Charter · AI Company Framework

Compliance — Charter

What compliance owns in an AI-operated company — obligations, evidence, audit readiness, AI governance frameworks, and the difference between passing an audit and actually being compliant.

Compliance Updated 2026-08-04 861 words · about 4 min read

Legal determines what applies. Compliance proves it is met — and the proving is the harder half, because it must be true on an ordinary Tuesday, not only on audit day.

In an AI-operated company the obligation set has expanded, and it now includes demonstrating things about systems whose behaviour is not fully deterministic.

What this role owns#

The obligations register. Every requirement that applies, its owner, its evidence, and when it was last verified.

Evidence. Not policies — proof that the control operated. A policy is an intention; a log is evidence.

Audit readiness. Continuous, not a quarterly scramble.

AI governance. Which frameworks apply, what is documented, and who signed what.

Control testing. Whether the controls actually work, checked independently of the people who run them.

KPIs#

MeasureWhy this one
Obligations with current evidenceThe core number. Anything without evidence is unproven, not compliant
Control test pass rateWhether controls work, not whether they exist
Findings closed within SLAOpen findings are accepted risk
Time to produce audit evidenceDays means it is continuous; weeks means it is a scramble
AI systems registeredOwner, purpose, decisions made, data used — should be all of them
Policy exceptionsTrending up means the policy is wrong, not that people are

That last one is worth taking seriously. A policy people constantly need exceptions from is a badly written policy.

The AI governance frameworks#

Three, and they do different jobs:

EU AI Act — law, not a framework. Risk-tiered obligations. Transparency requirements applied from 2 August 2026; high-risk obligations deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Applies based on where your users are, not where you are.

NIST AI Risk Management Framework — voluntary, provides the risk methodology and vocabulary. Useful as the discipline layer.

ISO/IEC 42001:2023 — the certifiable AI management system standard. Increasingly appearing in enterprise procurement due-diligence questionnaires, which is usually what makes it urgent rather than any regulator.

They are complementary. A common sequence is NIST first to establish the taxonomy and lifecycle discipline, then ISO/IEC 42001 certification once the documentation exists.

Position as at 2026-08-04. This area is moving; re-verify before relying on a date.

Passing an audit is not the same as being compliant#

Worth stating plainly because the confusion is expensive.

An audit samples controls at a point in time. Compliance means the control operated every time it should have. The gap between them is where incidents live — and it is why evidence should be a by-product of the work rather than something assembled for the auditor.

If producing evidence requires a project, the control is not really running.

AI agents in this function#

Evidence collection agent — gathers control evidence from systems on a schedule, so audit readiness is continuous rather than periodic.

Obligations mapping agent — maps regulatory text to internal controls and flags requirements with no control attached.

Policy gap analysis — compares policies against a framework and lists what is unaddressed.

Control monitoring agent — flags a control that has not operated when it should have. This is the highest-value one: silent control failure is the failure mode that matters.

What stays human: determining whether an obligation applies, accepting a risk, signing an attestation, and deciding a finding is closed. An agent that can close its own findings is not a control.

SOPs#

  • Obligations register maintenance — reviewed quarterly, updated on any regulatory change.
  • Control testing — schedule, sampling, and independence from the control owner.
  • AI system registration — before go-live: purpose, data, decisions made, human oversight, evaluation method, owner.
  • Finding management — owner, remediation date, verification, and explicit acceptance if not remediated.
  • Evidence retention — what, where, and for how long. Some obligations mandate minimum retention, which interacts awkwardly with deletion rights.

Templates#

Obligations register · control test record · AI system registration · Security Checklist governance section · Incident Report.

Workflows#

In: regulatory changes from Legal · new systems for registration · control evidence · findings from audits and reviews.

Out: compliance position · findings with owners · attestations · go/no-go on compliance grounds · evidence packs.

Handoffs: Legal for interpretation · Security for technical controls · CTO for AI system approval · CEO for accepted risk above a threshold.

FAQ#

Do we need ISO/IEC 42001 certification?#

If enterprise customers ask for it in due diligence — increasingly they do — it becomes a commercial requirement regardless of your own view. Achieve the controls first so the certificate documents something real.

Does the EU AI Act apply to us if we are not in the EU?#

Potentially yes. It applies based on where your users are and whether output is used in the EU, not on where you are incorporated. Get advice on your specific position.

How do we evidence compliance for a non-deterministic system?#

By evidencing the process, not the output: which model and prompt version, what evaluation was run and with what result, who reviewed, what the human oversight was, and the log of decisions made. You cannot promise a specific output; you can prove how it was controlled.

What is the most common compliance failure?#

Evidence that only exists when someone assembles it. If producing it takes a project, the control is not operating continuously — and the auditor is sampling a performance rather than a process.

What else is coming for Compliance

Charter Ready

What this department owns and is accountable for.

KPIs Not yet

The numbers it is judged on.

AI Agents Not yet

What is automated, and what stays human.

SOPs Not yet

How the recurring work is done.

Templates Not yet

The documents it produces.

Workflows Not yet

How work enters, moves and leaves.