Lesson 22 / 26

Compliance Operations

Turn legal requirements into controls, owners and evidence that run as part of normal work.

From clause to control

Compliance works when each requirement becomes a control with an owner and evidence. For example, "ensure human oversight" becomes: high-tier systems must have a named reviewer and an override button; evidence is the approval record and override logs; the owner is the product lead. "Maintain documentation" becomes a template filled at the design gate. Build these into the gates and tools people already use, test the controls occasionally ("does the control actually work?"), and have an independent check, such as internal audit, review them.

Requirement to control to evidence

A control matrix is the working document of compliance. Gaps show up as blanks.

Requirement              Control                              Owner         Evidence
Human oversight          named reviewer + override button     Product lead  approval record, override log
Transparency to users    AI notice in UI, tested each release  UX lead       release checklist, screenshots
Data minimisation        PII masking before model calls        Eng lead      pipeline tests, sample audits
Technical documentation  system card at design + launch gates  Product lead  versioned cards in repo
Incident reporting       runbook, 24h internal escalation      Risk lead     incident tickets, drill report

Quick check: What turns a legal requirement into something enforceable inside a company?

  • Waiting for an audit
  • A poster in the lobby
  • A promise in an email
  • A control with an owner and evidence
Answer

A control with an owner and evidence — Owners and evidence make a requirement checkable and sustainable.