---
title: "Compliance"
description: "4 posts about Compliance, summarised, each linking to the original."
---

# Compliance
> 4 posts about Compliance, summarised, each linking to the original.

## Articles

### [AI Governance Maturity Model: Matrix, Assessment, and Roadmap](https://yomu.fyi/post/ai-governance-maturity-model-matrix-assessment-and-roadmap.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Jun 2, 2026

The AI governance maturity model assesses how deeply governance practices are embedded across an organization’s data, process, and people dimensions, using five stages from Ad Hoc to Optimized. It frames the model as a diagnostic and roadmap for boards and executive sponsors, while a five-dimension matrix separately scores strategy and leadership, policy and ethics, risk management, data governance, and monitoring and observability. The progression moves from discovery and basic ownership through standardized controls, quantified risk, real-time indicators, lineage tracking, and automated, context-aware enforcement. The recommended roadmap starts with a baseline within 30 days, targets Level 3 across the five dimensions within 12 months, runs a 90-day pilot on two or three high-priority systems, then scales effective controls through CI/CD integration and monitoring, with quarterly reviews and annual reassessment.


### [Responsible AI Governance: A Practical Framework for Business Leaders](https://yomu.fyi/post/responsible-ai-governance-a-practical-framework-for-business-leaders.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: May 6, 2026

Responsible AI governance is presented as an operational framework for leaders overseeing systems that can produce biased outputs, expose sensitive data, and create regulatory, financial, or reputational harm. It draws on the NIST AI RMF and OECD AI principles, maps to EU AI Act requirements, and uses human dignity, fairness, privacy, accountability, transparency, and security as governance values. The program starts with a living inventory recording purpose, ownership, training-data sources, affected populations, review dates, model lineage, and third-party status, followed by risk classification and assessments based on potential impact. It calls for lifecycle controls including bias mitigation, security testing, human review, drift monitoring, audits, incident exercises, and confidential concern reporting. The roadmap recommends piloting governance on a highest-risk product line, scaling controls across business units, and reviewing the framework annually or after major incidents, regulatory updates, or portfolio changes.


### [A Modern AI Risk Management Framework](https://yomu.fyi/post/a-modern-ai-risk-management-framework.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Apr 22, 2026

AI systems introduce probabilistic behavior, model drift, adversarial manipulation, bias, and auditability challenges that traditional IT risk practices may not address. The framework described combines NIST AI RMF, EU AI Act, and ISO/IEC 23894:2023, using Govern, Map, Measure, and Manage as its operational structure while recognizing regulatory and societal context. It recommends cross-functional governance, clear risk ownership, an AI-BOM covering systems, data flows, dependencies, and accountability, plus continuous measurement of fairness, explainability, data quality, security vulnerabilities, and harm likelihood and severity. Across the AI lifecycle, the text identifies risks including data poisoning, model drift, malicious library injection, prompt injection, hallucinations, and platform vulnerabilities, and points to the AI RMF Playbook for checklists, timelines, and governance artifacts.


### [Data Governance Platforms: Evaluation & Feature Guide](https://yomu.fyi/post/data-governance-platforms-evaluation-feature-guide.md)
- Company: [Databricks](https://yomu.fyi/company/databricks.md)
- Author: Databricks Staff
- Published: Apr 21, 2026

This guide presents a framework for evaluating data governance platforms for enterprise deployment, distinguishing governance—the policies, roles, and controls for data use—from data management, the operational execution of those policies. It recommends assessing metadata-centered capabilities including continuous data profiling, catalog search and enrichment, end-to-end lineage, RBAC and ABAC, sensitive-data detection, masking, audit trails, compliance reporting, and data-subject request workflows. Vendor assessment should also cover pre-built connectors, REST APIs and SDKs, near-real-time metadata synchronization, schema-drift handling, cross-cloud federation, usability, support, implementation timelines, and three-to-five-year total cost of ownership. The proposed decision process selects three leading candidates, pilots them with representative structured and unstructured datasets, defines quality, lineage, adoption, and exit metrics, and uses executive review before procurement; governance is framed as an ongoing program that expands with AI workloads and regulatory change.
