Compliance operators own audit-packet curation, evidence preservation, release-gate enforcement, regulator engagement, and the compliance-mapping artifacts (EU AI Act, NIST AI RMF, UNCITRAL ODR, sector-specific obligations).
Audience and prerequisites#
- Audience: compliance staff and the compliance on-call rota.
- Prerequisites: legal-foundations, privacy-operators module overlap, evidence-preservation training, RBAC current.
- Refresh cadence: 6 months; mandatory micro-brief on each regulator update.
Learning objectives#
By certification, a compliance operator can independently:
- Curate an audit packet for a release gate, an incident, or a regulator request — structured, signed, write-once.
- Enforce the release-gate evidence requirements at
docs/security/v1-release-security-gates.md,docs/launch/go-no-go.md, and the compliance-mapping artifacts. - Run the compliance-mapping checks (EU AI Act, NIST AI RMF, UNCITRAL ODR, sector-specific) against a candidate release or incident.
- Engage regulators on Article-33-class notifications, audits, and sector-specific reporting obligations.
- Manage the audit-export pipeline (
admin.audit.export_*) — schedule, verify, archive, restore. - Coordinate with privacy, security, T&S, and legal on cross-cutting compliance work.
Curriculum modules#
| # | Module | Duration | Format | Assessment |
|---|---|---|---|---|
| 1 | Audit-packet curation | 120 min | guided + peer review | rubric pass on 5 packets |
| 2 | Release-gate enforcement | 120 min | hands-on against go/no-go fixtures | 2-release gate rehearsal (one pass, one block) |
| 3 | EU AI Act mapping (high-risk systems, transparency, logging) | 120 min | seminar + mapping exercise | per-clause mapping test (≥ 85% accuracy) |
| 4 | NIST AI RMF mapping (Govern, Map, Measure, Manage) | 120 min | seminar + mapping exercise | per-function mapping test |
| 5 | UNCITRAL ODR (online dispute resolution) | 90 min | seminar + mapping exercise | per-stage mapping test |
| 6 | Regulator engagement (notification, audit, response) | 120 min | drafting workshop with legal | 2-notification drill |
| 7 | Audit-export pipeline | 90 min | hands-on with audit tooling | export/verify/archive/restore drill |
| 8 | Cross-cutting coordination (privacy, security, T&S, legal) | 60 min | scenario rehearsal | 3-coordination drill |
Audit-packet protocol#
Every packet contains:
- Scope: subject (release ID / incident ID / regulator request ID), time window, residency, data classes.
- Evidence: signed audit-export from the audit pipeline, with each event's structural integrity verified.
- Decisions: structured decision record for each policy/release gate applied, with operator identity and reason code.
- Artifacts: evaluation results, security gate outputs, privacy-impact assessments, persona/model promotion records, runbook invocations.
- Mapping: a row per relevant compliance framework (EU AI Act, NIST AI RMF, UNCITRAL ODR, sector-specific) showing how the packet satisfies each obligation.
- Signatures: compliance operator + reviewer + legal counsel for external packets.
Release-gate enforcement protocol#
For every release reaching GA candidacy:
- Verify the security gates at
docs/security/v1-release-security-gates.md. - Verify the launch-readiness checklist at
docs/launch/go-no-go.md. - Verify the per-domain content gate, accessibility gate, locale gate, privacy gate, persona gate, model gate, watermark/provenance gate.
- Curate the release audit packet.
- Sign off (with legal counsel for any external commitment) or block with a structured remediation list.
Scenario rehearsal#
- Block a release on a missing safety gate: a release reaches the release-captain gate but the safety benchmark missed a class. Operator blocks, files structured remediation, communicates with the release captain.
- Engage a regulator on an Article-33 incident: privacy operator declares a sev1; compliance operator drafts the regulator notification with legal review, delivers within 72 h, captures delivery audit.
- Audit-export restore: a regulator requests evidence from 18 months ago. Operator verifies the audit-export archive, restores the relevant window into a sealed inspection environment, delivers restoration audit.
- EU AI Act high-risk system mapping: a candidate workflow is evaluated against the high-risk classification criteria; operator documents the mapping, identifies any missing obligations, files remediation tickets.
- Cross-cutting coordination: a persona rollback intersects with a DSAR-in-flight and a security advisory; operator coordinates the four leads (privacy, security, T&S, legal) into one audit packet.
Certification criteria#
- All 8 modules complete with passing assessment.
- All 5 scenarios passed.
- Operator has co-curated 3 release packets with a senior compliance operator.
- Operator has co-curated 1 incident packet with a senior compliance operator.
- Compliance lead, legal counsel, and privacy lead sign-off.
Tabletop drills#
- Per regulator update: mandatory micro-brief.
- Quarterly: release-gate enforcement drill alongside the release captain.
- Semiannually: regulator-engagement tabletop with legal.
Owner#
Compliance lead owns this training. Legal counsel co-owns the regulator-engagement and compliance-mapping modules. Updates require both sign-offs.