Join our Newsletter — 33% off our NHI Course

Compliance Programme

A compliance programme is the organised set of policies, processes, evidence, and accountability mechanisms used to demonstrate that an organisation meets relevant obligations. For AI and cloud teams, a mature programme links governance to engineering practice, ensuring controls, documentation, and oversight are maintained as systems change.

Expanded Definition

A compliance programme is the operating system for obligations, not a single policy document. In NHI and agentic AI environments, it ties together control design, evidence collection, exceptions handling, and accountability so that security posture can be demonstrated as systems, permissions, and workflows change. It usually spans legal, security, engineering, procurement, and audit functions, with clear ownership for the controls that matter most to identity, secrets, logging, retention, and third-party access.

Definitions vary across vendors when compliance is discussed in AI and cloud contexts, but the practical standard is consistency: requirements must be translated into repeatable technical and procedural checks. NIST CSF 2.0 provides a useful organising model for governance and risk management, while ISO/IEC 27001:2022 frames the management-system discipline behind policy, review, and continual improvement. For NHI controls, that means evidence must show who approved access, how secrets are stored, how rotation is enforced, and when revocation occurs. The most common misapplication is treating compliance as annual paperwork, which occurs when evidence is assembled after deployment rather than built into engineering and operations.

Examples and Use Cases

Implementing a compliance programme rigorously often introduces documentation and change-control overhead, requiring organisations to weigh audit readiness against delivery speed.

Why It Matters in NHI Security

In NHI security, a compliance programme is what prevents governance from collapsing when identities multiply faster than people can review them. NHIMG research shows NHIs outnumber human identities by 25x to 50x in modern enterprises, and 96% of organisations store secrets outside secrets managers in vulnerable locations including code, config files, and CI/CD tools. That scale makes manual assurance unreliable and turns weak programme design into a direct exposure problem. A strong programme also supports auditability, because the question is not only whether a control exists, but whether the organisation can prove it stayed effective after deployment changes, team turnover, or incident response.

Controls for rotation, offboarding, privileged access, and exception handling need recurring evidence, not one-time approval. This is why compliance is inseparable from NHI hygiene: once secrets leak or service accounts are over-privileged, the organisation needs demonstrable control ownership, remediation tracking, and attestation history to contain the blast radius. The most obvious failures surface only after compromised credentials are discovered, at which point the compliance programme becomes operationally unavoidable to reconstruct accountability and prove corrective action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC, GV.RM, ID.GV Frames governance, risk, and control oversight that a compliance programme must operationalise.
NIST SP 800-53 Rev 5 CA-2, AU-2, AU-6, AC-2 Defines assessment, logging, and access-control expectations that underpin compliance evidence.
OWASP Non-Human Identity Top 10 NHI-02 Secret management failures are a core NHI compliance concern covered by this control area.
CSA MAESTRO Connects agentic AI governance with operational control, accountability, and continuous oversight.
NIST AI RMF Provides risk management structure for AI systems where compliance evidence must track model and process change.

Use CSF governance functions to assign owners, track evidence, and review control effectiveness on a recurring cadence.