AI governance becomes inventory and approvals, sanctions screening turns network-based, and compliance shifts to live execution

By DripPublished

The gist

Compliance work is shifting from policy writing to operating named controls, tracing networked counterparties, and proving continuous execution under audit-ready systems.

This week’s developments

FSB and RBI Turn AI Governance Into Inventory and Approval Controls

The FSB’s 12-practice AI governance sound practices now put named control artifacts at the center of bank oversight: board-approved AI strategy and risk appetite, explicit accountability, enterprise risk integration, periodic governance review, and controls for materiality assessment, data quality, explainability, validation, monitoring, and human oversight. It goes further than many bank regimes by calling for AI inventories and approvals, formal override points for material decisions, AI-specific performance testing, and stronger third-party continuity and exit planning.

The RBI’s proposed bank AI framework pushes the same direction by requiring a comprehensive inventory of all AI models, including active, inactive, and decommissioned systems; banning use of any model not listed; and retaining decommissioned models for 10 years, with comments open until 24 July 2026. Colorado’s tightened high-risk AI rules require documentation of purpose, design, data used, risk controls, and monitoring evidence, while the EU is moving disclosure earlier in the workflow for recruitment AI.

For Compliance teams, this is the next step beyond lifecycle controls: turning governance into inventory management, approval logic, testing evidence, and exam-ready records across legal, risk, engineering, and HR.

How do we operationalize AI inventories, approvals, and evidence retention?

If you're an individual contributor

  • AI compliance is becoming evidence work, not policy reading.
  • Learn to trace inventories, approvals, testing, and monitoring records—you'll be judged on audit-ready proof, not just rule recall.

Sources

If you manage a team

  • Your team must shift from reviewing controls to proving them.
  • Coach people on inventory discipline, exception handling, and documentation quality; that's where team credibility will be won or lost.

Sources

If you lead the organization

  • AI governance now needs inventory, approvals, and retention by design.
  • Fund a cross-functional operating model for AI records, model approval, and exam evidence—or you'll fail consistency across legal, risk, and tech.

Sources

Third-Party Screening Shifts to Network-Based Investigation

U.S. regulators this week targeted crypto firm Shelbit Exchange over alleged Iran-linked activity routed through IRGC-associated wallets, Nobitex, and other counterparties. Treasury said more than $1 million moved from IRGC addresses to Shelbit, more than $2 million moved back to IRGC addresses, and about $2 million flowed from Shelbit-linked wallets to Nobitex, with additional activity through Aban Tether involving Wallex, Bitpin, and Ramzinex. In Austria, authorities uncovered a sanctions-evasion network that moved more than €3.3 million in industrial machinery and CNC tools to Russian military end users through intermediaries in Turkey, the UAE, Hong Kong, Belarus, Kyrgyzstan, South Korea, Poland, Lithuania, and Spain, using falsified end-user certificates. Armenian banks, effective August 12, are tightening Russia-related controls by screening counterparties, transaction context, and beneficial ownership, with pre-transaction suspension or rejection and re-review within one business day after sanctions-list or customer-data changes.

The enforcement message is clear: name screening alone is no longer enough. Regulators are testing hidden counterparties, affiliated institutions, payment rails, shipment routes, and end-user validation across multi-jurisdiction chains.

For compliance teams, the job is shifting from checking a customer record to reconstructing the transaction ecosystem before it clears. The practical edge now comes from tracing beneficial owners, mapping intermediaries, documenting escalation decisions, and using continuous monitoring that catches changes before execution.

How should your screening program adapt to network-based investigations?

If you're an individual contributor

  • Name screening is table stakes; network tracing is now your edge.
  • You need to read counterparties, wallets, routes, and BO links fast—or your value stays basic screening.

Sources

If you manage a team

  • Your team must move from alerts to ecosystem investigation.
  • Coach analysts to map hidden links, document escalations, and re-check changes before execution, not after.

Sources

If you lead the organization

  • Your operating model is behind if it still assumes single-name screening.
  • Invest in network analytics, BO data, and continuous monitoring; otherwise your controls will miss the real risk.

Sources

Compliance Becomes a Governed Change-Execution Workflow

PHMSA’s August 4, 2026 final rules (HM-268A through HM-268P) and the latest packaging compliance tooling point to the same shift: compliance is moving from periodic document upkeep to continuous, rule-driven execution. BDG updated ShipHazmat to reflect the new aerosol definition, smaller limited-quantity markings for certain highway, rail, and vessel shipments, higher lithium battery allowances under Materials of Trade, and revised special permit provisions. It also added options to retain certain emergency response and registration information electronically, while its built-in regulatory logic directs users through the required hazardous-material shipping papers by air, ground, and vessel.

On the packaging side, the Advilex + UnicornForms platform now supports PPWR declaration-of-conformity workflows, technical documentation, supplier declarations, regulatory assessments and approvals, plus version control, change management, and audit trails, with ARCAIS as the source of truth for product and packaging data. For compliance teams, the job is no longer just keeping records current. It is designing governed workflows that turn new rules into required actions, approvals, and defensible evidence across jurisdictions.

How should we redesign compliance workflows for continuous rule changes?

If you're an individual contributor

  • Manual compliance upkeep is fading; workflow design is now the value.
  • Learn to run rule-triggered tools, validate outputs, and manage evidence trails—those skills make you harder to replace.

Sources

If you manage a team

  • Your team must shift from record-keeping to governed execution.
  • Coach people on exception handling, approvals, and audit-ready workflows; stop measuring value by document maintenance alone.

Sources

If you lead the organization

  • Compliance is becoming an operating model, not a back-office function.
  • Invest in workflow platforms, data governance, and cross-functional ownership now, or your team will stay stuck in manual control.

Sources

Modulos Lands in Regulator Oversight as AI Control Stacks Converge

A European regulator’s choice of Modulos for internal AI oversight is the clearest sign yet that the control layer is moving from enterprise deployment into supervisory use. The same system is being used to audit the regulator’s own AI and to run a supervisory sandbox for insurance use cases, which raises the bar: buyers now need tools built for auditability, not just internal policy management.

That shift is happening alongside a broader convergence toward one operating layer for privacy, consent, lineage, and AI governance. Solidatus’ 2026.3 release pushes that direction with MCP support, Bring Your Own LLM, and persistent assistant sessions, while Actualyze and DataShyre add to the pressure toward integrated control stacks rather than standalone point tools. The practical change from last week’s real-time enforcement story is that organizations now have to connect those live controls to shared evidence and exception handling inside the same workflow.

For compliance professionals, the skill premium is moving further toward operating the full stack. Teams that can connect AI inventory, consent, lineage, monitoring, and supervisory-grade evidence in one system will be better positioned for regulator scrutiny and faster AI deployment. The work is becoming less about policy design in isolation and more about running the control layer day to day.

How should we adapt our control stack for supervisory-grade auditability?

If you're an individual contributor

  • AI compliance is becoming hands-on control work, not just policy review.
  • Build fluency in inventory, lineage, monitoring, and evidence trails—those who can run the stack will stay indispensable.

Sources

If you manage a team

  • Your team’s edge now comes from operating evidence, not drafting rules.
  • Coach people on exception handling and audit-ready workflows; shift time from policy upkeep to live control execution.

Sources

If you lead the organization

  • Buy tools and talent for supervisory-grade control, or fall behind scrutiny.
  • Invest in one integrated control stack and hire for AI governance ops; fragmented point tools won’t hold up under regulator use.

Sources

Part of these trends

Stay ahead in Compliance

Get the weekly Compliance brief in your inbox — the developments, what they mean by seniority, and what to do next.