title: Compliance packs description: Select FINTRAC, OSFI, CCCP, NIST AI RMF, HIPAA, and other packs for shadow gap discovery. audience: Compliance officers and control authors timeEstimate: 10 minutes prerequisites:

  • Shadow Bouncer deployed
  • Traffic fingerprints available (recommended)

Compliance packs

Compliance packs bundle observation Rego and manifest metadata that map shadow traffic to regulatory frameworks. Select packs during onboarding or in the Compliance dashboard.

Available packs (representative)

Pack IDFrameworkJurisdiction
fintrac_pcmltfaFINTRAC PCMLTFACA
osfi_b13OSFI B-13CA
osfi_e21_e23OSFI E-21 / E-23CA
cccp_level_1 / cccp_level_2CCCPCA
pipeda_bill_c27PIPEDA / Bill C-27CA
phipa_ontarioPHIPACA
nist_ai_rmfNIST AI RMFUS
nist_sp_800_53NIST SP 800-53US
hipaa_security_ruleHIPAA Security RuleUS
soc2_tscSOC 2 TSCGlobal
pci_dss_v4PCI DSS v4Global
iso_27001_2022ISO 27001:2022Global

How relevance scoring works

Each manifest declares relevance_signals (path tokens, request/response field names). The Control Plane compares signals to observed fingerprints and recommends packs above the confidence threshold.

Packs may declare controls with pip_required: false (assessable from traffic alone) or pip_required: true (needs PIP — may show CANNOT_ASSESS until connected).

Select packs in the UI

  1. Complete the Getting Started wizard step Select compliance frameworks, or
  2. Open Compliance & Gaps and filter by pack.

Troubleshooting: If a pack never appears, check fingerprint coverage for its signal tokens (e.g. FINTRAC expects transaction, payment, kyc). See Gap report.

Framework capability matrix

How shadow discovery → gap report → enforce maps to common frameworks. Use this when selecting packs and writing evidence narratives.

FrameworkShadow telemetryFingerprints / packsPIP-enriched controlsEnforce evidence
SOC 2 CC6 (logical access)SHADOW_WOULD_DENY on privileged pathssoc2_tsc observationsIdP / HR PIPs for joiner-mover-leaverLive DENY/mask + audit export
Law 25 §12 (accountability)Would-deny/allow with control idsPIPEDA / Law 25 pack rowsResidency + purpose attributesPDF clause mapping + change records
PIPEDA (safeguards 4.7)Shadow on PII routespipeda_bill_c27Consent / classification PIPsMask obligations + access logs
CCCP L2 / L3Identity & compartment gapscccp_level_1 / cccp_level_2 (+ L3 controls)Clearance / compartment PIPsEnforce + OPAL sync proof
OSFI B-13Wire / privileged / AI prompt gapsosfi_b13, osfi_e21_e23Workday certs, model risk registerPromote playbook + post-enforce verify
NIST AI RMFPrompt/tool shadow eventsnist_ai_rmfClearance + AI attestation PIPsGuardrail decisions in audit

CANNOT_ASSESS means the pack control needs PIP data not yet connected — continue discovery and track in the compliance report.

Next steps: Gap report