Compliance module administration

Enable framework assessments, review control gaps, create linked rules, record attestations, and export evidence from the Compliance module.

The Compliance module shows which technical controls your AIFW installation can prove and which it cannot. It reads the live rule configuration, evaluates selected frameworks, records gaps and attestations, and produces evidence reports.

The module is separate from the rules engine. The rules engine enforces traffic policy. The Compliance module assesses that configuration and reports the result. A compliance gap is not itself a traffic decision.

The Compliance module is not legal advice, certification, or a replacement for organizational controls. Use the primary sources for each framework and confirm applicability with qualified counsel, an auditor, assessor, or certification body.

Enable the module#

Open AI Firewall -> Agent Config -> Compliance. The Compliance section is available when the module is enabled. When it is off, no assessment runs, no scheduled compliance work runs, and the Compliance navigation item is hidden.

SettingDefaultMeaning
Enable the compliance module (ai_fw_compliance_enabled)OffTurns framework assessment and evidence generation on or off.
Frameworks (compliance_frameworks_enabled)None selectedSelect the frameworks to assess. The stored value is a comma-separated list of framework identifiers.
Report schedule (compliance_report_schedule)weeklyControls the schedule used for evidence reports: off, daily, weekly, or monthly.
Assessment interval (minutes) (compliance_assessment_interval_minutes)1440Controls scheduled assessment frequency. The application accepts values from 15 to 10080 minutes.
Evidence retention (days) (compliance_evidence_retention_days)Deployment settingControls how long generated evidence reports are retained. The UI accepts values from 30 to 3650 days.
Raise drift events (compliance_drift_alert_enabled)Deployment settingRecords an event when a rule change affects a control that was previously assessed.
Attestation expiry (days) (compliance_attestation_expiry_days)Deployment settingSets how long a manual attestation remains valid before it must be renewed. The UI accepts values from 1 to 3650 days.

The settings page also links to the Compliance page, where posture and evidence are reviewed.

Review the Compliance page#

Open Compliance from the sidebar after enabling the module. The page shows:

  • Frameworks under management: frameworks selected for assessment.
  • Controls assessed: controls included in the current scope.
  • Open gaps: controls that are missing, disabled, or misconfigured.
  • Posture score: the latest assessment score, or Not measured before the first assessment.

Use Run assessment to evaluate the selected scope. The page provides explicit empty states when the module is disabled or no assessment has run, so an empty page is not treated as a pass.

Manage frameworks and controls#

The framework table shows the current status, control count, gaps, and score for each framework. Use Enable or Disable to change which frameworks are under management.

The controls table can be filtered by:

FilterUse
StatusFocus on compliant controls, open gaps, unknown results, or other assessment outcomes.
SeverityPrioritize controls with higher impact.
MandatorySeparate mandatory controls from supporting controls.

Each control shows its requirement, severity, current status, attached rule, attestation, and evidence detail. A control whose rule is missing or disabled is reported as a gap rather than a pass.

When a selected framework provides a rule pack, choose a Control and Template, enter a Pattern or keywords value, and select Create and link.

The module supplies the expected direction, action, and severity. The new rule is created enabled and linked to the control, then appears in the control row for later assessment. Review the generated pattern before relying on it in production.

Record an attestation#

Some framework obligations require a named human decision or organizational activity. When a control supports an attestation, use Attest and provide the basis for the statement.

An attestation records:

  • The person who made the statement
  • The expiry date
  • An optional note describing its basis

Use Withdraw when the statement is no longer valid. Expired or withdrawn attestations do not count as proven controls.

Understand assessment results#

The Compliance page distinguishes between a missing control and an unknown result:

ResultMeaning
CompliantThe configured control satisfies the assessment checks.
UnknownThe module could not verify the underlying configuration or identity coverage.
GapMissingThe expected rule or control is not present.
GapDisabledThe expected rule exists but is disabled.
GapMisconfiguredThe rule exists but does not match the expected configuration.
AttestationExpiredA required human attestation has expired.

A control that exists but is switched off is a gap. An unreadable rule inventory is unknown, not an empty inventory. This distinction prevents an unavailable data source from being treated as evidence of compliance.

Evidence and drift#

Evidence reports are generated per framework and persist beyond the assessment that created them. Reports are available as:

  • JSON for machine-readable processing
  • CSV for review and spreadsheet workflows

Reports contain control status, rule state, relevant settings, retention information, and inventory evidence. Prompt and response content is not included in the evidence pack.

When Raise drift events is enabled, changing a rule that a control depends on records the affected control, the change, and the actor. Run a new assessment after resolving drift so the posture reflects the current configuration.

A2A identity prerequisite#

Identity-scoped controls require authenticated agent traffic. If a2a_auth_mode is off, the Compliance page identifies the prerequisite and reports affected identity controls as UNKNOWN rather than compliant. Enable A2A authentication from AI Firewall -> Agent Config -> Access & Identity before assessing identity coverage.

Where to go next#