AI agent blueprints for Compliance & Audit.
Control workflows that preserve source references and human attestation while organizing evidence and exceptions. Each pattern defines the evidence it reads, the artifacts it produces, the authority it may exercise, and the human who makes the consequential decision.
Compliance, internal audit, risk, and control-owner teams
compliance owner
private · read/propose · human-gated
Nine jobs with a crisp acceptance test.
These are implementation patterns, not generic “AI for Compliance & Audit” pages. Open one to see its exact trigger, topology, grants, approval boundary, failure modes, and KPI.
Control evidence collection
Map a control request to approved sources, collect a bounded evidence packet, and flag missing attestations.
evidence requests accepted first pass
Audit request response
Translate an audit request into attributes, sources, owners, and an approved response packet without over-answering scope.
audit response turnaround
Policy-to-control mapping
Map approved policy statements to controls and evidence expectations, highlighting unsupported or orphaned requirements.
unmapped policy requirements
Access control sample preparation
Select or ingest an approved sample and assemble entitlement, approval, and change evidence for control testing.
sample evidence preparation time
Vendor compliance evidence follow-up
Track required vendor artifacts, expiry, gaps, and approved follow-ups without asserting control coverage prematurely.
overdue vendor evidence
Compliance exception register review
Review exception expiry, ownership, compensating evidence, and remediation status and prepare an escalation queue.
past-due compliance exceptions
AI system logging review
Compare an AI system's documented event capture and retention evidence with an approved control requirement.
AI logging control gaps
Control remediation validation
Compare a control finding and acceptance criteria with current evidence and prepare an independent validation result.
remediations reopened
Regulatory change impact review
Structure an approved regulatory update into changed obligations, affected controls, owners, and counsel questions.
unowned regulatory actions
The workflow is autonomous. The authority is not.
- 01
Attach evidence
Put only this case’s approved inputs in a scoped workspace.
- 02
Run specialists
Each bounded node produces an artifact the next node can challenge.
- 03
Stop at proposal
External writes stay outside the agent’s default authority.
- 04
Record the decision
Keep the human approval as a decision record beside the signed evidence from the agent run.
Pick one expensive, inspectable job.
Start with real evidence, a named decision owner, and a measurable result. Expand the agent only after the receipt and acceptance test prove the workflow holds.