Compliance leaders, General Counsel, COOs, Security/IT, and HR leads in US/EU/UK SMB–mid-market.
A compliance checklist is a concise, auditable list of controls your team executes to meet laws, regulations, and policies. Each control names the required evidence of compliance, the owner, and the review cadence. Strong checklists are versioned, risk-mapped, and support board oversight, inspections, and continuous improvement.
Most mature deployments follow this pipeline:
AI Review: scan policies, minutes, and logs; flag vague or non-compliant language (e.g., no owner/cadence).
AI Suggestions: propose policy/control text; draft evidence requests; assemble board-ready summaries.
Safeguards: keep human approval; store redlines; log decisions for audit.
Keep board time on duties, cadence, and proof. Tie agenda items to risk. Track exceptions and decisions in minutes.
Board responsibilities and disclosure/oversight are core governance principles (OECD Corporate Governance Principles
Use the “three lines” model to clarify oversight vs. management roles (IIA Three Lines Model
Charity boards: record legal duties in packs and minutes (UK Charity Commission)
Name the function, mandate independence, define reporting lines to the board/audit committee.
US DOJ Evaluation of Corporate Compliance Programs
IIA Three Lines Model
Maintain a single, versioned manual that maps laws to controls and evidence. Keep it searchable.
ISO 37301
GAO Green Book
Cover hiring, training, conduct, accommodation, leave, and separation. Link policies to evidence of compliance.
HIPAA BAA guidance (HHS)
ICO GDPR/RoPA accountability guidance
Inventory data, maintain a RoPA, run DPIAs for high-risk processing, enforce access controls, and test incident response.
NIST Cybersecurity Framework 2.0
EDPB DPIA Guidelines
Close the books, validate filings, and certify key controls (billing, collections, segregation of duties). Do a year-end sweep.
GAO Green Book
Turn on only if applicable.
HIPAA overview (HHS)
PCI Security Standards Council
UK Charity Commission
Register models. Record purpose, data, risks, testing, and human oversight. Run DPIAs where needed. Track vendor AI. Keep an internal model registry linked to policies.
NIST AI Risk Management Framework
EU AI Act (informational)
Policy vs. control?
A policy states intent and rules. A control is a repeatable task that proves the policy is followed, with evidence, owner, and cadence.
How often should we review controls?
Quarterly for high-risk; at least annually for others. Align cadence to risk and document it.
Do SMBs really need board oversight?
Yes. Governance principles apply to all sizes; boards should oversee risk and compliance and record decisions.
Is there a standard format for evidence?
Use durable formats (PDF/CSV/exports) with timestamps and approver names; maintain records as documented information.
How do we handle AI systems?
Maintain a model registry, apply risk frameworks, run DPIAs where needed, and document human oversight.
Where do industry specifics fit?
Enable sector modules (HIPAA, PCI DSS, Charity) only if in scope; attach regulator-defined evidence.
Create one checklist file; add Control, Evidence, Owner, Frequency.
Add five governance controls and assign owners.
Add HR training and access-review controls.
Register any live AI models; add DPIA status.
Run an AI review on policies/minutes; accept AI suggestions to fill gaps.
Schedule quarterly reviews; link evidence locations.
OECD Corporate Governance Principles
ISO 37301
GAO Green Book
NIST Cybersecurity Framework
EDPB DPIA Guidelines
UK ICO GDPR guidance
HHS HIPAA guidance
PCI Security Standards Council
NIST AI Risk Management Framework
EU AI Act (informational)


