← All domains

Governance & ComplianceView domain

APRF-19

Compliance

Produce auditable evidence of controls without equating compliance with readiness.

Purpose

Map regulatory and contractual obligations to concrete AI controls and produce auditable evidence—while recognizing compliance alone does not prove production readiness.

Engineering philosophy

Compliance is necessary evidence, not sufficient engineering. APRF treats compliance as a pillar that packages proof of other pillars for auditors and customers.

Why it matters

Enterprises cannot buy or deploy AI systems that cannot demonstrate control evidence. Conversely, checkbox compliance without engineering depth still fails in production.

Common failures

  • Claiming 'we are compliant' without control-to-evidence mapping
  • Policies that do not match runtime behavior
  • No audit trail for model and prompt changes
  • Ignoring sector-specific AI obligations until late

Mandatory checks

Gate controls. Each check is pass/fail via artifact + pass condition. Expected from the annotated capability level when the system meets the minimum criticality tier.

  • CMP-M1L3 · DefinedTier 2 · Productionmanual

    Applicable obligations for the AI system shall be identified and owned

    Artifact
    Obligations register with owner per obligation for each production AI system
    Pass condition
    Every production AI system ID has ≥1 mapped obligation entry or an explicit “none in scope” attestation with owner and review date ≤ 12 months
  • CMP-M2L4 · Quantitatively ManagedTier 3 · Mission Criticalmanual

    Control-to-evidence mapping shall exist for in-scope requirements

    Artifact
    Control→evidence matrix linking obligations to APRF checks or internal control IDs
    Pass condition
    100% of in-scope obligations map to ≥1 evidence artifact ID; matrix review date ≤ 12 months; 0 orphan obligations without evidence pointer
  • CMP-M3L3 · DefinedTier 2 · Productionhybrid

    Audit logs for critical AI control-plane changes shall be retained per policy

    Artifact
    Audit log retention config + sample of control-plane change events
    Pass condition
    Retention configured ≥ policy minimum (e.g. ≥ 365 days); synthetic control-plane change appears in audit log within ≤ 5 minutes and remains queryable after retention smoke check

Evidence required

  • Obligations register for the AI product
  • Evidence packs per critical control
  • Audit log retention configuration

Severity & risk

Severity
high
Impact if violated
Risk level
medium
Typical residual risk (impact × likelihood)

Engineering best practices

  • Derive technical tickets from obligations; avoid orphan policies
  • Reuse APRF pillar evidence for multiple frameworks where mappings exist
  • Keep compliance language accurate: readiness ≠ certification
  • Version compliance artifacts with product releases

Automatic validations

  • Continuous control monitoring where automatable
  • Alerts on audit log pipeline failure
  • CI attaching evidence artifacts to releases

Manual validations

  • Internal audit sampling
  • Legal review of external AI claims

Examples

  • A SOC 2 narrative points to APRF eval gates and access reviews as evidence
  • Change tickets for prompt releases satisfy audit sampling requests

References

Crosswalks

  • GOVERN Govern

    NIST AI Risk Management Framework · supports

  • §4 Context of the organization

    ISO/IEC 42001 · aligns-with

  • §9 Performance evaluation

    ISO/IEC 42001 · supports

  • CC1 Control Environment

    SOC 2 Trust Services Criteria · evidence-for

  • P-series Privacy (selected)

    SOC 2 Trust Services Criteria · partial

Future evolution

Common control catalogs mapping APRF pillars to regional AI regulations.