Skip to main content
ShadowAI Defense GitHub

Compliance

Compliance crosswalk

FrameworkRequirementWhere it's satisfied
EU AI Act Article 4 — AI literacy obligations for deployers AUP + employee training; AI Acceptable Use Policy starter
NIST AI RMF GOVERN-4.1 — accountability for AI risk; MANAGE-4.1 — monitoring Runbooks RB-001 to RB-004; quarterly Shadow AI metrics
ISO/IEC 42001 8.2 / 8.4 — operational planning and control; performance monitoring Detection library DET-* + runbooks RB-*
NIST CSF DE.CM-3 — monitoring of personnel activity; DE.CM-7 — unauthorized resource detection DET-MS-SEN-001 to -005; DET-MS-MCAS-001; DET-MS-MDE-001
OSFI B-13 (Canada banking) Technology and Cyber Risk Management — third-party AI use governance AI Inventory + Shadow AI Policy + monitoring
NYDFS Part 500 (US) §500.13 — data retention and use limitations DLP rules + retention policy; AI-CTRL-013 reference

How auditors use this

An auditor assessing the Shadow AI program asks for: charter, AUP, sanctioned-tool list with last-updated date, detection rule inventory with deployment evidence, sample alerts and runbook execution, comms log of approved-tool launches, and quarterly metrics. Every artifact in this repo's library corresponds to one of those.

Audit evidence pack

For each in-scope quarter, assemble:

  1. Current AUP (signed, dated).
  2. Sanctioned-tool list (from your AI Inventory).
  3. Detection rule inventory: ID, platform, last tuned, status (active / audit / disabled).
  4. Sample DET-MS-SEN-001 alerts (or platform equivalent) with linked RB-001 execution.
  5. Sample DET-MS-PV-001 alerts (or platform equivalent) with linked RB-002 execution.
  6. Quarterly metrics: detection volume, time-to-respond, repeat rate, conversion-to-approved-pilot rate.
  7. Approved-tool launch communications log.

This pack maps to AI Controls Catalog control AI-CTRL-020 (Shadow AI Detection) Test of Operating Effectiveness.