← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI Audit Log Retention Under the EU AI Act: What Six Months Actually Means at the Storage Layer

Article 19 of the EU AI Act sets a minimum log retention floor of six months for high-risk AI systems, and existing sectoral rules extend it far beyond that. This piece walks through what the six-month floor means at the storage layer, how the retention interacts with GDPR, HIPAA, and financial-services record rules, and the inspection-layer architecture that produces logs suitable for both the retention window and the reconstruction test a regulator applies during an audit.

eu-ai-actai-audit-logscompliancelog-retentionai-governancearticle-19
Read post →

AI Agent Identity Governance: Setting Policy for Which Agents Exist and What They May Do

Agent identity governance is the policy layer that decides which AI agents may exist, what each is scoped to touch, and how an organization proves that oversight to an auditor. This walks through the lifecycle (provisioning, scoping, deprovisioning), the gap between policy on paper and enforcement at the request line, and how the discipline maps to the NIST three-pillar model, EU AI Act Article 12, and ISO/IEC 42001.

ai-governanceidentity-and-authorizationagentic-ainisteu-ai-actcomplianceaudit
Read post →

HITRUST AI Compliance Checklist: 9 Tests

A HITRUST AI compliance checklist for protected data flows: 9 tests covering assessment scope, model inventory, identity propagation, data classification, destination rules, response handling, audit evidence, vendor evidence, and recurring tests. Each test produces proof tied to actual AI request traffic, the kind an assessor can sample against real events rather than a written policy alone.

ai-compliancehipaaauditai-governancepolicy-enforcement
Read post →

UK ICO AI Compliance Checklist: 11 Tests

This UK ICO AI guidance compliance checklist converts the regulator's current AI chapters into eleven gradable tests for governance, transparency, lawfulness, fairness, accuracy, minimisation, security and rights. It records the guidance review warning and verifies operative duties against current UK data protection legislation.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

EU AI Act Article 99: Fines and Penalty Tiers

Article 99 of the EU AI Act sets three penalty tiers reaching 35M EUR or 7% of global turnover for prohibited practices, 15M EUR or 3% for high-risk non-compliance, and 7.5M EUR or 1% for supplying misleading information. Article 99 has applied since August 2, 2025; the Digital Omnibus deferred most of the Tier 2 obligations it backs to December 2027 and August 2028.

eu-ai-actai-governancecompliancepenaltiesenforcementregulation
Read post →

AI Audit Trail Requirements: EU AI Act, HIPAA, DORA

AI audit trail requirements for the EU AI Act, HIPAA, DORA, NIST, and mortgage decisions. See the decision-record fields, retention questions, and evidence boundary each regime brings to an AI audit and regulatory review.

auditcomplianceregulationeu-ai-actai-governanceforensic-audit
Read post →

AI Compliance Audit Checklist: The Evidence a Reviewer Will Actually Request

An AI compliance audit fails on the evidence you cannot produce, not the policy documents you can. This checklist walks through what a reviewer requests for a high-risk AI system: the inventory, the identity mapping, the per-decision records, the retention proof, and the vendor-AI coverage, with the EU AI Act and Fannie Mae as the reference deadlines.

ai-complianceauditcomplianceeu-ai-actai-governanceregulation
Read post →

NIST 800-53 AI Compliance Checklist: 12 Evidence Tests

Use this 12-item NIST 800-53 AI compliance checklist to prepare endpoint, identity, policy, and audit evidence an assessor can test. Every item maps to a control identifier and defines a concrete completion check for the next assessment.

nistcomplianceai-governanceauditai-security
Read post →

Swiss FADP Checklist: 11 AI Deployment Tests

A Swiss FADP checklist for live AI deployments: eleven tests for inventory, purpose, processor terms, records, foreign disclosure, transparency, automated decisions, DPIA, security, rights and incidents. Every test names its owner, evidence and completion condition.

complianceregulationai-complianceai-governanceauditai-security
Read post →

AI Governance Certification: ISO 42001, AIGP, plus NIST AI RMF

ISO/IEC 42001 certifies an organization’s AI management system. IAPP AIGP credentials people, and NIST AI RMF offers voluntary guidance. This guide separates the programs and explains the runtime evidence none of them automatically produces.

ai-governanceai-complianceiso-42001complianceauditregulation
Read post →