En este modulo

  1. The modern compliance challenge
  2. Regulatory mapping with AI
  3. Monitoring regulatory changes
  4. Automated compliance checks
  5. Gap analysis
  6. Audit preparation
  7. Compliance reporting and dashboards
  8. Key regulatory frameworks
  9. Ejercicio practico
  10. Puntos clave

The modern compliance challenge

A mid-sized European company in the financial sector must comply with over 200 regulatory requirements. GDPR, PSD2, MiFID II, AI Act, NIS2, DORA, Anti-Money Laundering Directives, sector-specific national regulations, EU directives, supervisory circulars. And every year, 10 to 20 new obligations are added.

The compliance officer has a scale problem. It is not that they do not know what they must comply with. It is that they cannot track everything, verify everything, and document everything with limited resources. AI does not solve the compliance problem. It solves the scale problem of compliance.

Where AI adds value

The compliance officer does not disappear

AI automates 60-70% of compliance work (reading, extraction, documentation). The remaining 30-40% (interpretation, prioritization, implementation, regulator relations) still requires expert human judgment. The compliance officer with AI is more effective, not expendable.

Regulatory mapping with AI

Regulatory mapping consists of identifying all regulations that apply to your organization and breaking them down into specific obligations. It is the foundation of any compliance program.

Identifying applicable regulations

My company has these characteristics:
- Sector: [financial/healthcare/technology/industrial/energy/other]
- Size: [employees] employees, [revenue] EUR revenue
- Countries of operation: [list]
- Activities: [list of main activities]
- Data processed: [types of personal/sensitive data]
- Critical infrastructure: [yes/no, type]
- Publicly listed: [yes/no]
- Obliged entity under AML Directives: [yes/no]

Identify ALL applicable regulations, organized by:

1. DIRECTLY APPLICABLE EU LEGISLATION
   (regulations, no transposition needed)

2. TRANSPOSED EU DIRECTIVES
   (indicate the national transposition law)

3. NATIONAL LEGISLATION

4. SECTOR-SPECIFIC REGULATION
   (circulars, binding guidance from the regulator)

5. STANDARDS AND FRAMEWORKS
   (ISO, NIST, COBIT, non-binding but expected by regulators)

For each: full name, date, status (in force/pending/planned),
compliance deadline if applicable.

Obligation breakdown

Break down the obligations of [regulation name] that apply to a
[sector] company with [characteristics].

For each obligation:
1. Article/section of the regulation
2. Specific obligation (what must I do)
3. Typical responsible person in the organization
4. Frequency (one-time/periodic/continuous)
5. Required compliance evidence
6. Penalty for non-compliance
7. Compliance deadline

Group by functional area:
- Corporate governance
- Data protection
- Information security
- Anti-money laundering
- Employment
- Tax
- Sector-specific

Format: table with the 7 columns.

Cross-mapping requirements

Many regulations require the same thing with different wording. Cross-mapping prevents you from duplicating work.

Compare the requirements of these 3 regulations on [information
security / data protection / AI governance]:

Regulation 1: [GDPR, relevant articles]
Regulation 2: [NIS2, relevant articles]
Regulation 3: [AI Act, relevant articles]

For each requirement:
1. What each regulation demands (summarized text)
2. Are they equivalent? (yes: complying with one satisfies the others)
3. Are they complementary? (require additional actions)
4. Are they contradictory? (regulatory conflict)

Generate an equivalence matrix that enables implementing a single
measure that satisfies multiple regulations simultaneously.

Format: table [Requirement | GDPR | NIS2 | AI Act | Unified measure]

Cross-mapping saves money

If you implement an information security management system (ISMS) compliant with ISO 27001, you are covering 60-70% of NIS2 requirements, 40-50% of DORA, and 30-40% of GDPR technical requirements. Mapping these equivalences prevents implementing duplicate controls.

Monitoring regulatory changes

Regulations change. New ones are published. Existing ones are amended. Others are repealed. A compliance officer needs to know the day it is published, not 6 months later during an audit.

Regulatory alert system

AI cannot monitor in real time (it does not browse the internet for you). But you can build a workflow:

  1. Sources: subscribe to the relevant official journals (Official Journal of the EU, national gazettes, regulatory authorities, sector regulators).
  2. Ingestion: automate collection with tools like n8n, Zapier, or RSS readers.
  3. AI filtering: pass each publication through a classification prompt to determine if it affects you.
  4. Impact analysis: for relevant regulations, use an impact analysis prompt.
  5. Action: generate tasks in your management tool (Jira, Asana, Notion) with an owner and deadline.

Regulatory filtering prompt

Analyze the following regulatory publication and determine if it
affects my organization:

Organization: [sector, size, activities]
Publication: [title, source, date, summary text]

Respond ONLY:
1. Affects my organization: YES / NO / POSSIBLY
2. If it does: which functional area is impacted
3. Urgency: IMMEDIATE / 30 DAYS / 90 DAYS / INFORMATIONAL
4. Required action: [1 line]

If the answer is NO, do not provide further information.

Regulatory impact analysis prompt

The following new regulation affects my organization:
[name, date, summary of the regulation]

Analyze the impact:

1. NEW OBLIGATIONS
   - What must I do that I was not doing before?
   - Who is responsible?
   - What is the deadline?

2. MODIFIED OBLIGATIONS
   - What changes compared to the previous regulation?
   - Are my current controls still sufficient?

3. OPERATIONAL IMPACT
   - Does it require process changes?
   - Does it require new technology or tools?
   - Does it require staff training?

4. FINANCIAL IMPACT
   - Estimated implementation cost
   - Penalty for non-compliance

5. ACTION PLAN
   - Specific actions ordered by priority
   - Implementation timeline

Automated compliance checks

Periodic checks are the core of operational compliance. AI can automate a large portion of these checks.

Automated checklist

Run a [monthly/quarterly] compliance check on
[area: data protection / security / AML / employment].

Current status provided:
[paste current status: active policies, implemented controls,
recent incidents, latest audits]

Verify:
1. Policies: are they up to date? (date of last review)
2. Controls: are they being executed as planned?
3. Incidents: have they been handled correctly? Lessons learned?
4. Training: is staff trained and up to date?
5. Documentation: is it sufficient to demonstrate compliance?
6. Regulatory changes: are there new obligations since the last check?

For each point:
- Status: COMPLIANT / NON-COMPLIANT / PARTIALLY COMPLIANT
- Required evidence
- Corrective action if applicable
- Owner and deadline

Internal policy verification

Compare our internal policy on [data protection / security /
AI usage / etc.] with current legal requirements.

Our policy: [paste policy text]

Applicable regulations: [list of regulations]

Identify:
1. GAPS: legal requirements not covered by our policy
2. EXCESSES: commitments in our policy that go beyond
   the law (may create unnecessary contractual obligations)
3. AMBIGUITIES: points an auditor would question
4. OUTDATED REFERENCES: references to repealed or amended regulations

For each gap: suggested text to add to the policy.

Gap analysis

Gap analysis is the exercise of comparing your current compliance status with what the regulation requires. It is the first thing an auditor does. Better that you do it first.

Structured gap analysis

Perform a [regulation] compliance gap analysis for my organization.

Regulation requirements: [list or regulation text]

Current status of my organization:
- Implemented policies: [list]
- Technical controls: [list]
- Operational processes: [list]
- Training completed: [description]
- Available documentation: [list]

For each regulation requirement:
1. Requirement (reference and description)
2. Status: COMPLIANT / NON-COMPLIANT / PARTIAL
3. Available evidence
4. Gap identified (if non-compliant)
5. Required corrective action
6. Estimated effort: LOW (< 1 week) / MEDIUM (1-4 weeks) / HIGH (> 1 month)
7. Priority: CRITICAL / HIGH / MEDIUM / LOW

Final summary:
- Overall compliance %
- Top 5 critical gaps
- Prioritized remediation plan
Practical tip: Do the gap analysis before hiring the external auditor. It is much cheaper to fix gaps internally than to pay the auditor to find them and then fix them under pressure.

Audit preparation

Preparing for a regulatory audit (data protection authority, financial regulator, ISO audit) is a process that consumes weeks of work. AI can accelerate the preparation.

Evidence generation

Prepare the evidence documentation for a [regulation] audit
in the [functional area] area.

For each regulation requirement in this area:
1. Regulatory requirement (reference)
2. Implemented control (description of what we do)
3. Available evidence:
   - Type (document/record/screenshot/log/minutes)
   - Location
   - Date
   - Owner
4. Missing evidence that we need to generate
5. Typical auditor questions for this control
6. Prepared response

Organize in the auditor's usual review order.

Audit simulation

Act as a [regulation] auditor conducting a compliance audit.

My organization has provided this information:
[paste documentation]

As auditor:
1. What questions would you ask the compliance officer?
2. What additional documentation would you request?
3. What inconsistencies do you see in the presented documentation?
4. Where would you issue a non-conformity finding?
5. What improvement recommendations would you give?

Be critical and demanding. I prefer to find problems now
rather than during the actual audit.

Compliance reporting and dashboards

The compliance officer needs to report to the Board, Management, and regulators. AI can generate these reports.

Board report

Generate a quarterly compliance report for the Board of Directors.
Maximum 2 pages.

Period data:
[incidents, findings, regulatory changes, control status]

Structure:
1. Overall compliance status: GREEN / AMBER / RED
2. Regulatory changes this quarter that affect us
3. Compliance incidents (if any)
4. Status of open remediation plans
5. Emerging risks identified
6. Resources needed (if requesting from the Board)
7. Upcoming obligations with deadlines

Tone: executive, concise, risk-oriented.
No unnecessary technical jargon.

Key regulatory frameworks

For each framework, AI can assist you differently:

Ejercicio practico

Ejercicio LG03: Compliance program for a fintech

Scenario: You are the compliance officer of a European fintech with 80 employees that processes payments (PSD2), processes personal data (GDPR), and is starting to use AI for risk scoring (AI Act).

  1. Mapping: Use the regulation identification prompt to list all applicable regulations.
  2. Breakdown: Choose 2 regulations (GDPR and AI Act) and break down the specific obligations.
  3. Gap analysis: Define a reasonable fictional current state and run a gap analysis against the AI Act.
  4. Cross-mapping: Identify overlapping requirements between GDPR, NIS2, and AI Act on security.
  5. Report: Generate a Board report with compliance status, gaps, and action plan.

Bonus: Simulate receiving an official gazette publication with a new regulatory circular. Use the filtering prompt to determine if it affects you and the impact analysis prompt if the answer is yes.

Puntos clave

Puntos clave from LG03

  1. Modern compliance is a scale problem. AI solves the scale, not the judgment.
  2. Regulatory mapping with AI gives you in hours what manually takes weeks. But it requires human validation.
  3. Cross-mapping requirements between regulations avoids duplicating controls and saves implementation costs.
  4. Build a regulatory alert system: source + ingestion + AI filtering + impact analysis + action.
  5. Do the gap analysis before the audit. It is cheaper to fix internally than under auditor pressure.
  6. Audit simulation with AI is the most valuable preparation exercise. Ask it to be critical.
  7. Board reports should be executive (2 pages), risk-oriented, without technical jargon.
Guia de estudio — Conceptos clave de LG03

El problema del compliance moderno

  • Lectura de normativa:la IA puede procesar un Reglamento de 100 articulos y extraer las obligaciones que aplican a tu empresa en minutos.
  • Monitorizacion continua:alertar cuando se publica una nueva norma que te afecta.
  • Mapeo cruzado:relacionar requisitos de diferentes normas que se solapan (RGPD + AI Act + NIS2 tienen requisitos sobre seguridad de datos que se superponen).
  • Evidencia de cumplimiento:generar documentacion que demuestre que estas cumpliendo.
  • El compliance officer no desaparece: La IA automatiza el 60-70% del trabajo de compliance (lectura, extraccion, documentacion). El 30-40% restante (interpretacion, priorizacion, implementacion, relacion con reguladores) sigue requiriendo criterio humano experto. El compliance officer con IA es mas eficaz, no prescindible.

Mapeo regulatorio con IA

  • Sector: [financiero/salud/tecnologia/industrial/energia/otro]
  • Tamano: [empleados] empleados, [facturacion] EUR facturacion
  • Paises donde opera: [lista]
  • Actividades: [lista de actividades principales]
  • Datos que trata: [tipos de datos personales/sensibles]
  • Infraestructura critica: [si/no, tipo]

Monitorizacion de cambios normativos

  • Fuentes:suscribete a los boletines oficiales relevantes (BOE, DOUE, CNMV, AEPD, INCIBE, reguladores sectoriales).
  • Ingesta:automatiza la recogida con herramientas como n8n, Zapier o RSS readers.
  • Filtrado con IA:pasa cada publicacion por un prompt de clasificacion para determinar si te afecta.
  • Analisis de impacto:para las normas relevantes, usa un prompt de analisis de impacto.
  • Accion:genera tareas en tu herramienta de gestion (Jira, Asana, Notion) con responsable y deadline.
  • Que debo hacer que antes no hacia?

Verificaciones automatizadas de compliance

  • Estado: CONFORME / NO CONFORME / PARCIALMENTE CONFORME
  • Evidencia necesaria
  • Accion correctiva si procede
  • Responsable y plazo

Analisis de gaps

  • Politicas implementadas: [lista]
  • Controles tecnicos: [lista]
  • Procesos operativos: [lista]
  • Formacion realizada: [descripcion]
  • Documentacion disponible: [lista]
  • % de cumplimiento global
Haz el gap analysis antes de contratar al auditor externo. Es mucho mas barato corregir gaps internamente que pagarle al auditor para que te los encuentre y luego corregirlos bajo presion.

Preparacion de auditorias

  • Tipo (documento/registro/screenshot/log/acta)
  • Responsable

Siguiente: LG04 - EU AI Act: Complete Practical Guide

The AI Act is the most relevant regulation of the decade for legal professionals. We will analyze it article by article with technical and legal depth.

Ir al modulo LG04