Search the Atlas

Search risks, controls, and glossary terms

Non-AgenticLegal Compliance

AI Regulation Compliance

Explanation

AI Regulation Compliance checks whether an AI system used in banking actually satisfies the laws and supervisory rules that apply to it — for example RBI accountability expectations and fair-lending obligations on a credit-decision model — so that the bank does not deploy automation that is unlawful or unauthorised. It matters because a single non-compliant high-risk model (say a loan-approval engine that ignores fair-lending requirements) can trigger penalties, customer harm and reputational damage. It is measured by the Regulatory Alignment Score, computed as Alignment Score = (Σ(Requirement_Met_i × Requirement_Weight_i)) / (Σ(Requirement_Weight_i)); for lending decisions this is alignment with fair lending laws, so each applicable requirement is weighted by importance and scored as met or not. To implement it, maintain a structured register of legal/regulatory requirements (using document-extraction and RAG over the rulebooks) mapped to specific system controls, assign weights and ownership per NIST GOVERN 1.1/2.1 and ISO Clause 5.2/5.3, evaluate each requirement at design and before release, and log the evidence (who assessed, against which clause, with what result). The threshold is 100% compliance for high-risk applications; any shortfall there is an immediate-priority breach that must block deployment until every weighted requirement is met.

Metric calculation

Alignment Score = (Σ(Requirement_Met_i × Requirement_Weight_i)) / (Σ(Requirement_Weight_i)) For lending decisions, alignment with fair lending laws.

Risks mitigated

30
ZYR-AG-001High
Authority Scope Violation
Accountability & Governance
ZYR-AG-004High
Unregistered Agent Operations
Accountability & Governance
ZYR-AG-005High
Validation Coverage Gaps
Accountability & Governance
ZYR-AG-007Medium
Non-Deterministic Agent Behaviour
Accountability & Governance
ZYR-AG-008Medium
Governance Attention Exploitation
Accountability & Governance
ZYR-AG-009Medium
Low-and-Slow Policy Bypass
Accountability & Governance
ZYR-AG-010High
MCP Server Confused-Deputy
Accountability & Governance
ZNR-PD-001High
PII memorization & regurgitation
Privacy & Data Protection
ZNR-PD-002Medium
Membership inference
Privacy & Data Protection
ZNR-PD-003Low
Model inversion / data reconstruction
Privacy & Data Protection
ZNR-PD-004Critical
Sensitive-information disclosure in output
Privacy & Data Protection
ZNR-PD-005Medium
Prompt & conversation retention/leakage
Privacy & Data Protection
ZNR-PD-006Medium
Re-identification from outputs
Privacy & Data Protection
ZNR-PD-007Low
Cross-session / cross-user context bleed
Privacy & Data Protection
ZNR-CS-001Medium
Toxic / hateful / harassing output
Content Safety & Integrity
ZNR-CS-002Low
Violent or self-harm content
Content Safety & Integrity
ZNR-CS-003Low
CBRN / dangerous capability uplift
Content Safety & Integrity
ZNR-CS-004Low
CSAM / NCII / obscene content
Content Safety & Integrity
ZNR-CS-005High
Misinformation / disinformation generation
Content Safety & Integrity
ZNR-CS-006Medium
IP / copyright infringement
Content Safety & Integrity
ZNR-CS-007Medium
Defamation / reputational harm
Content Safety & Integrity
ZNR-CS-008Critical
Unlicensed / unsuitable advice
Content Safety & Integrity
ZNR-GA-001High
Regulatory non-compliance
Governance, Accountability & Compliance
ZNR-GA-002High
Inadequate pre-deployment evaluation / red-team
Governance, Accountability & Compliance
ZNR-GA-003High
Missing human oversight
Governance, Accountability & Compliance
ZNR-GA-004Medium
Model & version change-management gaps
Governance, Accountability & Compliance
ZNR-GA-005High
Third-party / value-chain model risk
Governance, Accountability & Compliance
ZNR-GA-006Medium
Inadequate monitoring & incident response
Governance, Accountability & Compliance
ZNR-GA-007High
Shadow AI / ungoverned usage
Governance, Accountability & Compliance
ZNR-GA-008Medium
Unclear accountability / ownership
Governance, Accountability & Compliance