Regulatory coverage

Evidence of enforcement, not a description of intent.

Compliance programs for AI keep running into the same wall: the policies are written, and there is no runtime record showing they were applied. FaburAI is on the other side of that wall.

The honest position

No software makes you compliant.

Compliance is an organizational program involving people, process and documentation. What software can do is produce the evidence that program stands on — and for AI systems, that evidence has to come from runtime, because that is the only place it exists.

FaburAI produces four artifacts, and they are generated by the act of enforcement rather than written afterward. Mapping them onto the obligations you are actually being held to is work we would rather do with you early than have you discover a gap in the middle of an assessment.

What FaburAI produces

Four artifacts, generated by the work itself.

An inventory that is current

What AI systems exist, what each can reach down to the column, and which callers have appeared — discovered continuously rather than declared. Almost every obligation starts with being able to enumerate the estate.

A decision record per call

Which actor, acting for which user role, reached what, the outcome, and the rule that produced it. Recorded because enforcement happened, not because a report was scheduled.

The approval trail

Which rule was approved, by whom, and when — enforced structurally, because a rule that has not been approved cannot govern traffic at all.

Per-decision explainability

The conditions evaluated for a decision, which matched and which did not, and the ability to replay a past decision against current policy to see whether the answer changed.

Frameworks

The same records serve several regimes.

The artifacts are framework-neutral. What differs between regimes is which obligation each one answers, so the mappings are set out separately rather than blended together.

Other regimes the same artifacts support
ProgramWhat the runtime record contributes
SOC 2Access decisions with the rule that produced them, and the approval trail behind each rule.
GDPRWhich AI actors reached personal data, on whose behalf, through which operation. Columns carrying personal data are labeled at discovery.
HIPAAThe same, for health information, with column-level labels applied as the estate is discovered.
SOXEnforced separation between roles and the financial data AI systems may reach, evidenced per call.
Boundaries

What you will need other things for.

Worth stating plainly, because a governance layer that appears to cover an entire regulation is not one anybody should rely on.

  • Training-data quality, bias testing and fairness metricsYour MLOps and model evaluation practice. We govern what a model’s agents may reach, not how the model was trained.
  • Formal technical documentation generationYour GRC platform or counsel. We supply the inventory and decision records that documentation cites.
  • Fundamental-rights and privacy impact assessmentYour privacy and legal function. Our catalog shows which AI systems reach which categories of personal data, which is usually the hard input.
  • Regulator registration and incident notificationYour compliance function and its case management. We hold the underlying record; the workflow is theirs.
  • Model output accuracy and answer qualityYour evaluation harness. It checks whether the answer was good; we govern what the system was permitted to use to produce it.
  • End-user disclosure and marking of AI-generated contentYour product and application teams, at the point of delivery.
  • Anomaly detection and incident severity scoringYour detection and response tooling. Decision records are exportable, so they can feed whatever already aggregates and correlates your security telemetry.

Every line above is a reason we integrate rather than replace. We are glad to work alongside the tools and partners already in your compliance program — and where a handoff between us and one of them is awkward, we would like to hear about it, because that is usually something we can fix.

Talk to us

Start from what your auditors actually ask for.

The most useful conversation is usually about a specific request you have already received and could not answer easily.