Audit-Ready Compliance Platform Architecture for Large Language Model Regulated Enterprises.

Main Article Content

Santhosh Reddy Basireddy

Abstract

Generative language technology has entered regulated enterprises faster than the controls built to govern it, creating a widening gap between capability and defensibility. The probabilistic and opaque behavior of such systems sits uneasily beside supervisory regimes that expect deterministic, explainable, and reconstructable decisions. This article sets out an architecture that treats verifiability as a founding property rather than a later addition so that a regulated deployment can prove its own trustworthiness at any moment. The design begins from the obligations that bind operators, distills them into a small set of anchoring principles, and states plainly the threats it withstands and the assumptions on which its guarantees rest. It organizes the platform into cooperating layers for data governance, model lifecycle, and inference, then surrounds them with pre-deployment validation, continuous evidence capture, explanation of individual decisions, disciplined human oversight, and a retrieval workflow that turns supervisory questions into queries over standing evidence. Provenance, immutability, reproducibility, confidentiality, and accountability run through every layer, binding each recorded action to an identifiable actor and an authorizing policy. The result reframes readiness as a continuous background condition rather than an emergency response, letting an enterprise move quickly while remaining answerable. Honest attention to residual constraints, from imperfect drift detection to the tension between privacy and utility, strengthens the posture by making the boundaries of each guarantee legible to those who must rely on it.

Downloads

Download data is not yet available.

Article Details

How to Cite
Basireddy, S. (2023). Audit-Ready Compliance Platform Architecture for Large Language Model Regulated Enterprises. SAMRIDDHI : A Journal of Physical Sciences, Engineering and Technology, 15(01), 226-232. Retrieved from https://smsjournals.com/index.php/SAMRIDDHI/article/view/3549
Section
Articles

References

[1] T. B. Brown et al., “Language models are few-shot learners,”
in Advances in Neural Information Processing Systems, vol.
33, 2020, pp. 1877–1901. [Online]. Available: https://arxiv.org/
abs/2005.14165
[2] J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, “BERT:
Pre-training of deep bidirectional transformers for language
understanding,” in Proc. Conf. North Amer. Chapter Assoc.
Comput. Linguistics: Human Lang. Technol. (NAACL-HLT),
2019, pp. 4171–4186. [Online]. Available: https://aclanthology.
org/N19-1423/
[3] M. Mitchell et al., “Model cards for model reporting,” in Proc.
Conf. Fairness, Accountability, and Transparency (FAT*), 2019,
pp. 220–229, doi: 10.1145/3287560.3287596. [Online]. Available:
https://dl.acm.org/doi/10.1145/3287560.3287596
[4] J. Lu, A. Liu, F. Dong, F. Gu, J. Gama, and G. Zhang, “Learning
under concept drift: A review,” IEEE Trans. Knowl. Data
Eng., vol. 31, no. 12, pp. 2346–2363, Dec. 2019, doi: 10.1109/
TKDE.2018.2876857. [Online]. Available: https://doi.org/10.1109/
TKDE.2018.2876857
[5] A. Barredo Arrieta et al., “Explainable Artificial Intelligence
(XAI): Concepts, taxonomies, opportunities and challenges
toward responsible AI,” Inf. Fusion, vol. 58, pp. 82–115, 2020,
doi: 10.1016/j.inffus.2019.12.012. [Online]. Available: https://doi.
org/10.1016/j.inffus.2019.12.012
[6] T. Gebru et al., “Datasheets for datasets,” Commun. ACM, vol.
64, no. 12, pp. 86–92, Dec. 2021, doi: 10.1145/3458723. [Online].
Available: https://dl.acm.org/doi/10.1145/3458723
[7] R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman,
“Role-based access control models,” Computer, vol. 29, no. 2,
pp. 38–47, Feb. 1996, doi: 10.1109/2.485845. [Online]. Available:
https://doi.org/10.1109/2.485845
[8] D. Sculley et al., “Hidden technical debt in machine learning
systems,” in Advances in Neural Information Processing
Systems, vol. 28, 2015, pp. 2503–2511. [Online]. Available: https://
papers.nips.cc/paper/5656-hidden-technical-debt-in-machinelearning-
systems
[9] X. Liang, S. Shetty, D. Tosh, C. Kamhoua, K. Kwiat, and L.
Njilla, “ProvChain: A blockchain-based data provenance
architecture in cloud environment with enhanced privacy and
availability,” in Proc. 17th IEEE/ACM Int. Symp. Cluster, Cloud
and Grid Computing (CCGRID), 2017, pp. 468–477, doi: 10.1109/
CCGRID.2017.8. [Online]. Available: https://doi.org/10.1109/
CCGRID.2017.8
[10] C. Dwork and A. Roth, “The algorithmic foundations of
differential privacy,” Found. Trends Theor. Comput. Sci., vol. 9,
no. 3–4, pp. 211–407, 2014, doi: 10.1561/0400000042. [Online].
Available: https://doi.org/10.1561/0400000042
[11] B. Goodman and S. Flaxman, “European Union regulations
on algorithmic decision-making and a ‘right to explanation’,”
AI Mag., vol. 38, no. 3, pp. 50–57, 2017, doi: 10.1609/aimag.
v38i3.2741. [Online]. Available: https://doi.org/10.1609/aimag.
v38i3.2741
[12] N. Mehrabi, F. Morstatter, N. Saxena, K. Lerman, and
A. Galstyan, “A survey on bias and fairness in machine
learning,” ACM Comput. Surv., vol. 54, no. 6, pp. 1–35, Jul.
2021, doi: 10.1145/3457607. [Online]. Available: https://doi.
org/10.1145/3457607
[13] A. Vaswani et al., “Attention is all you need,” in Advances in
Neural Information Processing Systems, vol. 30, 2017, pp.
5998–6008. [Online]. Available: https://arxiv.org/abs/1706.03762
[14] L. Sweeney, “k-anonymity: A model for protecting privacy,” Int.
J. Uncertainty, Fuzziness and Knowledge-Based Systems, vol.
10, no. 5, pp. 557–570, 2002, doi: 10.1142/S0218488502001648.
[Online]. Available: https://doi.org/10.1142/S0218488502001648
[15] I. D. Raji et al., “Closing the AI accountability gap: Defining an
end-to-end framework for internal algorithmic auditing,” in
Proc. Conf. Fairness, Accountability, and Transparency (FAT*),
2020, pp. 33–44, doi: 10.1145/3351095.3372873. [Online].
Available: https://dl.acm.org/doi/10.1145/3351095.3372873
[16] S. Amershi et al., “Software engineering for machine learning:
A case study,” in Proc. IEEE/ACM 41st Int. Conf. Software
Engineering: Software Engineering in Practice (ICSE-SEIP),
2019, pp. 291–300, doi: 10.1109/ICSE-SEIP.2019.00042. [Online].
Available: https://doi.org/10.1109/ICSE-SEIP.2019.00042
[17] M. T. Ribeiro, S. Singh, and C. Guestrin, “‘Why should I trust you?’:
Explaining the predictions of any classifier,” in Proc. 22nd ACM
SIGKDD Int. Conf. Knowledge Discovery and Data Mining (KDD),
2016, pp. 1135–1144, doi: 10.1145/2939672.2939778. [Online].
Available: https://doi.org/10.1145/2939672.2939778
[18] S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting
model predictions,” in Advances in Neural Information
Processing Systems, vol. 30, 2017, pp. 4765–4774. [Online].
Available: https://arxiv.org/abs/1705.07874
[19] R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership
inference attacks against machine learning models,” in Proc.
IEEE Symp. Security and Privacy (SP), 2017, pp. 3–18, doi: 10.1109/
SP.2017.41. [Online]. Available: https://doi.org/10.1109/SP.2017.41