Business: Compliance · Lesson N.comp.7

The audit of the cited regulation: compliance's cardinal sin

In compliance, a legal article or policy clause cited wrong doesn't cost rework: it costs a false report to the committee or the regulator. This is the RESPOND moat lesson applied to compliance: AI proposes, the analyst verifies, and whoever signs the report is a person, always.

Examples for

A compliance analyst asked AI for the legal grounding to clear a new customer data flow and got back, in seconds, "in accordance with article 7, item IX, of the General Data Protection Law (LGPD), the processing is grounded in legitimate interest, waiving the need for consent." The wording was impeccable, the article number looked right. He almost attached it straight to the opinion going to the risk committee. A colleague, out of habit, opened the text of the law before filing it: item IX covers credit protection, a completely different case from what the flow required. The entire report was resting on a wrong reading of the article, and only checking the source, before reporting, kept the committee from approving a flow with no real legal basis.

Look, I'll be honest with you. The most dangerous part of AI in compliance isn't when it gets it wrong in an obvious way. It's when it nails the format and gets the regulation wrong. It hands you an article with a number, wording, and the tone of someone who knows the subject, and your guard drops because it looks like the work of an experienced colleague. That relaxation is the hole. In compliance, a wrongly cited regulation doesn't cost a bad comment: it costs a false report to the risk committee or the regulator, and it can cost the entire area's credibility.

The core idea of this lesson. AI doesn't "consult" the regulation: it predicts the most likely next piece of text. That's why it invents articles, internal policy clauses, and technical standard items with absolute confidence, and its confidence is exactly what fools you. The rule is simple and non-negotiable: never trust an AI regulation citation without checking. You audit it. And whoever signs the compliance report is a person, always, because "the AI that cited it" doesn't exist before the committee or the regulator.

01Why AI lies with the straightest face in the world

Let's clear up a misunderstanding that costs dearly. AI doesn't have a database of regulations in its head that it "opens" to answer you. It works by predicting the most likely next word, given everything that came before. When you ask for the article backing a decision, it doesn't search: it composes something that has the shape of a correct citation. Number, text, the tone of someone who knows the subject, all in the perfect format, because it has seen thousands of real citations and learned the mold. The mold is correct. The content can be wrong, or might not even exist.

The problem isn't that it gets things wrong; it's that it gets things wrong with the same confidence it gets things right. There's no warning, no "maybe," no hesitation. Out comes secure, polished text, the way an experienced specialist would write it. And there are real cases of institutions sanctioned for reporting a nonexistent or poorly grounded control to a regulator, long before any generative AI existed. Now, with AI generating that kind of text in seconds, the risk of repeating that error at scale increases, it doesn't decrease.

Notice the cruel inversion. In the analog world, the signal that something is trustworthy is that it looks well made. With AI, looking well made says nothing about being true, because producing something well made is exactly what it does best. Form stopped being proof. Only the fact is proof. And a fact, in compliance, gets checked at the official source.

02The speed paradox: you feel faster while getting it wrong

There's a study that needs to sink into your head before you trust your own sense of things. In 2025, METR measured experienced professionals working with and without AI assistance. The result went against everyone's expectations: with AI, they got slower, about nineteen percent slower. But the detail that matters for compliance is another one: they thought they were faster. The sense of acceleration was real; the gain wasn't.

Why does this happen? Because AI gives you an instant draft, and your brain registers that fast delivery as progress. Except the real work, checking, correcting, undoing what came out wrong, stays hidden and disappears from your perception. In compliance, this paradox costs more than hours. It costs a report wrongly submitted to the committee, a non-compliance that went unnoticed, a fine. That's why the regulation audit can't depend on how you feel about the report. You need an external, cold process, one that doesn't ask if you're confident. It asks whether the regulation exists and says what the report claims.

pace felt "faster" measured slower

03The compliance audit checklist: five questions before reporting

Here's the heart of the lesson. Auditing an AI-assisted report isn't intuition, it's a routine. Five questions, always the same, always at the source. If any one fails, the report doesn't go out. It's not about how much you trust it: it's about passing through all five gates.

  1. Does every cited regulation exist and say what AI claimed? Open the official text (law, technical standard, internal policy). Check the article, item, section number. And read the actual text, because a real article can say the opposite of what AI guaranteed it says.
  2. Is the regulation in effect? A cited regulation might be repealed, amended, or updated since the model's training. AI doesn't automatically track repeals. Confirm currency in the updated official text.
  3. Does the regulation apply to this process? Existing and being in effect isn't enough. The regulation needs to cover the case, the type of data, or the type of operation compatible with your real matter. A regulation out of context is ammunition that blows up in your hand at the next audit.
  4. Is any fact about the operation made up? AI fills gaps with what sounds plausible: data volume, a control's date, a responsible person's name. Cross-check every fact stated in the report against what the process actually shows and against the real evidence. A made-up fact about your own operation is the error that destroys the entire report's credibility.
  5. Can whoever signs actually stand behind it? If the risk committee or the regulator asks where that argument came from, on the spot, with no AI around, can you back it up? If the answer is no, the report still isn't yours. It's a draft you don't understand.
AI proposes the analyst verifies the person signs trust lives in the middle: no verifying, no signing the checklist's five gates live in the middle step

04The RESPOND principle: whoever signs the report is a person, always

Back in the map The 3 Moves, RESPOND is the moat: the part of AI-assisted work you don't outsource, because that's where accountability lives. In compliance, RESPOND has an exact and unforgiving translation: the report goes out with a human name under it, and that name answers for every regulation cited in it.

Think about what happens during a regulatory inspection. If there's a problem in the compliance report, the regulator doesn't call AI. There's no "the AI that cited it" before the risk committee, before the regulator, before the board. There's the analyst or manager who signed it. The machine executes, the machine proposes, the machine sweeps fast. But the signature is the boundary where responsibility stops being able to get pushed further along. It hits a person and stays there.

And here's the frame that changes your relationship with the audit. Checking every cited regulation isn't distrusting the tool, isn't old-fashioned, isn't a waste of time. Auditing protects three things at once: the company, which reports to the regulator based on what you sign; the real process, which gets committed to a single poorly cited article; and your professional credibility, which is your most expensive asset in the field. AI gave you speed in the draft. The audit is what turns that speed into something you can sign without losing sleep. Whoever skips the audit isn't being faster. They're outsourcing their own risk and pretending not to see it.

Do it now

Do it yourself

Take a real compliance report (your real task works well) where you'd use AI to ground a conclusion with a cited regulation. Before thinking about filing or reporting anything, build YOUR OWN five-item compliance audit checklist, adapted to your area of practice:

  1. REGULATION EXISTS AND CHECKS OUT: write the exact question and which official source you'll check every article, internal policy clause, or technical standard item against (which law, which document, which page).
  1. CURRENCY: how do you confirm every cited regulation is currently in effect, and not repealed or amended since the last update AI knows about?
  1. APPLICABILITY: what criterion do you use to decide whether the regulation really serves THIS process (type of data, type of operation, context)?
  1. OPERATION FACTS: how do you cross-check every fact stated in the report against the process's real evidence, to catch anything AI made up?
  1. STANDING BEHIND IT: the question you ask yourself to know whether you could defend each citation before the committee or the regulator, with no AI around.

Write the five out on one page and stick it next to your screen. If you report without going through all five, it wasn't AI that signed: it was you.

Practice

1. Why should a regulation cited by AI never enter a compliance report without checking the official source, even when it comes with a full article number and wording?

2. The 2025 METR study showed experienced professionals were slower with AI, but thought they were faster. What is the direct lesson for the compliance audit?

3. Applied to compliance, what does the RESPOND principle (AI proposes, the analyst verifies, the person signs) determine about responsibility for the report?

For the board

On the cardinal sinthe danger is not it being obviously wrong. It is getting the format right and the rule wrong.
On the feelingyou feel faster exactly when you should be more suspicious. The checklist does not ask if you trust it, it asks if the rule exists.
On the signatureit is the border where risk stops being passed along. Whoever signs the report is a person, always.
What did you think of this page?
Would you recommend this page to someone on your team?