The Quantrim Guardrails Framework

Ten guardrails, built from Australia's own AI standard

Most AI governance content is written for enterprises with a risk committee and a compliance team. This is the version for a 10 to 500-person Australian business: ten plain-English guardrails, translated from Australia's Voluntary AI Safety Standard, the Privacy Act and ISO/IEC 42001, built into every engagement rather than bolted on afterwards.

An empty glass-walled boardroom with a long table, ready for a governance meeting
Why this exists

Trust isn't a document. It's a habit built into how you work.

Ask most businesses who is accountable when an AI system gets something wrong, and the honest answer is often "the AI team", or nobody. The Quantrim Guardrails Framework exists so that answer is always a name, a record and a process, not a shrug.

It is a direct, ten-for-ten translation of Australia's own Voluntary AI Safety Standard into language a business without a compliance department can actually use, cross-checked against ISO/IEC 42001 and the Privacy Act. Not a wheel borrowed from a firm ten times our size. Ours, built for the businesses we actually work with.

Grounded in

  • Australia's Voluntary AI Safety Standard (10 guardrails)
  • The Privacy Act 1988 and the Australian Privacy Principles
  • ISO/IEC 42001, the international AI management standard
  • The NIST AI Risk Management Framework, where useful
The framework

Ten guardrails, one owner each

Every engagement we run is checked against all ten. Weakness in any one is where trust breaks down, usually quietly, usually before anyone notices.

01

Named Ownership

A named person owns every AI system in the business. Not "the AI team." A name, with the authority to pause it.

Named Ownership →

02

Risk-Mapped

Every use case gets a risk pass, weighed against what happens if it gets something wrong, before it goes near a customer.

Risk-Mapped →

03

Data Governed

Data is sourced, stored and used inside the Privacy Act and the Australian Privacy Principles, not around them.

Data Governed →

04

Tested & Watched

Nothing goes live untested, and nothing stays unwatched once it does. Performance is monitored, not assumed.

Tested & Watched →

05

Human in Control

A person can always step in, pause it, or overrule it. Judgement calls escalate, they don't get automated away.

Human in Control →

06

Plainly Disclosed

If AI is involved in talking to you, deciding something about you, or generating what you're reading, you're told.

Plainly Disclosed →

07

Open to Challenge

If an AI-influenced decision affects you, there's a clear way to question it and get a human to look again.

Open to Challenge →

08

Open Supply Chain

We tell you what a system is actually built on. No black boxes passed off as proprietary magic.

Open Supply Chain →

09

On the Record

What was tested, who signed off, what changed. Kept in a record you could hand to an auditor, not assumed.

On the Record →

10

Built With People

The staff and customers a system affects get a say before it ships, not a training session after.

Built With People →

Where it lives

Not a fifth service. A layer through the four we already run

The ten guardrails don't sit off to one side. They run through the same four-stage engagement described on Services, most active where they matter most at each stage.

Accountability is set before you spend a dollar. Safety and fairness get built in, not bolted on. A human stays in the loop once it's live. And there's a record of all of it, the whole way through.

Where things actually stand

Australia's AI rules, in plain terms

No hype, no scaremongering. Here's what's actually in force, what's voluntary, and what changed recently.

Voluntary today

Australia's AI Safety Standard sets ten guardrails. It's voluntary, not law, but it's what regulators and customers will expect a serious business to point to.

No new AI law, for now

A proposal for mandatory guardrails on high-risk AI was shelved in December 2025's National AI Plan. Existing privacy, consumer and discrimination law is the enforcement backstop.

The Privacy Act still applies

Wherever personal data touches an AI system, the Australian Privacy Principles apply. The OAIC published specific AI guidance in October 2024.

Not sure where you stand

Four stages of AI governance maturity

Most businesses sit somewhere between stage one and two. That's normal. The point is knowing which, and having a plan to close the gap.

1

Aware

An AI use inventory exists. One named owner. A basic acceptable-use policy.

2

Risk-checked

Each use case has had a risk pass. Human review sits on anything consequential.

3

Governed

Documented policy, an incident process, an AI register, plain disclosure to customers.

4

Audit-ready

Full ISO 42001 alignment, pursued when a tender, customer or EU exposure requires it.

Not sure where you sit? The free AI audit scores your governance readiness as one of six pillars. If it flags a gap, we'll walk the ladder with you.

FAQ

Frequently asked questions

What is the Quantrim Guardrails Framework?

Ten guardrails that run through every AI engagement we deliver, built as a plain-English translation of Australia's Voluntary AI Safety Standard, the Privacy Act and the Australian Privacy Principles, and the international ISO/IEC 42001 standard. It is how we make sure the AI we build for you is accountable, tested, fair and evidenced, not just deployed.

Is this legally required in Australia?

No. Australia's AI Safety Standard is voluntary, and a proposal for mandatory guardrails on high-risk AI was shelved in the government's National AI Plan in December 2025. Existing privacy, consumer and discrimination law is still the enforcement backstop, and it applies to AI the same as anything else.

How is this different from the free AI audit?

The free audit scores your business across six pillars of AI readiness, and governance is one of them. The Guardrails Framework is the detail behind that pillar: the ten specific guardrails that get built into every engagement once you start working with us.

We're a small business. Do we really need formal AI governance?

Governance here does not mean a compliance department. It means ten habits, done consistently, with one named owner. A 15-person business can put all ten in place without hiring anyone new.

Can you help us get ISO 42001 certified?

We can run a readiness and gap assessment against the standard as part of fractional AI consulting. Formal certification itself requires an accredited third-party auditor, which we will help you prepare for, not perform ourselves.

What if we sell to customers in the EU?

The EU AI Act can apply based on where an AI system's output is used, not where your company is based, so it's worth a conversation if you have EU-facing customers or exports. Talk to us before you assume it does or doesn't apply.

Find out where your governance actually stands. The AI audit is free, and governance is one of the six things it scores.

Get the free audit