Compliance packs

Compliance packs bundle observation Rego and manifest metadata that map shadow traffic to regulatory frameworks. Select packs during onboarding or in the Compliance dashboard.

Available packs (representative)

Pack IDFrameworkJurisdiction
fintrac_pcmltfaFINTRAC PCMLTFACA
fincen_bsaFinCEN Bank Secrecy Act (BSA/AML)US
osfi_b13OSFI B-13CA
osfi_e21_e23OSFI E-21 / E-23CA
osfi_e23_b10OSFI E-23 / B-10 (tech & cyber)CA
cccp_level_1 / cccp_level_2CCCPCA
pipeda_bill_c27PIPEDA / Bill C-27CA
bill_c27_aidaBill C-27 / AIDA (AI & Data Act)CA
phipa_ontarioPHIPACA
nist_ai_rmfNIST AI RMF (v1)US
nist_ai_rmf_v2NIST AI RMF v2US
sec_cyber_disclosureSEC cyber disclosure rulesUS
nist_sp_800_53NIST SP 800-53US
hipaa_security_ruleHIPAA Security RuleUS
soc2_tscSOC 2 TSCGlobal
pci_dss_v4PCI DSS v4Global
iso_27001_2022ISO 27001:2022Global

How relevance scoring works

Each manifest declares relevance_signals (path tokens, request/response field names). The Control Plane compares signals to observed fingerprints and recommends packs above the confidence threshold.

Packs may declare controls with pip_required: false (assessable from traffic alone) or pip_required: true (needs PIP — may show CANNOT_ASSESS until connected).

Select packs in the UI

  1. Complete the Getting Started wizard step Select compliance frameworks, or
  2. Open Compliance & Gaps and filter by pack.

Troubleshooting: If a pack never appears, check fingerprint coverage for its signal tokens (e.g. FINTRAC expects transaction, payment, kyc). See Gap report.

Framework capability matrix

How shadow discovery → gap report → enforce maps to common frameworks. Use this when selecting packs and writing evidence narratives.

FrameworkShadow telemetryFingerprints / packsPIP-enriched controlsEnforce evidence
SOC 2 CC6 (logical access)SHADOW_WOULD_DENY on privileged pathssoc2_tsc observationsIdP / HR PIPs for joiner-mover-leaverLive DENY/mask + audit export
Law 25 §12 (accountability)Would-deny/allow with control idsPIPEDA / Law 25 pack rowsResidency + purpose attributesPDF clause mapping + change records
PIPEDA (safeguards 4.7)Shadow on PII routespipeda_bill_c27Consent / classification PIPsMask obligations + access logs
CCCP L2 / L3Identity & compartment gapscccp_level_1 / cccp_level_2 (+ L3 controls)Clearance / compartment PIPsEnforce + Policy Bridge sync proof
OSFI B-13Wire / privileged / AI prompt gapsosfi_b13, osfi_e21_e23, osfi_e23_b10Workday certs, model risk registerPromote playbook + post-enforce verify
Bill C-27 / AIDAAI system & automated decision gapsbill_c27_aida, pipeda_bill_c27Consent / AI impact PIPsMask + purpose limitation in audit
SEC cyber disclosureMaterial incident & risk gapssec_cyber_disclosureGRC / incident PIPsEnforce + executive report export
FinCEN BSAAML / funds transfer gapsfincen_bsa, fintrac_pcmltfaKYC / transaction PIPsLive deny on flagged flows
NIST AI RMFPrompt/tool shadow eventsnist_ai_rmf, nist_ai_rmf_v2Clearance + AI attestation PIPsGuardrail decisions in audit

CANNOT_ASSESS means the pack control needs PIP data not yet connected — continue discovery and track in the compliance report.

Next steps: Gap report