Compliance hub
AI compliance evidence for eight regulatory frameworks
Regulators increasingly ask how an AI system behaved, not only how it was designed. This hub summarises what eight frameworks expect from AI in production and the records Perimattic AI Suite can produce for each.
Last reviewed by the Perimattic AI Suite team
In short
Which regulations require AI observability?
None names a specific tool, but most now expect records that only monitoring can produce. The EU AI Act requires logging and post-market monitoring for high-risk systems. HIPAA requires audit controls on systems holding health data. SOC 2 auditors sample monitoring and change records. DORA, BaFin, MAS and OSFI expect financial firms to inventory, monitor and control their AI, and India’s DPDP rules require access logs kept for a year.
One set of telemetry, many audiences
The same traces, scores and access records can support several frameworks at once. What changes is how they are grouped, retained and reported.
Evidence, not certification
A tool can’t make an organisation compliant. It can make the records your compliance programme depends on complete, consistent and easy to produce.
All frameworks
The eight frameworks at a glance
| Framework | Region | Status | What it expects from AI in production | Evidence observability provides |
|---|---|---|---|---|
| HIPAA | US | In force | Audit controls, access control and integrity for systems with electronic PHI | Redacted request traces, access logs for AI and its telemetry |
| SOC 2 | US / global | Annual attestation | Monitoring (CC7), change management (CC8) and vendor oversight (CC9.2) | Alert history, model and prompt change records, vendor metrics |
| EU AI Act | EU | High-risk duties from 2 Dec 2027 / 2 Aug 2028 | Logging, log retention, human oversight, post-market monitoring, incident reporting | Event logs, oversight records, monitoring data, incident files |
| DORA | EU | Applies since 17 Jan 2025 | ICT risk management, incident classification and reporting, third-party risk | Provider dependency map, incident timelines, provider performance |
| BaFin | Germany | DORA-based AI guidance (Dec 2025) | AI treated as an ICT system across its lifecycle, with third-party control | AI inventory from traces, operational monitoring, provider oversight data |
| MAS FEAT | Singapore | Principles since 2018; AI risk guidelines consulted 2025-26 | Fairness, ethics, accountability and transparency; AI inventory and lifecycle controls | Decision records, quality and fairness monitoring, AI inventory |
| OSFI E-23 | Canada | Effective 1 May 2027 | Enterprise model risk management covering AI and ML models | Model inventory, ongoing performance monitoring, change history |
| DPDP | India | Most duties from 13 May 2027 | Security safeguards incl. access logs kept one year; breach reporting | Access and processing logs, redaction coverage, breach timelines |
United States
HIPAA
The HIPAA Security Rule requires audit controls that record and examine activity in systems containing electronic PHI (45 CFR 164.312(b)). For AI, that includes the model calls and their logs. Telemetry vendors that store PHI are business associates. Read AI observability for HIPAA for the full requirement-to-evidence map.
United States and global
SOC 2
SOC 2 Type II tests whether controls operated over a period. AI systems in scope mostly touch CC7 (monitoring and incidents), CC8 (change management, including model and prompt versions) and CC9.2 (vendor risk for LLM providers). Read SOC 2 evidence for AI systems for the control-to-signal table.
European Union
EU AI Act
After the Digital Omnibus (Regulation (EU) 2026/1744), high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. Article 50 transparency duties have applied since 2 August 2026. Read AI observability for the EU AI Act for the full timeline and obligation map.
European Union
DORA
DORA has applied to EU financial entities since 17 January 2025. AI systems sit inside its ICT risk, incident reporting and third-party rules, and an LLM API used in an important function is an ICT third-party service. Read AI observability for DORA for the article-by-article evidence map.
Germany
BaFin
BaFin, Germany’s Federal Financial Supervisory Authority, supervises banks, insurers and other financial firms. In June 2021 it published supervisory principles for using algorithms in decision-making. On 18 December 2025 it issued non-binding guidance on managing ICT risks when using AI, aimed at firms subject to DORA, including institutions under the Capital Requirements Regulation and insurers under Solvency II.
The guidance treats AI as a network and information system under DORA. It looks at risks across the AI lifecycle, from data acquisition and model development to operation and retirement, with particular attention to ICT third-party risk. Although it is non-binding, firms that depart from it should expect to show that their own measures are at least as effective.
- An inventory of AI systems and the providers behind them, built from traces
- Operational monitoring of each AI system through its whole life
- Performance and incident data for every external model provider
- Records that show controls working, not only policies that describe them
Singapore
MAS FEAT and AI risk management
In 2018 the Monetary Authority of Singapore and industry published the FEAT principles (Fairness, Ethics, Accountability and Transparency) for AI and data analytics in finance. The Veritas initiative, started in 2019, built methods for financial institutions to assess their AI against those principles.
On 13 November 2025 MAS consulted on Guidelines on Artificial Intelligence Risk Management, which move from principles to supervisory expectations: board and senior management oversight, an accurate AI inventory, risk materiality assessments, and lifecycle controls, with stricter controls for higher-risk uses such as credit decisions and customer advice. The consultation closed on 31 January 2026. Check MAS for the final text before relying on the details.
- An AI inventory kept current from production telemetry
- Quality, drift and outcome monitoring per AI use case
- Decision records that support accountability and explanation
- Evidence for independent validation and periodic review
Canada
OSFI Guideline E-23
The Office of the Superintendent of Financial Institutions published the final Guideline E-23 on model risk management on 11 September 2025. It takes effect on 1 May 2027 and applies to federally regulated financial institutions.
The revised guideline widens the definition of a model to any system that processes input data to generate results, which brings AI and machine learning systems, including LLM applications, into scope. It expects an enterprise-wide, risk-based model risk management framework covering the full model lifecycle, applied in proportion to each institution’s size and risk profile.
- A model inventory that includes AI and LLM applications
- Ongoing performance monitoring against agreed thresholds
- Change history for model versions, prompts and data sources
- Records that support validation and periodic review
India
DPDP Act and Rules
India’s Digital Personal Data Protection Act, 2023 is being brought into force by the DPDP Rules, notified on 13 November 2025. The Data Protection Board was set up first, consent-manager provisions follow in November 2026, and most obligations on data fiduciaries apply from 13 May 2027.
Rule 6 lists reasonable security safeguards, including encryption, access control, and logs that give visibility of access to personal data so unauthorised access can be detected and investigated. Those logs must normally be kept for one year. Rule 7 requires breaches to be reported to the Board within 72 hours of becoming aware of them. Failing to take reasonable security safeguards can lead to a penalty of up to ₹250 crore.
- Logs of who accessed personal data through AI systems, kept for the required period
- Redaction of personal data before telemetry is stored
- Detection of unusual access patterns
- Breach timelines that support the 72-hour report
Sample evidence
One record, several frameworks
The same request record can be tagged for every framework that applies to the system, so one export answers several auditors.
This hub summarises public regulatory texts and guidance for planning purposes. It is not legal advice, and Perimattic AI Suite does not certify compliance with any framework.
{
"request_id": "req_5be0…",
"service": "loan-assistant",
"frameworks": ["eu_ai_act.art12", "dora.art17", "osfi.e23"],
"model": "<provider/model@version>",
"eval": { "faithfulness": 0.9 },
"personal_data": { "redacted": true },
"retention_until": "2027-10-01"
}Regulation details last verified on 1 October 2026.
FAQ
Common questions
Short answers to common questions. They are general information, not legal advice.
What is enterprise AI governance?
The policies, roles and controls an organisation uses to manage the risks of its AI systems: who approves a use case, how models are tested and changed, how they are monitored, and who acts when something goes wrong. Observability provides the evidence that those controls actually operate.
Does one AI system need to meet several frameworks at once?
Often. A Canadian bank’s customer assistant may fall under OSFI E-23 and SOC 2 commitments to clients; a German insurer’s claims model under DORA, BaFin guidance and possibly the EU AI Act. The records overlap heavily, which is why tagging one set of telemetry for several frameworks saves work.
Which of these frameworks applies to me?
It depends on your sector, where you operate and what the AI system does. The AI compliance readiness assessment gives a first view across the main frameworks; your legal and compliance team should confirm the result.
Is Perimattic AI Suite itself certified under these frameworks?
This page describes how the product supports your compliance programme, not attestations held by Perimattic. Questions about Perimattic’s own security posture are covered in the security review during early access.
Go further
Related tools, guides and services
- Free toolAI compliance readiness assessmentScore your readiness across the EU AI Act, HIPAA, GDPR, SOC 2 and DORA.Open
- White papersEnterprise AI white papersIncludes “AI in Regulatory Compliance”.Open
- IndustryAI for financial servicesAI delivery for banks, insurers and fintech within regulatory limits.Open
- IndustryAI for healthcareAI delivery for providers, payers and health-tech teams.Open
See what your AI systems are doing, with evidence to back it up
Perimattic AI Suite is in early access. Tell us what you are building and a Perimattic engineer will follow up to scope your first instrumented system.
Prefer email? sales@perimattic.com