← All posts

Compliance & Regulation

305 posts on compliance & regulation.

ISO 27001 Annex A Controls Applied to AI Systems: Where the 2022 Revision Already Covers AI and Where It Does Not

The 2022 revision of ISO 27001 collapsed the Annex A control set from 114 to 93 controls across four themes. Several controls apply cleanly to AI systems without any AI-specific supplement. Others surface gaps the auditor tests when AI is in scope. A walk through the controls that matter (5.15 access control, 8.10 information deletion, 8.15 logging, 8.16 monitoring, 8.24 cryptography, 8.28 secure coding) with the specific evidence a policy gateway produces.

iso-27001complianceai-governanceannex-aauditai-security
Read post →

HIPAA Business Associate Agreements for AI Vendors: The Clauses That Actually Matter When PHI Reaches an LLM

A signed BAA does not, on its own, make an AI deployment HIPAA-compliant. The BAA covers the vendor relationship; the deployer still owns the safeguards under 45 CFR 164.308, 164.312, and 164.316. This walks through the clauses that matter when PHI flows into an LLM, the training-on-PHI question every BAA now has to address, and the audit-trail requirements HIPAA imposes on the deployer regardless of what the vendor logs.

hipaacomplianceai-securityphibusiness-associate-agreementhealthcare
Read post →

AI Governance Platform: The Runtime Enforcement Layer a Documentation Tool Cannot Provide

Most tools sold as AI governance platforms manage policies, risk registers, and model documentation. None of that touches a live AI request. A governance platform that changes outcomes needs a runtime enforcement point, a policy decision point, and an independent audit system of record at the AI request boundary. This walks through those three functions and the evidence they produce for the EU AI Act.

ai-governanceai-complianceeu-ai-actpolicy-enforcementaudit
Read post →

AI Audit Trail Requirements by Regulation: What Each Regime Actually Asks For

The EU AI Act, Fannie Mae LL-2026-04, NIST, HIPAA, and DORA all require an audit trail for AI decisions, using different vocabulary for the same underlying record. This maps the AI audit trail requirements across those regimes, shows what a compliant record contains, and explains why application logs fail the independence test every one of them assumes.

auditcomplianceregulationeu-ai-actai-governanceforensic-audit
Read post →

AI Compliance Audit Checklist: The Evidence a Reviewer Will Actually Request

An AI compliance audit fails on the evidence you cannot produce, not the policy documents you can. This checklist walks through what a reviewer requests for a high-risk AI system: the inventory, the identity mapping, the per-decision records, the retention proof, and the vendor-AI coverage, with the EU AI Act and Fannie Mae as the reference deadlines.

ai-complianceauditcomplianceeu-ai-actai-governanceregulation
Read post →

AI Compliance Automation: Generating Evidence at the Enforcement Layer

Most AI compliance automation stops at workflow: reminders, questionnaires, and dashboards that track whether a policy was written. The evidence a regulator wants is generated somewhere else entirely. This explains why real AI compliance automation produces per-decision records at the point AI traffic is enforced, and what that changes about audit readiness.

ai-complianceai-governancecomplianceauditinline-enforcementregulation
Read post →

AI Compliance Monitoring: What to Watch and Where Monitoring Stops

AI compliance monitoring tells you a policy was violated. At machine speed, that notice arrives after the violation completed. This covers the signals worth monitoring for a high-risk AI system, why monitoring produces forensic value rather than prevention, and where the boundary between watching AI traffic and enforcing policy on it actually falls.

ai-complianceai-governancecomplianceauditinline-enforcementregulation
Read post →

AI Compliance Tools: The Five Categories and the Gap Each One Leaves

AI compliance tools fall into five categories: governance platforms, model governance, AI-aware data protection, audit and logging, and policy enforcement. Each covers part of the obligation and leaves a specific gap. This breaks down what each category does, where it stops, and why the evidence a regulator requests is generated at the enforcement layer.

ai-complianceai-governancecomplianceauditpolicy-enforcementregulation
Read post →

AI Governance Best Practices: Six Controls That Survive an Audit

Most AI governance best-practice lists stop at committees and policy documents. A reviewer tests the controls underneath them. This covers six AI governance practices that produce evidence rather than intent: an inventory derived from traffic, identity on every request, inline policy, independent audit records, vendor-AI coverage, and annual regulatory re-verification.

ai-governanceai-compliancecomplianceauditregulationpolicy-enforcement
Read post →

AI Governance Committee Charter: What to Put in It and What It Needs to Function

An AI governance committee charter defines who decides what about AI risk. Most charters get the membership and mandate right and leave out the thing that determines whether the committee can function: the evidence it reviews. This covers the sections a working charter needs and why the committee''s authority depends on records generated at the AI enforcement layer.

ai-governanceai-compliancecomplianceregulationauditnist-ai-rmf
Read post →

AI Governance Implementation Roadmap: The Sequence That Reaches Runtime

Most AI governance roadmaps sequence policy authorship first and enforcement last, so the controls never reach production. This roadmap inverts the order: it phases the work as a set of runtime capabilities you turn on, starting with discovery and inline policy at the AI request layer, and shows where each phase produces the audit evidence a regulator or board will ask for.

ai-governancecomplianceimplementationroadmapai-security
Read post →

AI Governance Metrics and KPIs: What to Measure at the AI Request Layer

AI governance metrics fail when they measure documents instead of decisions. This piece defines the KPIs that come from the AI request layer, coverage, policy-decision latency, audit-log completeness, exception rates, and identity attribution, and shows why telemetry from the enforcement point is the only governance metric a board or auditor can verify.

ai-governancemetricskpiscomplianceai-security
Read post →