compliance

Designs and implements policies, controls, processes, and monitoring mechanisms to ensure systems and organizational activities adhere to applicable laws, regulations, standards, contracts, and internal policies. Builds documentation, evidence, and audit/reporting workflows and analyzes audit findings and compliance risk to remediate gaps and demonstrate conformance.

compliance

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-2.17
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$190K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Reviewing Uses of Regulatory Compliance Monitoring

Dec 06, 2024
FK
F. Klessascheck
🏛️ Technical University of Munich | Weizenbaum Institute

This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)

Identifies manual steps and research gaps in compliance monitoringInvestigates techniques for monitoring regulatory compliance in business processesReviews application and results of compliance checking methods

A Task Taxonomy for Conformance Checking

Jul 16, 2025
JR
Jana-Rebecca Rehse

Existing visualization tools for compliance checking lack systematic characterization of analytical tasks, hindering rigorous effectiveness evaluation. This paper introduces the first multidimensional task taxonomy specifically designed for compliance checking, modeling core trace-to-model alignment tasks in process mining along six dimensions: objective, method, constraint type, data characteristics, data target, and cardinality. Crucially, this taxonomy explicitly links the semantic requirements of compliance checking with established visual analytics design principles—thereby bridging the semantic gap between process mining and visual analytics. It provides a reusable theoretical framework to rigorously define visualization purposes, evaluate tool effectiveness, and support co-design of analysis systems. As a result, the interpretability and practical utility of complex compliance analysis outcomes are significantly enhanced.

Clarify purposes of diverse conformance checking visualizations.Classify tasks in conformance checking analyses.Enable systematic evaluation of visualization usefulness.

Towards Enforcing Company Policy Adherence in Agentic Workflows

Jul 22, 2025
NZ
Naama Zwerdling
🏛️ IBM Research

Large language model (LLM) agents exhibit unreliable adherence to corporate policies in business process automation. To address this, we propose a deterministic, transparent, and modular policy compliance framework comprising two phases: (1) an offline phase that compiles natural-language policy documents into verifiable guard code, and (2) a runtime phase that inserts lightweight, policy-agnostic guards before tool invocation—thereby decoupling policy enforcement from agent logic. This design enhances interpretability, maintainability, and agility in policy updates. Experiments on the τ-bench Airlines testbed demonstrate the framework’s effectiveness in intercepting policy-violating actions, validating its feasibility. However, empirical evaluation also uncovers critical deployment challenges, including incompleteness in policy coverage and difficulties in dynamically adapting guards to contextual changes. The framework thus advances policy-aware LLM agent deployment while surfacing key open issues for future work.

Compiling policies into verifiable guard code for toolsEnforcing company policy adherence in LLM agent workflowsEnsuring compliance before agent actions at runtime

Mining Constraints from Reference Process Models for Detecting Best-Practice Violations in Event Log

Jul 02, 2024
AR
Adrian Rebmann
🏛️ University of Mannheim | SAP Signavio | University of Koblenz

Event logs often lack formal process models, hindering compliance checking. Method: This paper proposes a declarative, model-free approach to automatically mine and adapt best-practice constraints from multi-source reference process models. It introduces (i) automated extraction of transferable constraints based on LTL/Declare templates; (ii) a log-driven relevance scoring mechanism to dynamically select semantically matched constraint subsets; and (iii) lightweight compliance assessment via multi-model aggregation and violation detection. Contribution/Results: Experiments on real-world model repositories and event logs demonstrate that the method significantly improves detection rates of best-practice violations, reduces modeling effort, and enables cross-organizational, quantitative analysis of process health.

Automatically selecting constraints relevant to event logsDetecting best-practice violations without dedicated modelsMining declarative constraints from reference process models

Latest Papers

What's happening recently
View more

Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.

autonomous enterprise agentscompliance-aware behaviorgeneralist agents

This work addresses the limitations of existing end-to-end large-model approaches in organizational policy compliance review, which implicitly encode policy logic, thereby hindering system inspection, updating, and testing. To overcome this, the authors propose PolicyGuard, a neurosymbolic framework that decouples policy formalization, localized document parsing, and symbolic compliance evaluation for the first time. PolicyGuard leverages large language models to extract local evidential fragments from documents and combines them with typed relational logical rules to perform explicit symbolic reasoning. Deployed successfully in enterprise non-disclosure agreement (NDA) compliance review, the framework significantly enhances the transparency, maintainability, and testability of the compliance process, effectively identifying inconsistencies between contractual clauses and organizational negotiation policies, thus demonstrating its systematic advantages and practical utility.

compliance evaluationdocument reviewneuro-symbolic

This work addresses the semantic gap faced by current AI agents in enforcing natural language policies: the intended policy semantics are difficult to enforce precisely and interpretably at the system level. To bridge this gap, the authors propose a novel approach that integrates agent-side context with kernel-level enforcement mechanisms. For the first time, policy context is preserved on the agent side, while a domain-specific language (DSL) for information flow control (IFC), implemented via eBPF, enables comprehensive, action-level policy enforcement within the operating system kernel. This framework supports cross-event data-flow and ordering constraints, significantly improving policy compliance rates by covering indirect execution paths invisible to conventional tool-call interception. The system incurs only 1.9%–8.4% runtime overhead and provides semantically clear feedback instead of ambiguous errors.

AI agentsinformation-flow controlpolicy enforcement