Lesson 22 / 26
Compliance Operations
Turn legal requirements into controls, owners and evidence that run as part of normal work.
From clause to control
Compliance works when each requirement becomes a control with an owner and evidence. For example, "ensure human oversight" becomes: high-tier systems must have a named reviewer and an override button; evidence is the approval record and override logs; the owner is the product lead. "Maintain documentation" becomes a template filled at the design gate. Build these into the gates and tools people already use, test the controls occasionally ("does the control actually work?"), and have an independent check, such as internal audit, review them.
Requirement to control to evidence
A control matrix is the working document of compliance. Gaps show up as blanks.
Requirement Control Owner Evidence
Human oversight named reviewer + override button Product lead approval record, override log
Transparency to users AI notice in UI, tested each release UX lead release checklist, screenshots
Data minimisation PII masking before model calls Eng lead pipeline tests, sample audits
Technical documentation system card at design + launch gates Product lead versioned cards in repo
Incident reporting runbook, 24h internal escalation Risk lead incident tickets, drill reportQuick check: What turns a legal requirement into something enforceable inside a company?
- Waiting for an audit
- A poster in the lobby
- A promise in an email
- A control with an owner and evidence
Answer
A control with an owner and evidence — Owners and evidence make a requirement checkable and sustainable.