Score
Designs, implements, and evaluates organizational and technical compliance programs and controls to meet formal regulations and standards such as the EU AI Act, GxP frameworks, ISO 21434, ISO 26262, and SOX. Work includes requirements mapping and gap analysis, specification and deployment of process and system controls, documentation and evidence generation, control testing and remediation, and establishment of governance, monitoring, and audit‑ready processes.
This study addresses the absence of concrete mapping mechanisms for implementing the EU AI Act within agile teams. Employing a Design Science Research methodology, this work proposes a novel framework that translates abstract regulatory requirements into actionable agile compliance guidelines. Through a traffic light taxonomy and expert interviews, an action catalog comprising twelve practices covering roles and risk management was constructed. The results demonstrate that these guidelines are both comprehensible and relevant, establishing that compliance should be integrated into existing agile activities rather than treated as a parallel process. Ultimately, this research bridges the gap in regulatory operationalization, providing a reusable methodological foundation that enables agile teams to achieve compliance without compromising iterative efficiency.
This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)
本文针对欧盟AI法案在生成式AI系统中的技术缺口,提出了一种名为Governance-as-Code的框架,通过CI/CD管道实现自动化合规检查。
This study addresses the challenge small and medium-sized enterprises face in translating EU AI Act compliance requirements into engineering practice by presenting the first systematic empirical evaluation of twelve mainstream compliance-checking tools. Employing multi-dimensional feature characterization, legal alignment analysis, and structured report assessment, this work comprehensively examines the tools’ legal coverage and result actionability. The findings reveal significant quality disparities among existing tools, indicating their suitability is largely confined to early-stage compliance orientation while posing risks of false compliance. By establishing a critical benchmark in this domain, this research exposes current tool limitations and proposes design principles for reliable compliance instruments, thereby charting a clear direction for future optimization efforts.
This paper addresses the regulatory compliance challenges faced by edge AI systems under frameworks such as the EU Artificial Intelligence Act, with a focus on dataset compliance as a critical bottleneck. Methodologically, it integrates regulatory mapping analysis, edge-computing–constrained modeling, data governance assessment, and AI lifecycle auditing to systematically identify prevalent compliance barriers across development, deployment, and operation phases. Its primary contributions are threefold: (1) the first end-to-end legal compliance framework specifically designed for edge AI; (2) the formal establishment of dataset compliance as the technical and ethical foundation for trustworthy, transparent, and explainable AI; and (3) the deep integration of ethical requirements into technical implementation pathways. The resulting artifact is a practical, actionable best-practice guideline that enables responsible deployment of embedded AI systems and facilitates regulatory alignment and collaboration.
This work addresses the error-prone and labor-intensive process of manually translating regulatory texts such as the GDPR and the EU AI Act into actionable software requirements. The authors propose Reg2Req, the first end-to-end automated pipeline that leverages natural language processing to identify regulatory provisions, generate system-agnostic software requirements accompanied by plain-language explanations, and establish traceability links. The approach supports requirement classification, use case seed generation, and cross-reference analysis, achieving macro-averaged F1 scores of 0.82 on the GDPR and 0.78 on the EU AI Act. A user study demonstrates that the generated plain-language explanations significantly enhance users’ comprehension and confidence in taking compliance actions (p < 0.001), with all participants expressing willingness to adopt the output as a starting point for compliance efforts.
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
本文提出一种模型,通过设计科学研究方法解决在软件工程中选择大型语言模型时面临的治理与合规难题,采用多层结构和评估协议以增强决策过程中的合规性。
This study addresses a critical gap between compliance and effectiveness in current auditing standards—such as ASB 018—whose reliance on ambiguous language and undefined terminology obscures the potential risks associated with the use of probabilistic genotyping software in criminal justice. Through a qualitative content analysis comparing the standard’s text with five real-world audit reports, this work demonstrates for the first time that audits deemed compliant often fail to delineate the boundaries of software application. The research attributes this disconnect to structural deficiencies in the standard itself and offers concrete recommendations for revising auditing frameworks and evaluating their practical efficacy. These contributions provide both theoretical insight and actionable guidance for enhancing the governance of forensic technologies within the justice system.
This study addresses widespread compliance issues in GitHub Actions workflows, such as excessive permissions and weak secret management. It proposes the first documentation-driven compliance checking framework, which derives a 30-item checklist from official documentation and implements a hybrid auditing pipeline combining large language models (LLMs) with expert oversight. The authors automatically evaluate 95 real-world Java workflows using four open-source LLMs, employ GPT-5 as a conflict arbitrator, and integrate manual review into a multi-tiered validation system. Experimental results reveal an overall compliance rate of only 28%, with permission control as low as 4%. The proposed approach reduces manual verification effort by 81% while achieving 87% agreement with expert judgments, significantly enhancing audit efficiency and reproducibility.