One control set, ten regimes: the master crosswalk
Lesson 2 of 5 in Capstone: Building and Defending a US AI Compliance Program.
Week two you build the document that makes the whole program auditable: the master crosswalk. One axis lists your controls, keyed to RMF subcategories; the other lists every regime with a claim on Windrose. Each cell answers: does this control produce the evidence this law demands, in the form and on the clock it demands?
The crosswalk’s value is bidirectional. Forward: when the Colorado AG’s office asks how you comply with SB 26-189’s explanation duty, you point to one control (adverse-decision explanation workflow, MANAGE 4 documentation) and its state renderings. Backward: when a new law lands, you diff it against the control column and discover that 80% already exists — what is genuinely new is usually a clock, a form, or a filing.
| Control (RMF anchor) | Colorado SB 26-189 | CCPA ADMT regs | NYC LL144 / IL HB 3773 | Texas TRAIGA | ECOA / SR 11-7 | SB 53 (via vendor) |
|---|---|---|---|---|---|---|
Point-of-use notice (GOVERN 1, MAP 1) | Point-of-interaction notice | Pre-use notice + opt-out handling | 10-business-day candidate notice / notice of AI use | Government + healthcare disclosure analogs | Not the mechanism — ECOA acts at denial | n/a |
Adverse-decision explanation + human review (MANAGE 4, GOVERN 5) | Plain-language explanation in 30 days; correction; reconsideration | Access/explanation rights | Alternative-process requests | Reasonableness evidence | Adverse action notice with specific principal reasons — no black-box excuse | n/a |
Disaggregated outcome testing (MEASURE 2) | Evidence for fault allocation | Risk-assessment content | The bias audit itself / IHRA defense evidence | Rebuts intent inference | Fair-lending analysis; model validation | n/a |
Vendor documentation + contract clauses (GOVERN 6, MAP 4) | Receive developer technical docs (due from Jan 1, 2027) | Service-provider terms | Audit data access from vendor | Developer representations | SR 11-7 vendor-model validation | Vendor’s frontier framework + incident duties flow into your contract |
Incident response + reporting (MANAGE 4, GOVERN 4) | Cure-period response readiness | Breach/security overlay | DCWP/IDHR inquiry response | 60-day cure execution | Regulator notification norms | Cal OES clocks (vendor primary; you feed evidence) |
Records retention (GOVERN 1) | 3-year records | Assessment retention + Apr 2028 submissions | Audit history | Defense documentation | Model inventory + validation reports | Transparency report inputs |
Week three, you draft the artifacts — the concrete documents regulators, consumers, and counterparties actually see. Templates are where programs live or die: a beautiful policy with no explanation template means a panicked paralegal improvising one at day 28 of a 30-day clock.
Impact assessment
One template serving CCPA risk assessments (first submissions due April 1, 2028) and internal tiering: purpose and context (MAP 1), affected populations and plausible harms (MAP 5), disaggregated performance results (MEASURE 2), mitigations and residual risk with sign-off (MANAGE 1). Write it knowing an AG may read it — factual, specific, free of both marketing and self-incrimination-by-adjective.
Notices
Layered, not duplicated: a point-of-interaction notice (Colorado wording as the strictest base, rendered also as the CCPA pre-use notice with opt-out mechanics and the Illinois AI-use notice) plus the LL144 candidate notice on its 10-business-day clock. Windy’s chat interface carries the Utah-compliant bot disclosure by default — cheaper than detecting Utah users.
Adverse-decision explanation
The hardest artifact. For AdvanceScore it must double as an ECOA adverse action notice: specific principal reasons for the denial — regulators have said plainly that model complexity is no excuse. For SiftIQ it renders as Colorado’s 30-day plain-language explanation with data-correction and human-review pathways. Design rule: if the model cannot yield reason codes a consumer can act on, that is a model requirement, discovered now, not a letter-drafting problem discovered in production.
Model + system cards
Internal model cards (intended use, training data, evaluations, limits) feed everything external: the vendor documentation Colorado requires SiftIQ’s developer to supply, the AB 2013 training-data posting if Windy is deemed made available to Californians, and SR 11-7-grade validation records for AdvanceScore’s bank partner.
Frontier paperwork (vendor)
Windrose is no frontier developer, but its GenAI vendor is: SB 53 obliges the vendor to publish a frontier framework and transparency reports and to report critical incidents to Cal OES; RAISE adds New York duties from January 1, 2027. Your artifact is the contract: warranties that those duties are met, incident-notification flow-down on defined clocks, and audit rights — GOVERN 6 rendered as clauses.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.