Skip to main content
Compliance Doctrine

Building an AI compliance program

Build it in four layers: inventory every AI system and the data it touches, classify each by risk and applicable law, attach controls and a human owner proportional to that risk, and log decisions so you can prove compliance rather than merely assert it.

6 min read/Written by Perry Luzier/Reviewed

The four layers of a durable program

Inventory, classify, control, and log. Skip the inventory and shadow AI hides; skip the logs and you cannot prove anything to an auditor. Each layer feeds the next.

The inventory is the foundation, you cannot govern what you have not catalogued. Classification tells you which regime applies and how much control each system needs. Controls and human ownership make the system safe to run. Logs make it defensible. Organizations that treat compliance as documentation they generate continuously, rather than a report they write once, are the ones that pass audits without a fire drill.

  1. Inventory every AI system, its inputs, and the data it processes.
  2. Classify each by risk tier and applicable regulation (EU AI Act, HIPAA, GDPR, sector rules).
  3. Attach proportional controls, a named human owner, and oversight for consequential decisions.
  4. Log inputs, outputs, and overrides so every decision is reconstructable on demand.
Questions

Frequently asked questions.

Where should a mid-market company start with AI compliance?

Start with an inventory of every AI tool already in use and the data each touches. Most compliance gaps are really visibility gaps, you cannot classify or control systems you do not know exist.

Want this built into your operation?

We install the systems described here as owned infrastructure. Start with a diagnostic of where your business actually loses time and margin.