← All posts

Compliance & Regulation

402 posts on compliance & regulation.

FedRAMP AI Audit Evidence Has to Resolve Each Model Call

FedRAMP assessors need evidence that connects an AI event to its user, model endpoint, authorization boundary, policy, and outcome. Standard application telemetry rarely contains that full chain. A per-decision record on the AI request path gives federal teams evidence that maps cleanly to NIST SP 800-53 audit requirements.

ai-complianceauditnistai-securityinline-enforcement
Read post →

FedRAMP AI Controls Mapping for the LLM Request Path

FedRAMP AI controls mapping becomes concrete when NIST SP 800-53 families are attached to the LLM request path. AC governs who may call a model, AU governs the decision record, SC protects the connection, SI handles monitoring, and CM governs route and policy changes.

nistai-compliancepolicy-enforcementauditarchitecture
Read post →

HITRUST AI Audit Evidence Needs Identity at the Model Call

HITRUST AI audit evidence should connect each model request with the authenticated principal, protected data classification, approved destination, policy version, and enforcement result. That event-level chain gives healthcare and regulated teams testable proof beyond screenshots and application status logs.

ai-complianceaudithipaaai-securityidentity-and-authorization
Read post →

Illinois AI Video Interview Audit Evidence for Hiring Teams

Illinois hiring teams using AI analysis of applicant video interviews need evidence connecting notice, consent, approved sharing, deletion handling, and each model interaction. Request-level records can support technical reconstruction, while the application remains responsible for candidate notices and consent workflows.

ai-complianceregulationauditai-governanceidentity-and-authorization
Read post →

HITRUST AI Controls Mapping at the Request Boundary

HITRUST AI controls mapping should connect access control, information protection, logging, communications security, vendor management, and configuration practices to observable model requests. A narrow request-boundary map gives assessors clear mechanisms and evidence owners.

ai-compliancehipaaauditarchitectureidentity-and-authorization
Read post →

Illinois AI Video Interview Act Controls Mapping

Illinois Artificial Intelligence Video Interview Act creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

Illinois AI Video Interview Act Compliance Checklist

Illinois Artificial Intelligence Video Interview Act creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act Audit Evidence for Enterprise AI

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act AI Controls Mapping

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act AI Compliance Checklist

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 23894 AI Compliance Checklist

ISO/IEC 23894:2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 23894 AI Audit Evidence at the Request Boundary

ISO/IEC 23894:2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →