← All posts

Industry Verticals

227 posts on industry verticals.

Shadow AI in Credit Unions: Member Data, NCUA Oversight, and Vendor Risk

Shadow AI in credit unions can place member records, loan files, fraud cases, and call-center transcripts into AI services outside approved vendor oversight. This article maps the exposure to NCUA Part 748 safeguards, the agency's AI supervision guidance, and third-party risk duties, then defines enforceable controls for managed HTTP AI traffic.

shadow-aiai-securityai-governancecompliancepolicy-enforcementaudit
Read post →

Shadow AI in Capital Markets: MNPI, Supervision, and Books and Records

Shadow AI in capital markets can move MNPI and draft research into unapproved model services while leaving the firm without a supervisory record. This article maps the traffic to FINRA''s technology-neutral rules and SEC books-and-records duties, then defines the controls required at the managed HTTP AI boundary.

shadow-aiai-securityai-governancecompliancepolicy-enforcementaudit
Read post →

SEC Cyber Disclosure AI Controls Mapping

SEC cyber disclosure AI controls mapping should connect each Item 1.05 and Item 106 disclosure objective to an owner, control point, test, retained evidence, result, and open gap. This guide keeps legal materiality and disclosure decisions separate from the narrower incident evidence available for routed authenticated AI HTTP traffic.

ai-complianceai-governancecybersecurityregulationauditpolicy-enforcement
Read post →

Shadow AI in Defense Contractors: CUI, CMMC, and the Managed AI Boundary

Shadow AI in defense contractors can move CUI, engineering changes, proposal data, and program details into model services outside the assessed environment. This article maps the exposure to NIST SP 800-171, DFARS 252.204-7012, and CMMC, then defines what contractors can enforce and prove across authenticated HTTP AI traffic.

shadow-aiai-securityai-governancecompliancenistzero-trust
Read post →

Shadow AI in Accounting Firms: Confidentiality for Tax Data and Workpapers

Shadow AI in accounting firms moves taxpayer data, payroll files, audit workpapers, and transaction details into AI services outside the firm''s approved workflow. This article maps that exposure to professional confidentiality and Internal Revenue Code Section 7216, plus the FTC Safeguards Rule, then sets out an enforceable control pattern for routed HTTP AI traffic.

shadow-aiai-securityai-governancecompliancedata-loss-preventionaudit
Read post →

SEC Cyber Disclosure AI Compliance Checklist

This SEC cyber disclosure AI compliance checklist turns Form 8-K Item 1.05 and Regulation S-K Item 106 into eight owner-led tests. It covers incident populations, materiality escalation, filing timing, annual disclosures, third parties, and evidence, while limiting AI HTTP records to support for cyber incidents and materiality analysis.

ai-complianceai-governancecompliancecybersecurityregulationaudit
Read post →

SEC Cyber Disclosure AI Audit Evidence for Public Companies

SEC cyber disclosure AI audit evidence should connect a complete incident population to the registrant's materiality process, filing clock, annual risk disclosures, and retained source records. This guide shows where routed AI request evidence can support that chain without treating the SEC cyber rules as AI-specific requirements.

ai-complianceai-governanceauditcybersecurityregulationforensic-audit
Read post →

OCC AI Controls Mapping for Bank Model-Risk Governance

This OCC model risk AI controls mapping connects the current 2026 interagency guidance to control objectives and bank owners; repeatable tests and retained evidence; gaps and retests. It keeps the scope boundary explicit: OCC Bulletin 2026-13 excludes generative and agentic AI models, so a bank applying these disciplines to an LLM must anchor that decision in its own policy or another applicable source.

ai-complianceai-governanceauditcomplianceregulationarchitecture
Read post →

NYDFS Part 500 AI Compliance Checklist for Covered Entities

A NYDFS Part 500 AI compliance checklist grades LLM traffic against the amended 23 NYCRR 500, including the asset inventory at 500.13(a), access privileges at 500.7, monitoring of authorized user activity at 500.14(a)(1), the 72 hour incident notice at 500.17(a), and the April 15 certification at 500.17(b). Each check carries an owner, a pass condition, evidence fields, and a boundary line.

ai-complianceai-governancenydfsfinancial-servicesregulationaudit
Read post →

NYDFS Part 500 AI Audit Evidence for Monitoring and the 72 Hour Notice

NYDFS Part 500 AI audit evidence has to support two readers: an examiner testing the monitoring duty at 500.14(a)(1) and access privileges at 500.7, and a CISO assembling a 72 hour notice under 500.17(a)(1). This guide covers population definition, sample binding, integrity testing, asset inventory alignment under 500.13(a), retention, and the April 15 certification file.

ai-complianceauditnydfsfinancial-servicesai-governancezero-trust
Read post →

OCC AI Audit Evidence for Model-Risk Governance

OCC model risk AI audit evidence should connect a bank-approved LLM use case to the routed request population and reviewer-selected samples, then connect model and policy changes to monitoring results, exceptions, and third-party oversight. This guide reflects OCC Bulletin 2026-13, which replaced the 2011 model-risk guidance and excludes generative and agentic AI from its direct scope.

ai-complianceai-governanceauditfinancial-servicesregulationforensic-audit
Read post →

FFIEC AI Compliance Checklist for Financial Institutions

This FFIEC AI compliance checklist turns technology-neutral examination themes into eight gradable checks for AI governance, inventory, risk, lifecycle controls, access, logging, providers, and assurance. Each check names an accountable owner, pass criteria, retained evidence, and the condition that sends the item to remediation.

ai-complianceai-governancefinancial-servicesregulationauditpolicy-enforcement
Read post →