AIF-C01 notes
Security, compliance, and governance

Compliance Standards for AI Systems

Why governance matters

The story: A restaurant with health certificates on the wall earns customers' trust, can open more branches because each one follows the same standards, and avoids lawsuits and bad press. The landlord has already passed a long list of building and safety inspections, which helps.

In AI/AWS terms: Governance builds trust, lets AI scale, and protects the organization from legal and reputational risk such as bias, privacy violations, and unintended consequences. AWS supports 143 security standards and compliance certifications.

For the exam: AWS supports 143 security standards and compliance certifications.

Standards to recognize

The story: Different certificates for different kinds of kitchens: one for government canteens in the US, one issued by a European agency, an international standard for kitchen practices, an outside inspector's report, one for hospital food, one for how European diners' personal details are handled, and one from the card companies for taking card payments.

In AI/AWS terms:

Kitchen certificateStandardWhat it covers
US government canteensNIST SP 800-53Security controls for US federal information systems: confidentiality, integrity, availability
European agencyENISAThe EU cybersecurity agency. Drafts EU cybersecurity certification schemes
International practicesISO (ISO/IEC 27002)Recommended security management practices and controls
Outside inspector's reportSOC reportsIndependent third-party assessments of AWS controls
Hospital foodHIPAAProtected health information in the US
European diners' detailsGDPRPrivacy of EU citizens' personal data
Card companies' rulesPCI DSSPayment card data, run by a council of card companies

For the exam: Health data = HIPAA. EU personal data = GDPR. Card payments = PCI DSS. US federal systems = NIST SP 800-53. Third-party assessment = SOC.

Why AI compliance is different

The story: Inspecting a regular kitchen is straightforward: follow the recipe, check the temperature. Now imagine a kitchen where the chef invents new dishes every day, can't explain how, keeps changing after the inspection, sometimes discovers a skill nobody taught them, and might serve some customers worse than others. New laws start requiring the restaurant to explain decisions and keep a human in charge.

In AI/AWS terms:

  • Complexity and opacity: hard to audit how an LLM reaches its output.
  • Dynamism and adaptability: models change after deployment, so static standards fit poorly.
  • Emergent capabilities: unexpected abilities that no one designed.
  • Unique risks: algorithmic bias (from biased training data or human bias), privacy, misinformation, job displacement.
  • Algorithm accountability: laws requiring transparency, risk assessment, and human oversight, such as the EU AI Act and New York City's Automated Decision Systems law.

For the exam: AI compliance is harder because models are opaque, change over time, and can show emergent capabilities.

Regulated workloads

The story: Some kitchens are under stricter rules than others: a hospital kitchen, an airline kitchen, a kitchen whose menu decisions affect people's health. Before building one, you ask: will inspectors check this? Do we have to keep our records for years? Does each meal ticket count as an official record? Are we storing customers' home addresses?

In AI/AWS terms: A workload is regulated when it must meet a framework like HIPAA, GDPR, or PCI DSS, or has regulated processes, outcomes (mortgage and credit decisions), usage (safety-critical systems), or liabilities. Common industries: financial services, healthcare, aerospace. Examples: HR, safety, and inspection workloads.

Questions to ask:

  • Do you need to audit this workload?
  • Do you need to archive the data for a period of time?
  • Will the model's predictions count as a record?
  • Does the source data include classifications restricted by internal governance, such as customer addresses?

For the exam: For a regulated workload, ask about auditing, archiving, predictions as records, and restricted data.

On this page