HDQ started in 2012, doing the unglamorous work: making the technology inside Australian businesses behave, and making the way those businesses ran legible enough that somebody other than the owner could follow it.
Every standard we've picked up since then came from a client's problem, not from a marketing plan. Here's the order it happened in, and why it matters now.
2014: quality, environment and safety
By 2014 clients needed something more formal than good intentions. A customer wanted evidence. A tender asked for certification. An incident made it obvious that "we've always done it that way" was not going to hold up. So we started implementing management systems: ISO 9001 for quality, ISO 14001 for environment, ISO 45001 for work health and safety.
That work teaches you a discipline that has almost nothing to do with paperwork. It's the ability to answer three questions in front of someone who doesn't trust you yet. What do you actually do? How do you know it happened? What did you change when it went wrong?
2016: laboratories, continuity and risk
Testing and calibration clients needed ISO 17025 accreditation, where the evidence bar is higher again: you have to show the result is right, not just that you followed a procedure. Others had been through an outage bad enough that they wanted ISO 22301 business continuity in place before the next one. ISO 31000 gave us a common language for risk across all of it, and while it's guidance rather than something you certify against, it's the piece that stops a risk register turning into a list of things nobody owns.
2020: information security
Then everyone's workforce went home at once, and information security stopped being an IT topic. ISO 27001 became the standard clients asked for by name, usually because a customer or an insurer had asked them first. We spent those years hardening Microsoft 365, cleaning up after break-ins, and explaining to owners what a single click had just cost them. Greg wrote a book about it.
2025: Ai
ISO 42001 is the management system standard for Ai, and we took it on for the same reason we took on the others. Clients had Ai in the building already, usually without knowing how much, and they could not answer the questions that matter: which tools are in use, who approved them, what data went in, who reviews the output, and what happens when one of them gets something badly wrong.
Australia still has no dedicated Ai law. That has never meant no obligations. Privacy, consumer protection, work health and safety, record-keeping and sector regulation all apply to what your Ai does today. Mandatory guardrails for high-risk uses are on the way, and South Australia has called a Royal Commission into Artificial Intelligence. We keep track of what genuinely changes in our latest updates.
The throughline
Ai governance is a management system with a harder subject than the ones before it. You scope it, name the risks in language your own people recognise, and decide who approves what. You put a human where a human is needed, keep the records, and review the lot when something moves. That is ISO 9001's logic and ISO 27001's logic, and it is ISO 42001's logic too.
Twelve years of doing that for quality, safety, laboratories, continuity, risk and information security is why we can do it for Ai without guessing at what an auditor will accept. It's also why we won't hand you a policy document and call it governance. A management system nobody runs is just a folder.
That's the discipline behind the three ways to work with us.