1、Orlando,FLOctober 69IBM TechXchange 2025Session ID:1492 AI-aided Continuous Compliance Detection and EnforcementChristophe Elek,IBM CanadaMichael Rennie,IBM CanadaChris Brealey,IBM CanadaMete Isiksalan,York University,CanadaKostas Kontogiannis,York University,CanadaMarios Grigoriou,Western Universit
2、y,CanadaPioush Korlepara,Western University,CanadaAndres Ishida,Western University,CanadaAgenda010203040506BackgroundContinuous Software Engineering Extreme Shift LeftExtreme Shift RightDocumentation GenerationConclusion and Challenges3Regulatory IT System ComplianceThe objective is to:Ensure that I
3、T systems are safesafe,securesecure,reliablereliable,and protectprotect sensitive or private information,such as personal data,financial data,and intellectual property.Infrastructure and actions to:Adhere to laws,regulations,guidelines,and specifications relevant to software applications,IT infrastr
4、ucture,and data management processes within an organization.IBM TechXchange|2025 IBM CorporationIT Regulatory Compliance:A MultiIT Regulatory Compliance:A Multi-faceted Landscapefaceted LandscapeData Privacy RegulationsData Privacy RegulationsSector Specific RegulationsSector Specific RegulationsGov
5、ernment Regulatory ComplianceGovernment Regulatory ComplianceGlobal Trade RegulationsGlobal Trade RegulationsCyberCyber-Security RegulationsSecurity RegulationsCorporate Governance RegulationsCorporate Governance RegulationsEnvironmental RegulationsEnvironmental RegulationsCloud and 3Cloud and 3rdrd
6、 Party Compliance Party Compliance GDPR,CCPA GDPR,CCPA HIPAA,FINRA,SOXHIPAA,FINRA,SOX FedRAMP,FISMA,NISTFedRAMP,FISMA,NISTEAR,ITAREAR,ITARCIS Controls,NIS DirectiveCIS Controls,NIS DirectiveIFRS,SOXIFRS,SOXEnergy Star Energy Star SOC 2,ISO/IEC 27001SOC 2,ISO/IEC 27001Technology Response:Technology R