Playbook 5 — The Compliance File
One audit-ready record that answers a regulator, a client, and an ISO auditor
Three different parties will eventually ask what you do about AI, and they ask in different languages. A regulator wants to know how the law applies and what you did about the parts that apply. An enterprise client’s procurement team wants assurance that using you does not import their own risk. An ISO 42001 auditor wants evidence the management system exists and runs. Underneath, they are asking for the same thing.
The mistake is to build a separate pack for each. That produces three documents that drift apart, and the drift is what fails an audit — not the missing control. The better move is one compliance file, assembled from records the governance series already produces, that each reader can open at the point they care about.
Three sources feed it. The Documentation Register from the Governance Playbook Series is the spine: the AI system inventory, the project sheets, the decision log. The AI Risk Management series supplies the risk register — categories, scores, treatments. And the Act’s own required records attach to the same rows, which is the point: a high-risk system’s required documentation and its risk-register entry are the same system, described once, twice referenced.
What each reader finds. The regulator finds the tier classification and the transparency notices, mapped to the calendar in Playbook 2. The client’s procurement team finds the vendor-onboarding records and the data-and-bias checks, which answer most of their questionnaire before it arrives. The ISO auditor finds the crosswalk in Playbook 3 — each clause area pointing to the document behind it, with the Support and Continual Improvement gaps marked as known rather than hidden.
Two habits keep it alive. First, one owner, not a committee — the register dies the moment it belongs to everyone. Second, one review cadence, aligned to the checkpoints already in use: the register is reviewed on the same 30/90/180-day rhythm as the value measurements, so the file is current by construction rather than assembled in a panic.
A file that holds:
- One register, with the risk register and the Act’s records pointing into it.
- Tier, role, and transparency status per system.
- Vendor due-diligence records attached to the systems they cover.
- The ISO 42001 crosswalk, with gaps named.
- One named owner and one review date.
The whole series in one line: classify what you have built, know which obligations are already enforceable versus still ahead, map what you have already written to ISO 42001’s clauses, close the transparency gap that is live today, and keep one file that proves all of it — an extension of the governance work, not a parallel project.