top of page
BLOG
Compliance Principles, Practices, & Insights


Is This The Best GRC Has To Offer?
I just attended a webinar from a leading GRC vendor promoting continuous risk assessment for AI. The topic seemed timely and the solution promising, so I gave it my full attention. What I heard : AI introduces significant risk across organizations and within every functional silo. Fair enough. ⚡ The pitch: With all this risk, you need a system to manage it comprehensively. OK. What they demonstrated was little more than a risk register combined with task management—where task


Regulating the Unregulatable: Applying Cybernetic Principles to AI Governance
As artificial intelligence systems reshape entire industries and societal structures, we face an unprecedented regulatory challenge: how do you effectively govern systems that often exceed human comprehension in their complexity and decision-making processes? Traditional compliance frameworks, designed for predictable industrial processes and human-operated systems, are proving inadequate for the dynamic, emergent behaviors of modern AI. The rapid proliferation of AI across c


Operationalizing AI Governance: A Lean Compliance Approach
AI governance policies typically describe what organizations intend to do. Lean Compliance focuses on how those intentions become operational capabilities that keep promises under uncertainty. Mapping an AI governance policy means creating an operational, regulation framework that links legal , ethical , engineering , and management commitments across AI use‑cases and life-cycle stages. The goal isn't compliance documentation—it's designing the operational capabilitie


Deploy First, Engineer Later: The AI Risk We Can’t Afford
The sequence matters: proper engineering design must occur before deployment, not afterwards. by Raimund Laqua, PMP, P.Eng As a professional engineer with over three decades of experience in highly regulated industries, I firmly believe we can and should embrace AI technology. However, the current approach to deployment poses a risk we simply cannot afford. Across industries, I’m observing a troubling pattern: organizations are bypassing the engineering design phase and dire


AI Regulating AI: Are we pouring fuel on the fire?
Raimund Laqua, P.Eng., PMP Note: Link to my strategy briefing document is located at the end of the blog post. About a year ago, I heard an AI expert suggest that we might need AI to control AI. My immediate reaction? That's nonsense. Why would you control something uncertain with more uncertainty? It seemed like doubling down on the problem rather than solving it. Turns out I was wrong. Or at least, I was asking the wrong question. The Problem That Won't Go Away I'm an engin


Governing Large Language Models - A Cybernetic Approach to AI Compliance
I've been thinking a lot about promises lately. Not the kind we make at year-end meetings, but the deeper promises organizations make when they deploy AI systems. Promises about safety, fairness, and accountability. Promises that become very real when something goes wrong. The challenge with Large Language Models is that traditional compliance approaches assume you can audit the decision-making process. You write procedures, train people, create controls around logical steps


How to Prove Your Compliance Actually Works: A Practical Guide to Building Confidence
If you're responsible for compliance, you've probably faced this uncomfortable question: "How do you know you're actually compliant?" Most organizations point to policies, training records, and audit reports. But there's often a nagging gap between having documentation and having genuine confidence that your obligations are truly being met. This is where Goal Structuring Notation (GSN ) and claim trees become game-changers. They're tools borrowed from safety-critical industr


Jidoka and AI: Lessons for Compliance
As someone working in compliance during this wave of AI adoption, I've been thinking about how we approach automation differently than other industries. The compliance field is naturally cautious about new technology—and for good reason. When we fail to meet regulatory standards, performance targets, or outcome requirements, the consequences extend far beyond operational inefficiency. Recently, I've been reflecting on Jidoka, Toyota's manufacturing principle that emerged over


Safety Design Principles for AI Adoption in Organizations
How do we deliver safe AI? This is the question every organization grappling with AI adoption must answer. Yet too often, discussions...


Why Risk Assessments Should Begin with Uncertainty
By Raimund Laqua, Founder of Lean Compliance Why Risk Assessments Should Start with Uncertainty Walk into most organizations today, and you'll find risk management teams armed with comprehensive checklists, detailed taxonomies, and colour-coded matrices that promise to capture every conceivable threat. These frameworks are seductive in their apparent completeness—neat categories for operational risks, financial risks, strategic risks, compliance risks. Everything has its plac


AI Risk Containment in Industrial Systems
AI Risk Containment Architecture Industrial leaders in safety-critical, highly regulated sectors like energy, chemical processing,...


Why Your IT Playbook Won't Work for AI Systems
Organizational leadership faces a critical decision: apply familiar commodity IT approaches to AI development or invest in systematic...


Have We Reached The End of Software Engineering?
By Raimund Laqua, P.Eng The End of Software Engineering? I've spent over three decades practising engineering in both Canada and the...


Why AI Isn't Ready for Commoditization
Technology Life-cycle As I observe the current state of Artificial Intelligence (AI) and the rush surrounding its deployment, I find...


Intelligent Design for Intelligent Systems: Restoring Engineering Discipline in AI Development
The Current Challenge AI systems are increasingly deployed without the systematic design approaches that have proven effective in other...


Which is Better for AI Safety: STAMP/STPA or HAZOP/PHA?
STAMP/STPA and traditional PHA methods like HAZOP represent fundamentally different safety analysis philosophies. STAMP/STPA views...


AI Engineering: The Last Discipline Standing
The software engineering and related domains are undergoing their most dramatic transformation in decades. In discussions I have had over...


AI's Category Failure
When a technology can reshape entire industries, automate critical decisions, and potentially act autonomously in the physical world, how...


Does Your AI Strategy Pass the Ketchup Test?
A simple test to bust through the hype These days, AI providers, leaders, and evangelists claim that AI technology will transform any...


Promise Architectures: The New Guardrails for Agentic AI
As AI systems evolve from simple tools into autonomous agents capable of independent decision-making and action, we face a fundamental...


AI's Most Serious Blindspot and Bias
Working with AI over the past year opened my eyes to a systemic problem: AI systems are stuck in the past. This creates both a serious...


The New Face of AI Assurance: Why Audits and Certifications Are Not Enough
AI Assurance isn't just about checking boxes before deployment. As the European Defence Agency shows us, it's now a continuous journey...


Compliance is Probabilistic
In my three decades as a compliance engineer, I've watched our profession's obsession with check-boxes undermine effective risk...


Why Ethics Makes AI Innovation Better
Ethics in AI is fundamentally an alignment problem between technological capabilities and human values. While discussions often focus on...
bottom of page
