Perimattic

Compliance hub

AI compliance evidence for eight regulatory frameworks

Regulators increasingly ask how an AI system behaved, not only how it was designed. This hub summarises what eight frameworks expect from AI in production and the records Perimattic AI Suite can produce for each.

Last reviewed by the Perimattic AI Suite team

In short

Which regulations require AI observability?

None names a specific tool, but most now expect records that only monitoring can produce. The EU AI Act requires logging and post-market monitoring for high-risk systems. HIPAA requires audit controls on systems holding health data. SOC 2 auditors sample monitoring and change records. DORA, BaFin, MAS and OSFI expect financial firms to inventory, monitor and control their AI, and India’s DPDP rules require access logs kept for a year.

  • One set of telemetry, many audiences

    The same traces, scores and access records can support several frameworks at once. What changes is how they are grouped, retained and reported.

  • Evidence, not certification

    A tool can’t make an organisation compliant. It can make the records your compliance programme depends on complete, consistent and easy to produce.

All frameworks

The eight frameworks at a glance

Regulatory frameworks, what they expect from AI systems, and the evidence observability provides
FrameworkRegionStatusWhat it expects from AI in productionEvidence observability provides
HIPAAUSIn forceAudit controls, access control and integrity for systems with electronic PHIRedacted request traces, access logs for AI and its telemetry
SOC 2US / globalAnnual attestationMonitoring (CC7), change management (CC8) and vendor oversight (CC9.2)Alert history, model and prompt change records, vendor metrics
EU AI ActEUHigh-risk duties from 2 Dec 2027 / 2 Aug 2028Logging, log retention, human oversight, post-market monitoring, incident reportingEvent logs, oversight records, monitoring data, incident files
DORAEUApplies since 17 Jan 2025ICT risk management, incident classification and reporting, third-party riskProvider dependency map, incident timelines, provider performance
BaFinGermanyDORA-based AI guidance (Dec 2025)AI treated as an ICT system across its lifecycle, with third-party controlAI inventory from traces, operational monitoring, provider oversight data
MAS FEATSingaporePrinciples since 2018; AI risk guidelines consulted 2025-26Fairness, ethics, accountability and transparency; AI inventory and lifecycle controlsDecision records, quality and fairness monitoring, AI inventory
OSFI E-23CanadaEffective 1 May 2027Enterprise model risk management covering AI and ML modelsModel inventory, ongoing performance monitoring, change history
DPDPIndiaMost duties from 13 May 2027Security safeguards incl. access logs kept one year; breach reportingAccess and processing logs, redaction coverage, breach timelines

United States

HIPAA

The HIPAA Security Rule requires audit controls that record and examine activity in systems containing electronic PHI (45 CFR 164.312(b)). For AI, that includes the model calls and their logs. Telemetry vendors that store PHI are business associates. Read AI observability for HIPAA for the full requirement-to-evidence map.

United States and global

SOC 2

SOC 2 Type II tests whether controls operated over a period. AI systems in scope mostly touch CC7 (monitoring and incidents), CC8 (change management, including model and prompt versions) and CC9.2 (vendor risk for LLM providers). Read SOC 2 evidence for AI systems for the control-to-signal table.

European Union

EU AI Act

After the Digital Omnibus (Regulation (EU) 2026/1744), high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. Article 50 transparency duties have applied since 2 August 2026. Read AI observability for the EU AI Act for the full timeline and obligation map.

European Union

DORA

DORA has applied to EU financial entities since 17 January 2025. AI systems sit inside its ICT risk, incident reporting and third-party rules, and an LLM API used in an important function is an ICT third-party service. Read AI observability for DORA for the article-by-article evidence map.

Germany

BaFin

BaFin, Germany’s Federal Financial Supervisory Authority, supervises banks, insurers and other financial firms. In June 2021 it published supervisory principles for using algorithms in decision-making. On 18 December 2025 it issued non-binding guidance on managing ICT risks when using AI, aimed at firms subject to DORA, including institutions under the Capital Requirements Regulation and insurers under Solvency II.

The guidance treats AI as a network and information system under DORA. It looks at risks across the AI lifecycle, from data acquisition and model development to operation and retirement, with particular attention to ICT third-party risk. Although it is non-binding, firms that depart from it should expect to show that their own measures are at least as effective.

  • An inventory of AI systems and the providers behind them, built from traces
  • Operational monitoring of each AI system through its whole life
  • Performance and incident data for every external model provider
  • Records that show controls working, not only policies that describe them

Singapore

MAS FEAT and AI risk management

In 2018 the Monetary Authority of Singapore and industry published the FEAT principles (Fairness, Ethics, Accountability and Transparency) for AI and data analytics in finance. The Veritas initiative, started in 2019, built methods for financial institutions to assess their AI against those principles.

On 13 November 2025 MAS consulted on Guidelines on Artificial Intelligence Risk Management, which move from principles to supervisory expectations: board and senior management oversight, an accurate AI inventory, risk materiality assessments, and lifecycle controls, with stricter controls for higher-risk uses such as credit decisions and customer advice. The consultation closed on 31 January 2026. Check MAS for the final text before relying on the details.

  • An AI inventory kept current from production telemetry
  • Quality, drift and outcome monitoring per AI use case
  • Decision records that support accountability and explanation
  • Evidence for independent validation and periodic review

Canada

OSFI Guideline E-23

The Office of the Superintendent of Financial Institutions published the final Guideline E-23 on model risk management on 11 September 2025. It takes effect on 1 May 2027 and applies to federally regulated financial institutions.

The revised guideline widens the definition of a model to any system that processes input data to generate results, which brings AI and machine learning systems, including LLM applications, into scope. It expects an enterprise-wide, risk-based model risk management framework covering the full model lifecycle, applied in proportion to each institution’s size and risk profile.

  • A model inventory that includes AI and LLM applications
  • Ongoing performance monitoring against agreed thresholds
  • Change history for model versions, prompts and data sources
  • Records that support validation and periodic review

India

DPDP Act and Rules

India’s Digital Personal Data Protection Act, 2023 is being brought into force by the DPDP Rules, notified on 13 November 2025. The Data Protection Board was set up first, consent-manager provisions follow in November 2026, and most obligations on data fiduciaries apply from 13 May 2027.

Rule 6 lists reasonable security safeguards, including encryption, access control, and logs that give visibility of access to personal data so unauthorised access can be detected and investigated. Those logs must normally be kept for one year. Rule 7 requires breaches to be reported to the Board within 72 hours of becoming aware of them. Failing to take reasonable security safeguards can lead to a penalty of up to ₹250 crore.

  • Logs of who accessed personal data through AI systems, kept for the required period
  • Redaction of personal data before telemetry is stored
  • Detection of unusual access patterns
  • Breach timelines that support the 72-hour report

Sample evidence

One record, several frameworks

The same request record can be tagged for every framework that applies to the system, so one export answers several auditors.

This hub summarises public regulatory texts and guidance for planning purposes. It is not legal advice, and Perimattic AI Suite does not certify compliance with any framework.

{
  "request_id": "req_5be0…",
  "service": "loan-assistant",
  "frameworks": ["eu_ai_act.art12", "dora.art17", "osfi.e23"],
  "model": "<provider/model@version>",
  "eval": { "faithfulness": 0.9 },
  "personal_data": { "redacted": true },
  "retention_until": "2027-10-01"
}
Illustrative record with sample values, not customer data.

FAQ

Common questions

Short answers to common questions. They are general information, not legal advice.

What is enterprise AI governance?

The policies, roles and controls an organisation uses to manage the risks of its AI systems: who approves a use case, how models are tested and changed, how they are monitored, and who acts when something goes wrong. Observability provides the evidence that those controls actually operate.

Does one AI system need to meet several frameworks at once?

Often. A Canadian bank’s customer assistant may fall under OSFI E-23 and SOC 2 commitments to clients; a German insurer’s claims model under DORA, BaFin guidance and possibly the EU AI Act. The records overlap heavily, which is why tagging one set of telemetry for several frameworks saves work.

Which of these frameworks applies to me?

It depends on your sector, where you operate and what the AI system does. The AI compliance readiness assessment gives a first view across the main frameworks; your legal and compliance team should confirm the result.

Is Perimattic AI Suite itself certified under these frameworks?

This page describes how the product supports your compliance programme, not attestations held by Perimattic. Questions about Perimattic’s own security posture are covered in the security review during early access.