AI Governance Institute

AI Governance Compliance

Compliance work starts with identifying applicable obligations and keeping evidence that you meet them. Connect that work to your governance program.

Keep evidence of compliance

AI compliance requires evidence that your organization meets its legal and regulatory obligations. Map applicable regulations to your systems and retain records showing how controls operate. A governance framework also needs to cover risks beyond those legal requirements.

Which obligations apply

Organizations often face several overlapping AI requirements. Check each source against the systems you operate.

EU AI Act: Risk-based requirements can apply to organizations outside the EU. Check the Act’s scope against your systems and activities.
State-level US law: Colorado’s AI Act, Illinois’ BIPA, and NYC Local Law 144 address different activities. Other state laws add sector and geographic requirements.
NIST AI RMF: A voluntary US framework referenced in procurement requirements and regulatory guidance. Check whether your contracts require its use.
ISO/IEC 42001:2023: A certifiable AI management system standard. Certification can demonstrate governance processes to customers and auditors across jurisdictions.

A system’s obligations depend on its users’ locations, sector, and decisions. Use multi-jurisdiction compliance mapping to identify the rules that apply.

What evidence auditors and regulators expect

Prepare these five types of evidence for regulatory inquiries and audits. Each should describe work your team has completed.

AI system inventory and risk classification: A current inventory with a named owner and risk tier for each system. Keep it available for regulators and auditors.
Documented risk assessments: Evidence that each system was evaluated for bias, reliability, security, and privacy risk before and after deployment.
Audit-ready documentation: Records of approvals, model changes, and monitoring results, accessible, dated, and tied to a named owner.
Human oversight evidence: Records showing that human review checkpoints operate and cannot be bypassed through the normal workflow.
Vendor and third-party AI due diligence: Records showing which AI features your vendors provide and how your team assessed them.

Where compliance programs fail

Teams can struggle to produce records supporting their policies when regulators or lawyers request them. One reported incident involved a pre-production approval gate that exists on paper but wasn't enforced. The failure led to a full system rollback. A human review checkpoint that could be technically bypassed allowed an enforcement bug to affect thousands of users. Keep evidence showing that controls operate inside the deployed system.

Review obligations as rules change

New regulations and enforcement actions arrive weekly. A program assessed six months ago may need changes today. Assign ongoing responsibility for regulatory monitoring. Revisit controls when enforcement actions or standards change expectations for adequate safeguards.

A minimal AI compliance policy template

Start with written answers to these five questions. Have Legal review the resulting policy.

  1. Applicable obligations: which regulations apply to which systems, by jurisdiction and use case?
  2. Required evidence: what documentation must exist before a system reaches production?
  3. Review and approval: who signs off before deployment, and what triggers re-review?
  4. Monitoring obligations: what ongoing evidence must be retained after deployment?
  5. Who receives notice of a compliance failure, and how quickly must they receive it?

Assign an owner to each responsibility and record how reviewers can verify completed work. See how to audit whether a compliance control is actually enforced.

Find out which obligations apply to you

Use the self-assessment to identify relevant regulations, missing evidence, and gaps in your compliance program.

Start the self-assessment