Compliance Mapping
We are the workforce documentation layer of AI governance. We support existing regulatory and audit frameworks by documenting policy communication, training, and acknowledgment.
Healthcare (HIPAA Alignment)
Regulatory Anchors
- 45 CFR —164.530 — Workforce training & documentation requirements
- 45 CFR —164.308(a)(5) — Security awareness and training
What We Provide
- Policy version history with effective dates
- Workforce training documentation
- Attestation tracking (who acknowledged which version)
- Date-range evidence export for audits
?? What We Do NOT Provide
Does not replace BAAs, DLP systems, breach response programs, or HIPAA compliance software.
Financial Services (Supervision & Safeguards Alignment)
Regulatory Anchors
- FINRA Rule 3110 — Supervision and written supervisory procedures
- GLBA Safeguards Rule — Administrative safeguards requirements
- SEC compliance program expectations — Training & policy documentation
What We Provide
- Written AI policy documentation
- Training completion records
- Employee acknowledgment logs
- Supervisory review evidence
?? What We Do NOT Provide
Does not replace communication archiving, surveillance systems, or model risk validation programs.
Audit Framework Alignment (SOC 2 / ISO 27001)
Framework Requirements
- SOC 2 Trust Services Criteria — Security awareness and control documentation
- ISO 27001 Annex A — Information security awareness & training controls
- Communication of security responsibilities
- Control evidence retention
What We Provide
- AI policy version control
- Training completion tracking
- Attestation documentation
- Control evidence for auditor review
?? What We Do NOT Provide
We are not a certification body and do not issue SOC 2 or ISO certifications.
What We Explicitly Do NOT Do
- ? We do not monitor employee prompts
- ? We do not inspect AI outputs
- ? We are not a DLP suite
- ? We are not a system-level AI conformity engine
- ? We are not legal advice
We are the workforce documentation layer — not the technical control layer.
✓ No prompt monitoring
✓ No PHI required
✓ No system telemetry
✓ Evidence export by date range