One control set, ten regimes: the master crosswalk

Lesson 2 of 5 in Capstone: Building and Defending a US AI Compliance Program.

Week two you build the document that makes the whole program auditable: the master crosswalk. One axis lists your controls, keyed to RMF subcategories; the other lists every regime with a claim on Windrose. Each cell answers: does this control produce the evidence this law demands, in the form and on the clock it demands?

The crosswalk’s value is bidirectional. Forward: when the Colorado AG’s office asks how you comply with SB 26-189’s explanation duty, you point to one control (adverse-decision explanation workflow, MANAGE 4 documentation) and its state renderings. Backward: when a new law lands, you diff it against the control column and discover that 80% already exists — what is genuinely new is usually a clock, a form, or a filing.

Master crosswalk (excerpt) — controls to regimes
Control (RMF anchor)Colorado SB 26-189CCPA ADMT regsNYC LL144 / IL HB 3773Texas TRAIGAECOA / SR 11-7SB 53 (via vendor)

Point-of-use notice (GOVERN 1, MAP 1)

Point-of-interaction notice

Pre-use notice + opt-out handling

10-business-day candidate notice / notice of AI use

Government + healthcare disclosure analogs

Not the mechanism — ECOA acts at denial

n/a

Adverse-decision explanation + human review (MANAGE 4, GOVERN 5)

Plain-language explanation in 30 days; correction; reconsideration

Access/explanation rights

Alternative-process requests

Reasonableness evidence

Adverse action notice with specific principal reasons — no black-box excuse

n/a

Disaggregated outcome testing (MEASURE 2)

Evidence for fault allocation

Risk-assessment content

The bias audit itself / IHRA defense evidence

Rebuts intent inference

Fair-lending analysis; model validation

n/a

Vendor documentation + contract clauses (GOVERN 6, MAP 4)

Receive developer technical docs (due from Jan 1, 2027)

Service-provider terms

Audit data access from vendor

Developer representations

SR 11-7 vendor-model validation

Vendor’s frontier framework + incident duties flow into your contract

Incident response + reporting (MANAGE 4, GOVERN 4)

Cure-period response readiness

Breach/security overlay

DCWP/IDHR inquiry response

60-day cure execution

Regulator notification norms

Cal OES clocks (vendor primary; you feed evidence)

Records retention (GOVERN 1)

3-year records

Assessment retention + Apr 2028 submissions

Audit history

Defense documentation

Model inventory + validation reports

Transparency report inputs

Week three, you draft the artifacts — the concrete documents regulators, consumers, and counterparties actually see. Templates are where programs live or die: a beautiful policy with no explanation template means a panicked paralegal improvising one at day 28 of a 30-day clock.

Impact assessment

One template serving CCPA risk assessments (first submissions due April 1, 2028) and internal tiering: purpose and context (MAP 1), affected populations and plausible harms (MAP 5), disaggregated performance results (MEASURE 2), mitigations and residual risk with sign-off (MANAGE 1). Write it knowing an AG may read it — factual, specific, free of both marketing and self-incrimination-by-adjective.

Notices

Layered, not duplicated: a point-of-interaction notice (Colorado wording as the strictest base, rendered also as the CCPA pre-use notice with opt-out mechanics and the Illinois AI-use notice) plus the LL144 candidate notice on its 10-business-day clock. Windy’s chat interface carries the Utah-compliant bot disclosure by default — cheaper than detecting Utah users.

Adverse-decision explanation

The hardest artifact. For AdvanceScore it must double as an ECOA adverse action notice: specific principal reasons for the denial — regulators have said plainly that model complexity is no excuse. For SiftIQ it renders as Colorado’s 30-day plain-language explanation with data-correction and human-review pathways. Design rule: if the model cannot yield reason codes a consumer can act on, that is a model requirement, discovered now, not a letter-drafting problem discovered in production.

Model + system cards

Internal model cards (intended use, training data, evaluations, limits) feed everything external: the vendor documentation Colorado requires SiftIQ’s developer to supply, the AB 2013 training-data posting if Windy is deemed made available to Californians, and SR 11-7-grade validation records for AdvanceScore’s bank partner.

Frontier paperwork (vendor)

Windrose is no frontier developer, but its GenAI vendor is: SB 53 obliges the vendor to publish a frontier framework and transparency reports and to report critical incidents to Cal OES; RAISE adds New York duties from January 1, 2027. Your artifact is the contract: warranties that those duties are met, incident-notification flow-down on defined clocks, and audit rights — GOVERN 6 rendered as clauses.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.