The Audit Defense Library

Practitioner-depth analysis across federal and private compliance: FISMA and NIST RMF, FedRAMP, CMMC, federal AI governance, SOC 2, AI governance, cybersecurity, and GRC engineering. Written by a CPA, CISSP, CISA with Big 4 audit experience.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
AI Governance

Singapore Agentic AI Governance Framework: Four Dimensions of Trust

Every AI governance conversation in 2026 starts with the EU AI Act. That is the wrong starting point. Europe built a compliance machine: 113 articles, six risk tiers, penalties up to EUR 35 million. It...

Read the Guide
HIPAA

HIPAA Security Rule 2026: What the Proposed Overhaul Means for Covered Entities

The original HIPAA Security Rule took effect on April 21, 2005. Covered entities had two years of implementation runway after HHS published the final rule in February 2003. The regulatory logic was simple: set baseline...

Read the Guide
GRC Engineering

OpenSSF Gemara Model: The Seven-Layer Architecture for Automated GRC

Networking had no common language until 1984. Engineers at different vendors described the same functions using different terms. Troubleshooting meant decoding tribal knowledge. Then the OSI model introduced seven layers, and every network engineer on...

Read the Guide
Cybersecurity

SEC Cybersecurity Disclosure Rules: A CPA’s Guide to Materiality Determinations

The CFO calls at 6:47 AM. Your SIEM flagged unauthorized access to a database containing 2.3 million customer records. The incident response team is already working containment. But the CFO is not asking about the...

Read the Guide
AI Governance

Colorado AI Act Compliance Playbook: SB 24-205 and SB 26-189

Editor's Note, June 2, 2026. This playbook was originally written for Colorado SB 24-205 as first enacted. That version of the law no longer controls. A federal court stayed enforcement of SB 24-205 on April...

Read the Guide
AI Governance

US State AI Laws 2026: The Multi-State Compliance Map

Colorado Update, May 2026: Governor Polis signed SB 26-189 on May 14, 2026. The effective date moves to January 1, 2027 and the risk-based framework (six obligations, rebuttable presumption, NIST AI RMF affirmative defense) is...

Read the Guide
AI Governance

NIST AI RMF Affirmative Defense: Compliance as Protection

Editor's Note (July 13, 2026): Colorado's AI Act has been rewritten. After the original SB 24-205 compliance date slipped from February 1, 2026 to June 30, 2026, Governor Polis signed SB 26-189 on May 14,...

Read the Guide
AI Governance

AI Agent Audit Trails: Logging Autonomous Decisions

AI agent audit trails demand capabilities that traditional logging architectures were never designed to provide. Your application logs record what happened. They capture timestamps, user IDs, API calls, error codes. For every software system your...

Read the Guide
AI Governance

Agentic AI Risk Assessment: The 5-Layer Evaluation Framework

Agentic AI risk assessment requires a fundamentally different methodology than traditional AI evaluation. A one-percent misalignment in a prediction model produces a one-percent error rate. A one-percent misalignment in an autonomous agent compounds across every...

Read the Guide
AI Governance

Multi-Agent System Governance: When Agents Manage Agents

Multi-agent system governance is becoming the defining challenge of enterprise AI deployment. KPMG deployed 50 AI agents through its Workbench platform in June 2025, with additional agents in development [KPMG Jun 2025]. These are not...

Read the Guide
AI Governance

EU AI Act Human Oversight: Article 14 Compliance for High-Risk AI Systems

The greatest risk in high-risk AI is not the algorithm. It is the human approving the algorithm's output without reading it. A 2025 systematic review of studies involving thousands of participants confirmed what practitioners already...

Read the Guide
AI Governance

EU AI Act Risk Management System: Article 9 Implementation Guide

Organizations report active AI governance programs while lacking a systematic inventory of the AI systems those programs are meant to govern. Eighteen percent of deployed AI systems are confirmed high-risk under the EU AI Act...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.