top of page
BLOG
Compliance Principles, Practices, & Insights


Two Kinds of AI Strategy: Adopt or Adapt?
Which one will you choose? Digital transformation has always been a challenge. Re-engineering a business to use new technology carries real risk, and more so when the benefits aren't easily realized. That is the part the current AI conversation keeps skipping. There are two ways to bring AI into a business, and they are not the same thing. You can adopt it: take the technology as given and fit the business around it. Or you can adapt it: start from the business you already ha


Should You Adopt ISO 42001 or ISO 5338?
ISO 42001 has quickly become a standard organizations reach for when they want to take AI seriously. It is the first international management system standard for artificial intelligence — a framework for governing AI across an organization, built in the same family as ISO 9001 for quality and ISO 27001 for information security. It is a genuine step forward, and for many businesses it can help. But before adding it to the shelf alongside your other management systems, it is wo


Managing Requisite Context for AI Workflows
Many organizations are adopting AI in their business, whether as generative AI or as AI agents. In all cases, the AI needs a context to work from, and for the AI to be effective that context must be requisite. An AI model knows nothing about your organization. Everything it produces on your behalf rests on the context supplied at the moment of use. If that context covers what the task requires, the workflow can be trusted. If it doesn't, the model fills the gaps with public d


Irresponsible AI Adoption in Safety-Critical Sectors
There was a time when safety was engineered into the business, the plant, and the operations. It required qualified engineers to ensure harm was avoided, and that risks, when they occurred, were mitigated. Systems were built with instrumentation, controls, and adaptive regulators to keep everything operating within safe limits. This was done so that everyone had the best possible chance of returning home to their families at the end of the day. Then someone threw a stochastic


The Golden Thread of Assurance - Wrap Up
We just completed the final session in our series on the Golden Thread of Assurance. Assurance is the proactive means of providing confidence that obligations have been met, are being met, and will be met. It runs through everything critical to compliance — and it answers a question many organizations have had to ask: why did we have an incident when we had checked all the boxes? The boxes were checked. The thread was broken. The golden thread connects the spaces in between.


OOPS, we put the obligations in the wrong place.
For years I've watched the same thing happen across every regulated sector I've worked in. The obligations are documented. The controls are implemented. The audit gets passed. And still, when something goes wrong, you find that no one — not one identifiable person, not one accountable part of the organization — was holding the thing that failed. It's tempting to call this negligence: managers handing their responsibilities off to consultants, departments, and auditors. There


Regulating AI with Institutional Knowledge
Today many organizations use AI that is general. It was trained on the public record, not on any one sector or business. It does not know your mission, your values, your goals, your processes, your protocols, or your standard operating procedures. When you ask it a question, it answers from what is common across everyone, not from how that knowledge applies to the particulars of what you do. In a regulated, high-risk domain this is a problem. The general model gives you the


Engineered Regulation for AI Systems
In every industry where failure is consequential, we learned to engineer control into a system before we trusted it to run. With AI, we are skipping that step. The discipline we are missing has a name: engineered regulation. Engineered Regulation for AI Systems No one runs a refinery with a big red button and good intentions. Before the plant starts, engineers design the control loops that hold temperature and pressure where they belong. They add independent safety systems th


Is AI Causing Your Mission to Drift?
Compliance is now vulnerable. Every promise you've made — privacy, security, quality, financial integrity, legal adherence, ethical values — now runs through systems that are unreliable, uncertain, and unable to align with your mission. So ask the hard questions: Does your AI know your obligations, your values, your promises? Does it follow your processes, your standard operating procedures, your policies? Will it cost you your legal license — or your social license — to oper


AI Adoption Is Leading to Greater Efficiency, Not Innovation
There is a quiet assumption running underneath the loudest investment of our age, and Sunday is a good day to bring it into the light. We are building compute. Enormous, almost unimaginable quantities of it. We are miniaturizing computers at one end — fabricating features measured in handfuls of atoms — and scaling them up at the other into hyperscale clouds that span continents. The capital is real, the engineering is genuine, and the people doing it are among the most capab


What Full-Text Search Already Taught Us About AI
We have been here before. In the enterprise, there have always been two kinds of searches. The first looks for the exact answer you get from a query (deterministic). The second looks for the closest answer you can find through full-text search (probabilistic). We knew the difference, and we learned how to use each kind. Full-text search gave us the approximate answers. It returned a ranked list of the most relevant results — useful when you are browsing, less so when you need


Why Compliance Must Speak Up About AI
Just because AI may not yet be regulated does not mean compliance should sit on the sidelines. Compliance has always struggled to know how it creates and preserves value. AI now presents both the opportunity and the necessity to do so. Here is why. Organizations everywhere are adopting AI. Many are slowly realizing that adoption is not the objective: AI must create value. But this prompts a question few are asking. Not what value is AI creating, but what value is it losing? T


Introducing the Record of Assurance
The regulatory landscape has changed, as I have been writing about for almost a decade. For a long time, compliance asked one thing of an organization: that procedures were in place, and that there was evidence they had been followed. That's procedural compliance, and it's well served. A certificate or an audit gives you exactly that — confirmation of procedural integrity. It's useful, honest work, and it isn't going away. But increasingly, boards, stakeholders and regulators


You're Not Using AI. AI Is Using You.
When we use AI in its most common form, we come to realize something about it. The large language models (LLMs) behind it have been trained on public knowledge, not on the knowledge your organization, business, or institution owns. We can provide a model with our documents to process, but this does not change the model. It does not learn that way. The exchange is one-directional in a way that is easy to miss. The model answers our prompts and forgets us, but the data we send


The Collapse of Governance and Management
Raimund Laqua, P.Eng., PMP We need to talk about the collapse of governance and management. Much of what gets written these days about governance is really management wearing governance clothing. Frameworks, control libraries, risk registers, maturity models, oversight committees — all of it operates on the parts of a system. None of it sets direction or steers toward mission outcomes. We kept the word governance and filled it with the work of the layer below. Nowhere is this


The problem with AI adoption is you, not AI.
That's the line being sold to executives right now — wrapped in maturity models, readiness assessments, and seven-dimension frameworks. And it's patently false. This is an old argument dressed up in AI clothing. When a technology fails to deliver, blame the organization for not being ready to receive it: Your workflows are too fragmented Your processes are too manual Your processes lack ownership Your data isn't clean enough Your business has too many regulations Of course ex
bottom of page
