The Audit Defense Library

Practitioner-depth analysis across federal and private compliance: FISMA and NIST RMF, FedRAMP, CMMC, federal AI governance, SOC 2, AI governance, cybersecurity, and GRC engineering. Written by a CPA, CISSP, CISA with Big 4 audit experience.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
AI Governance

EU AI Act GPAI Provider Obligations: Documentation, Copyright, and Transparency Requirements

A compliance officer at a mid-size SaaS company opens the EU AI Office's notification portal in September 2025. The company integrated GPT-4 into its customer support platform six months ago. The portal asks a question...

Read the Guide
AI Governance

AI Model Cards for Compliance: What Auditors Expect Under the EU AI Act, NIST, and ISO 42001

Your auditor asks for the model card on the credit-scoring system deployed in Q3. The ML team points to a README in the GitHub repo: model name, accuracy metric, training date. Three sentences. The auditor...

Read the Guide
AI Governance

AI Vendor Risk Assessment: The Inherited Compliance Risk Your TPRM Program Misses

Your TPRM program assessed the AI vendor. Security questionnaire completed. SOC 2 report reviewed. Penetration test results on file. The vendor passed. Six months later, the vendor's credit-scoring model rejects applicants over age 55 at...

Read the Guide
GRC Engineering

Compliance Drift Detection: How to Find Control Failures Before Your Auditor Does

Your SOC 2 Type II audit closed clean in January. No exceptions. Every control tested and verified. By April, the quarterly access review did not happen because the person who ran it changed roles. By...

Read the Guide
GRC Engineering

Automated Access Reviews: From Audit Theater to Continuous Assurance

The spreadsheet arrives every quarter. 2,400 rows. One column for username, one for application, one for role. The reviewer, a department manager already behind on three deliverables, scrolls through 300 rows of entitlements she does...

Read the Guide
AI Governance

AI Governance for SOX Compliance: Controls, Risks, and the COSO GenAI Framework

Your CFO signs the Section 302 certification. She attests that internal controls over financial reporting are effective and that the financial statements are materially accurate. What she does not know: the revenue recognition system now...

Read the Guide
AI Governance

AI Bias Auditing: Compliance Requirements Across Three Jurisdictions

State-level AI laws in the United States more than doubled from 49 to 131 in a single year [Stanford AI Index 2025]. Federal agencies issued 59 AI regulations in 2024, up from 25 the year...

Read the Guide
GRC Engineering

Third-Party Risk Management: Compliance Across Four Frameworks

Every third-party risk management program I have reviewed in the last two years shares the same structural weakness. The vendor inventory exists. The initial assessments exist. The onboarding process is thorough, sometimes impressively so. Then...

Read the Guide
Cybersecurity

CCPA Cybersecurity Audit Requirements: What the 2026 Rules Mean for Your Organization

When the FTC Safeguards Rule took effect in June 2023, most financial institutions treated it as a sector-specific obligation. A cybersecurity audit mandate for banks, lenders, and auto dealers. Eighteen months later, the rule reshaped...

Read the Guide
Cybersecurity

Cyber Insurance and Compliance: How Frameworks Reduce Premiums

Insurers materially tightened cyber underwriting in 2024. U.S. direct written premium fell for the first time since the National Association of Insurance Commissioners began tracking the market, while Coalition's mid-year 2024 claims data shows that...

Read the Guide
GRC Engineering

Non-Human Identity Governance: Service Accounts, API Tokens, and CI/CD Credentials

Ninety-seven percent of non-human identities hold excessive privileges [Entro Security 2025 State of NHI Report]. Not a sampling error. Not a niche finding from a handful of startups. Entro analyzed production environments across industries and...

Read the Guide
AI Governance

NIST AI RMF 1.0 Explained: The Four Functions Every AI Program Needs

Eighty-eight percent of organizations now use AI in at least one business function [McKinsey State of AI 2025]. Among organizations planning to deploy agentic AI, only 21% report a mature model for agent governance [Deloitte...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.