Regulatory Mapping Tool
When to activate
When identifying applicable regulations for AI systems, designing regulatory compliance controls, mapping specific regulatory requirements to operational procedures, assessing compliance gaps, or preparing for regulatory audits.
When NOT to use
For legal advice or formal regulatory interpretation. This skill is for operational mapping: identifying which rules apply and designing compliance controls. For regulatory questions, consult qualified legal counsel.
Instructions
Regulatory Mapping Process
Define System Scope
- Model name and business use case
- Geographic scope: Where is model deployed? (US, EU, China, Canada, etc.)
- Industry: What sector? (Finance, Healthcare, Employment, Consumer, etc.)
- User/affected population: Employees, customers, vulnerable groups?
- Decision type: Consequential (loan, hiring, medical) or advisory (recommendation)?
Identify Applicable Regulations
Use this framework to identify relevant regulations:
Jurisdiction-Based:
- EU: GDPR, AI Act, sector-specific (ePrivacy, financial regulations, healthcare)
- US: FTC Act, FCRA, HIPAA, EEOC employment rules, NIST AI RMF guidance, state laws (CCPA, etc.)
- Global: Consider where data flows, where model is deployed
Industry-Specific:
- Finance: SEC disclosure rules, FINRA, banking regulations, Fair Lending laws (FCRA, ECOA)
- Healthcare: HIPAA, FDA (if medical device), state licensing boards
- Employment: Title VII, EEOC guidance, state hiring laws, anti-discrimination rules
- Consumer Protection: FTC Act, CCPA, state consumer protection laws
- Automated Decision-Making: AI Act (EU), state algorithmic transparency laws
Risk-Based:
- High-stakes decisions: Additional scrutiny (hiring, credit, criminal justice)
- Vulnerable populations: Children, elderly, low-income require heightened protection
- PII/sensitive data: GDPR, CCPA, HIPAA, state privacy laws
Decision type-based:
- Consequential (deny/approve decisions): Fair lending, employment discrimination, due process rules apply
- Ranking/scoring: Transparency and explainability requirements
- Advisory: Fewer compliance requirements but still governance needed
Map Regulatory Requirements to Specific Controls
For each applicable regulation, identify specific requirements:
Example: GDPR Requirements
| Article |
Requirement |
Operational Control |
| Article 5(1)(a) |
Lawful processing |
Document lawful basis (consent, legitimate interest, contract, etc.); evidence of compliance |
| Article 5(1)(b) |
Specified purpose |
Define AI system purpose in documentation; do not use for unrelated purposes |
| Article 5(1)(c) |
Data minimization |
Use only features necessary for model purpose; justify each feature |
| Article 5(1)(f) |
Security |
Encrypt PII; access controls; breach notification plan |
| Article 13/14 |
Transparency |
Privacy notice to users explaining model and data use |
| Article 22 |
Right to explanation |
Provide explanation of model decisions when consequential |
| Article 35 |
DPIA |
Conduct Data Protection Impact Assessment for high-risk processing |
| Article 37 |
DPO |
Appoint Data Protection Officer if processing requires |
Example: AI Act Requirements (EU) - High-Risk Systems
| Requirement |
Operational Control |
| Risk classification |
Classify model as prohibited, high-risk, or low-risk; document assessment |
| Technical documentation |
Maintain complete documentation of training, testing, deployment |
| Conformity assessment |
Third-party assessment required for high-risk systems |
| Quality management |
Implement QMS for AI development and monitoring |
| Bias and fairness monitoring |
Establish metrics and monitoring for discrimination |
| Transparency and user info |
Disclose that AI is making decisions; explain how it works |
| Human oversight |
Establish mechanisms for human review of decisions |
| Record-keeping |
Maintain audit logs and decision records for 3 years |
Example: FCRA Requirements (US Fair Lending)
| Requirement |
Operational Control |
| Permissible purpose |
Ensure model used only for credit decisions (not other purposes) |
| Adverse action notice |
When credit is denied, provide notice explaining why; right to dispute |
| Dispute procedures |
Establish process for consumers to dispute model decisions and correct data |
| Accuracy |
Validate training data accuracy; monitor model for errors |
| Non-discrimination |
Ensure model does not discriminate based on protected class (race, gender, age, etc.) |
Example: EEOC Guidance on AI in Hiring (US)
| Requirement |
Operational Control |
| Disparate impact analysis |
Monitor hiring outcomes by protected class (race, gender, age) |
| Transparency |
Job applicants informed that AI is used in hiring; high-performing candidates subject to human review |
| Validation |
Ensure model predicts job performance; establish baseline (human hiring performance) and compare |
| Record-keeping |
Maintain records of hiring decisions, model inputs, outcomes by protected class for 1+ years |
| Reasonable accommodation |
Process for applicants to request accommodations if AI excludes them |
Assess Compliance Gaps
For each requirement, evaluate:
- Is control currently implemented? (Yes/No/Partial)
- What evidence exists? (Policy, procedure, audit trail, logs)
- What is the gap? (Missing, undocumented, untested)
- What is the risk if not addressed? (Regulatory enforcement, litigation, reputational)
Gap Assessment Template:
| Regulation |
Requirement |
Current Status |
Evidence |
Gap |
Risk Level |
Remediation |
| GDPR |
Lawful basis documented |
Partial |
Consent form signed; not documented in records |
Consent not logged/tracked |
Medium |
Create consent tracking database |
| GDPR |
DPIA completed |
No |
N/A |
No DPIA started |
High |
Conduct DPIA by [Date] |
| AI Act |
Risk classification |
Yes |
Risk assessment completed |
N/A |
Low |
Update quarterly |
| FCRA |
Adverse action notice |
Yes |
Process documented |
Unclear if all denials get notice |
Medium |
Audit process; test with sample |
| EEOC |
Disparate impact analysis |
Partial |
Quarterly monitoring report |
Limited to hiring outcomes; not updated since Q1 |
High |
Establish monthly monitoring dashboard |
Design Compliance Roadmap
Prioritize and sequence remediation:
Priority 1 (Critical - implement before deployment):
- High-risk gaps in critical regulations
- Gaps affecting consequential decisions (loan, hiring, medical)
- Gaps in fairness/anti-discrimination controls
Priority 2 (High - implement within 90 days):
- Medium-risk gaps in core regulations
- Gaps in documentation/transparency
- Gaps in monitoring procedures
Priority 3 (Medium - implement within 6 months):
- Low-risk gaps
- Gaps in less-critical regulations
- Enhancements beyond compliance baseline
Document Regulatory Assessment
Prepare Regulatory Mapping document including:
- Applicable regulations identified
- Regulatory requirements mapped to controls
- Compliance assessment (current state)
- Gaps and risk assessment
- Remediation plan with timeline
- Sign-off by Legal and Compliance
Example
Scenario: US fintech company deploying AI model to predict loan defaults. Model used for pre-approval screening. Model affects both consumer loan applicants and business loan decisions.
# Regulatory Mapping: Loan Default Prediction Model
## 1. System Scope
**Model:** Loan Default Risk Predictor (LDP)
**Business Purpose:** Pre-approval scoring for consumer auto loans and small business lines of credit
**Geographic Scope:** All 50 US states + DC; some international customers (secondary market)
**Affected Parties:** Consumer loan applicants (primary; FCRA protected); business applicants (secondary; less regulated)
**Decision Type:** Consequential (affects loan approval/denial/interest rate)
**Data Scope:** Credit bureau data, bank account data, transaction data
---
## 2. Applicable Regulations - Identified
### Primary (Direct Impact)
**Federal Fair Lending Laws:**
- Fair Credit Reporting Act (FCRA, 15 U.S.C. § 1681)
- Equal Credit Opportunity Act (ECOA, 15 U.S.C. § 1691)
- Fair Housing Act (FHA, 42 U.S.C. § 3601) - if used for mortgage or housing-related credit
- Community Reinvestment Act (CRA) - if depository institution
**Consumer Privacy Laws:**
- Gramm-Leach-Bliley Act (GLBA) - financial privacy rules
- California Consumer Privacy Act (CCPA) - if California customers
- State privacy laws (NY BitLicense, MA requirements, etc.)
**AI/Algorithmic Transparency Laws:**
- NY Local Law 144 (algorithmic accountability; requires notice that AI used in decisions)
- State consumer protection laws (FTC Act enforced by states)
- NIST AI Risk Management Framework (guidance, not binding but increasingly expected)
**Industry Guidance:**
- FDIC/Fed/OCC Fair Lending Guidance (2023)
- EEOC AI Guidance (emerging standards for employment; not directly applicable but principles informative)
### Secondary (Indirect)
**Data Security:**
- State data breach notification laws
- PCI DSS (if credit card data handled)
- FTC Safeguards Rule (for financial institutions)
**International (if applicable):**
- GDPR (if EU customers; less likely for consumer loans but assess)
- UK AI Bill (if UK expansion planned)
---
## 3. Regulatory Requirements Mapped to Controls
### FCRA Compliance (Fair Credit Reporting Act)
| FCRA Requirement | Application to LDP Model | Operational Control Required | Current Status | Gap |
|---|---|---|---|---|
| **Permissible Purpose** | Model must be used ONLY for credit decisions (loan/credit limit/interest rate). Cannot use for marketing, employment, insurance, etc. | Document model's permitted use case; restrict model API access to loan decisions only | Yes — documented in model card | None |
| **Accuracy** | Ensure model training data is accurate; monitor for systematic errors | Validate training data sources; quarterly accuracy audits; retraining pipeline | Partial — accuracy audit not currently scheduled | Medium: Implement quarterly audit schedule |
| **Adverse Action Notice** | When loan is DENIED (or credit terms unfavorable), provide consumer with notice explaining the reason and right to dispute | When model score triggers decline, system must provide adverse action notice (not just model score) | Partial — adverse action sent but insufficient explanation of model factors | Medium: Enhance notice to explain top factors influencing score |
| **Dispute Procedures** | Consumer can dispute accuracy of data/decision; company must reinvestigate | Establish process for loan applicants to dispute model decisions; escalate to human review | No — not currently implemented | High: Critical for compliance; implement dispute intake form and process |
| **Non-Discrimination** | Model cannot discriminate based on protected class (race, color, religion, national origin, sex, marital/family status, age, receipt of public assistance) | Monitor outcomes by protected class; conduct disparate impact analysis; identify proxy variables | Partial — demographic monitoring attempted but incomplete; no disparate impact analysis | High: Implement comprehensive disparate impact testing |
| **Fair Credit Reporting Practices** | Follow FTC guidelines for consumer information use | Privacy notice (privacy policy), consent practices, data security | Yes — privacy policy and consent in place | None |
**FCRA Assessment:** Partial compliance. Critical gaps in dispute procedures and disparate impact analysis.
---
### ECOA Compliance (Equal Credit Opportunity Act)
| ECOA Requirement | Application to LDP Model | Control | Status | Gap |
|---|---|---|---|---|
| **Non-discrimination** | Cannot discriminate based on sex, marital status, age, race, color, religion, national origin, receipt of public assistance, or exercise of consumer rights | Ensure model not trained on protected class features; monitor for proxy discrimination | Partial — no protected class features used explicitly, but proxy risk assessed | Medium: Document proxy variable risk; implement monitoring |
| **Adverse Action Notice** | Similar to FCRA; consumer right to know why credit was denied | See FCRA adverse action notice requirement | Partial | Medium: (same as FCRA) |
| **Appraisal Independence** (if mortgage-related) | Independent appraisals required; model cannot override | Not applicable to auto/business loans | N/A | None |
**ECOA Assessment:** Largely aligned with FCRA compliance. Focus on disparate impact and proxy discrimination.
---
### NY Local Law 144 (Algorithmic Accountability; if customers in NY)
| Requirement | Application to LDP | Control | Status | Gap |
|---|---|---|---|---|
| **Notice** | Notify consumers that automated decision system is used in hiring (not directly applicable to credit but principle is important) | For credit decisions, disclose that AI is used; explain how it works | Partial — privacy policy mentions model but not clear or prominent | Low: Add clear disclosure to loan application and adverse action notice |
| **Annual Bias Audit** | Audit for bias and disparate impact; document findings | Conduct and document annual fairness/bias audit | No — not currently audited | High: Critical for compliance; implement annual audit by [Date] |
| **Data Minimization** | Use only necessary data; justify use of each data source | Document why each data source is used; remove unnecessary features | Partial — features justified but not systematically reviewed | Medium: Conduct feature justification review |
**LL 144 Assessment:** Significant gaps. Not yet compliant; must implement before full deployment.
---
### State Consumer Protection / GLBA (Financial Privacy)
| Requirement | Control | Status | Gap |
|---|---|---|---|
| Privacy notice (what data you collect and how you use it) | Detailed privacy policy; model use disclosed | Yes | None |
| Consent (for some data sharing) | Opt-in consent for sharing with third parties | Yes — privacy policy includes consent mechanism | None |
| Data security (reasonable security measures) | Encryption, access controls, breach notification plan | Partial — encryption in place; access controls limited | Medium: Strengthen access controls |
| Breach notification | Notify affected users if breach occurs | Process documented | None |
---
## 4. Compliance Gaps & Risk Assessment
### High-Risk Gaps (Must remediate before deployment)
**Gap 1: Disparate Impact Analysis**
- **Regulation:** FCRA, ECOA
- **Requirement:** Monitor outcomes for discrimination; ensure model does not have disparate impact
- **Current State:** No systematic monitoring
- **Risk Level:** High — regulatory enforcement risk, litigation risk, reputational risk
- **Remediation:**
1. Conduct baseline disparate impact analysis (identify protected classes; compare outcomes)
2. Establish quarterly monitoring
3. Design mitigation if disparate impact detected (e.g., fairness constraints, manual review threshold)
4. **Timeline:** By [Deployment Date - 4 weeks]; ongoing quarterly
**Gap 2: Dispute Procedures**
- **Regulation:** FCRA
- **Requirement:** Provide process for consumers to dispute decisions
- **Current State:** No documented process
- **Risk Level:** High — direct FCRA violation; regulatory enforcement likely
- **Remediation:**
1. Design dispute intake process
2. Document reinvestigation procedure
3. Train staff on dispute handling
4. Log all disputes and outcomes for audit trail
5. **Timeline:** By [Deployment Date - 2 weeks]; before going live
**Gap 3: Bias Audit Procedures**
- **Regulation:** NY LL 144, FTC guidance
- **Requirement:** Conduct annual bias audit; document findings
- **Current State:** Audit not scheduled; no procedures defined
- **Risk Level:** Medium (regulatory expectation, not yet legal requirement nationally)
- **Remediation:**
1. Define audit scope, methodology, protected classes
2. Schedule annual audit before [Date]
3. Document findings and remediation actions
4. **Timeline:** First audit by [Date + 90 days]; then annually
### Medium-Risk Gaps (Remediate within 90 days of deployment)
**Gap 4: Enhanced Adverse Action Notices**
- **Regulation:** FCRA
- **Requirement:** Notice must explain decision; currently sent but lacks detail
- **Risk Level:** Medium — currently compliant but opportunity to enhance
- **Remediation:** Update notice template to include top 3 model factors; example: "Your application was not approved primarily due to: (1) High debt-to-income ratio, (2) Limited credit history, (3) Recent delinquency. You have the right to..."
- **Timeline:** Implement by [Deployment + 30 days]
**Gap 5: Access Control Enhancement**
- **Regulation:** GLBA, GDPR (if EU customers)
- **Requirement:** Restrict data access; log all access
- **Risk Level:** Medium — security and privacy risk
- **Remediation:** Implement field-level access control; log all credit bureau data access
- **Timeline:** Implement by [Deployment + 90 days]
---
## 5. Regulatory Compliance Status Summary
| Regulation | Critical Requirement | Status | Gap Level | Remediation Timeline |
|---|---|---|---|---|
| FCRA | Adverse action notice | Partial | Medium | Deployment + 30 days |
| FCRA | Dispute procedures | No | High | Before deployment |
| FCRA | Accuracy monitoring | Partial | Medium | Q1 Year 2 |
| FCRA | Permissible purpose | Yes | None | — |
| ECOA | Non-discrimination | Partial | High | Before deployment |
| ECOA | Disparate impact analysis | No | High | Before deployment |
| NY LL 144 | Notice of AI use | Partial | Low | Deployment + 30 days |
| NY LL 144 | Annual bias audit | No | Medium | Deployment + 90 days |
| NY LL 144 | Data minimization | Partial | Low | Deployment + 60 days |
| GLBA | Privacy & consent | Yes | None | — |
| GLBA | Data security | Partial | Medium | Deployment + 90 days |
**Overall Compliance Status:** CONDITIONAL APPROVAL
- **Before Deployment:** Remediate dispute procedures (Gap 2) and disparate impact analysis (Gap 1)
- **By Deployment + 30 days:** Remediate adverse action notices (Gap 4) and AI use disclosure (LL 144)
- **By Deployment + 90 days:** Remediate bias audit (Gap 3), data minimization (Gap 5), access controls (Gap 5)
---
## 6. Regulatory Compliance Roadmap
BEFORE DEPLOYMENT (Critical)
├─ Disparate impact analysis: complete baseline assessment
├─ Dispute procedures: design and document process
├─ Staff training: ensure staff understand FCRA/ECOA requirements
└─ Legal review: final sign-off on compliance posture
DEPLOYMENT + 30 DAYS (High Priority)
├─ Adverse action notice: implement enhanced template with model factors
├─ AI use disclosure: add clear disclosure to loan app and notices
└─ Monitoring dashboard: implement to track outcomes by protected class
DEPLOYMENT + 90 DAYS (Medium Priority)
├─ Bias audit procedures: define and document annual audit process
├─ Access control: implement field-level restrictions and logging
├─ Data minimization: review features; document justification for each
└─ Incident response: finalize procedures for regulatory inquiries
ONGOING (Continuous)
├─ Quarterly: disparate impact monitoring (protected class outcomes)
├─ Quarterly: adverse action audit (sample 10 denials; verify notice provided)
├─ Annually: bias and fairness audit (full assessment)
├─ Continuously: dispute intake and reinvestigation (log all)
└─ Continuously: incident response (escalate any signs of discrimination)
---
## 7. Approvals & Sign-Off
**Regulatory Compliance Assessment completed:** [Date]
- **Legal Counsel:** _____________________ Date: _____ [Confirms regulatory assessment and remediation plan]
- **Compliance Officer:** _____________________ Date: _____ [Confirms compliance roadmap feasible and resourced]
- **Model Owner:** _____________________ Date: _____ [Confirms ability to implement technical controls]
- **Executive Sponsor:** _____________________ Date: _____ [Approves deployment contingent on Gap 1 & 2 remediation]
**Deployment Authorized:** [Date] pending completion of Critical remediation items
**Follow-up Audit Scheduled:** [Date + 120 days]
---
## Regulatory Reference
**Federal:**
- FCRA: 15 U.S.C. § 1681
- ECOA: 15 U.S.C. § 1691
- GLBA: 15 U.S.C. § 6801
- FDIC/Fed/OCC Fair Lending Guidance (2023)
**State:**
- NY LL 144: Local Law 144 (2023)
- CA CCPA: California Consumer Privacy Act (2018)
- MA AI Transparency: "An Act Relative to the Oversight of Artificial Intelligence" (2023)
**International:**
- GDPR: Regulation (EU) 2016/679
- UK AI Bill (pending)
**Guidance:**
- NIST AI Risk Management Framework (2023)
- FTC "Endorsement Guides" for AI recommendations
Regulatory Mapping Checklist
Ensure comprehensive assessment:
Regulatory Identification:
Requirements Mapping:
Gap Assessment:
Compliance Roadmap:
Documentation & Approval:
1---2name: regulatory-mapping-tool3description: Regulatory Mapping Tool4---5# Regulatory Mapping Tool67## When to activate89When identifying applicable regulations for AI systems, designing regulatory compliance controls, mapping specific regulatory requirements to operational procedures, assessing compliance gaps, or preparing for regulatory audits.1011## When NOT to use1213For legal advice or formal regulatory interpretation. This skill is for operational mapping: identifying which rules apply and designing compliance controls. For regulatory questions, consult qualified legal counsel.1415## Instructions1617### Regulatory Mapping Process18191. **Define System Scope**20 - Model name and business use case21 - Geographic scope: Where is model deployed? (US, EU, China, Canada, etc.)22 - Industry: What sector? (Finance, Healthcare, Employment, Consumer, etc.)23 - User/affected population: Employees, customers, vulnerable groups?24 - Decision type: Consequential (loan, hiring, medical) or advisory (recommendation)?25262. **Identify Applicable Regulations**27 28 Use this framework to identify relevant regulations:29 30 **Jurisdiction-Based:**31 - EU: GDPR, AI Act, sector-specific (ePrivacy, financial regulations, healthcare)32 - US: FTC Act, FCRA, HIPAA, EEOC employment rules, NIST AI RMF guidance, state laws (CCPA, etc.)33 - Global: Consider where data flows, where model is deployed34 35 **Industry-Specific:**36 - **Finance:** SEC disclosure rules, FINRA, banking regulations, Fair Lending laws (FCRA, ECOA)37 - **Healthcare:** HIPAA, FDA (if medical device), state licensing boards38 - **Employment:** Title VII, EEOC guidance, state hiring laws, anti-discrimination rules39 - **Consumer Protection:** FTC Act, CCPA, state consumer protection laws40 - **Automated Decision-Making:** AI Act (EU), state algorithmic transparency laws41 42 **Risk-Based:**43 - **High-stakes decisions:** Additional scrutiny (hiring, credit, criminal justice)44 - **Vulnerable populations:** Children, elderly, low-income require heightened protection45 - **PII/sensitive data:** GDPR, CCPA, HIPAA, state privacy laws46 47 **Decision type-based:**48 - **Consequential (deny/approve decisions):** Fair lending, employment discrimination, due process rules apply49 - **Ranking/scoring:** Transparency and explainability requirements50 - **Advisory:** Fewer compliance requirements but still governance needed51523. **Map Regulatory Requirements to Specific Controls**53 54 For each applicable regulation, identify specific requirements:55 56 **Example: GDPR Requirements**57 58 | Article | Requirement | Operational Control |59 |---------|-------------|---|60 | Article 5(1)(a) | Lawful processing | Document lawful basis (consent, legitimate interest, contract, etc.); evidence of compliance |61 | Article 5(1)(b) | Specified purpose | Define AI system purpose in documentation; do not use for unrelated purposes |62 | Article 5(1)(c) | Data minimization | Use only features necessary for model purpose; justify each feature |63 | Article 5(1)(f) | Security | Encrypt PII; access controls; breach notification plan |64 | Article 13/14 | Transparency | Privacy notice to users explaining model and data use |65 | Article 22 | Right to explanation | Provide explanation of model decisions when consequential |66 | Article 35 | DPIA | Conduct Data Protection Impact Assessment for high-risk processing |67 | Article 37 | DPO | Appoint Data Protection Officer if processing requires |68 69 **Example: AI Act Requirements (EU) - High-Risk Systems**70 71 | Requirement | Operational Control |72 |---|---|73 | Risk classification | Classify model as prohibited, high-risk, or low-risk; document assessment |74 | Technical documentation | Maintain complete documentation of training, testing, deployment |75 | Conformity assessment | Third-party assessment required for high-risk systems |76 | Quality management | Implement QMS for AI development and monitoring |77 | Bias and fairness monitoring | Establish metrics and monitoring for discrimination |78 | Transparency and user info | Disclose that AI is making decisions; explain how it works |79 | Human oversight | Establish mechanisms for human review of decisions |80 | Record-keeping | Maintain audit logs and decision records for 3 years |81 82 **Example: FCRA Requirements (US Fair Lending)**83 84 | Requirement | Operational Control |85 |---|---|86 | Permissible purpose | Ensure model used only for credit decisions (not other purposes) |87 | Adverse action notice | When credit is denied, provide notice explaining why; right to dispute |88 | Dispute procedures | Establish process for consumers to dispute model decisions and correct data |89 | Accuracy | Validate training data accuracy; monitor model for errors |90 | Non-discrimination | Ensure model does not discriminate based on protected class (race, gender, age, etc.) |91 92 **Example: EEOC Guidance on AI in Hiring (US)**93 94 | Requirement | Operational Control |95 |---|---|96 | Disparate impact analysis | Monitor hiring outcomes by protected class (race, gender, age) |97 | Transparency | Job applicants informed that AI is used in hiring; high-performing candidates subject to human review |98 | Validation | Ensure model predicts job performance; establish baseline (human hiring performance) and compare |99 | Record-keeping | Maintain records of hiring decisions, model inputs, outcomes by protected class for 1+ years |100 | Reasonable accommodation | Process for applicants to request accommodations if AI excludes them |1011024. **Assess Compliance Gaps**103 104 For each requirement, evaluate:105 - Is control currently implemented? (Yes/No/Partial)106 - What evidence exists? (Policy, procedure, audit trail, logs)107 - What is the gap? (Missing, undocumented, untested)108 - What is the risk if not addressed? (Regulatory enforcement, litigation, reputational)109 110 **Gap Assessment Template:**111 112 | Regulation | Requirement | Current Status | Evidence | Gap | Risk Level | Remediation |113 |---|---|---|---|---|---|---|114 | GDPR | Lawful basis documented | Partial | Consent form signed; not documented in records | Consent not logged/tracked | Medium | Create consent tracking database |115 | GDPR | DPIA completed | No | N/A | No DPIA started | High | Conduct DPIA by [Date] |116 | AI Act | Risk classification | Yes | Risk assessment completed | N/A | Low | Update quarterly |117 | FCRA | Adverse action notice | Yes | Process documented | Unclear if all denials get notice | Medium | Audit process; test with sample |118 | EEOC | Disparate impact analysis | Partial | Quarterly monitoring report | Limited to hiring outcomes; not updated since Q1 | High | Establish monthly monitoring dashboard |1191205. **Design Compliance Roadmap**121 122 Prioritize and sequence remediation:123 124 **Priority 1 (Critical - implement before deployment):**125 - High-risk gaps in critical regulations126 - Gaps affecting consequential decisions (loan, hiring, medical)127 - Gaps in fairness/anti-discrimination controls128 129 **Priority 2 (High - implement within 90 days):**130 - Medium-risk gaps in core regulations131 - Gaps in documentation/transparency132 - Gaps in monitoring procedures133 134 **Priority 3 (Medium - implement within 6 months):**135 - Low-risk gaps136 - Gaps in less-critical regulations137 - Enhancements beyond compliance baseline1381396. **Document Regulatory Assessment**140 141 Prepare Regulatory Mapping document including:142 - Applicable regulations identified143 - Regulatory requirements mapped to controls144 - Compliance assessment (current state)145 - Gaps and risk assessment146 - Remediation plan with timeline147 - Sign-off by Legal and Compliance148149## Example150151**Scenario:** US fintech company deploying AI model to predict loan defaults. Model used for pre-approval screening. Model affects both consumer loan applicants and business loan decisions.152153```154# Regulatory Mapping: Loan Default Prediction Model155156## 1. System Scope157158**Model:** Loan Default Risk Predictor (LDP) 159**Business Purpose:** Pre-approval scoring for consumer auto loans and small business lines of credit 160**Geographic Scope:** All 50 US states + DC; some international customers (secondary market) 161**Affected Parties:** Consumer loan applicants (primary; FCRA protected); business applicants (secondary; less regulated) 162**Decision Type:** Consequential (affects loan approval/denial/interest rate) 163**Data Scope:** Credit bureau data, bank account data, transaction data 164165---166167## 2. Applicable Regulations - Identified168169### Primary (Direct Impact)170171**Federal Fair Lending Laws:**172- Fair Credit Reporting Act (FCRA, 15 U.S.C. § 1681)173- Equal Credit Opportunity Act (ECOA, 15 U.S.C. § 1691)174- Fair Housing Act (FHA, 42 U.S.C. § 3601) - if used for mortgage or housing-related credit175- Community Reinvestment Act (CRA) - if depository institution176177**Consumer Privacy Laws:**178- Gramm-Leach-Bliley Act (GLBA) - financial privacy rules179- California Consumer Privacy Act (CCPA) - if California customers180- State privacy laws (NY BitLicense, MA requirements, etc.)181182**AI/Algorithmic Transparency Laws:**183- NY Local Law 144 (algorithmic accountability; requires notice that AI used in decisions)184- State consumer protection laws (FTC Act enforced by states)185- NIST AI Risk Management Framework (guidance, not binding but increasingly expected)186187**Industry Guidance:**188- FDIC/Fed/OCC Fair Lending Guidance (2023)189- EEOC AI Guidance (emerging standards for employment; not directly applicable but principles informative)190191### Secondary (Indirect)192193**Data Security:**194- State data breach notification laws195- PCI DSS (if credit card data handled)196- FTC Safeguards Rule (for financial institutions)197198**International (if applicable):**199- GDPR (if EU customers; less likely for consumer loans but assess)200- UK AI Bill (if UK expansion planned)201202---203204## 3. Regulatory Requirements Mapped to Controls205206### FCRA Compliance (Fair Credit Reporting Act)207208| FCRA Requirement | Application to LDP Model | Operational Control Required | Current Status | Gap |209|---|---|---|---|---|210| **Permissible Purpose** | Model must be used ONLY for credit decisions (loan/credit limit/interest rate). Cannot use for marketing, employment, insurance, etc. | Document model's permitted use case; restrict model API access to loan decisions only | Yes — documented in model card | None |211| **Accuracy** | Ensure model training data is accurate; monitor for systematic errors | Validate training data sources; quarterly accuracy audits; retraining pipeline | Partial — accuracy audit not currently scheduled | Medium: Implement quarterly audit schedule |212| **Adverse Action Notice** | When loan is DENIED (or credit terms unfavorable), provide consumer with notice explaining the reason and right to dispute | When model score triggers decline, system must provide adverse action notice (not just model score) | Partial — adverse action sent but insufficient explanation of model factors | Medium: Enhance notice to explain top factors influencing score |213| **Dispute Procedures** | Consumer can dispute accuracy of data/decision; company must reinvestigate | Establish process for loan applicants to dispute model decisions; escalate to human review | No — not currently implemented | High: Critical for compliance; implement dispute intake form and process |214| **Non-Discrimination** | Model cannot discriminate based on protected class (race, color, religion, national origin, sex, marital/family status, age, receipt of public assistance) | Monitor outcomes by protected class; conduct disparate impact analysis; identify proxy variables | Partial — demographic monitoring attempted but incomplete; no disparate impact analysis | High: Implement comprehensive disparate impact testing |215| **Fair Credit Reporting Practices** | Follow FTC guidelines for consumer information use | Privacy notice (privacy policy), consent practices, data security | Yes — privacy policy and consent in place | None |216217**FCRA Assessment:** Partial compliance. Critical gaps in dispute procedures and disparate impact analysis.218219---220221### ECOA Compliance (Equal Credit Opportunity Act)222223| ECOA Requirement | Application to LDP Model | Control | Status | Gap |224|---|---|---|---|---|225| **Non-discrimination** | Cannot discriminate based on sex, marital status, age, race, color, religion, national origin, receipt of public assistance, or exercise of consumer rights | Ensure model not trained on protected class features; monitor for proxy discrimination | Partial — no protected class features used explicitly, but proxy risk assessed | Medium: Document proxy variable risk; implement monitoring |226| **Adverse Action Notice** | Similar to FCRA; consumer right to know why credit was denied | See FCRA adverse action notice requirement | Partial | Medium: (same as FCRA) |227| **Appraisal Independence** (if mortgage-related) | Independent appraisals required; model cannot override | Not applicable to auto/business loans | N/A | None |228229**ECOA Assessment:** Largely aligned with FCRA compliance. Focus on disparate impact and proxy discrimination.230231---232233### NY Local Law 144 (Algorithmic Accountability; if customers in NY)234235| Requirement | Application to LDP | Control | Status | Gap |236|---|---|---|---|---|237| **Notice** | Notify consumers that automated decision system is used in hiring (not directly applicable to credit but principle is important) | For credit decisions, disclose that AI is used; explain how it works | Partial — privacy policy mentions model but not clear or prominent | Low: Add clear disclosure to loan application and adverse action notice |238| **Annual Bias Audit** | Audit for bias and disparate impact; document findings | Conduct and document annual fairness/bias audit | No — not currently audited | High: Critical for compliance; implement annual audit by [Date] |239| **Data Minimization** | Use only necessary data; justify use of each data source | Document why each data source is used; remove unnecessary features | Partial — features justified but not systematically reviewed | Medium: Conduct feature justification review |240241**LL 144 Assessment:** Significant gaps. Not yet compliant; must implement before full deployment.242243---244245### State Consumer Protection / GLBA (Financial Privacy)246247| Requirement | Control | Status | Gap |248|---|---|---|---|249| Privacy notice (what data you collect and how you use it) | Detailed privacy policy; model use disclosed | Yes | None |250| Consent (for some data sharing) | Opt-in consent for sharing with third parties | Yes — privacy policy includes consent mechanism | None |251| Data security (reasonable security measures) | Encryption, access controls, breach notification plan | Partial — encryption in place; access controls limited | Medium: Strengthen access controls |252| Breach notification | Notify affected users if breach occurs | Process documented | None |253254---255256## 4. Compliance Gaps & Risk Assessment257258### High-Risk Gaps (Must remediate before deployment)259260**Gap 1: Disparate Impact Analysis**261- **Regulation:** FCRA, ECOA262- **Requirement:** Monitor outcomes for discrimination; ensure model does not have disparate impact263- **Current State:** No systematic monitoring264- **Risk Level:** High — regulatory enforcement risk, litigation risk, reputational risk265- **Remediation:** 266 1. Conduct baseline disparate impact analysis (identify protected classes; compare outcomes)267 2. Establish quarterly monitoring268 3. Design mitigation if disparate impact detected (e.g., fairness constraints, manual review threshold)269 4. **Timeline:** By [Deployment Date - 4 weeks]; ongoing quarterly270271**Gap 2: Dispute Procedures**272- **Regulation:** FCRA273- **Requirement:** Provide process for consumers to dispute decisions274- **Current State:** No documented process275- **Risk Level:** High — direct FCRA violation; regulatory enforcement likely276- **Remediation:**277 1. Design dispute intake process278 2. Document reinvestigation procedure279 3. Train staff on dispute handling280 4. Log all disputes and outcomes for audit trail281 5. **Timeline:** By [Deployment Date - 2 weeks]; before going live282283**Gap 3: Bias Audit Procedures**284- **Regulation:** NY LL 144, FTC guidance285- **Requirement:** Conduct annual bias audit; document findings286- **Current State:** Audit not scheduled; no procedures defined287- **Risk Level:** Medium (regulatory expectation, not yet legal requirement nationally)288- **Remediation:**289 1. Define audit scope, methodology, protected classes290 2. Schedule annual audit before [Date]291 3. Document findings and remediation actions292 4. **Timeline:** First audit by [Date + 90 days]; then annually293294### Medium-Risk Gaps (Remediate within 90 days of deployment)295296**Gap 4: Enhanced Adverse Action Notices**297- **Regulation:** FCRA298- **Requirement:** Notice must explain decision; currently sent but lacks detail299- **Risk Level:** Medium — currently compliant but opportunity to enhance300- **Remediation:** Update notice template to include top 3 model factors; example: "Your application was not approved primarily due to: (1) High debt-to-income ratio, (2) Limited credit history, (3) Recent delinquency. You have the right to..."301- **Timeline:** Implement by [Deployment + 30 days]302303**Gap 5: Access Control Enhancement**304- **Regulation:** GLBA, GDPR (if EU customers)305- **Requirement:** Restrict data access; log all access306- **Risk Level:** Medium — security and privacy risk307- **Remediation:** Implement field-level access control; log all credit bureau data access308- **Timeline:** Implement by [Deployment + 90 days]309310---311312## 5. Regulatory Compliance Status Summary313314| Regulation | Critical Requirement | Status | Gap Level | Remediation Timeline |315|---|---|---|---|---|316| FCRA | Adverse action notice | Partial | Medium | Deployment + 30 days |317| FCRA | Dispute procedures | No | High | Before deployment |318| FCRA | Accuracy monitoring | Partial | Medium | Q1 Year 2 |319| FCRA | Permissible purpose | Yes | None | — |320| ECOA | Non-discrimination | Partial | High | Before deployment |321| ECOA | Disparate impact analysis | No | High | Before deployment |322| NY LL 144 | Notice of AI use | Partial | Low | Deployment + 30 days |323| NY LL 144 | Annual bias audit | No | Medium | Deployment + 90 days |324| NY LL 144 | Data minimization | Partial | Low | Deployment + 60 days |325| GLBA | Privacy & consent | Yes | None | — |326| GLBA | Data security | Partial | Medium | Deployment + 90 days |327328**Overall Compliance Status:** CONDITIONAL APPROVAL329330- **Before Deployment:** Remediate dispute procedures (Gap 2) and disparate impact analysis (Gap 1)331- **By Deployment + 30 days:** Remediate adverse action notices (Gap 4) and AI use disclosure (LL 144)332- **By Deployment + 90 days:** Remediate bias audit (Gap 3), data minimization (Gap 5), access controls (Gap 5)333334---335336## 6. Regulatory Compliance Roadmap337338```339BEFORE DEPLOYMENT (Critical)340├─ Disparate impact analysis: complete baseline assessment341├─ Dispute procedures: design and document process342├─ Staff training: ensure staff understand FCRA/ECOA requirements343└─ Legal review: final sign-off on compliance posture344345DEPLOYMENT + 30 DAYS (High Priority)346├─ Adverse action notice: implement enhanced template with model factors347├─ AI use disclosure: add clear disclosure to loan app and notices348└─ Monitoring dashboard: implement to track outcomes by protected class349350DEPLOYMENT + 90 DAYS (Medium Priority)351├─ Bias audit procedures: define and document annual audit process352├─ Access control: implement field-level restrictions and logging353├─ Data minimization: review features; document justification for each354└─ Incident response: finalize procedures for regulatory inquiries355356ONGOING (Continuous)357├─ Quarterly: disparate impact monitoring (protected class outcomes)358├─ Quarterly: adverse action audit (sample 10 denials; verify notice provided)359├─ Annually: bias and fairness audit (full assessment)360├─ Continuously: dispute intake and reinvestigation (log all)361└─ Continuously: incident response (escalate any signs of discrimination)362```363364---365366## 7. Approvals & Sign-Off367368**Regulatory Compliance Assessment completed:** [Date]369370- **Legal Counsel:** _____________________ Date: _____ [Confirms regulatory assessment and remediation plan]371- **Compliance Officer:** _____________________ Date: _____ [Confirms compliance roadmap feasible and resourced]372- **Model Owner:** _____________________ Date: _____ [Confirms ability to implement technical controls]373- **Executive Sponsor:** _____________________ Date: _____ [Approves deployment contingent on Gap 1 & 2 remediation]374375**Deployment Authorized:** [Date] pending completion of Critical remediation items376377**Follow-up Audit Scheduled:** [Date + 120 days]378379---380381## Regulatory Reference382383**Federal:**384- FCRA: 15 U.S.C. § 1681385- ECOA: 15 U.S.C. § 1691386- GLBA: 15 U.S.C. § 6801387- FDIC/Fed/OCC Fair Lending Guidance (2023)388389**State:**390- NY LL 144: Local Law 144 (2023)391- CA CCPA: California Consumer Privacy Act (2018)392- MA AI Transparency: "An Act Relative to the Oversight of Artificial Intelligence" (2023)393394**International:**395- GDPR: Regulation (EU) 2016/679396- UK AI Bill (pending)397398**Guidance:**399- NIST AI Risk Management Framework (2023)400- FTC "Endorsement Guides" for AI recommendations401```402403---404405## Regulatory Mapping Checklist406407Ensure comprehensive assessment:408409**Regulatory Identification:**410- [ ] Geographic scope identified (US/EU/other jurisdictions)411- [ ] Industry identified (finance, healthcare, employment, consumer)412- [ ] Decision type identified (consequential, ranking, advisory)413- [ ] All applicable regulations identified (federal, state, industry-specific)414- [ ] Regulatory landscape documented415416**Requirements Mapping:**417- [ ] For each regulation, specific requirements identified418- [ ] Requirements mapped to operational controls419- [ ] Control implementation status assessed (yes/no/partial)420- [ ] Evidence of compliance documented421422**Gap Assessment:**423- [ ] Current state vs. required state documented424- [ ] Risk level assigned to each gap (critical/high/medium/low)425- [ ] Remediation required or waived426- [ ] Resource requirements estimated427428**Compliance Roadmap:**429- [ ] Remediation prioritized (before deployment vs. after)430- [ ] Timeline established with specific dates431- [ ] Owner assigned for each remediation432- [ ] Dependencies identified (order of implementation)433434**Documentation & Approval:**435- [ ] Regulatory Mapping document prepared436- [ ] Gap assessment documented437- [ ] Compliance roadmap documented438- [ ] Sign-off from Legal, Compliance, and Executive Sponsor439- [ ] Follow-up audit scheduled