← All posts

Compliance & Regulation

402 posts on compliance & regulation.

ISO/IEC 27701:2025 Audit Evidence for AI Processing

ISO/IEC 27701:2025 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 23894 AI Controls Mapping

ISO/IEC 23894:2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 27701 AI Compliance Checklist for the Request Boundary

ISO/IEC 27701:2025 turns privacy management into operational work for AI systems. This checklist covers inventory, identity, purpose, prompt classification, processor routes, retention, incident response, testing, and request-level evidence, with a clear boundary between privacy governance and HTTP AI enforcement.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 5338 AI Audit Evidence Across the System Life Cycle

ISO/IEC 5338:2023 defines AI system life cycle processes covering acquisition, organizational support, technical management, engineering, operation, maintenance, and disposal. This guide shows how to build an evidence chain across those processes, connect design decisions to production AI requests, and keep the distinction between process conformance and ISO/IEC 42001 management-system certification clear.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

Japan APPI AI Audit Evidence at the Request Boundary

Japan's APPI turns enterprise AI traffic into a privacy evidence problem when prompts, responses, or retrieved context contain personal information. Audit evidence must connect the stated purpose, caller, data category, model destination, transfer basis, policy decision, and retention action for each relevant request. This guide separates records the Act expressly requires from operational proof that supports a PPC inquiry.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

Japan APPI AI Compliance Checklist for Enterprise Model Traffic

This Japan APPI AI compliance checklist converts purpose limitation, special care-required information, security measures, entrusted-person supervision, foreign transfers, incident response, and individual rights into testable work at the LLM request boundary. Each item names the evidence an owner should retain and flags the applicability decisions that depend on the provider contract and processing route.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

Korea AI Basic Act AI Audit Evidence: What MSIT Asks a High-Impact Operator to Produce

South Korea''s AI Basic Act and its Enforcement Decree took effect on 22 January 2026, with a one-year grace period on administrative fines running to 22 January 2027. This walks the evidence artifacts an operator in the high-impact category has to hand over when the Ministry of Science and ICT inspects: the classification record, the meaningful-explanation record, the prior-notification record, the generative AI labelling record, and the human-supervision record. Each artifact is named alongside the point in the request path that produces it.

complianceai-governanceauditregulationai-security
Read post →

Korea AI Basic Act AI Compliance Checklist: Ten Actions Before the Grace Period Closes

South Korea''s AI Basic Act took effect on 22 January 2026 with a one-year grace period on administrative fines that closes on 22 January 2027. This is a working checklist of ten actions for an operator running AI traffic into or out of Korea, covering the high-impact determination, the domestic representative thresholds, prior notification, generative AI labelling, human supervision, and the evidence each action produces. Every item names the artifact an MSIT inspection reads rather than the policy it references.

complianceai-governanceauditregulationai-security
Read post →

MITRE ATLAS AI Audit Evidence: The Telemetry That Proves a Technique Fired

MITRE ATLAS reached 16 tactics, 84 techniques, 56 sub-techniques, 32 mitigations, and 42 case studies at version 5.1.0 in November 2025, with agent-focused techniques added in the February 2026 update. A technique is only useful in a review if you can show whether it fired. This walks the evidence artifacts that answer that question for the ATLAS tactics reachable over HTTP AI traffic, and names the tactics where no request-path telemetry helps.

ai-securityllm-securityauditforensic-auditai-governance
Read post →

MITRE ATLAS AI Compliance Checklist: Ten Actions Against the Techniques That Reach Your Traffic

MITRE ATLAS carries 16 tactics and 84 techniques as of version 5.1.0 in November 2025, with agent-focused additions landing in February 2026. Most of the matrix describes attacks on models you train. This checklist works the subset that reaches an enterprise consuming hosted models over HTTP, giving ten actions with the ATLAS tactic each one addresses and the evidence it produces, and marking the techniques that need build-pipeline work instead.

ai-securityllm-securityprompt-injectionauditai-governance
Read post →

NIST SP 800-171 AI Compliance Checklist: Ten Actions Before CUI Reaches a Model API

NIST SP 800-171 Revision 3 carries 97 requirements across 17 families and never mentions AI, which is why a single prompt carrying Controlled Unclassified Information to a commercial model endpoint engages five families at once. This checklist gives ten actions for a contractor whose engineers already have access to hosted models, naming the requirement family each one serves and the artifact it produces for an assessment.

complianceai-governanceauditnistai-security
Read post →

NIST SP 800-171 AI Audit Evidence: What an Assessor Asks When CUI Reaches a Model

NIST SP 800-171 Revision 3, finalised on 14 May 2024, carries 97 security requirements across 17 families and governs Controlled Unclassified Information in nonfederal systems. An engineer pasting CUI into a hosted model moves that data outside the assessed boundary in one HTTPS request. This walks the evidence artifacts an assessor requests once AI traffic is in scope, family by family, and names where the assessment boundary actually sits.

complianceai-governanceauditnistai-security
Read post →