← All posts

Industry Verticals

227 posts on industry verticals.

AI Governance for ML Engineers: Put the Control Contract Into the Deployment Path

ML engineers make AI governance executable by binding model releases to owners, approved purposes, data classes, evaluation evidence, routes, and rollback conditions. Runtime model calls then need identity-aware policy and a decision record so production use can be traced to the control contract approved for that release.

ai-governancedevsecopsarchitecturepolicy-enforcementauditnist-ai-rmf
Read post →

AI Governance for SOC Analysts: Turn Policy Decisions Into Investigable Events

A SOC analyst needs AI governance to produce events that can be triaged, correlated, and escalated. This article defines the event fields, detection logic, evidence chain, and response handoffs for governed HTTP model traffic, while keeping endpoint activity, local MCP processes, and destination-system actions inside their proper control boundaries.

ai-governanceai-securitycybersecurityforensic-auditauditpolicy-enforcement
Read post →

SR 11-7 AI Audit Evidence After SR 26-2

SR 11-7 AI audit evidence needs a current-source correction before fieldwork begins. SR 26-2 superseded the 2011 letter on April 17, 2026 and excludes generative and agentic AI from direct scope. Banks that apply its model-risk disciplines to LLMs through internal policy should freeze complete populations, let reviewers select samples, trace each request to approval and change records, and preserve gaps through retest.

ai-complianceai-governanceauditforensic-auditregulationpolicy-enforcement
Read post →

SR 11-7 AI Controls Mapping After SR 26-2

This SR 11-7 AI controls mapping uses the current SR 26-2 source and assigns bank-defined LLM controls to real owners. It maps governance, inventory, review, monitoring, change, third-party, and routed HTTP objectives to implementation points, repeatable tests, evidence, coverage verdicts, and open gaps while preserving the direct-scope exclusion for generative and agentic AI.

ai-complianceai-governanceauditregulationpolicy-enforcementforensic-audit
Read post →

AI Governance for Risk Managers: Turn Risk Appetite Into Runtime Decisions

A risk manager can approve an AI risk appetite and maintain the risk register. The role can assign control owners yet still lack evidence that production requests stayed inside those limits. This article gives the role an operating model for translating risk statements into request-level rules and monitoring exceptions, with escalation decisions supported by a traceable record.

ai-governanceai-compliancenist-ai-rmfauditpolicy-enforcementcompliance
Read post →

AI Governance for Behavioral Health Starts With the Treatment Context

AI governance for behavioral health has to distinguish treatment support, documentation, outreach, crisis workflows, and administrative work. The control model should bind every approved LLM call to a person, purpose, data class, and provider route while preserving the stricter handling that applies to substance use disorder records.

ai-governanceai-compliancehipaaauditpolicy-enforcementidentity-and-authorization
Read post →

Singapore MAS AI Controls Mapping: Owners for Agentic Finance

This Singapore MAS AI controls mapping assigns the proposed AI risk management and SAFR runtime outcomes to accountable owners. Each row connects a source position to an objective, operational control point, test, evidence contribution and open gap, while keeping an HTTP policy gateway inside its actual boundary.

ai-complianceai-governanceagentic-airegulationpolicy-enforcementaudit
Read post →

Singapore MAS FEAT AI Compliance Checklist: 8 Runtime Checks

This Singapore MAS FEAT AI compliance checklist gives financial institutions eight gradable actions for agent identity, delegated authority, governance envelopes, runtime decisions, human escalation, audit records, route testing, and governance ownership. It uses the Monetary Authority of Singapore SAFR paper and August 2026 parliamentary reply as its current sources while keeping the checklist focused on execution rather than audit packaging or control mapping.

ai-complianceai-governanceagentic-airegulationpolicy-enforcementaudit
Read post →

Singapore MAS AI Audit Evidence for Agentic Finance

Singapore MAS AI audit evidence for agentic finance should preserve three linked artifacts: an authorization decision record, proof that a defined human oversight trigger fired and reached an accountable reviewer, and a consequential decision record tied to the business outcome. This article turns the SAFR framing into a practical evidence package for authenticated HTTP traffic between financial-institution users or agents and LLM endpoints.

ai-complianceai-governanceauditagentic-aiforensic-auditregulation
Read post →

Shadow AI in Energy and Utilities: Grid Data, Outage Plans, and Vendor Risk

Shadow AI in energy and utilities can transmit grid operations material, outage plans, engineering records, and vendor data to unapproved LLM services. This article maps that exposure to NERC CIP information-protection and supply-chain requirements, distinguishes regulated BES Cyber System Information from other sensitive utility data, and defines enforceable controls for authenticated HTTP AI traffic.

shadow-aiai-securityai-governancecritical-infrastructurepolicy-enforcementzero-trust
Read post →

AI Governance for the Public Sector Needs Program-Level Accountability

AI governance for the public sector needs an enterprise control plane and program-level accountability. Federal agencies can use OMB M-25-21 to assign Chief AI Officer, governance-board, inventory, and high-impact risk duties while M-25-22 connects acquisition to testing, data rights, monitoring, and exit terms. State agencies need the same operating chain under their own authorities: a use-case owner, risk decision, production evidence, appeal path, and reassessment trigger.

ai-governanceai-compliancenist-ai-rmfpolicy-enforcementaudit
Read post →

AI Governance for Dental Practices Starts Before PHI Reaches a Model

AI governance for dental practices should connect every approved use case to its PHI exposure, individual user, exact model service, Business Associate Agreement, reviewer, and retained evidence. HIPAA already requires risk analysis, access management, activity review, business-associate safeguards, and audit controls. Dental AI programs need to apply those duties to clinical notes, radiology assistance, claims, patient messages, and vendor-managed features.

ai-governanceai-compliancehipaapolicy-enforcementaudit
Read post →