Compliance-as-Code, Grounded in Observability: Continuous Controls Monitoring in AI-Driven Banking
DOI:
https://doi.org/10.70917/ijcisim-2026-5474Keywords:
compliance-as-code, continuous controls monitoring, observability, OpenTelemetry, AI governance, model risk management, regulatory technology, continuous assurance, tamper-evident audit, algorithmic fairness, explainability, model drift, data drift, data lineage, agentic AI governance, policy-as-code, AI-driven bankingAbstract
Banks increasingly place machine learning at the point of decision, and those systems change continuously through retraining, threshold tuning and challenger promotion. Control assurance has not kept pace. Controls are still validated discretely, at a quarterly review, an annual validation or a single audit sample, so an institution can hold a clean validation opinion and still be unable to demonstrate that a control operated on every decision taken between checkpoints. This paper presents a reference model for compliance-as-code grounded in observability, and a proof of concept that instantiates part of that model and is evaluated empirically. The reference model contributes a three-layer obligation to control to signal taxonomy with layered ownership, a machine-readable control signal descriptor that is the executable control rather than documentation about one, a many-to-many obligation mapping that makes coverage gaps visible by inspection, and a five-level maturity model. The proof of concept instruments a credit decisioning service with distributed tracing, evaluates five controls against live telemetry, and writes every verdict to a hash-chained, signed, append-only ledger. Across 1,220 decisions it produced 5,722 signed evidence records with no gaps, control observability coverage of 1.0, a baseline false-positive rate of 0.0, full-chain integrity verification, correct detection of a deliberately altered record, and per-control detection latency of 0 to 66 decisions. All evaluation used public and synthetically generated data.