Back to Models

Model

Audit and Compliance Model

Regulator-grade evidence for every agent decision. The model connects what an AI agent did to which regulation applies and who approved the outcome.

Overview

The Audit and Compliance Model continuously monitors AI agent activity and behavior, maps it to regulatory obligations and internal controls, investigates when something looks wrong, and packages evidence that compliance teams, auditors, and regulators can review easily. AI handles the repetitive, document-heavy, rule-driven work, while humans stay accountable for material decisions such as alert dispositions, escalations, regulatory filings, and customer notices. The system prepares documentation, but it does not autonomously file reports or close high-risk cases without human review.

Regulatory alignment

  • NIST AI RMF 1.0: govern, map, measure, and manage AI risk, balancing innovation with responsibility.
  • NIST AI 600-1: extends the RMF to generative content and autonomous agent risk, where agents perceive, plan multi-step tasks, and chain external tools with limited human oversight.
  • Emerging supervisory guidance, including FINRA's 2026 focus on agentic AI: narrow agent scope, human checkpoints before material actions, and complete audit trails across multi-step reasoning.

The compliance loop

  • Obligation discovery: know which laws and policies apply.
  • Control design: translate obligations into concrete controls.
  • Operational monitoring: watch agent activity for violations or gaps.
  • Case investigation: review alerts, gather evidence, and find root cause.
  • Reporting: draft internal and regulatory reports.
  • Remediation: track fixes to controls, processes, or models.
  • Evidence retention: keep proof for auditors and examiners.

Compliance domains

  • BSA/AML alert triage: AI-assisted alert disposition review.
  • Agentic AI governance: inventory and oversight of AI agents.
  • Model risk documentation: validation and limitations for AI tools.
  • Privacy and data governance: control AI access to customer data.
  • Records and audit readiness: retention indexing across domains.

Evidence the system produces

  • The original alert or agent input and output.
  • The reasoning and tools the agent used.
  • Which control and regulation applied.
  • The AI triage recommendation and its confidence.
  • The human reviewer decision and notes, when required.
  • Retention metadata and an immutable audit log.