AI Compliance

Clear rules. Practical controls. Accountable AI.

Give your business a practical way to use AI responsibly. ETS helps you decide which tools are approved, protect the information they use, and build evidence of how AI is managed across your organization.

Get the value of AI with clearer oversight

Your team may already use AI to draft messages, summarize documents, or connect business systems. Useful adoption needs more than individual accounts and a policy nobody reads.

Know what is being used

Identify approved tools, business use cases, and the people responsible for them. Reduce uncertainty about personal AI accounts, connected applications, and where business information goes.

Set boundaries people can follow

Explain which information may be shared, which actions require approval, and when staff must check an answer. Give employees a usable path to adopt AI safely.

Show how decisions are managed

Keep policies, risk reviews, ownership, and supporting records organized. Be better prepared when customers, leadership, or auditors ask how your business uses AI.

Our options combine Vanta for compliance-program organization, gateways or proxies for supported AI connections, and enterprise management practices. These address different needs; none replaces the others or makes every AI use compliant automatically.

Vanta: organize the work behind AI compliance

Move policies, evidence, and follow-up work into a structured program. ETS can help assess Vanta’s fit and support configuration around the frameworks and responsibilities relevant to your business.

Prepare for ISO/IEC 42001

Vanta offers AI-focused templates, mapped controls, risk scenarios, and evidence-management tools to support readiness for an AI management system.

Organize AI risk management

Vanta’s NIST AI Risk Management Framework offering helps organize risk registers, documents, mapped controls, and evidence in one place.

Keep preparation moving

Available integrations and monitoring can reduce repeated evidence collection. Track gaps and follow-up work while people remain responsible for reviewing the records and resolving issues.

Vanta features depend on your subscription and integrations. Its separate AI Governance agent-discovery offering is currently waitlisted; availability must be confirmed before it is included in a project. Vanta is not a certification body, and using it does not guarantee a successful audit.

Vanta ISO 42001 · Vanta NIST AI RMF · AI Governance availability

AI gateways & proxies: controls around connected AI

A gateway or proxy is a managed checkpoint between a connected application and an AI service. It can apply agreed rules to requests that pass through it.

Control approved access

Where supported, give applications scoped access to approved models and providers. Keep provider credentials in a managed service instead of sharing them broadly with staff or embedding them in application code.

Limit avoidable exposure

Configured checks can flag, block, or redact certain sensitive content before forwarding it. We assess coverage and test real examples; automated checks can miss information or block legitimate requests.

See usage and manage costs

Available controls can track requests, errors, and spending, with limits by application or team. Define useful records and retention periods without automatically keeping every prompt and response.

A checkpoint only covers the traffic routed through it

A gateway does not automatically control personal AI accounts, browser chats, or AI built into every business application. Those need appropriate account, device, network, and application controls alongside clear staff guidance.

Logs, caches, and inspection services can also contain sensitive information. Review who can see it, where it is processed, and how long it is retained. A filter does not guarantee confidentiality, correct answers, or immunity from malicious instructions.

Gateway capabilities vary by product, model, hosting choice, and licensing. We confirm compatibility, data handling, and outage behavior before deployment. Any backup provider must meet the same approved data requirements.

Manage AI as part of the business

Enterprise AI management joins technology controls with ownership, training, and review. ETS can help establish a program for copilots, internal assistants, and AI-enabled workflows.

  • Approved tools and use cases: record what each system does, who owns it, and how employees request a new use.
  • Business identities and permissions: use managed accounts, stronger sign-in checks, and access limited to the information each person or agent needs.
  • Data and supplier review: examine provider terms, model-training settings, retention, connected data, and any third parties receiving information.
  • People and accountability: teach staff how to check outputs, report concerns, and recognize tasks that need a qualified human decision.
  • Ongoing review: monitor quality, exceptions, usage, and costs. Reassess when models, connections, permissions, or business purposes change.

For Microsoft 365 environments, we can review Copilot access and available administrative controls. Copilot can surface information a user already has permission to view, so overly broad sharing permissions need attention before rollout.

Available controls depend on your Microsoft products, licenses, and configuration. Microsoft Copilot security and governance.

Give AI agents a defined job—not unrestricted access

An agent may do more than produce text: it can use connected tools to move work forward. The permissions and approval steps around those actions matter as much as the quality of its answers.

Limit the actions

Define which tools, records, and actions an agent may use. Outside messages and documents must not be treated as permission to change those rules.

Keep consequential decisions with people

Require authorized review for sensitive communications, payments, permission changes, and other high-impact actions. Hiring, lending, healthcare, and similar uses need specific assessment and qualified oversight.

Test, monitor, and pause

Test incorrect answers, unusual requests, and failed connections. Give a named owner a way to stop the workflow and handle exceptions without silently bypassing safeguards.

Separate useful frameworks from legal obligations

The right approach depends on what your organization does, the information involved, and where it operates. A framework can organize the work; it does not replace checking which requirements apply.

ISO/IEC 42001 readiness

This international standard sets requirements for establishing and improving an AI management system. ETS can support preparation and technology work; certification requires a separate independent assessment.

ISO’s overview of the standard

NIST AI Risk Management Framework

This voluntary framework helps organizations understand and manage AI risk. It provides a structure for governance and review, not a NIST certification or automatic legal compliance.

NIST’s framework overview

Privacy, sector-specific rules, customer contracts, and AI-specific laws may create additional responsibilities. ETS supports technical readiness and evidence preparation; qualified legal or compliance advisers should confirm applicability. No platform alone guarantees compliance.

See our broader IT compliance and readiness services

Start with a manageable scope

You do not need to solve every AI question at once. Begin with the tools and business processes that carry the most value or risk.

1. Understand current use

Review existing AI tools, data, access, responsibilities, and requirements. Identify unmanaged use and prioritize the areas that need attention.

2. Agree and pilot the controls

Define the policies, evidence needs, approval steps, and platform choices. Test one useful workflow and confirm costs and limitations before expanding.

3. Put ownership in place

Document who approves changes, reviews evidence, and handles incidents. Train staff and agree a review schedule so the program stays useful after launch.

Common questions about AI compliance

Practical answers before you choose a platform or start a project.

Do we need governance if we only use AI, rather than build it?

Yes, your business still needs decisions about acceptable use, data, access, and review. The level of oversight and any legal obligations depend on the use case. An internal drafting assistant and a system influencing an important decision should not be treated as identical risks.

Does Vanta make us AI compliant?

No. Vanta can support organization, evidence, and follow-up work. Your business must choose and operate appropriate controls, confirm applicable obligations, and obtain any required independent assessment.

Can a gateway see or block every employee’s AI activity?

No. It covers the supported connections routed through it. Standalone websites, personal accounts, and AI inside third-party software may require different controls. We assess those gaps instead of promising complete visibility.

Will prompts and responses be stored?

That depends on the application, gateway, provider, and settings. We review logging, caching, retention, and access before deployment. The goal is useful oversight with only the records your business needs—not unrestricted collection of sensitive conversations.

Can we keep the AI tools we already use?

Often, existing tools can be part of the plan. We review their business account options, permissions, data handling, available controls, and licensing. Some use cases may need a different service or tighter boundaries.

Make responsible AI part of everyday work

Tell us how your team uses AI and where you need clearer control. ETS can help identify a practical starting point for governance, secure connections, and compliance readiness.

Do not send passwords, confidential prompts, or regulated records through the contact form.

Discuss my AI governance needs