Home / Current Issue / Paper 1713349
The SAIS-GRC Framework: Engineering Trust and Secure, Agile Systems for Proactive AI Governance and Compliance
Subject area: Science,Engineering and Technology · Area of research: GenAI GRC, AI
DOI: https://doi.org/10.64388/IREV7I5-1713349
Abstract
Organisations urgently require a unified model to manage the escalating technical risks and regulatory demands of Artificial Intelligence (AI). Current governance methods fail because they address security and compliance in a reactive manner. This paper introduces the Secure, Agile, Integrated System for Governance, Risk, and Compliance (SAIS-GRC) model. SAIS-GRC integrates adversarial robustness controls directly into the enterprise operating system, ensuring compliance velocity and organisational agility. The model uses technical defence mechanisms, such as Differential Privacy, to proactively mitigate supply chain risks, including data poisoning and model manipulation. Structurally, SAIS-GRC mandates the cross-functional integration of engineering and legal expertise, aligning directly with global mandates such as the NIST AI Risk Management Model and the EU AI Act. Validation demonstrates tangible operational benefits. Enterprise implementations based on SAIS-GRC principles achieve operational cost reductions of up to 25% and deliver platform modernisation 2X faster than legacy methods (Siana Capital Management, 2024). This integrated structure transforms fragmented risk management into an immediate source of competitive advantage.
References
[1] Blanco-Justicia, A., Sánchez, D., Domingo-Ferrer, J., & Muralidhar, K. (2022). A critical review on the use (and misuse) of differential privacy in machine learning. arXiv preprint, arXiv:2206.04621v2. https://doi.org/10.48550/arXiv.2206.04621
[2] European Commission. (2024). Regulatory Framework for AI. Official Journal of the European Union. Retrieved from https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
[3] Ghosh, R. (2024). Navigating Digital Personal Data Protection Act Compliance and Deepfake Phishing. Times of India. Retrieved from https://timesofindia.indiatimes.com/city/ahmedabad/new-data-law-turns-consent-into-currency-strict-corporate-discipline-needed-say-experts-at-toi-nfsus-hacked-2-0-session-hosted-by-jito-at-gcci/articleshow/125794681.cms
[4] Global Compliance News. (2024). The Growing Importance of the NIST AI Risk Management Model. Global Compliance News. Retrieved from https://www.globalcompliancenews.com/2024/10/22/https-insightplus-bakermckenzie-com-bm-technology-media-telecommunications_1-united-states-the-growing-importance-of-the-nist-ai-risk-management-framework_09132024/
[5] NIST. (2022). NIST Artificial Intelligence Risk Management Model. National Institute of Standards and Technology. Retrieved from https://www.nist.gov/itl/ai-risk-management-framework
[6] NIST. (2025). Taxonomy of Adversarial Machine Learning Attacks. NIST.AI.100-2e2025. National Institute of Standards and Technology. Retrieved from(https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf)
[7] Siana Capital Management. (2024). Enterprise AI platform CoreOps.AI has 3.5 million in new round. The Economic Times. Retrieved from https://m.economictimes.com/tech/funding/coreops-ai-has-3-5-million-in-new-round/articleshow/125757349.cms
[8] Stanford AI Index. (2024). India's People-First AI Strategy. The Economic Times. Retrieved from https://m.economictimes.com/tech/artificial-intelligence/indias-people-first-ai-strategy-accelerates-adoption-across-sectors-and-cities/articleshow/125743926.cms
[9] Srivastava, R. (2024). Adversarial Manipulation and Supply-Chain Risks in Enterprise AI Model Lifecycles. International Journal of Computer Science and Network Security, 24(5), 18-25.
[10] Times of India. (2024). Apple Watch adds hypertension notifications in India where heart health data tells a worrying story. Times of India. Retrieved from https://timesofindia.indiatimes.com/technology/tech-news/apple-watch-adds-hypertension-notifications-in-india-where-heart-health-data-tells-a-worrying-story/articleshow/125758529.cms
[11] Times of India. (2024). Meta brings new account features for quicker and easier recovery of hacked Facebook, Instagram accounts. Times of India. Retrieved from https://timesofindia.indiatimes.com/technology/tech-news/meta-brings-new-account-features-for-quicker-and-easier-recovery-of-hacked-facebook-instagram-accounts/articleshow/125792949.cms
[12] Times of India. (2024). Europe fines Elon Musk's X €140 million, calls blue checkmark deceptive design. Times of India. Retrieved from https://timesofindia.indiatimes.com/technology/social/europe-fines-elon-musks-x-140-million-calls-blue-checkmark-deceptive-design/articleshow/125791488.cms
[13] Times of India. (2024). US government is quite angry with Europe and the reason is Elon Musk's X, says 'stop troubling our companies'. Times of India. Retrieved from https://timesofindia.indiatimes.com/technology/tech-news/us-government-is-quite-angry-with-europe-and-the-reason-is-elon-musks-twitter-says-stop-troubling-our-companies/articleshow/125795338.cms
[14] Wyatt, A. (2023). Examining supply chain risks in autonomous weapon systems and artificial intelligence. ACIG Journal, 2(1), 1-21. https://doi.org/10.60097/ACIG/162874
How to cite this paper
@article{1713349,
author = {Adetunji Oludele Adebayo},
title = {The SAIS-GRC Framework: Engineering Trust and Secure, Agile Systems for Proactive AI Governance and Compliance},
journal = {Iconic Research And Engineering Journals},
year = {2024},
volume = {8},
number = {5},
pages = {1475-1480},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1713349.pdf},
abstract = {Organisations urgently require a unified model to manage the escalating technical risks and regulatory demands of Artificial Intelligence (AI). Current governance methods fail because they address security and compliance in a reactive manner. This paper introduces the Secure, Agile, Integrated System for Governance, Risk, and Compliance (SAIS-GRC) model. SAIS-GRC integrates adversarial robustness controls directly into the enterprise operating system, ensuring compliance velocity and organisational agility. The model uses technical defence mechanisms, such as Differential Privacy, to proactively mitigate supply chain risks, including data poisoning and model manipulation. Structurally, SAIS-GRC mandates the cross-functional integration of engineering and legal expertise, aligning directly with global mandates such as the NIST AI Risk Management Model and the EU AI Act. Validation demonstrates tangible operational benefits. Enterprise implementations based on SAIS-GRC principles achieve operational cost reductions of up to 25% and deliver platform modernisation 2X faster than legacy methods (Siana Capital Management, 2024). This integrated structure transforms fragmented risk management into an immediate source of competitive advantage.},
month = {November},
doi = {https://doi.org/10.64388/IREV7I5-1713349}
}