Enterprise AI Compliance
Enterprise AI compliance means building an evidence chain that lets you prove to a regulator or auditor exactly how an AI-assisted decision was made.
Executive perspective
At some point, a regulator, auditor or customer will ask a specific question: how do you know your AI is under control. Answering with a policy document is not sufficient. The answer that satisfies scrutiny is evidence — a record of what was decided, by whom, using what data, with what outcome.
Compliance, in this context, is distinct from governance and from risk management. Governance decides who has authority. Risk management decides what could go wrong and how it is controlled. Compliance is the external-facing discipline of proving, after the fact, that both of those things happened as intended.
The organizations that pass this test comfortably are not the ones with the most policies. They are the ones that can retrieve a specific record, for a specific decision, on request, without a scramble.
Business context
A regional bank using AI to summarize loan documentation will eventually be asked, during an examination, to show how a specific summary was generated, what source documents it drew from, and who reviewed it before a decision was made. If that trail does not exist, the summary itself becomes a liability regardless of its accuracy.
Obligations vary by sector and jurisdiction — data protection requirements, sector-specific regulation, and data residency rules all apply differently depending on where a business operates and what it handles. What is common across all of them is the underlying expectation: that a business can reconstruct how a decision was made, not just what the decision was.
A national utility subject to sector regulation may face this test not from a financial regulator but from a safety authority reviewing how an AI-assisted maintenance recommendation was reached. The nature of the obligation differs; the need for a reconstructable record does not.
The core insight
Compliance is not achieved by writing a policy that says decisions will be recorded. It is achieved by designing the recording into the process itself, so that evidence is a byproduct of normal operation rather than a separate task someone has to remember to do.
An organization is not compliant because it has rules. It is compliant because it can reconstruct, on request, exactly how a specific decision was made.
This reframes the compliance question from "do we have a policy" to "can we produce the record." The second question is the one an auditor actually asks, and it is the one most organizations struggle to answer quickly.
The Evidence Chain
The Evidence Chain identifies five points at which a record must be created for an AI-assisted decision to be auditable: Policy, Permission, Provenance, Proof and Preservation. Missing any one link breaks the chain, even if the other four are complete.
The five links
| Link | What must be recorded | Question it answers |
|---|---|---|
| Policy | The rule that governed this type of decision at the time it was made | What standard applied here |
| Permission | Who was authorized to approve this use and this data access | Who allowed this |
| Provenance | What data and sources the AI system drew on for this specific output | Where did this come from |
| Proof | Evidence that a human reviewed or approved the output where required | Who checked this |
| Preservation | How long the above records are retained and how they can be retrieved | Can we still produce this later |
How long should AI decision records be kept
Retention periods should follow the same rules already applied to the underlying business process. A lending decision governed by a seven-year retention requirement should have its AI-assisted evidence retained on the same schedule. The Preservation link exists to make that connection explicit rather than assumed.
What this looks like in practice
In banking, a loan documentation summary tool logs the source documents used, the reviewer who signed off, and the policy version in effect at the time, so that a decision made two years earlier can be fully reconstructed during an examination.
In healthcare, a clinical documentation assistant retains a record of which clinician approved an AI-drafted note before it entered the patient record, satisfying the Proof link even though the drafting itself was automated.
In utilities, a maintenance prioritization system preserves the sensor data and asset history it used to generate a recommendation, so a safety regulator can trace a specific maintenance decision back to its inputs.
In insurance, a claims assessment tool logs the permission granted to access a customer's claims history, distinct from the general approval to use the tool, so that data access and system use are each independently auditable.
Executive checklist
- For our highest-risk AI use cases, could we reconstruct a specific decision from six months ago today?
- Is the policy version in effect at the time of a decision recorded alongside the decision itself?
- Do we distinguish between permission to use a system and permission to access specific data?
- Is provenance — the sources behind a specific output — captured automatically or only on request?
- Where human review is required, is that review itself evidenced, not just assumed?
- Are retention periods for AI-related records aligned with the retention rules of the underlying process?
- Could we retrieve a specific record fast enough to satisfy an auditor's timeline?
- Does our compliance function participate in AI deployment decisions, or only review them afterward?
Key takeaways
- Compliance is proven with retrievable evidence, not with policy documents.
- The Evidence Chain has five links — Policy, Permission, Provenance, Proof, Preservation — and any missing link breaks auditability.
- Obligations vary by sector and jurisdiction, but the need for a reconstructable decision trail is common to all of them.
- Evidence should be a byproduct of the process, not a separate task performed after the fact.
- Retention rules for AI-related records should follow the retention rules of the process they support.
Continue reading
Next article: Building Trust in Enterprise AI. Compliance proves control to a regulator; the next guide addresses a related but separate goal — earning the confidence of employees, customers and the board.
