← All posts

Compliance & Regulation

305 posts on compliance & regulation.

NIST CSF 2.0 AI Compliance Checklist: 10 Outcomes to Evidence for AI Traffic

CSF 2.0 states outcomes rather than requirements, so a Profile that claims AI coverage is only as good as the evidence behind it. This is a sequenced checklist of 10 items covering the categories AI traffic actually touches, from GV.SC through RC.RP. Each item names the category it serves and a completion test somebody outside the security team could run, and the ordering follows dependency rather than the Function wheel.

nistcomplianceai-governanceauditzero-trust
Read post →

NIST CSF 2.0 AI Audit Evidence: The Artifacts an Assessor Reads Per Function

CSF 2.0 is written as outcomes rather than requirements, which makes an assessment a conversation about evidence rather than a checkbox exercise. When AI traffic sits in scope, the assessor asks who called which model, what the prompt carried, what rule governed the decision, and which record proves it. This walks the artifact each Function expects for AI traffic, and the property that decides whether an artifact counts.

nistauditcomplianceai-governanceforensic-audit
Read post →

NYC Local Law 144 AI Compliance Checklist: 11 Items With an Objective Completion Test

Local Law 144 has been enforced since 5 July 2023, and a December 2025 New York State Comptroller audit found the enforcement ineffective and re-read 32 posted bias audits DCWP had cleared, identifying at least 17 potential issues. This is an 11-item checklist covering scoping, the annual bias audit, the published summary, candidate notice, and the invocation record underneath all of them, each with a test somebody outside HR could run.

complianceregulationai-complianceai-governanceaudit
Read post →

NYC Local Law 144 AI Audit Evidence: What the Comptroller Found When It Re-Read 32 Bias Audits

In December 2025 the New York State Comptroller published an audit of how the Department of Consumer and Worker Protection enforces Local Law 144. DCWP had reviewed 32 published bias audits and found one non-compliance issue. The Comptroller re-read the same 32 and identified at least 17. That gap is a statement about evidence quality, and it changes what an employer should be able to produce about its own AEDT.

complianceregulationauditai-governanceai-compliance
Read post →

OWASP Agentic Top 10 AI Audit Evidence: The Artifacts That Prove a Control Ran

OWASP released the Top 10 for Agentic Applications on 9 December 2025, built with more than 100 contributors. A framework tells an assurance function what to look for and stops short of telling it what a passing answer looks like on paper. This walks the evidence an auditor or a customer security review can actually inspect for each risk category, separates the categories that produce inspectable artifacts from the ones that do not, and names where the record has to come from.

ai-securityagentic-aiauditcomplianceai-governancepolicy-enforcement
Read post →

NYC Local Law 144 AI Controls Mapping: Each Obligation Against the Control That Satisfies It

Local Law 144 imposes four obligations on an employer using an automated employment decision tool: an annual bias audit by an independent auditor, publication of the results summary, candidate notice at least ten business days before use, and the record-keeping underneath all three. This maps each obligation to the control that satisfies it, names the owner, and states plainly which of the four an identity-aware gateway on the request path touches and which it contributes nothing to.

complianceregulationai-governanceai-complianceauditpolicy-enforcement
Read post →

OWASP Agentic Top 10 AI Controls Mapping: Which Risks an Assurance Programme Can Actually Own

The OWASP Top 10 for Agentic Applications, published 9 December 2025 with more than 100 contributors, is a risk list rather than a control framework. An assurance function has to convert it into named controls with named owners before it can be used in an ISO 42001 statement of applicability or a customer security review. This maps each risk area to the control that addresses it, the function that owns that control, and the coverage verdict a reviewer should expect.

ai-securityagentic-aicomplianceai-governancearchitecturepolicy-enforcement
Read post →

OWASP Agentic Top 10 AI Compliance Checklist: 12 Items With an Objective Completion Test

The OWASP Top 10 for Agentic Applications landed on 9 December 2025 and most teams read it, agreed with it, and filed it. This is a twelve-item checklist that turns the framework into work with a completion test on each item, ordered by dependency rather than by risk rank, and split between the items a platform team can close and the four that belong to application engineering.

ai-securityagentic-aicomplianceai-governanceauditpolicy-enforcement
Read post →

PIPEDA AI Audit Evidence: What the OPC Asked OpenAI For and Will Ask You For

On 6 May 2026 the Privacy Commissioner of Canada published findings from a joint investigation with Quebec, British Columbia and Alberta into OpenAI, running the analysis against appropriate purposes, consent, openness, accuracy, access, retention and accountability. The findings read as a list of the artifacts a Canadian organisation deploying AI should be able to produce. This walks each one and separates what a record on the request path establishes from what it does not.

complianceregulationai-governanceai-complianceauditdata-privacy
Read post →

PIPEDA AI Compliance Checklist: 12 Items With an Objective Completion Test

The Privacy Commissioner of Canada published joint findings into OpenAI on 6 May 2026 and opened complaints against X Corp. and X.AI on 15 January 2026, both analysed against the ordinary PIPEDA principles. This is a twelve-item checklist for a Canadian organisation deploying AI, in dependency order, each with a test somebody outside the privacy team could run, and honest about the four items that stay with your governance and business teams.

complianceregulationai-complianceai-governancedata-privacyaudit
Read post →

Saudi PDPL AI Audit Evidence: What SDAIA Asks For After 48 Enforcement Decisions

The Saudi Data and Artificial Intelligence Authority moved from grace period to enforcement when the PDPL transition window closed on 14 September 2024, and its specialised committees have since issued 48 decisions against organisations found in violation. The common failures were legal basis, unauthorised disclosure, and absent technical safeguards. This walks the evidence an organisation running AI in the Kingdom should be able to produce against each.

complianceregulationai-governanceai-complianceauditdata-privacy
Read post →

PIPEDA AI Controls Mapping: The Ten Schedule 1 Principles Against AI Traffic

PIPEDA carries ten fair information principles in Schedule 1, written in 2000 and applied to AI deployments without amendment. Seven of the ten change shape when the processing is a prompt sent to a third-party model, and three do not move at all. This maps each principle to the control that satisfies it for AI traffic, names the owner, and gives an honest coverage verdict rather than ten green rows.

complianceregulationai-governanceai-compliancedata-privacypolicy-enforcement
Read post →