regulatory compliance mapping

Designs, builds, and maintains structured mappings and data models that translate laws, regulations, and policy obligations into specific technical and organizational controls, system requirements, and accountability assignments. Analyzes and monitors regulatory landscapes, produces compliance documentation and forecasts regulatory change impacts to keep controls and requirements aligned and auditable.

regulatorycompliancemapping

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
1.43
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$209K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the challenges posed by the proliferation, complexity, and expanding scope of regulatory requirements in software engineering, which hinder their systematic integration into development processes. To tackle this issue, the paper proposes a viewpoint-centered, artifact-based approach to regulatory requirements engineering. The approach innovatively integrates viewpoint analysis with artifact modeling to develop the AM4RRE (Artifact Modeling for Regulatory Requirements Engineering) framework, which facilitates cross-functional collaboration and ensures consistency in compliance-driven design. Preliminary validation demonstrates that AM4RRE effectively bridges the gap between organizational regulatory processes and software development practices, enabling a shift from ad hoc compliance responses toward systematic integration. This foundational work paves the way for further empirical investigation into scalable and sustainable regulatory compliance in software engineering.

compliance by designregulatory compliancerequirements engineering

Reviewing Uses of Regulatory Compliance Monitoring

Dec 06, 2024
FK
F. Klessascheck
🏛️ Technical University of Munich | Weizenbaum Institute

This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)

Identifies manual steps and research gaps in compliance monitoringInvestigates techniques for monitoring regulatory compliance in business processesReviews application and results of compliance checking methods

This work addresses the error-prone and labor-intensive process of manually translating regulatory texts such as the GDPR and the EU AI Act into actionable software requirements. The authors propose Reg2Req, the first end-to-end automated pipeline that leverages natural language processing to identify regulatory provisions, generate system-agnostic software requirements accompanied by plain-language explanations, and establish traceability links. The approach supports requirement classification, use case seed generation, and cross-reference analysis, achieving macro-averaged F1 scores of 0.82 on the GDPR and 0.78 on the EU AI Act. A user study demonstrates that the generated plain-language explanations significantly enhance users’ comprehension and confidence in taking compliance actions (p < 0.001), with all participants expressing willingness to adopt the output as a starting point for compliance efforts.

AI regulationlegal text processingregulatory compliance

Representing Normative Regulations in OWL DL for Automated Compliance Checking Supported by Text Annotation

Apr 08, 2025
IB
Ildar Baimuratov
🏛️ L3S Research Center | Leibniz University Hannover | ITMO University

To address the inefficiency and error-proneness of manual regulatory compliance checking, this paper proposes an OWL DL formalization method for natural language specifications. The method introduces a novel structured text annotation scheme and employs a rule-driven deterministic transformation algorithm to automatically map specification texts to OWL DL ontologies. It further integrates Protégé with the HermiT reasoner to enable machine-readable semantic representation and automated compliance verification. A proof-of-concept evaluation in the construction domain demonstrates successful translation of multiple natural language regulations into OWL DL ontologies and accurate identification of compliant and non-compliant scenarios. This work bridges a critical gap between regulatory semantic modeling and automated reasoning, delivering a scalable, methodology-driven foundation for automating compliance checking.

Automating compliance checking using OWL DL representationReducing manual effort and errors in regulation adherenceTransforming text annotations into machine-readable OWL DL code

This study addresses the compliance challenges faced by data practitioners in machine learning systems under regulations such as the GDPR and the AI Act, particularly concerning data quality. Through semi-structured interviews with practitioners in the European Union, combined with thematic analysis of regulatory texts and engineering workflows, the research systematically uncovers a structural disconnect between regulation-driven data quality requirements and ML engineering practices. It identifies five core challenges: misalignment between legal principles and engineering implementation, fragmented data pipelines, lack of purpose-built compliance tools, ambiguous accountability, and reactive responses to audits. Building on these findings, the work proposes directions for designing compliance-oriented tooling, establishing effective governance mechanisms, and fostering cultural transformation to bridge the gap between regulatory mandates and practical ML development.

AI Actdata qualityGDPR

Latest Papers

What's happening recently
View more

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

Current AI systems rely heavily on manual auditing and documentation, which hinders scalable governance for automated services. This work proposes Ontological Knowledge Blocks (OKBs), a novel framework that formalizes regulatory obligations as quintuples comprising ontologies, SHACL rules, evidence requirements, and provenance links. By leveraging RDF/OWL modeling, PROV-O for provenance tracking, and an intermediate representation–driven deterministic compiler, the approach enables dynamic switching of governance configurations without modifying service code. Evaluation in an AI-assisted HPC scheduling scenario demonstrates that compliance checks are configuration-sensitive, violations accumulate strictly additively, SHACL validation incurs only 12.6–100.3 milliseconds of latency, and the Combined configuration provides the most comprehensive coverage.

AI governanceautomated verificationcompliance

This study addresses critical challenges faced by regulated enterprises—including cross-system data inconsistencies, reconciliation difficulties, asset record drift, and overreliance on manual audits—by proposing the GERA framework. GERA innovatively integrates deterministic reconciliation, robust anomaly detection based on Z-Score and its variants, governance-driven semantic standardization, and NIST CSF 2.0 security controls within a four-layer architecture comprising ingestion, staging, core modeling, and semantic services. Empirical validation across banking, broadband service providers, and technology firms demonstrates that the framework significantly enhances reconciliation automation and audit readiness, effectively mitigating 39% of compliance deficiencies identified during PCAOB inspections.

Audit ReadinessCross-System ReconciliationData Fragmentation

Hot Scholars

SC

Stephen Casper

PhD student, MIT
AI safetyAI responsibilityred-teamingrobustness
KM

Kristof Meding

University of Tübingen
Research Group Lead for Computational Law
AC

Aaron Ceross

Ministry of Justice, United Kingdom
data sciencelegal informaticsnatural language processingregulatory science
FB

Fazl Barez

University of Oxford
AI SafetyExplainabilityInterpretabilityAI Governance and Policy
ZP

Zoe Porter

University of York
Ethics of AIPhilosophy of AIAutonomous SystemsAssurance