AICP · Domain 2
AI Compliance Frameworks
About 35% of the exam
EU AI Act obligations map
- Prohibited
- unacceptable practices, banned outright
- High-risk, Annex I
- safety components of regulated products
- High-risk, Annex III
- listed uses such as employment
- Limited risk
- transparency duties only
- Minimal risk
- no new legal duties
- GPAI
- documentation, copyright policy, training summary
- Systemic risk GPAI
- evaluations, incident reports, cybersecurity
- Extraterritorial reach
- output used inside the Union
- Regulatory sandbox
- supervised testing before market placement
Classification drives everything downstream, so settle the intended purpose and your own role before arguing about which controls apply
Standards you must place
Management systems
- ISO/IEC 42001 certifies an AI management system
- Statement of Applicability records the control choices
- Clause 4 covers context and interested parties
- ISO/IEC 23894 gives risk guidance only
- ISO 31000 is the parent risk standard
Frameworks
- NIST AI RMF: govern, map, measure, manage
- Voluntary and not certifiable
- Generative AI Profile names confabulation
- ISO/IEC 38507 extends IT governance to AI
- Harmonized standards give presumption of conformity
Assurance reports
- SOC 2 always includes the security criteria
- Type 1 tests design, type 2 operation
- Suitable criteria: relevant, complete, reliable, neutral
- Certification differs from an assurance opinion
- Accreditation vouches for the certification body
Building the AI inventory
- Record intended purpose and your role
- Assign a risk tier per system
- Name an accountable owner for each
- Tie updates to lifecycle events
- Cover models embedded in purchased software
- Coverage percentage is the headline metric
- Discover through egress analysis and spend
- Retire entries when systems are decommissioned
Data governance for AI
- Provenance
- origin plus the supplier's right
- Legal basis
- recorded per source, not globally
- Data card
- collection, subgroups, known limitations
- Data quality duty
- best extent possible, documented effort
- Special category use
- narrow bias-correction allowance only
- Splitting rule
- keep one entity in one split
- Data contract
- automated checks that block publication
- Lineage
- column level shows the blast radius
- Unlearning
- retrain, shard, or approximate removal
Evidence and control design
- One repository mapped to many frameworks
- Every control needs an owner and cadence
- Incident-only cadence proves nothing between incidents
- Evidence must substantiate the control claimed
- Continuous control monitoring beats annual sampling
- Training completion records evidence AI literacy
- Sample across the period, not one date
- Test edge cases and degraded inputs
Registration and records
- Provider registers before placing on market
- Public body deployers register their use
- Technical documentation kept for about a decade
- Automatic logs retained as the Act requires
- Logging captures runtime, not management records
- Declaration of conformity names the applied standards
- CE marking affixed before market entry
Penalty bands
- Prohibited practices
- up to 7% of turnover
- Most other obligations
- up to 3% of turnover
- Misleading the authorities
- up to 1% of turnover
- Euro caps
- 35, 15 and 7.5 million
- Smaller firms
- the lower of the two figures
- GPAI providers
- a separate Commission enforcement route
- Aggravating factors
- intent, duration, cooperation, prior findings
Governance structures
- Charter fixes scope, membership and escalation
- Approving the risk appetite is governance
- Implementing controls within it is management
- Highest-impact use cases reach the board
- Sign-off independent of the build team
- Exception process handles justified deviations
- Maturity levels guide the next increment
Shadow AI
- Unsanctioned tools appear when procurement drags
- Prohibition alone pushes usage underground
- Publish a fast, sanctioned tool catalog
- Detect through egress and expense review
- Fold every finding into the inventory
- Acceptable use covers free tools too
Certification and audit journey
- Gap assessment
- Stage 1 readiness
- Stage 2 audit
- Certificate
- Surveillance
- Recertification
- Stage 1 issues no certificate
- Major nonconformity means a systemic process failure
- Minor nonconformity is an isolated lapse
- An audit plan schedules coverage over years
- Competence assessed before accepting the engagement
- Internal audit and management review are mandatory
Audit evidence for AI
- Stale test set
- cannot support a current conclusion
- Automatic logs
- traceability across the lifecycle
- Model documentation
- architecture, training, limits, intended use
- Bias audit timing
- within the prior year in NYC
- Bias audit scope
- sex, race and their intersections
- Sock-puppet testing
- synthetic profiles probe live behavior
- Retrieval systems
- source freshness, access control, faithfulness
- Continuous control monitoring
- automated testing between formal audits
Beyond Europe
United States
- Model risk guidance demands independent validation
- Adverse action notices need specific reasons
- New York City requires an annual bias audit
- Colorado imposes a reasonable care duty
- Federal agencies follow the budget office memorandum
- Insurance regulators issued a model bulletin
Other jurisdictions
- The United Kingdom uses five cross-sectoral principles
- Contestability and redress is one of them
- Canada proposed duties for high-impact systems
- China requires labeling of deep synthesis
- Brazil reviews automated decisions under its statute
Working across them
- Map obligations, then find the overlap
- One baseline plus jurisdiction modules
- Reuse a single control for many rules
- Sector law applies whether or not AI
- Divergent definitions block mutual recognition
Metrics for the board
- KPI
- process performance, usually lagging
- KRI
- exposure warning, ideally leading
- KCI
- whether the control actually operates
- Coverage
- share of systems risk-tiered
- Assessment completion
- high-risk systems assessed on time
- Overdue remediation
- aging of open findings
- Literacy
- training completion by audience
Glossary
- Harmonized standard
- cited standard granting presumed conformity
- Notifying authority
- designates and monitors notified bodies
- Market surveillance
- supervises products already on sale
- AI Office
- Commission unit overseeing GPAI
- Sandbox exit report
- record supporting later conformity discussions
- Statement of Applicability
- selected controls with written justification
- Nonconformity
- a requirement not met
- Presumption of conformity
- compliance assumed until challenged
Reference strip: Act, standards, data, audit, world
The Act
- Four tiers plus separate GPAI duties
- Provider registers, deployer oversees
- Conformity, CE marking, then registration
- Fines at 7, 3 and 1 percent
Standards
- 42001 certifies, 23894 only guides
- NIST AI RMF is voluntary
- Harmonized standards presume conformity
- Accreditation sits above certification
Data
- Legal basis recorded per source
- Data card describes the dataset
- Entity stays inside one split
- Deletion is hard once trained in
Audit
- Stage 1 readiness, stage 2 audit
- Major means a systemic failure
- Evidence must match the control
- Sample across the whole period
World
- Bias audits, adverse action, model risk
- Five principles in the United Kingdom
- One baseline, jurisdiction modules on top
- Sector law never goes away
Quick exam traps
- Trap: Adopting the NIST AI RMF makes the organization certifiable against it
- Trap: Following a harmonized standard is the only lawful route to conformity
- Trap: Article 12 runtime logging and management system records are the same evidence
- Trap: A free consumer chatbot falls outside the acceptable use policy
- Trap: Banning unapproved AI tools is enough to eliminate shadow AI
- Trap: One inventory entry per vendor is sufficient regardless of use case
- Trap: Passing stage 1 of a certification audit earns the certificate
cybercertprep.com · original revision sheet written from the public body of knowledge