Field guide · 10 lessons · 4 tracks
AI compliance field guide
Short answer
Ten lessons in four tracks, from what an AI GRC platform is to how to test an agent claim in a demo. Each takes 3 to 5 minutes and links to the data behind it.
Track 1: Foundations
Lesson 1 · · 3 min read
What is an AI GRC platform?What compliance automation and AI GRC platforms do, and where AI agents fit.
Lesson 2 · · 3 min read
SOC 2 and ISO 27001: an attestation and a certificationThe two frameworks most buyers start with, and why they are audited differently.
Lesson 3 · · 2 min read
Control cross-mapping and common control frameworksHow one control can satisfy several frameworks, and which vendors describe it.
Track 2: Who does the work
Lesson 4 · · 2 min read
What AI agents do in compliance platformsEvidence, policies, questionnaires and remediation: the tasks vendors say their agents handle.
Lesson 5 · · 2 min read
Human expert models: dedicated expert, Slack access, partnersThree ways vendors put people into the compliance process, and what each means for your team.
Lesson 6 · · 3 min read
The audit path: built-in auditors, networks and bring your ownWho audits you, who arranges it, and the questions to ask about auditor independence.
Track 3: Adding frameworks
Lesson 7 · · 3 min read
Planning framework two and three before you buy for framework oneEntry-plan limits, add-ons and the questions that keep the second framework affordable.
Lesson 8 · · 2 min read
AI governance frameworks: ISO 42001, the EU AI Act and NIST AI RMFThe AI-specific frameworks that increasingly arrive as framework three, and who names them.
Track 4: Buying
Lesson 9 · · 2 min read
Plan limits and quote-based pricing: what vendors publishNo vendor here publishes a price. Here is what they do publish and how to use it.
Lesson 10 · · 2 min read
How to test an AI agent claim in a compliance demoA short script for checking what an agent actually does before you sign.