Compliance Mapping

We are the workforce documentation layer of AI governance. We support existing regulatory and audit frameworks by documenting policy communication, training, and acknowledgment.

Healthcare (HIPAA Alignment)

Regulatory Anchors

  • 45 CFR —164.530 — Workforce training & documentation requirements
  • 45 CFR —164.308(a)(5) — Security awareness and training

What We Provide

  • Policy version history with effective dates
  • Workforce training documentation
  • Attestation tracking (who acknowledged which version)
  • Date-range evidence export for audits

?? What We Do NOT Provide

Does not replace BAAs, DLP systems, breach response programs, or HIPAA compliance software.

Financial Services (Supervision & Safeguards Alignment)

Regulatory Anchors

  • FINRA Rule 3110 — Supervision and written supervisory procedures
  • GLBA Safeguards Rule — Administrative safeguards requirements
  • SEC compliance program expectations — Training & policy documentation

What We Provide

  • Written AI policy documentation
  • Training completion records
  • Employee acknowledgment logs
  • Supervisory review evidence

?? What We Do NOT Provide

Does not replace communication archiving, surveillance systems, or model risk validation programs.

Audit Framework Alignment (SOC 2 / ISO 27001)

Framework Requirements

  • SOC 2 Trust Services Criteria — Security awareness and control documentation
  • ISO 27001 Annex A — Information security awareness & training controls
  • Communication of security responsibilities
  • Control evidence retention

What We Provide

  • AI policy version control
  • Training completion tracking
  • Attestation documentation
  • Control evidence for auditor review

?? What We Do NOT Provide

We are not a certification body and do not issue SOC 2 or ISO certifications.

What We Explicitly Do NOT Do

  • ? We do not monitor employee prompts
  • ? We do not inspect AI outputs
  • ? We are not a DLP suite
  • ? We are not a system-level AI conformity engine
  • ? We are not legal advice

We are the workforce documentation layer — not the technical control layer.

✓ No prompt monitoring

✓ No PHI required

✓ No system telemetry

✓ Evidence export by date range