International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1716619

1716619 Vol 8 · Issue 9 Download Paper

Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom)

AMIL USLU

Subject area: Science,Engineering and Technology  ·  Area of research: Artificial Intelligence

DOI: 10.64388/IREV8I9-1716619

Abstract

The integration of artificial intelligence into regulated industries such as finance, healthcare, and telecommunications has introduced a new class of engineering challenges centered on security, compliance, and trust. While AI technologies offer significant benefits in terms of automation, predictive analytics, and operational efficiency, their deployment in regulated environments requires strict adherence to legal, ethical, and technical constraints. These systems must not only perform accurately but also operate transparently, securely, and in full alignment with regulatory requirements. This paper explores the architectural and engineering principles required to design secure and compliant software systems that integrate AI capabilities within highly regulated domains. It examines how traditional secure software engineering practices must be extended to address AI-specific risks, including model opacity, data sensitivity, and adversarial vulnerabilities. By combining principles from software engineering, cybersecurity, and AI governance, organizations can develop systems that balance innovation with regulatory compliance. The study analyzes the regulatory landscape across finance, healthcare, and telecommunications, highlighting common requirements such as data protection, auditability, and decision traceability. It discusses how these requirements influence system architecture, necessitating the inclusion of control points, monitoring mechanisms, and policy enforcement layers within AI-driven systems. A significant focus is placed on data governance and privacy engineering, where sensitive data must be managed throughout its lifecycle in a secure and compliant manner. Techniques such as access control, data anonymization, and secure data pipelines are examined as essential components of system design. The paper also addresses model governance, emphasizing the importance of explainability, validation, and lifecycle management to ensure that AI systems remain transparent and accountable. Security engineering considerations are explored in detail, including threat modeling, adversarial risks, and the protection of model and data assets. The integration of DevSecOps and MLOps practices is analyzed as a means of embedding security and compliance into continuous development and deployment processes. Through the examination of industry-specific use cases, the paper demonstrates how these principles are applied in real-world systems, illustrating the practical challenges and solutions associated with deploying AI in regulated environments. It also discusses future directions, including the evolution of regulatory frameworks and the emergence of automated compliance systems. By providing a comprehensive framework for engineering secure and compliant AI systems, this research offers guidance for organizations seeking to deploy AI technologies responsibly within regulated domains. The findings highlight the importance of integrating security, governance, and compliance into every stage of system design and operation.

Keywords

Secure AI Systems, Regulatory Compliance, AI Governance, Data Privacy, Explainable AI, DevSecOps, MLOps, Financial Systems, Healthcare Systems, Telecom Systems

References

[1] EuropeanCommission.(2021). Proposal for a RegulationLayingDown Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act).

[2] Goodfellow, I., McDaniel, P., & Papernot, N. (2018). Making Machine Learning Robust Against Adversarial Inputs. Communications of the ACM, 61(7), 56–66.

[3] ISO/IEC 27001. (2013). Information Security Management Systems Requirements. International Organization for Standardization.

[4] ISO/IEC 23894. (2023). Artificial Intelligence — Risk Management. International Organization for Standardization.

[5] Kroll, J. A., Huey, J., Barocas, S., et al. (2017). Accountable Algorithms. University of Pennsylvania Law Review, 165(3), 633–705.

[6] Mittelstadt, B. D., Allo, P., Taddeo, M., Wachter, S., & Floridi, L. (2016). The Ethics of Algorithms: Mapping the Debate. Big Data & Society, 3(2).

[7] National Institute of Standards and Technology (NIST). (2023). AI Risk Management Framework (AI RMF 1.0).

[8] Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. (2018). SoK: Security and Privacy in Machine Learning. IEEE European Symposium on Security and Privacy.

[9] Rieke, N., Hancox, J., Li, W., et al. (2020). The Future of Digital Health with Federated Learning. npj Digital Medicine, 3(119).

[10] Shokri, R., Stronati, M., Song, C., & Shmatikov, V. (2017). Membership Inference Attacks Against Machine Learning Models. IEEE Symposium on Security and Privacy.

[11] Shortliffe, E. H., & Sepúlveda, M. J. (2018). Clinical Decision Support in the Era of Artificial Intelligence. JAMA, 320(21), 2199–2200.

[12] Veale, M., & Edwards, L. (2018). Clarity, Surprises, and Further Questions in the Article 29 Working Party Guidelines on Automated Decision-Making and Profiling. Computer Law & Security Review, 34(2), 398–404.

[13] World Health Organization (WHO). (2021). Ethics and Governance of Artificial Intelligence for Health.

[14] Xu, H., & Guo, H. (2020). Privacy-Preserving Machine Learning: Methods, Challenges, and Directions. IEEE Access, 8, 41003–41026.

[15] Zhang, J., Chen, Y., & Yang, X. (2021). AI Governance in Regulated Industries: Frameworks and Implementation Challenges. IEEE Transactions on Technology and Society, 2(4), 213–223.

[16] Zuboff, S. (2019). The Age of Surveillance Capitalism. PublicAffairs.

How to cite this paper

AMIL USLU "Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom)" Iconic Research And Engineering Journals Volume 8 Issue 9 2025 Page 2008-2020 https://doi.org/10.64388/IREV8I9-1716619
AMIL USLU "Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom)" Iconic Research And Engineering Journals, vol. 8, no. 9, Mar. 2025, doi: https://doi.org/10.64388/IREV8I9-1716619
AMIL USLU (2025). Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom). Iconic Research And Engineering Journals, 8(9). doi: https://doi.org/10.64388/IREV8I9-1716619
AMIL USLU "Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom)" Iconic Research And Engineering Journals, vol. 8, no. 9, Mar. 2025. Crossref, https://doi.org/10.64388/IREV8I9-1716619
@article{1716619,
      author = {AMIL USLU},
      title = {Engineering Secure and Compliant Software Systems: Integrating AI into Regulated Domains (Finance, Healthcare, and Telecom)},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {8},
      number = {9},
      pages = {2008-2020},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1716619.pdf},
      abstract = {The integration of artificial intelligence into regulated industries such as finance, healthcare, and telecommunications has introduced a new class of engineering challenges centered on security, compliance, and trust. While AI technologies offer significant benefits in terms of automation, predictive analytics, and operational efficiency, their deployment in regulated environments requires strict adherence to legal, ethical, and technical constraints. These systems must not only perform accurately but also operate transparently, securely, and in full alignment with regulatory requirements. This paper explores the architectural and engineering principles required to design secure and compliant software systems that integrate AI capabilities within highly regulated domains. It examines how traditional secure software engineering practices must be extended to address AI-specific risks, including model opacity, data sensitivity, and adversarial vulnerabilities. By combining principles from software engineering, cybersecurity, and AI governance, organizations can develop systems that balance innovation with regulatory compliance. The study analyzes the regulatory landscape across finance, healthcare, and telecommunications, highlighting common requirements such as data protection, auditability, and decision traceability. It discusses how these requirements influence system architecture, necessitating the inclusion of control points, monitoring mechanisms, and policy enforcement layers within AI-driven systems. A significant focus is placed on data governance and privacy engineering, where sensitive data must be managed throughout its lifecycle in a secure and compliant manner. Techniques such as access control, data anonymization, and secure data pipelines are examined as essential components of system design. The paper also addresses model governance, emphasizing the importance of explainability, validation, and lifecycle management to ensure that AI systems remain transparent and accountable. Security engineering considerations are explored in detail, including threat modeling, adversarial risks, and the protection of model and data assets. The integration of DevSecOps and MLOps practices is analyzed as a means of embedding security and compliance into continuous development and deployment processes. Through the examination of industry-specific use cases, the paper demonstrates how these principles are applied in real-world systems, illustrating the practical challenges and solutions associated with deploying AI in regulated environments. It also discusses future directions, including the evolution of regulatory frameworks and the emergence of automated compliance systems. By providing a comprehensive framework for engineering secure and compliant AI systems, this research offers guidance for organizations seeking to deploy AI technologies responsibly within regulated domains. The findings highlight the importance of integrating security, governance, and compliance into every stage of system design and operation.},
      keywords = {Secure AI Systems, Regulatory Compliance, AI Governance, Data Privacy, Explainable AI, DevSecOps, MLOps, Financial Systems, Healthcare Systems, Telecom Systems},
      month = {March},
      doi = {https://doi.org/10.64388/IREV8I9-1716619}
  }