Data Governance
Operational controls for data governance, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →6 controls
Training Data Provenance
Track and document the origin, composition, licensing, and preparation history of data used to train or fine-tune AI models.
PII Handling in AI Systems
Establish controls governing how personally identifiable information is handled when it flows through AI inputs, outputs, training data, and logs.
Data Minimization for AI Systems
Limit AI processing to data needed for its defined purpose. Avoid unnecessary collection, retention, or use of personal information.
AI Output Retention and Deletion
Define and enforce retention schedules and deletion procedures for AI-generated content, decisions, and the personal data contained within them.
Cross-Border Data Transfer Controls for AI
Govern international personal-data transfers through AI systems. Include transfers to AI service providers, model training systems, and cloud infrastructure in other jurisdictions.
AI-Generated Code and Open-Source License Compliance
Identify open-source license obligations and supply-chain risks in AI-generated code. Address them before adding the code to production systems.
Data Governance, tracked weekly
New data governance controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
