Trust Center / AI Governance

AI and Model Governance

TRAK uses AI to assist compliance work, never to make unaccountable decisions about a participant. This page sets out how that AI is governed, in line with the NDIS Quality and Safeguards framework and the Privacy and Other Legislation Amendment Act 2024 (Automated Decision Making provisions live 10 December 2026).

Training-data provenance

  • Customer data does not train any AI model. No NDIS participant information, provider operational data, or staff record is ever used as training data.
  • AI features run on third-party model APIs under zero-retention terms. Prompts are processed for the single request and are not retained to improve a model.

AI Sub-Processors

ProviderRoleData policy (no-train evidence)Region
AnthropicClaude LLM API (compliance auditor and support agent features, Phase 4+)Zero-retention Trust Tier. No NDIS participant PII is transmitted without explicit consent, and customer data does not train models.US control plane (AU-region model access via AWS Bedrock is the swap path)

The full register is on the sub-processors page.

Automated Decision Making disclosure and appeal

  • Any AI-assisted output that may affect a participant (for example compliance scoring or roster gating) carries an Automated Decision Making disclosure stating that AI contributed and how.
  • A human reviews and is accountable for the decision. There is an appeal path: a participant or provider can request human re-review of any AI-assisted outcome.
  • AI-assisted decisions are recorded in the immutable audit log alongside the disclosure.

Model guardrails

  • Inputs are sanitised before reaching a model: a fail-closed PII egress guard blocks NDIS participant identifiers from leaving Australia without explicit consent.
  • Outputs are schema-validated. The platform does not surface free-form regulatory advice without a cited primary source.
  • Per-user rate limits and per-workflow cost caps bound any single AI interaction.

Your controls and opt-out

  • A provider can opt out of optional AI-assisted features and continue to use TRAK; core compliance recording never depends on an AI sub-processor.
  • To opt out or to ask an AI-governance question, email security@ironbarktech.com.au.

AI Assurance Roadmap

ISO 42001 AIMS: first NDIS AI certification target (post ISO 27001). Status: planned. TRAK does not claim certifications it does not hold.