← All posts

Compliance & Regulation

402 posts on compliance & regulation.

ISO/IEC 5338 AI Compliance Checklist for Lifecycle Controls

ISO/IEC 5338:2023 extends system and software life cycle processes for machine-learning and heuristic AI systems. This checklist turns its agreement, organizational, technical-management and technical process groups into inspectable work: scope the system, control suppliers and changes, engineer data, validate continuously, preserve runtime evidence, maintain the system and prove disposal.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

FedRAMP AI Compliance Checklist for Request-Level Controls

A FedRAMP AI compliance review should test the authorization boundary, model inventory, identity propagation, least-privilege rules, data classification, event logging, evidence integrity, and continuous monitoring. This checklist translates those requirements into request-level tests an assessor can repeat.

ai-compliancenistauditpolicy-enforcementai-governance
Read post →

AI Audit Trail for Payments: Recordkeeping When Transmittal Data Reaches a Model

BSA recordkeeping under 31 CFR 1010.410 obliges a transmittor financial institution to retain named details for transmittals of 3,000 dollars or more. Operations and fraud teams now send that same data to language models to draft summaries and investigation notes. This article maps the recordkeeping duty onto the authenticated model request and sets out what the per-request record has to carry.

ai-compliancepaymentsbsafincenauditfinancial-services
Read post →

AI Audit Trail for Ecommerce: What the FTC Safeguards Rule Expects You to Log

The FTC Safeguards Rule obliges covered businesses to monitor and log the activity of authorized users and to detect unauthorized use of customer information by those users. Support agents and agentic workflows sending order data to language models are authorized users doing exactly that. This article maps 16 CFR 314.4(c)(8) onto the model request and sets out what the record has to hold.

ai-complianceecommerceftcsafeguards-ruleauditcustomer-data
Read post →

Google Agentspace Compliance Starts with the Current Product Record

Google Agentspace compliance work should begin by reconciling the name and edition in the contract with Google Cloud’s current Gemini Enterprise documentation. The operating record then needs the project, location, connectors, agents, IAM roles, processing terms, regional limitations, control owners, evidence tests. This article focuses on that customer-owned compliance file. The security and audit-log reviews are published separately, as is the DLP review.

ai-complianceai-governancecomplianceauditidentity-and-authorizationcloud-security
Read post →

AI Audit Trail for Higher Education: The FERPA Disclosure Record Nobody Keeps

FERPA requires an institution to maintain a record of each request for and each disclosure of personally identifiable information from education records, kept as long as the education record itself. Advisors and faculty sending student data to language models create disclosures with no such record. This article maps 34 CFR 99.32 onto the model request and sets out what to capture.

ai-compliancehigher-educationferpastudent-privacyauditeducation
Read post →

Grok Enterprise Compliance Starts with Route and Retention Scope

Grok enterprise compliance depends on the exact xAI surface, endpoint, retention mode, enabled capability set and contract in use. The global API, US regional endpoint, Zero Data Retention, Files, Collections, server-side tools, and Grok Build have different boundaries. A defensible approval records those choices and verifies the active route in production.

ai-complianceai-governancecomplianceauditpolicy-enforcementcloud-security
Read post →

AI Audit Trail for Maritime: Cyber Risk Records Inside the Safety Management System

IMO Resolution MSC.428(98) pushed cyber risk into the safety management system that every Document of Compliance rests on. Model requests from voyage planning, cargo documentation and shoreside operations now sit inside that scope. This article sets out what a per-request record has to carry so a flag state auditor can verify the control instead of reading a policy about it.

ai-compliancemaritimeimoism-codeauditoperational-resilience
Read post →

AI Audit Trail for Automotive: UN R155 Forensics Applied to Model Traffic

UN Regulation No. 155 obliges a manufacturer to detect cyber-attacks, support monitoring of its vehicle types, and provide data forensic capability for analysing attempted attacks. Those duties assume logging exists. This article applies the same reasoning to the model requests engineers and agents make inside the manufacturer, and sets out the per-request record an approval authority discussion can rest on.

ai-complianceautomotiveunecer155auditproduct-security
Read post →

AI Audit Trail for Airlines: Part-IS Records When Operations Uses a Model

EASA Part-IS has applied since 22 February 2026 and obliges aviation organisations to detect information security events, report qualifying ones within 72 hours, and retain incident records for five years. Model requests from operations, maintenance and crew systems sit inside that scope. This article maps the relevant points onto the authenticated request and sets out what the record has to carry.

ai-complianceaviationeasapart-isauditoperational-resilience
Read post →

AI Audit Trail for Biotech: What 21 CFR Part 11 Expects at the Model Boundary

When a language model drafts text that lands in a GxP electronic record, the validated system records the paste and nothing before it. This article maps 21 CFR Part 11 audit trail language onto the authenticated request between a scientist and a model, describes the fields a QA reviewer can reconcile, and marks where the predicate rule rather than Part 11 sets retention.

ai-compliancebiotechgxpfdaauditlife-sciences
Read post →

AI Audit Trail for Aerospace: DFARS Evidence When CUI Reaches a Model

DFARS 252.204-7012 obliges a defense contractor to report a cyber incident within 72 hours and to preserve relevant monitoring data for at least 90 days. Both obligations assume the traffic was monitored. This article maps those clauses onto authenticated requests from engineers and agents to language models, and sets out the per-request record that makes the obligations answerable.

ai-complianceaerospacedfarscuidefenseaudit
Read post →