← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI Vendor Due Diligence Checklist: 30 Questions Your SIG and CAIQ Miss

30 questions a standard SIG Lite or CAIQ never asks an AI vendor: where the model runs, who trained it, how the vendor logs a single AI decision for audit, what is behind the vendor in the AI supply chain, and where the EU AI Act obligations land. This checklist covers model provenance, identity and access, data flow, logging and audit, regulatory mapping, and the AI supply chain, the AI-specific surface a SaaS vendor review leaves untouched. It is designed to be added to an existing vendor-risk workflow without replacing it.

vendor-managementai-procurementcompliancedue-diligencesecurity-review
Read post →

GDPR AI DPIA: When Article 35 Requires an Assessment

A GDPR AI DPIA starts with the processing operation, not the presence of a model. This guide applies Article 35's likely-high-risk threshold, the nine WP248 rev.01 screening criteria, and EDPB Opinion 28/2024 to practical AI deployments. It also covers controller and processor roles, the minimum assessment record, Article 27 FRIA coordination, review triggers, and the limited but useful evidence available at an authenticated HTTP AI gateway.

gdprdpiaarticle-35privacyai-complianceedpb
Read post →

NIST GenAI Profile (NIST AI 600-1): Risks, Actions, and Evidence

NIST AI 600-1 is a voluntary Generative AI Profile with 12 risk categories and suggested actions under GOVERN, MAP, MEASURE, and MANAGE. This current guide explains confabulation, correct action IDs, the relationship with OMB M-25-21, and the evidence an organization can collect without pretending one runtime log satisfies the whole framework.

nist-ai-rmfgenai-profilenist-ai-600-1omb-m-25-21compliancefederal
Read post →

PCI DSS 4.0 AI Controls: Where an LLM Deployment Touches the Cardholder Data Environment

PCI DSS 4.0 does not name AI systems in its 12 requirements. It does describe the cardholder data environment and the controls that apply to systems that store, process, or transmit cardholder data. An LLM deployment that touches cardholder data joins the CDE. This piece walks through the PCI DSS 4.0 requirements that apply to LLM deployments, the cardholder-data flow patterns that pull the LLM into scope, and the audit evidence a QSA accepts for the AI-specific controls at the gateway boundary.

pci-dsscompliancecardholder-dataai-securityllm-dlpai-gateway
Read post →

SOC 2 AI Controls Mapping: Which Trust Services Criteria a Policy Gateway Actually Evidences

SOC 2 auditors are asking about AI systems this year. The Trust Services Criteria did not change, but the scope of the audit expanded to cover AI request handling, model access controls, and AI-produced data. This piece maps CC6, CC7, and PI trust services categories to the inspection-layer controls that produce SOC 2 evidence for AI systems on a per-decision basis.

soc2ai-compliancetrust-services-criteriaauditai-governance
Read post →

SOC 2 AI Controls: Which Trust Services Criteria a Policy Gateway Actually Evidences

SOC 2 does not have an AI-specific control category, but every AI deployment inside a Type II audit surfaces control gaps under the same five Trust Services Criteria. The auditor questions center on who accessed the model, what data flowed through it, whether policy enforcement is deterministic, and whether the audit trail is tamper-evident. Application-controlled logs fail the CC7 evidence bar. The fix is architectural.

soc-2complianceai-governanceauditai-securitytrust-services
Read post →

ISO 27001 Annex A Controls Applied to AI Systems: Where the 2022 Revision Already Covers AI and Where It Does Not

The 2022 revision of ISO 27001 collapsed the Annex A control set from 114 to 93 controls across four themes. Several controls apply cleanly to AI systems without any AI-specific supplement. Others surface gaps the auditor tests when AI is in scope. A walk through the controls that matter (5.15 access control, 8.10 information deletion, 8.15 logging, 8.16 monitoring, 8.24 cryptography, 8.28 secure coding) with the specific evidence a policy gateway produces.

iso-27001complianceai-governanceannex-aauditai-security
Read post →

AI Governance Platform: The Runtime Enforcement Layer a Documentation Tool Cannot Provide

Most tools sold as AI governance platforms manage policies, risk registers, and model documentation. None of that touches a live AI request. A governance platform that changes outcomes needs a runtime enforcement point, a policy decision point, and an independent audit system of record at the AI request boundary. This walks through those three functions and the evidence they produce for the EU AI Act.

ai-governanceai-complianceeu-ai-actpolicy-enforcementaudit
Read post →

AI Compliance Automation: Generating Evidence at the Enforcement Layer

Most AI compliance automation stops at workflow: reminders, questionnaires, and dashboards that track whether a policy was written. The evidence a regulator wants is generated somewhere else entirely. This explains why real AI compliance automation produces per-decision records at the point AI traffic is enforced, and what that changes about audit readiness.

ai-complianceai-governancecomplianceauditinline-enforcementregulation
Read post →

AI Compliance Monitoring: What to Watch and Where Monitoring Stops

AI compliance monitoring tells you a policy was violated. At machine speed, that notice arrives after the violation completed. This covers the signals worth monitoring for a high-risk AI system, why monitoring produces forensic value rather than prevention, and where the boundary between watching AI traffic and enforcing policy on it actually falls.

ai-complianceai-governancecomplianceauditinline-enforcementregulation
Read post →

AI Compliance Tools: The Five Categories and the Gap Each One Leaves

AI compliance tools fall into five categories: governance platforms, model governance, AI-aware data protection, audit and logging, and policy enforcement. Each covers part of the obligation and leaves a specific gap. This breaks down what each category does, where it stops, and why the evidence a regulator requests is generated at the enforcement layer.

ai-complianceai-governancecomplianceauditpolicy-enforcementregulation
Read post →