Skip to content

Compliance Packs

Compliance Packs are pre-built sets of CHAM policies designed to align your AI governance with specific regulatory frameworks.

Overview

Configuring governance policies from scratch for every regulatory requirement is time-consuming and error-prone. Compliance Packs give you a head start by providing curated policy sets mapped to the requirements of major compliance frameworks. Apply a pack with one click and get immediate governance coverage for a specific regulation.

Available Packs

HIPAA -- 8 Policies

For organizations handling protected health information (PHI):

PolicyPurpose
PHI Access ControlRestricts which agents can access PHI-related services
Minimum NecessaryEnforces minimum necessary data access principle
Audit LoggingEnsures all PHI-related actions are fully logged
Encryption RequirementBlocks actions that would transmit PHI without encryption
Access RevocationEnforces immediate grant revocation on deauthorization
Breach Notification TriggerFlags potential breach scenarios for immediate review
Business Associate CheckValidates third-party service authorization
Data Retention LimitEnforces data retention windows on stored PHI

SOC 2 -- 10 Policies

For organizations pursuing or maintaining SOC 2 compliance:

PolicyPurpose
Change ManagementRequires approval for production changes
Access ReviewEnforces periodic access grant reviews
Incident ResponseTriggers alerts on anomalous governance events
Logical Access ControlRestricts actions based on agent role and scope
Data ClassificationEnforces handling rules based on data sensitivity
Monitoring and AlertingEnsures continuous governance monitoring
Vendor ManagementValidates actions targeting third-party services
Encryption in TransitBlocks unencrypted outbound data actions
Availability SLARate limits to prevent agent-caused outages
Audit Trail IntegrityEnforces hash chain verification schedules

GDPR -- 9 Policies

For organizations processing data of EU residents:

PolicyPurpose
Lawful Basis CheckRequires documented lawful basis for data processing
Data MinimizationRestricts data collection to stated purposes
Right to ErasureSupports data deletion action workflows
Consent VerificationValidates consent before processing personal data
Cross-Border TransferBlocks transfers to non-adequate jurisdictions without safeguards
Data Protection ImpactFlags high-risk processing for DPIA review
Breach NotificationTriggers 72-hour notification workflow on detection
Record of ProcessingMaintains processing activity records
Purpose LimitationBlocks actions that use data beyond stated purposes

FINRA + SOX -- 8 Policies

For financial services organizations:

PolicyPurpose
Trade SurveillanceMonitors agent actions involving trade execution
Communication ArchiveEnsures all outbound communications are archived
Segregation of DutiesPrevents single agents from executing conflicting actions
Material Change ControlRequires multi-level approval for material changes
Financial Data IntegrityValidates data accuracy for financial reporting actions
Insider Trading PreventionBlocks actions during restricted trading windows
Regulatory ReportingEnsures timely filing of required reports
Record RetentionEnforces retention schedules for governed financial actions

EU AI Act -- 9 Policies

For organizations deploying AI within EU jurisdiction:

PolicyPurpose
Risk ClassificationClassifies agent actions by EU AI Act risk categories
High-Risk OversightEnforces human oversight for high-risk AI operations
TransparencyRequires disclosure when AI is acting autonomously
Technical DocumentationValidates that actions reference documented AI systems
Conformity AssessmentTriggers assessment workflow for new agent registrations
Prohibited Practice BlockBlocks actions classified as prohibited under the Act
Bias DetectionFlags actions with potential discriminatory outcomes
Post-Market MonitoringEnsures ongoing monitoring of deployed AI actions
Incident ReportingTriggers reporting workflow for serious AI incidents

NIST AI RMF -- 7 Policies

Aligned with the NIST AI Risk Management Framework:

PolicyPurpose
Risk IdentificationTags actions with identified AI risk categories
Impact AssessmentRequires impact analysis for high-consequence actions
Continuous MonitoringEnforces ongoing governance telemetry
Accountability AssignmentRequires named responsible party for governed actions
Bias and FairnessFlags actions for fairness review
ExplainabilityRequires governance reasoning for all decisions
Lifecycle GovernanceEnforces governance across the full AI lifecycle

Applying a Compliance Pack

  1. Navigate to Compliance Packs in the sidebar
  2. Select the pack you want to apply
  3. Review the policies that will be created
  4. Click Apply Pack
  5. The policies are created in an active state and immediately begin governing actions

TIP

You can apply multiple packs. If two packs contain overlapping policies, the more restrictive policy takes precedence. Review applied policies after applying multiple packs to check for any conflicts.

WARNING

Compliance packs provide a strong starting point but are not a substitute for legal and compliance review. Each pack is designed to map to the regulatory framework's requirements, but your organization's specific implementation may require additional policies or configuration adjustments.

Customizing Pack Policies

After applying a pack, all created policies are fully editable. You can:

  • Adjust thresholds and configuration values
  • Deactivate policies that do not apply to your use case
  • Add supplemental policies for requirements unique to your organization

AI Governance for Every Organization