrug.

Trust is a habit, not a document.

Two colleagues at a wall of sticky notes

Ask most businesses who is accountable when an AI system gets something wrong, and the honest answer is "the AI team", or nobody. The framework exists so that answer is always a name, a record and a process.

It is a direct, ten-for-ten translation of Australia's own Voluntary AI Safety Standard into language a business without a compliance department can use, cross-checked against ISO/IEC 42001 and the Privacy Act. Ours, built for the businesses we work with, and published in full.

Grounded in

  1. 01
    Australia's Voluntary AI Safety Standard, ten guardrails, September 2024.
  2. 02
    The Privacy Act 1988 and the Australian Privacy Principles, with the OAIC's AI guidance of October 2024.
  3. 03
    ISO/IEC 42001, the international AI management system standard.
  4. 04
    The NIST AI Risk Management Framework, where it is useful.

The ten, one owner each.

Every engagement we run is checked against all ten. Weakness in any one is where trust breaks down, usually quietly, usually before anyone notices. Each guardrail has its own page with the full text.

  1. 01
    Named ownershipA named person owns every AI system in the business, with the authority to pause it.
  2. 02
    Risk mappedEvery use case gets a risk pass, weighed against what happens if it gets something wrong, before it goes near a customer.
  3. 03
    Data governedData is sourced, stored and used inside the Privacy Act and the Australian Privacy Principles, not around them.
  4. 04
    Tested and watchedNothing goes live untested, and nothing stays unwatched once it does. Performance is monitored, not assumed.
  5. 05
    Human in controlA person can always step in, pause it, or overrule it. Judgement calls escalate; they do not get automated away.
  6. 06
    Plainly disclosedIf AI is involved in talking to you, deciding something about you, or generating what you are reading, you are told.
  7. 07
    Open to challengeIf an AI-influenced decision affects you, there is a clear way to question it and get a person to look again.
  8. 08
    Open supply chainWe tell you what a system is built on. No black boxes passed off as proprietary magic.
  9. 09
    On the recordWhat was tested, who signed off, what changed. Kept in a record you could hand to an auditor.
  10. 10
    Built with peopleThe staff and customers a system affects get a say before it ships, not a training session after.

A layer through all four stages.

The ten guardrails are not a fifth service. They run through the same four-stage engagement described on Services. Accountability is set before you spend a dollar, safety is built in, a person stays in the loop once it is live, and there is a record of all of it.

  1. 01

    Consult and enable

    Named ownership, risk mapped, data governed. Set in the audit and the roadmap, before anything is built.

  2. 02

    Design and construct

    Tested and watched, open supply chain. Written into the architecture and the test plan.

  3. 03

    Implement and sustain

    Human in control, plainly disclosed, open to challenge, on the record. Live in every deployment, every month.

  4. 04

    Educate and adopt

    Built with people. The staff who live with the tool shape it, and the policy they follow is written for them.

Australia's AI rules, in plain terms.

No hype, no scaremongering. What is in force, what is voluntary, and what changed recently.

Voluntary

The AI Safety Standard

Australia's Voluntary AI Safety Standard sets ten guardrails. It is voluntary, not law, but it is what regulators and customers will expect a serious business to point to.

No new law, for now

Mandatory guardrails shelved

A proposal for mandatory guardrails on high-risk AI was shelved in the National AI Plan of December 2025. Existing privacy, consumer and discrimination law is the enforcement backstop.

In force

The Privacy Act still applies

Wherever personal data touches an AI system, the Australian Privacy Principles apply. The OAIC published specific AI guidance in October 2024.

The crosswalk.

Each guardrail maps to the standard it was translated from, so a tender response or an auditor's question has an answer. Mappings are indicative; the standards' own text governs.

GuardrailVoluntary AI Safety StandardISO/IEC 42001NIST AI RMFPrivacy Act
01 Named ownershipGuardrail 1, accountabilityClause 5, leadership; A.3 rolesGovern 2
02 Risk mappedGuardrail 2, risk managementClause 6.1; A.5 impact assessmentMap 1, Map 5APP 1 privacy impact
03 Data governedGuardrail 3, data governanceA.7 data for AI systemsMap 2, Measure 2APPs 3, 6, 8, 11
04 Tested and watchedGuardrail 4, testing and monitoringA.6.2 lifecycle; Clause 9 evaluationMeasure 2, Manage 2
05 Human in controlGuardrail 5, human oversightA.9 responsible useGovern 1, Manage 2
06 Plainly disclosedGuardrail 6, transparency to usersA.8 information for interested partiesGovern 4APPs 1, 5 notification
07 Open to challengeGuardrail 7, contestabilityA.8.3 reporting concernsGovern 5APPs 12, 13 access and correction
08 Open supply chainGuardrail 8, supply chain transparencyA.10 third parties and suppliersGovern 6, Map 4APP 8 overseas disclosure
09 On the recordGuardrail 9, recordkeepingClause 7.5 documented information; A.6.2.8Govern 1.7, Measure 3
10 Built with peopleGuardrail 10, stakeholder engagementA.5.4 impact on individuals and groupsGovern 5, Map 1.6

Print this framework

Where do you sit? Ten questions.

Tick what is true today. The result places you on the four-stage ladder and names what is missing. Nothing is sent anywhere; it runs in your browser.

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07
  8. 08
  9. 09
  10. 10

Four stages of maturity.

Most businesses sit between stage one and two. That is normal. The point is knowing which, and having a plan to close the gap. The free audit tells you where you sit.

Stage 1

Aware

An AI use inventory exists. One named owner. A basic acceptable-use policy.

Stage 2

Risk-checked

Each use case has had a risk pass. Human review sits on anything consequential.

Stage 3

Governed

Documented policy, an incident process, an AI register, plain disclosure to customers.

Stage 4

Audit-ready

Full ISO 42001 alignment, pursued when a tender, customer or EU exposure requires it.

Questions.

What is the Quantrim Guardrails Framework?

Ten guardrails that run through every AI engagement we deliver, built as a plain-English translation of Australia's Voluntary AI Safety Standard, the Privacy Act and the Australian Privacy Principles, and the international ISO/IEC 42001 standard. It is how we make sure the AI we build for you is accountable, tested, fair and evidenced, not just deployed.

Is this legally required in Australia?

No. Australia's AI Safety Standard is voluntary, and a proposal for mandatory guardrails on high-risk AI was shelved in the government's National AI Plan in December 2025. Existing privacy, consumer and discrimination law is still the enforcement backstop, and it applies to AI the same as anything else.

How is this different from the free AI audit?

The free audit scores your business across six pillars of AI readiness, and governance is one of them. The Guardrails Framework is the detail behind that pillar: the ten specific guardrails that get built into every engagement once you start working with us.

We're a small business. Do we really need formal AI governance?

Governance here does not mean a compliance department. It means ten habits, done consistently, with one named owner. A 15-person business can put all ten in place without hiring anyone new.

Can you help us get ISO 42001 certified?

We can run a readiness and gap assessment against the standard as part of fractional AI consulting. Formal certification itself requires an accredited third-party auditor, which we will help you prepare for, not perform ourselves.

What if we sell to customers in the EU?

The EU AI Act can apply based on where an AI system's output is used, not where your company is based, so it's worth a conversation if you have EU-facing customers or exports. Talk to us before you assume it does or doesn't apply.