|
This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. |
|
|
Newsletter #59 - June 2026 |
|
|
How I scope compliance obligations for AI governance |
|
|
By James Kavanagh
|
|
The biggest compliance obligations on your AI systems rarely come from AI regulation. Here's how I work out what actually applies, starting from what the business does, not the law. |
When practitioners new to AI Governance start scoping their compliance work, they tend to reach for the AI-specific stuff first. They pick up the EU AI Act, or ISO 42001, or the NIST AI RMF, work through it asking "does this apply to us?", and quietly assume the rest, privacy law, sector regulation, employment law, consumer protection, the client contracts, has already been handled by someone else. More often than not it hasn't, at least not in a way that accounts for AI. And that existing body of requirements is where the most consequential obligations on your use of AI almost always sit.
So I flip the order. Instead of starting with a regulation and asking whether it applies, I start by describing the business: what it does, where it operates, who it serves, what data it handles, what decisions it makes about people. It's an idea I've borrowed from environmental management, of all places, where ISO 14001 has organisations identify their "aspects" first and let the legal requirements follow from them. I use seven categories of aspects to do the same for AI, and once they're described, the applicable regulations surface from them rather than the other way round.
The payoff is that you can scope quickly and roughly, then iterate, instead of reading a hundred regulations one at a time and still missing the ones that matter. The full method, the seven categories, how organisation-level and system-level aspects stack, and where you absolutely need a lawyer in the room, is in the article.
|
|
|
This kind of risk prioritisation is the work we cover in the AI Governance Foundation Track and AI Compliance Speciality course. Join the waitlist. |
|
|
What's your AI governance practitioner capability score?
|
|
|
|
How I map compliance expectations to controls and mechanisms |
|
|
By James Kavanagh
|
|
New AI regulations don't replace your existing compliance work, they pile on top of it. Here's how I map every source into one common control framework, as an essential first step in building a scalable and efficient compliance program. |
This is the natural sequel to scoping. Once you know what's in scope, you're left holding a stack of regulations, standards and contracts that all speak different languages but keep pointing at the same governance territory. The tempting thing is to give each one its own owner and its own workstream: the EU AI Act here, ISO 42001 there, GDPR somewhere else, the client contracts with whoever was closest when they landed. It grows that way without anyone deciding it should, and it fails in three predictable ways. It duplicates effort, it leaves gaps at the boundaries between programs, and it quietly papers over the conflicts nobody gets around to resolving.
The alternative is one internal framework, organised by what governance actually does rather than by where each requirement came from. Functional domains like risk management, security and incident management, with every external source mapped into it, but most importantly tailored to your organization.
The article walks through the methodology I use to create this kind of consolidated crosswalk: Artifact to Expectation to Control to Mechanism. It's a straightforward but powerful approach to building your crosswalk and mechanism portfolio across all twelve domains of AI governance and all the major regulatory and compliance sources.
|
|
|
If your compliance pile keeps growing while the work stays the same size, this is what to do about it. It sits at the center of our AI Compliance Specialty Course, launching in July, with AI Risk close behind. Join the waitlist. |
|
|
We started our first Foundation Track Practitioner Cohort last week with 15 participants from a range of legal, technology and policy disciplines. Through one complex case study of AI governance in a children's hospital, we're working to identify harms, set principles and commitments, build inventory, diagnose and redesign mechanisms and finally write policies that people will genuinely use. And all of it implemented within the VerifyWise GRC platform. This is hands-on real practice of AI governance. Our next cohort starts in August and spots are filling fast - secure your place here.
Our AI Compliance Specialty Course is coming along nicely and is on schedule for a July release date. Right now, we're focusing on the Balcony tool you'll use throughout the course. We will go out to our waitlist with a special offer prior to the course being made available to the general public, so be sure to join the waitlist here.
And for those of you who have completed, or are working through, the Foundation Track, we'll be in touch over the coming weeks with more information on our new credential - the Practitioner Award, AI Governance Foundations. Learn more about AI Career Pro Practitioner Awards and other credentials here.
As always, reach out if you have questions or need further clarity on any of our work, or if you need help navigating your professional path. We're learning with you and really appreciate your enquiries and feedback.
|
|
|
PS. You're receiving this as a subscriber to communications from AI Career Pro. We respect your privacy, so please unsubscribe through the link below if you do not wish to receive these communications in the future. |
|
|