Black Shard

Insights20 September 2026

The Voluntary AI Safety Standard's 10 guardrails

The National AI Centre published the Voluntary AI Safety Standard on 5 September 2024. It sets 10 voluntary guardrails covering accountability, risk management, protection and data governance, testing and monitoring, human control, user disclosure, contestability, supply chain information, records and stakeholder engagement, and they apply to all organisations throughout the AI supply chain. Each guardrail maps onto a clause or an Annex A control in ISO/IEC 42001:2023. On 21 October 2025 the National AI Centre published Guidance for AI Adoption, which the department describes as updated and simplified guidance that evolves the standard into 6 essential practices.

Ten low guardrail posts recede into dark space, lit violet along the nearest post.

What the Voluntary AI Safety Standard's 10 guardrails require

The National AI Centre, within the Department of Industry, Science and Resources, published the Voluntary AI Safety Standard on 5 September 2024. It sets out 10 voluntary guardrails that apply to all organisations throughout the AI supply chain. The first version of the standard applies to both AI deployers and AI developers, and focuses its organisational and system level guidance on deployers, the majority of Australian businesses using AI. Being voluntary, the standard does not create new legal duties about AI systems or their use. Government tenders, customer security questionnaires and insurer due diligence packs name the guardrails anyway. The standard states that the first 9 guardrails were aligned closely with the mandatory guardrails then proposed for high-risk settings.

Guardrail 1 asks for an accountability process that is established, implemented and published, covering governance, internal capability and a strategy for regulatory compliance. It names an overall owner for AI use, an AI strategy, and a documented training needs analysis across the organisation. Guardrail 2 asks for a risk management process that sets an organisational risk tolerance, documents risk criteria, and runs a risk assessment for each AI system, including systems procured from third parties. Guardrail 3 asks for protection of AI systems and for data governance measures covering data quality and provenance. It names three Australian instruments directly: an organisation-wide process to apply the Australian Privacy Principles to all AI systems, application of the Essential Eight Maturity Model to each AI system with that application documented system by system, and consideration of data breach reporting duties for each AI system under the Notifiable Data Breach scheme.

Guardrail 4 covers testing before deployment and monitoring once deployed, run against acceptance criteria set from the risk and impact assessment. Guardrail 5 covers human control or intervention for meaningful human oversight across the life cycle. It asks that accountability for each AI system sits with a named person holding the authority to oversee, intervene and act. Guardrail 6 requires end users to be informed about AI-enabled decisions, interactions with AI and AI-generated content. Guardrail 7 requires a process for people impacted by an AI system to challenge its use or its outcomes. An accountable person oversees concerns, challenges and requests for remediation. Guardrail 8 covers the data, model and system information organisations pass to each other across the AI supply chain. Guardrail 9 requires records that let a third party assess compliance with the guardrails, including an organisation-wide AI inventory. Guardrail 10 requires stakeholder engagement with a focus on safety, diversity, inclusion and fairness, and it feeds the stakeholder impact assessment that guardrail 2 starts from. The standard directs organisations to start with guardrail 1, and states that complete adoption means adopting all 10.

How do the 10 guardrails map to ISO/IEC 42001?

ISO/IEC 42001:2023 is the certifiable AI management system standard, and the Voluntary AI Safety Standard states that its guardrails align with it. ISO/IEC 42001 uses the clause structure common to management system standards. Context sits in Clause 4, leadership in Clause 5, planning in Clause 6, support in Clause 7, operation in Clause 8, performance evaluation in Clause 9 and improvement in Clause 10. Annex A carries 38 controls in 9 groups numbered A.2 to A.10. Every guardrail lands on a clause or an Annex A control. The mapping is not one to one: several guardrails touch the same control group, and several Annex A controls sit outside the guardrails.

GuardrailWhat it requiresISO/IEC 42001 coverage
1. Accountability processA published accountability process covering governance, internal capability and a strategy for regulatory compliance, with an overall owner named for AI useClause 5 leadership, and Annex A.3, which sets AI roles and responsibilities (A.3.2) and a channel for reporting concerns (A.3.3)
2. Risk managementAn organisational risk tolerance, documented risk criteria, and a risk assessment for each AI system including systems procured from third partiesClause 6.1.2 AI risk assessment and Clause 6.1.3 AI risk treatment, with Clause 6.1.4 AI system impact assessment, and Annex A.5, which requires an impact assessment process (A.5.2) and documentation of those assessments (A.5.3)
3. Protection and data governanceData quality and provenance controls, plus the Australian Privacy Principles, the Essential Eight Maturity Model and breach reporting duties applied to each AI systemAnnex A.7, covering acquisition of data (A.7.3), quality of data for AI systems (A.7.4) and data provenance (A.7.5)
4. Testing and monitoringTesting against defined acceptance criteria before deployment, then monitoring for behaviour change or unintended consequences once deployedAnnex A.6, which requires AI system verification and validation (A.6.2.4) and AI system operation and monitoring (A.6.2.6)
5. Human controlHuman control or intervention for meaningful human oversight, with a named accountable person holding authority to oversee and interveneAnnex A.9, processes for responsible use of AI systems (A.9.2), with the accountable role set under Clause 5.3 and Annex A.3.2
6. Informing end usersEnd users informed about AI-enabled decisions, interactions with AI and AI-generated contentAnnex A.8.2, system documentation and information for users, which covers the system's purpose, its instructions for use and its known limitations
7. ContestabilityA process for people impacted by a system to challenge its use or outcomes, with an accountable owner and a review of the contests raisedAnnex A.8.3 external reporting, which requires a capability for interested parties to report adverse impacts of the AI system
8. Supply chain informationData, model and system information passed to other organisations in the AI supply chain so they can manage their own riskAnnex A.10, covering allocation of responsibilities (A.10.2), suppliers (A.10.3) and customers (A.10.4)
9. RecordsRecords a third party can assess against the guardrails, including an organisation-wide AI inventory and consistent system documentationClause 7.5 documented information, with Annex A.6.2.7 AI system technical documentation and Annex A.4.2 resource documentation
10. Stakeholder engagementStakeholder groups identified, needs documented, and engagement run with a focus on safety, diversity, inclusion and fairnessClause 4.2 needs and expectations of interested parties, and Annex A.5.4 and A.5.5 on impacts to individuals, groups and society

The 10 guardrails mapped to ISO/IEC 42001 clauses and Annex A controls

What the National AI Centre published on 21 October 2025

On 21 October 2025 the National AI Centre published Guidance for AI Adoption. The Department of Industry, Science and Resources describes it as updated and simplified guidance for industry that evolves the Voluntary AI Safety Standard. It sets 6 essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control.

The guidance comes in two versions. Foundations is written for organisations earlier in their AI use and in lower-risk settings. Implementation guidance is written for teams that build or customise AI systems, use AI in more complex ways, manage higher-risk use cases or need stronger controls and oversight. The National AI Centre published a crosswalk between the guardrails and the implementation practices, so evidence already produced against a guardrail can be located in the newer document.

The Voluntary AI Safety Standard remains published, carries a notice pointing to the newer guidance, and was last updated on 2 December 2025. Its control-level detail under each guardrail has no equivalent in the Foundations version. A questionnaire or tender schedule written before October 2025 names the guardrails. One written after it may name the practices instead, so confirm which document a request cites before answering it.

Where the guardrails and ISO 42001 diverge

The guardrails are a checklist. ISO/IEC 42001 requires a management system built around one. Clauses 4 to 10 require a documented AI policy and resourced roles. They also require an internal audit programme under Clause 9.2, management review under Clause 9.3, and a Statement of Applicability under Clause 6.1.3 that justifies including or excluding every Annex A control. Working through the 10 guardrails produces none of that scaffolding by itself. An organisation can hold evidence against every guardrail item and still run no internal audit cycle, hold no management review record, and keep no record of which controls it deliberately excluded.

Certification is the second divergence. Certification bodies accredited for ISO/IEC 42001 certify an organisation's AI management system against the standard. The Voluntary AI Safety Standard carries no certification scheme of its own. It states that the records kept under guardrail 9 may be required as input to conformity assessments mandated in future for high-risk settings. The documentation recorded now is the foundation for demonstrating compliance with future regulation. An ISO/IEC 42001 audit still runs against the management system requirements.

Scope is the third divergence. An ISO/IEC 42001 certificate covers the management system the certified organisation runs. Annex A.10.3 requires processes for managing suppliers, while guardrail 8 asks for specific artefacts from each supplier: capabilities and limitations, technical details of the system, and test results relevant to the deployer's use. It also asks for known risks and the mitigations applied, data management processes including known bias and provenance, and the privacy and security practices in place. Those artefacts are collected vendor by vendor.

What order should the guardrail work run in?

The standard directs organisations to start with guardrail 1 and to adopt all 10. The order after that follows the dependencies the guardrails set between themselves.

  • Register every AI system and use case in the business, name the accountable owner for each, and publish the accountability process guardrail 1 asks for.
  • Run the stakeholder engagement of guardrail 10 before the risk work, because guardrail 2 says to begin risk assessment from the harms identified in the stakeholder impact assessment.
  • Run the risk and impact assessment next. The same assessment feeds AI risk treatment under Clause 6.1.3 of ISO/IEC 42001, so scope it once and use it for both.
  • Fix the data governance and provenance gaps the assessment finds, and document how the Australian Privacy Principles and the Essential Eight Maturity Model have been applied to each AI system. This step is usually the slowest, because it touches vendor contracts and data pipelines outside a security team's control.
  • Put verification, monitoring and human oversight in place before testing anything for an audit, so the testing evidence and the oversight evidence carry the same dates.
  • Draft the user disclosure and the challenge process guardrails 6 and 7 ask for, then route a real request through the challenge process. Guardrail 7 requires an accountable person and a documented review of the contests raised, which only produces evidence once the process has been used.
  • Collect supply chain evidence from every AI vendor. It depends on each vendor's own documentation and stalls most often.
  • Fold the guardrail 9 records and the AI inventory into the documented information register Clause 7.5 of ISO/IEC 42001 requires, so the evidence is built once and read for both purposes.

How does guardrail evidence feed an ISO 42001 gap analysis?

Confirm which document a customer, tender or insurer cites before answering. The 10 guardrails and the 6 essential practices ask for the same underlying evidence in different groupings, and the crosswalk maps one onto the other.

An organisation holding current evidence against all 10 guardrails already has most of what an ISO/IEC 42001 gap analysis asks for. What is usually missing is the management system scaffolding: a documented AI policy, an internal audit programme and a Statement of Applicability. Black Shard runs AI governance and ISO/IEC 42001 readiness work, with the gap analysis and the remediation order led by a certified ISO/IEC 27001:2022 Lead Auditor.

Tell us what AI you need secured.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au