← All posts

Industry Verticals

237 posts on industry verticals.

FFIEC AI Audit Evidence: Build an Examiner-Ready Record

FFIEC AI audit evidence should let an examiner start from a complete population of AI systems, providers, releases, changes, incidents, and exceptions, then select samples and reconstruct what happened. This guide applies technology-neutral FFIEC examination procedures to AI without presenting them as a dedicated AI rule.

ai-complianceai-governanceauditfinancial-servicesregulationforensic-audit
Read post →

GxP AI Compliance Checklist for Regulated Computerised Systems

This GxP AI compliance checklist turns FDA 21 CFR Part 11 and EU GMP Annex 11 into eight gradable checks for scope, intended use, suppliers, validation, access, audit trails, change control, retention, and routed LLM traffic. Every check names an action, owner, pass condition, evidence artifact, and remediation trigger while preserving the regulated organization''s validation responsibility.

ai-complianceai-governanceauditcomplianceregulationpolicy-enforcement
Read post →

FINRA AI Audit Evidence for Supervisory Reviews

FINRA AI audit evidence should let a reviewer select an AI-assisted communication or supervisory event and reconstruct the user, input, model destination, output, review, approval, policy decision, and retained business record. This guide defines the evidence population, sample joins, integrity tests, and request-gateway boundary for broker-dealers.

ai-complianceai-governanceauditcomplianceregulationforensic-audit
Read post →

AI Governance for Professional Services Starts With the Client Matter

AI governance for professional services should approve work at the client-matter level, where contractual restrictions, confidentiality, team access, data classes, model routes, and review duties can be joined in one operating record. Firmwide vendor approval supplies a baseline. Engagement owners still need to authorize each use, preserve source and disposition evidence, and reopen the decision when the scope, model, connector, or client terms change.

ai-governanceai-compliancepolicy-enforcementauditidentity-and-authorization
Read post →

GxP AI Audit Evidence for Regulated Computerised Systems

GxP AI audit evidence should connect a regulated use and approved requirements to risk, validation, change control, access, operation, incidents, audit trails, retention, and historical retrieval. This guide separates FDA 21 CFR Part 11 scope from EU GMP Annex 11 expectations and limits an HTTP gateway to routed request decision evidence, never validation of the regulated system.

ai-complianceai-governanceauditcomplianceregulationforensic-audit
Read post →

FFIEC AI Controls Mapping: Owners, Tests, Evidence, and Gaps

FFIEC AI controls mapping should connect each technology-neutral examination anchor to a scoped AI control, accountable owner, enforcement point, repeatable test, retained evidence, current result, and open gap. This guide builds that map across governance, inventory, lifecycle, access, logging, providers, resilience, and assurance.

ai-complianceai-governancefinancial-servicesregulationauditpolicy-enforcement
Read post →

B2B SaaS AI Compliance: 7 Enterprise Buyer Checks

Enterprise buyers ask B2B SaaS vendors seven AI compliance questions about data flow, prompt controls, audit evidence, provider incidents, access requests, output controls, and regulatory posture. Each answer needs named systems, accountable owners, and records the buyer can inspect during security review.

b2b-saasai-compliancesecurity-questionnaireeu-ai-actenterprise-salesaudit
Read post →

EU MDR AI Compliance Checklist for Medical Device Software

This EU MDR AI compliance checklist turns intended purpose, software classification, technical documentation, quality management, post-market surveillance, change control, and routed LLM evidence into owner-assigned tests. Each check has a pass condition and retained artifact, with the request gateway boundary stated plainly.

ai-complianceai-governanceauditregulationpolicy-enforcementcompliance
Read post →

FERPA AI Controls Mapping for the Authenticated LLM Path

This FERPA AI controls mapping connects disclosure authority, legitimate educational interest, identity, purpose, destination policy, audit records, retention, and vendor evidence to named owners and repeatable tests. It keeps the authenticated HTTP enforcement boundary separate from consent, contract, student-rights, endpoint, and legal obligations.

ai-complianceai-governancecomplianceauditidentity-and-authorizationpolicy-enforcement
Read post →

EU MDR AI Audit Evidence for a Notified Body Review

EU MDR AI audit evidence should let a notified body move from a selected device to its intended purpose, approved software configuration, risk and validation records, field signals, changes, and corrective actions. This guide builds that assessor package while keeping routed LLM evidence inside its actual HTTP boundary.

ai-complianceai-governanceauditregulationpolicy-enforcementforensic-audit
Read post →

FDA AI/ML Guidance AI Compliance Checklist for Device Software

This FDA AI/ML guidance AI compliance checklist gives medical-device teams seven gradable checks for scope, lifecycle documentation, data and validation, PCCP changes, quality-system records, postmarket response, and routed LLM traffic. Each check names an owner, pass condition, retained evidence, and remediation state without presenting nonbinding guidance as a regulation.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

FERPA AI Audit Evidence for Student Record Disclosures

FERPA AI audit evidence should reconstruct each governed disclosure of personally identifiable information from education records, including the recipient, legitimate interest, authority, identity, purpose, policy decision, and retained record. This guide separates request-layer evidence from consent, contract, student-access, and vendor-governance records owned elsewhere.

ai-complianceai-governancecomplianceauditidentity-and-authorizationpolicy-enforcement
Read post →