Quaintitative

MindForge Toolkit

Guardrails and metrics

Guardrails and metrics is about building an AI use case with the controls that keep it safe and the measures that tell you whether it is working. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit, the Singapore industry's practices for the AIRG. MindForge is the practices; the AIRG is the expectations and standards. I wrote the AIRG, and this guide sets out the practice and the expectation it meets.

What the AIRG expects

Several AIRG expectations converge on how a system is built: that the firm justifies its choice of model rather than reaching for the most complex by default; that transparency and explainability are provided in proportion to risk; that harmful bias is found and mitigated; and that development is documented well enough to be reproduced. The AIRG sets the outcomes (selection and justification, transparency and explainability, fairness, and reproducibility); it does not hand you a list of guardrails. For how these controls work together, see the AIRG in practice.

What MindForge says to do

The Toolkit turns those expectations into concrete build practices.

Choose and justify the model

Select algorithms and features against the use case's objectives and risks, weighing fairness, explainability, performance, complexity, and computational cost together rather than optimising for accuracy alone. For higher-materiality use cases, favour models with inherent explainability or supplement them with tools and interpretable features, and assess fairness across relevant subgroups during selection so trade-offs are a like-for-like comparison. Builders justify and document the choice, especially when they reach for a more complex or less understood model.

Put guardrails in, proportionate to risk

Apply controls sized to the use case's materiality, drawing on established guardrail libraries rather than inventing from scratch. For generative and agentic systems, that includes measures against the specific failure modes, such as grounding outputs in sources and controlling what the system can do.

Define metrics you will act on

Set use-case-specific, risk-related metrics tailored to the business expectations and the risks. Traditional AI leans on accuracy, fairness, and stability measures; generative AI adds dimensions such as groundedness, toxicity, drift, and injection-resistance, because unstructured output is harder to quantify. Using consistent metrics across similar use cases makes portfolio-level risk comparable.

Build transparency and documentation in

Calibrate disclosures to how autonomous the system is and who it affects: a tool that only advises a human needs less external disclosure than one acting without a human in the loop. Where explanations go to customers, focus on the factors that drove the outcome, not the modelling technique. And document the build - data handling, training, selection rationale, evaluations - well enough that a competent reviewer could reproduce it.

In practice

What good looks like. A documented reason the model was chosen over a simpler alternative, guardrails sized to the risk, a small set of risk-related metrics the team actually acts on, transparency matched to the system's autonomy, and a build record complete enough to reproduce.

Evidence to hold:

  • A model-selection record with the fairness, explainability, performance and complexity trade-offs set out.
  • The guardrails applied and the metrics tracked, with the thresholds that trigger action.
  • The build documentation (data, training, configuration, evaluations) and the customer-facing disclosures used.

How banks do it

The MindForge Implementation Examples show firms building transparency into the tool itself: in-product disclaimers that AI is in use, guidance shown at the point of use, and mandatory source citations on generated output, each sized to how much the output matters.

My take

A number nobody acts on is decoration. Pick the ones you would actually move on.

Guardrails and metrics multiply fast, and most firms track far more than they use. A handful of metrics with a threshold and an owner beats a dashboard of fifty nobody reads. (From my book, AI Risk Management for Directors.)

Work with me

I train and advise financial institutions on building AI with guardrails and metrics that hold, as part of the wider AIRG programme. See the courses and workshops, read more on AI risk management, or get in touch.