Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: What Compliance Problems Arise when AI is Writing Your Policies?
Quick Take
On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result.
Listen, as Todd Coshow and Adam Goslin discuss why AI-generated policies often fail in audits and incident reviews, and how to use AI for drafting without losing accountability.
Read The Transcript:
So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.
Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow with Adam Goslin.
Todd Coshow:
Well, welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the pineapple and cherry in your piña colada, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I am doing fantastic today, Todd. How about you?
Todd Coshow:
I cannot complain. It is definitely piña colada weather out here.
Today, we’re gonna talk about compliance problems that arise from a certain compliance approach, and we’ll get to that.
But before we do, I wanna say thank you to all the folks that take the time to listen to our podcast and share it with their friends.
Please do us a favor and give us a rating or review on your podcast app of choice.
If you’d like to reach out, share with us how much you love Adam, or how much you wanna hear a specific topic covered, please feel free and do so. Our email is [email protected].
Today, Adam, we’re gonna talk about what compliance problems arise when AI is writing your policy.
So if AI wrote your security policy and no one really reviewed it, whose policy is it?
Adam Goslin:
I love the compliance problems. That was good.
Before I go there, every time that you’re like, “Hey, tell a few friends that may be interested in what we’re doing here,” I always had that thing. I don’t remember what the frick commercial it was back in the day, but it’s like, “And they too tell two friends, and they tell two friends, and so on and so on.”
I forget what the hell the topic was. It was like some PSA or something.
Todd Coshow:
Sounds like a pyramid scheme. I don’t know.
Adam Goslin:
Nah. I’m gonna be forced to go figure that out now.
Anyway, if you just go jam it into AI and it spits out a policy and nobody’s taken a look at it, whose policy is it?
AI is becoming a good productive tool for compliance teams.
It isn’t a problem to have AI go take a whack at the first draft.
The problem is, and quite honestly, this is the same issue that organizations have had now for some time.
For some time you’ve been able to go out to whatever, I’m just gonna make it up, like www.writemycompliancepolicyforme.com, and you too can fill in blanks and get some steaming pile of garbage as a policy.
Some people literally do.
I’ve been doing engagements, and we’re going through the policy for the annual review, etc., and there’s literally placeholders left in the damn policy for where things that they should have filled in, obviously.
They didn’t do anything other than take a half-hearted whack at find and replace a couple of times and called it a policy.
It’s really no different.
When you’ve got AI blasting out the first draft and then you just go ahead and put your signature on the dotted line, it’s not terribly useful.
Quite honestly, one of the biggest problems that poses when you’re trying to go through your engagement, the relationship between people going through compliance and the folks that are gonna be assessing compliance, it’s one where there is a certain amount of built-up trust that happens between those parties.
There is absolutely no better way to erode any notion of trust building when you’re just serving up what usually is one of the earliest things.
Normally when you go and sit down, you go through the overview of the company and what is the scope, and the assessor’s asking all sorts of questions so they can get their arms around it.
But the very first thing that they’re actually looking at generally is the policies.
Do you wanna start it off on completely the wrong foot?
Go have AI write the initial draft and put your signature on the bottom line, or go grab a template policy and you haven’t really reviewed it.
Policies are more than just well-written language.
It’s literally a written commitment about how the organization is actually operating.
If leadership is signing off on policies that aren’t reflective of reality, aren’t reflective of coverage for the various standards that you’re ostensibly going up against, if it isn’t reflecting how you’re actually doing what you’re doing, etc., you’re creating compliance risk in advance of your assessor walking in to bat you over the head.
It’s really not a good look when you’re sitting there at your annual assessment or onsite and running square into that wall.
Certainly, AI can play a part accelerating the generation of the documentation, but you can’t ever just call it done and put the accountability into the hands of the AI.
What are you gonna do? Turn around to the assessor and say, “Well, AI wrote that”?
You don’t like the stand on.
Todd Coshow:
Why are so many organizations turning to AI to write policies in the first place?
Adam Goslin:
Compliance teams are under a lot of pressure to do more with less.
Certainly, I’ve met more than a handful of organizations where their goal or objective for navigating the world of compliance is quite literally, “We do whatever we need to do to get the check boxes, get the piece of paper that says that we’re compliant,” or in many cases conflating that to secure.
We talked about that on one of the recent prior pods.
AI dramatically reduces the amount of time to blast out that first draft.
You can let it do the initial heavy lifting.
It helps organizations get started instead of just staring at a blank page or, let’s turn back the hands of time a decade, sitting down and literally writing policy from scratch in accordance with whatever target security and compliance standards the organization’s going up against.
Having AI take the first swing of the bat, that’s fine.
That’s a good use case for a starting point.
But when organizations are confusing “we’ve generated a policy” with the approval of the policy, that’s where they tend to run afoul.
Faster documentation isn’t translating into better governance and honestly is putting a lot of things at risk for the organization.
Todd Coshow:
What’s the biggest mistake organizations make when they rely too heavily on AI-generated policies?
Adam Goslin:
Generic policies that sound impressive but don’t describe how the organization’s actually functioning.
Policies that are referencing technologies or processes that the company doesn’t even have in play are gonna cause issues as well.
I’ve seen more than a handful, especially from the old-school kind of pull-the-template-off-the-shelf.
Even if I went through and did the find and replace of the placeholders, if whoever made the template did not highlight all of the arenas and realms that needed to be reviewed, if the company didn’t go through and review it themselves, now you’ve got things literally written into your ostensibly approved policy that don’t have anything to do with how you’re doing and what you’re doing.
AI can make assumptions based on common practices that don’t necessarily translate to the organization itself.
You’ve got the added risk, we’ve talked in the past about AI hallucinating, making shit up, where it’s just cooking up some reference that sounds right, sounds legitimate.
But it’s just throwing in regulatory references into the policy documents.
Is it right? Is it wrong? No idea.
Inaccurate control descriptions.
When you’re going through an assessment, those inconsistencies are astoundingly obvious very quickly.
There’s nothing that is going to diminish any notion of built-up trust faster than the assessor running square into that.
The policy is intended to describe the operational workings, the alignment to standards for a particular organization, namely yours, not some aggregate of the average company.
Those are some of the roadblocks that folks will run into with these AI-generated policies.
Todd Coshow:
How does that disconnect between documentation and reality create compliance risk?
Adam Goslin:
Go under the guiding assumption that I’ve got a current policy that I either tore off of the find-and-replace notion or it was a first draft of AI, but nobody bothered to validate it.
Assessors aren’t just going in, reading the policy and going, “Okay, well, they got a statement in there for this particular control. Check. Move on.”
Instead, that forms the basis of their evaluation.
What’s written into the policy needs to match the standard that you’re going up against, but then they take that and put it up against operational execution.
You could have this policy that basically is a parrot of whatever the target standard or certification is, but if that’s not what you’re doing or specifically how you’re doing it, then now you’ve got a problem.
If the policy’s promising quarterly reviews of fill-in-the-blank, but the organization’s only doing them every six months or once a year, well, guess what?
You just handed non-compliance straight to your assessor as a result.
The worst part is that you did this to you.
Policies are evidence, just like the validated proof that you’re actually following the policies are evidence.
The more detailed the promise within the policy, then the more evidence that’s expected to produce on the back end of it.
Poorly reviewed AI-generated policies can have a tendency, if not reviewed properly, to increase negative assessment findings as you’re going through your annual assessment.
No matter what, at the end of the day, good documentation should be an accurate depiction of what’s really happening within your environment, not some idealistic version of it.
Where I see a lot of organizations go sideways is they look at the detail that may be placed into some automated or template-based policy generation, and they look at all of this detail as being positive things.
“Ooh, we’re gonna bang this out of the park because we’ve got all this ad nauseam detail in the policy governing exactly what we’re doing and how.”
But the minute that that doesn’t line up with what you’re actually doing, you might as well just hold the shotgun right at your own foot and pull the trigger.
Todd Coshow:
Who should ultimately own policies if AI is helping create them?
Adam Goslin:
Walk in with the notion that, like we said earlier, AI is a fine starting point if that’s the direction that you wanna go.
But you can’t attribute the ownership of the policy to AI.
For every given policy, you need to have some type of business owner that’s owning the overall policy.
You need technical owners for certain of the policy statements as appropriate.
And you need some form of executive sign-off and approval.
Everybody needs to be accountable for the accuracy of the policies that are generated.
AI can certainly help, but at the end of the day, a real live human being needs to maintain ultimate responsibility for the governance.
If nobody’s owning the document, you don’t have ownership of the control of it.
The stark reality is that a lot of times what I will see, and this is typically in an earlier-stage organization when it comes to running and maturing their security and compliance program, the operational boots-on-the-ground people have gone through and reviewed the policy, but those that are responsible for the higher-end sign-offs kind of get tone deaf to the review process over time.
“Oh, yeah, whatever. Bob or Mary looked through this, so it must be good.”
At the end of the day, you’re literally putting signatures on paper saying, “This is what we’re doing.”
Everybody better be good with being able to review that policy, know what’s in it, and understand that that is going to hold the organization responsible.
Todd Coshow:
What’s the right way to use AI without creating automated compliance debt?
We’ve talked about compliance debt in the past. How do you do that effectively here?
Adam Goslin:
It’s a mentality.
No more than would I take a template policy, do find and replace, and go get blind executive sign-off, should we be doing the same thing with an AI-generated policy.
You need to treat it as if it’s a junior analyst putting this thing together, not that it’s a well-seasoned, multi-decade compliance officer that has sat down and done this by hand.
They’re in completely different ballparks.
Good uses of AI: initial drafting of the policies, improved readability of the policy itself, using it for validating and comparing different compliance standard or framework requirements, tearing through and identifying missing topics within the policy.
Those are all good uses.
That said, one thing I wanna say before I get too far away from this.
Let’s say I’ve got this amazing, perfect policy. It’s been through all the appropriate reviews, etc.
But now I decide I’m gonna run this through the AI engine to help out.
I wanna reword this. I wanna put it in plain English. I wanna improve the readability of the document.
You don’t have any damn idea what the hell the AI decided to rip out of the document versus when it was attempting to streamline the policy content.
What did it drop off to the side?
Did it, in the process, end up removing policy statements which were requirements for the standard or framework that you’re going up against?
You don’t know.
No differently than if I’m going through some form of legal review of an agreement.
When I draft an initial agreement and I hand it to another third party, they go through and redline it.
When I get it back, I wanna be able to say, “Here’s what I had originally. Here’s what it changed it to. Am I cool with this?”
All the way down the line, yes, yes, no, etc.
Those are the types of things that you’ve gotta do.
Again, go back full circle to treating your AI like it’s an intern.
You have to take that mentality.
You need subject matter experts to come through, do the validation of the accuracy, compare prior version with current version that spat out of AI, making sure that the policies are lining up with what you’re actually operationally doing, making sure that AI didn’t fluff some stuff up and throw in some blinding assumptions, making sure that you’re good with the final language that you’ve got within the document.
The goal isn’t AI-written compliance.
The goal is AI assistance with human accountability.
Technology should help with making governance more efficient, but it cannot replace governance outright.
The responsibility needs to be on the organization.
Todd Coshow:
Maybe the question isn’t whether AI should help write your policies. Maybe it’s whether your organization has reviewed them carefully enough to stand behind every word.
Adam Goslin:
That’s spot on.
Assessors don’t give a flying crap who drafted the policy.
Was this written by Bob? Was this off of a template? Did this go through this gigantic process?
The regulators don’t care who drafted the policy.
After an incident, nobody’s coming back and going, “So did ChatGPT write your policy?”
Instead, they’re gonna come back and say, “Did your organization do what the policy said it was going to do, and did that policy live up to the organizational obligations to meet fill-in-the-blank standard?”
At the end of the day, it’s a human responsibility for making sure that the policies are lined up appropriately, and that what is in it is appropriate and that they’re doing what they said.
Those are the standards that are going to be held to the target organization.
If you’re in a position where you haven’t gone through and done the appropriate due diligence, make no mistake, man.
If I go and throw a task out at an AI engine to go produce something, is it glorious having it rough in a single 80-page policy doc that ostensibly lines up to fill-in-the-blank standard?
Yeah. That’s great.
There are some real benefits in terms of shortcutting the amount of sheer effing pain that a lot of organizations go through.
Yes, it’s amazing to be able to gather and gain that benefit.
But I think a lot of organizations in their AI zombie walk fervor just gloss over and miss the boat on it.
Todd Coshow:
Parting shots and thoughts for the folks this week, Adam?
Adam Goslin:
I think I’ve hammered the crap out of this one this time around.
AI’s got a place, but it can’t supplant the human responsibility.
More and more we’re seeing requirements being integrated into AI and its use.
The last couple of years have been this blinding fervor for everything that’s AI must be cool, and we’ve gotta be able to sanity check this with reality here.
The organization has to do its due diligence.
I really like the notion of treating AI like it’s an intern.
Until such point as AI has validated, vetted, and proved itself out to be fully capable of doing these tasks, etc., we have to have human oversight of what’s going on.
Especially when it comes to the policies.
The policies is a dangerous arena for an organization to just half-ass.
You can run yourself into a tremendous amount of problems and headaches.
The notion we were talking about earlier about what happens when an incident occurs, you can bet your bottom dollar that, yeah, there’s gonna be a technical portion of that investigation and analysis into what the hell happened.
But there’s also going to be more of a procedural review, which abso-freaking-lutely is going to be a scouring of your policy statements against what you’re actually doing in reality.
If those two diverge, boy, do you have a freaking problem on your hands.
Todd Coshow:
And that right there, that’s the good stuff.
Well, that’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.
Adam Goslin:
And I’m Adam Goslin.
Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.