Legal Compliance Policy¶
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Jan/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Objectives¶
To avoid breaches of any law, statutory, regulatory, or contractual obligations, and of any security requirements. The Purpose of the document is to provide guidelines to adhere and comply with all legislative, statutory, regulatory, and contractual requirements and provide guidance to meet this requirement.
Scope¶
Scope includes all functions and processes of tecciance.
Requirement¶
Policy (Statutory, Regulatory, Contractual, IPR)¶
-
All organizational policy decisions cover legal and compliance requirements.
-
All applicable legislative and regulatory requirements are identified and listed.
-
All material statutory compliances are reviewed on an annual basis.
-
Only licensed software is used by tecciance in accordance with the defined IT Policy documents. The IT department ensures the provisioning of the same. The same is checked through ISMS audits on a regular basis.
-
Important records are protected from loss, destruction, and falsification, in accordance with statutory, regulatory, contractual, and business requirements.
-
Employees and Vendors sign code of conduct and confidentiality requirements with tecciance.
-
Employees are conscious of acceptable usage policy, a violation of which may also result in Disciplinary Action.
-
The organization does not use any special export-restricted encryption (embedded or otherwise) software.
-
The design, operation, use and management of information systems are subject to statutory, regulatory, and contractual security requirements. Advice on specific legal requirements is taken from the organization’s legal advisers, as and when required.
-
All software should be acquired only through known and reputable sources and copyright should not be violated.
-
Proof of ownership of licenses should be maintained.
Review¶
This policy is subject to continuous changes. In case there are no changes, then an annual review shall be performed.
Exceptions¶
Any exception to this requirement shall be reviewed and approved by the Finance Head prior to acceptance.
Control mapping¶
Mapping to ISO 27001 Control (s)¶
| Control No | Control Objective |
|---|---|
| 5.31 | Legal, statutory, regulatory, and contractual requirements |
6.
7.
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
Applicable frameworks in default packs: ISO/IEC 27001, SOC 2, GDPR (where personal data of EU/EEA residents is processed), ISO/IEC 42001 when AI systems are operated. HIPAA only when PHI is in scope.