Compliance
Compliance crosswalk
| Framework | Requirement | Where it's satisfied |
|---|---|---|
| EU AI Act | Article 4 — AI literacy obligations for deployers | AUP + employee training; AI Acceptable Use Policy starter |
| NIST AI RMF | GOVERN-4.1 — accountability for AI risk; MANAGE-4.1 — monitoring | Runbooks RB-001 to RB-004; quarterly Shadow AI metrics |
| ISO/IEC 42001 | 8.2 / 8.4 — operational planning and control; performance monitoring | Detection library DET-* + runbooks RB-* |
| NIST CSF | DE.CM-3 — monitoring of personnel activity; DE.CM-7 — unauthorized resource detection | DET-MS-SEN-001 to -005; DET-MS-MCAS-001; DET-MS-MDE-001 |
| OSFI B-13 (Canada banking) | Technology and Cyber Risk Management — third-party AI use governance | AI Inventory + Shadow AI Policy + monitoring |
| NYDFS Part 500 (US) | §500.13 — data retention and use limitations | DLP rules + retention policy; AI-CTRL-013 reference |
How auditors use this
An auditor assessing the Shadow AI program asks for: charter, AUP, sanctioned-tool list with last-updated date, detection rule inventory with deployment evidence, sample alerts and runbook execution, comms log of approved-tool launches, and quarterly metrics. Every artifact in this repo's library corresponds to one of those.
Audit evidence pack
For each in-scope quarter, assemble:
- Current AUP (signed, dated).
- Sanctioned-tool list (from your AI Inventory).
- Detection rule inventory: ID, platform, last tuned, status (active / audit / disabled).
- Sample DET-MS-SEN-001 alerts (or platform equivalent) with linked RB-001 execution.
- Sample DET-MS-PV-001 alerts (or platform equivalent) with linked RB-002 execution.
- Quarterly metrics: detection volume, time-to-respond, repeat rate, conversion-to-approved-pilot rate.
- Approved-tool launch communications log.
This pack maps to AI Controls Catalog control AI-CTRL-020 (Shadow AI Detection) Test of Operating Effectiveness.