BlueLabs3

Policy manual

01 Document control

2026-09-25
Build v121
gate.consensor.io

Policies.

02 Manual

BL3 Policy Manual v1.0.

What governs this gate

Fourteen policies and procedures and an index, adopted by the Director on 21 September 2026 and reviewed at least once a year, after any serious incident, and whenever the law or standards change. Each states its purpose, scope, testable requirements and the records it produces, and maps to SOC 2 Trust Services Criteria and the Australian Voluntary AI Safety Standard guardrails.

This is a one-director company. The policies say so plainly and make the compensating controls explicit: written procedures, a receipt for every significant change, and independent anchoring of the decision record.

03 Index

Purpose and mapping of each.

The policies

  1. 01 Information security. How systems, keys and access are protected, and who holds them. SOC 2 CC6 · Guardrail 3.
  2. 02 AI governance and accountability. Who is accountable for the gate, the AI register, and how decisions are owned. SOC 2 CC1 · Guardrail 1.
  3. 03 AI risk management. How risks are identified, rated, treated and reviewed. SOC 2 CC3 · Guardrail 2.
  4. 04 Change management. How changes are proposed, tested, approved and released, with rollback. SOC 2 CC8 · Guardrails 3, 4.
  5. 05 Testing, monitoring and evaluation. What is tested before release and watched in operation. SOC 2 CC4, CC7 · Guardrail 4.
  6. 06 Incident response. Severities, containment, notification and review. SOC 2 CC7 · Guardrails 2, 9.
  7. 07 Human oversight and control. How a person can halt, override or decommission the gate. SOC 2 CC5 · Guardrail 5.
  8. 08 Transparency and end-user information. What users are told about AI use and its limits. Guardrails 6, 8.
  9. 09 Challenge, feedback and redress. How anyone affected can challenge a decision and get a remedy. Guardrail 7.
  10. 10 Stakeholder engagement and inclusion. How affected people and groups are consulted. Guardrail 10.
  11. 11 Records, evidence and audit trail. What is recorded, for how long, and how it is kept tamper-evident. SOC 2 CC2, CC4 · Guardrail 9.
  12. 12 Data governance, privacy and confidentiality. What data is processed, minimised and protected. SOC 2 C1, P1–P8 · Guardrails 3, 6.
  13. 13 Vendor and supply chain. How providers are chosen, reviewed and relied on. SOC 2 CC9 · Guardrail 8.
  14. 14 Business continuity and recovery. How service is restored after failure, and how that is tested. SOC 2 A1, CC9 · Guardrail 3.

04 Full text

On request.

Reading the full documents

The full text, the risk register and the assurance checklist are provided to named clients and assessors on request to zfa@consensor.io. They are not published because they describe internal controls in detail. A policy manual is written practice, not a certification: no SOC 2 report or ISO certificate is held.