<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Compliance | Haksung</title><link>https://haksungjang.github.io/en/tags/compliance/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 09 Aug 2026 17:03:59 +0900</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>AI SBOM Compliance Guide</title><link>https://haksungjang.github.io/en/docs/ai-sbom_guide/</link><pubDate>Sun, 09 Aug 2026 17:03:59 +0900</pubDate><guid>https://haksungjang.github.io/en/docs/ai-sbom_guide/</guid><description>An enterprise practice guide that explains the requirements of the OpenChain AI SBOM Compliance Guide (Version 1.0) clause by clause.</description><content:encoded>&lt;![CDATA[<p>This guide explains, one by one, each requirement of<em>AI System Bill of Materials — Compliance
Management Guide for the Supply Chain</em> (Version 1.0), published by the OpenChain AI Work Group.
It walks through what verification material each clause requires, how to comply with it, and
what samples and tools are ready to use.</p><p>This specification carries the same structure as ISO/IEC 5230, the open source license
compliance standard — requirements, verification material, and rationale — over into the AI
supply chain. It brings into scope not only code but also the licensing and transparency
obligations of model weights, training datasets, and the Model Tree.</p><p><strong>Author : OpenChain Korea Work Group /<a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a></strong></p><div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Note</div><p>All 10 requirements (3.1–3.10) per the specification body have been written. The compare page
that positions the standards relative to each other is still being expanded.</p></div><h2 id="intended-audience">Intended Audience</h2><ul><li>Compliance staff at organizations that develop AI systems or exchange them through the supply chain</li><li>Practitioners who have an open source compliance (ISO/IEC 5230) program in place and want to extend it into AI</li><li>Legal, security, and development staff who need to check the licensing and transparency obligations of AI models and datasets</li></ul><h2 id="how-to-use-this-guide">How to Use This Guide</h2><div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">Division of Roles Between the OpenChain Specification and the KWG Practice Guide</div><p>The OpenChain specification defines &ldquo;what must be demonstrated.&rdquo; This guide fills in &ldquo;how to
achieve it.&rdquo; Each clause page does more than restate the specification&rsquo;s requirements — it walks
through the actual procedures, samples, tools, and how to handle the parts that tools alone
cannot fill.</p></div><div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Notation — [Specification Requirement] vs [Guide Recommendation]</div><p>The content of each clause page falls into two categories.</p><ul><li><strong>[Specification Requirement]</strong> — Items the AI SBOM Compliance Guide body specifies with<code>shall</code> or as verification material.</li><li><strong>[Guide Recommendation]</strong> — Items not found in the specification body but recommended by the
OpenChain Korea Work Group based on practical experience, best practices, and other standards
(ISO/IEC 5230, 42001, etc.). Adoption is at the organization&rsquo;s discretion.</li></ul><p>Activities presented alongside a verification material number (e.g.,<code>3.1.1</code>) are<strong>[Specification Requirement]</strong>. Enhancements this guide adds, such as automation, tool use, and
intake gates, are<strong>[Guide Recommendation]</strong>.</p></div><div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Note on Clause Numbering</div><p>The original specification&rsquo;s table of contents and body section numbers are out of sync (the
&ldquo;3.9 AI content review and approval&rdquo; section listed in the table of contents does not appear in
the body, shifting all subsequent numbers down by one). This discrepancy has been reported to
the OpenChain AI Work Group. This guide follows the<strong>body&rsquo;s section numbers (3.1–3.10)</strong>.</p></div><h2 id="phased-implementation-roadmap">Phased Implementation Roadmap</h2><p>The 10 requirements are divided into four phases by implementation priority. Phase 1 establishes
the program&rsquo;s foundation, Phase 2 builds AI-specific compliance processes, Phase 3 puts
operational structures in place, and Phase 4 establishes governance.</p><hr><h3 id="phase-1--program-foundation">Phase 1 — Program Foundation</h3><p><strong>Goal</strong>: Define the program&rsquo;s scope, establish policy, and secure competence and awareness.</p><table><thead><tr><th style="text-align: center">Done</th><th>Verification Material</th><th>Description</th><th>Detailed Guide</th></tr></thead><tbody><tr><td style="text-align: center">☐</td><td><strong>3.4.1</strong></td><td>Program scope statement</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/4-scope/">3.4 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.1.1</strong></td><td>Documented AI SBOM policy</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/1-policy/">3.1 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.1.2</strong></td><td>Policy awareness procedure</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/1-policy/">3.1 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.2.1~3.2.3</strong></td><td>Role list, competence definitions, competence assessment evidence</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/2-competence/">3.2 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.3.1</strong></td><td>Evidence of participant awareness assessment</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/3-awareness/">3.3 →</a></td></tr></tbody></table><hr><h3 id="phase-2--ai-extension-processes">Phase 2 — AI Extension Processes</h3><p><strong>Goal</strong>: Build AI-specific licensing, transparency, and SBOM processes that cover not just code
but also models, weights, and datasets. This is the area where the AI SBOM Guide expands most on
ISO/IEC 5230.</p><table><thead><tr><th style="text-align: center">Done</th><th>Verification Material</th><th>Description</th><th>Detailed Guide</th></tr></thead><tbody><tr><td style="text-align: center">☐</td><td><strong>3.5.1</strong></td><td>License obligation review and documentation procedure</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/1-license-obligations/">3.5 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.6.1</strong></td><td>Transparency obligation review procedure</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/2-transparency-obligations/">3.6 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.9.1</strong></td><td>AI SBOM identification, tracking, review, approval, and archiving procedure</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/3-ai-sbom/">3.9 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.9.2</strong></td><td>Records demonstrating procedure compliance</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/3-ai-sbom/">3.9 →</a></td></tr></tbody></table><hr><h3 id="phase-3--operational-structure">Phase 3 — Operational Structure</h3><p><strong>Goal</strong>: Create a channel for responding to external compliance inquiries, and assign
accountability and resources to the program.</p><table><thead><tr><th style="text-align: center">Done</th><th>Verification Material</th><th>Description</th><th>Detailed Guide</th></tr></thead><tbody><tr><td style="text-align: center">☐</td><td><strong>3.7.1~3.7.2</strong></td><td>Public inquiry channel, internal response procedure</td><td><a href="/en/docs/ai-sbom_guide/3-relevant-tasks/1-access/">3.7 →</a></td></tr><tr><td style="text-align: center">☐</td><td><strong>3.8.1~3.8.5</strong></td><td>Role assignment, resources, legal expertise, remediation procedure</td><td><a href="/en/docs/ai-sbom_guide/3-relevant-tasks/2-resourced/">3.8 →</a></td></tr></tbody></table><hr><h3 id="phase-4--governance">Phase 4 — Governance</h3><p><strong>Goal</strong>: Put in place a governance framework spanning the full AI system lifecycle, and reflect
emerging AI regulation.</p><table><thead><tr><th style="text-align: center">Done</th><th>Verification Material</th><th>Description</th><th>Detailed Guide</th></tr></thead><tbody><tr><td style="text-align: center">☐</td><td><strong>3.10.1</strong></td><td>AI governance framework and periodic review procedure</td><td><a href="/en/docs/ai-sbom_guide/4-governance/1-governance/">3.10 →</a></td></tr></tbody></table><hr><h2 id="full-clause-checklist">Full Clause Checklist</h2><p>The body of the AI SBOM Compliance Guide consists of<strong>10 clauses and 19 verification material
items</strong> in total (by this guide&rsquo;s verification material numbering).</p><table><thead><tr><th>Clause</th><th>Title</th><th style="text-align: center">Verification Material</th><th>Detail</th></tr></thead><tbody><tr><td>3.1</td><td>Policy</td><td style="text-align: center">2 items</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/1-policy/">Go to →</a></td></tr><tr><td>3.2</td><td>Competence</td><td style="text-align: center">3 items</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/2-competence/">Go to →</a></td></tr><tr><td>3.3</td><td>Awareness</td><td style="text-align: center">1 item</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/3-awareness/">Go to →</a></td></tr><tr><td>3.4</td><td>Program Scope</td><td style="text-align: center">1 item</td><td><a href="/en/docs/ai-sbom_guide/1-program-foundation/4-scope/">Go to →</a></td></tr><tr><td>3.5</td><td>License Obligations</td><td style="text-align: center">1 item</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/1-license-obligations/">Go to →</a></td></tr><tr><td>3.6</td><td>Transparency Obligations</td><td style="text-align: center">1 item</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/2-transparency-obligations/">Go to →</a></td></tr><tr><td>3.7</td><td>Access</td><td style="text-align: center">2 items</td><td><a href="/en/docs/ai-sbom_guide/3-relevant-tasks/1-access/">Go to →</a></td></tr><tr><td>3.8</td><td>Effectively Resourced</td><td style="text-align: center">5 items</td><td><a href="/en/docs/ai-sbom_guide/3-relevant-tasks/2-resourced/">Go to →</a></td></tr><tr><td>3.9</td><td>AI SBOM</td><td style="text-align: center">2 items</td><td><a href="/en/docs/ai-sbom_guide/2-ai-extension/3-ai-sbom/">Go to →</a></td></tr><tr><td>3.10</td><td>Governance</td><td style="text-align: center">1 item</td><td><a href="/en/docs/ai-sbom_guide/4-governance/1-governance/">Go to →</a></td></tr></tbody></table><p><strong>Total: 10 clauses / 19 verification material items</strong></p><h2 id="automation-maturity-map">Automation Maturity Map</h2><p>This is an honest breakdown of how far each AI SBOM compliance task is automated by tools today.
For &ldquo;generation,&rdquo; usable open source tools already exist. Interpreting license obligations and
tracking compliance with non-standard licenses, on the other hand, remain the work of people and
policy. Each clause page follows this line to distinguish &ldquo;what a tool handles&rdquo; from &ldquo;what a
person must fill in.&rdquo;</p><table><thead><tr><th>Task</th><th>Automation Level</th><th>Representative Open Source Tool</th></tr></thead><tbody><tr><td>Code/dependency SBOM generation</td><td>Mature</td><td>cdxgen, Syft</td></tr><tr><td>AI model/metadata BOM generation</td><td>Tools emerging</td><td>OWASP AIBOM Generator, cdxgen<code>aibom</code> mode</td></tr><tr><td>Static analysis of model binaries</td><td>Tools emerging</td><td>Lab700x AI SBOM Scanner</td></tr><tr><td>Identifying LLM inference servers and AI packages</td><td>Mature</td><td>Trivy, Syft</td></tr><tr><td>SBOM storage and vulnerability monitoring</td><td>Mature</td><td>Dependency-Track, SW360</td></tr><tr><td>Interpreting license obligations, tracking non-standard compliance</td><td>Immature (people/policy)</td><td>Tool support still developing</td></tr></tbody></table><div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Generation by Tool, Interpretation by People</div><p>Several tools already generate AI SBOMs automatically. But whether the license fields in a
generated BOM are accurate, whether the behavioral use restrictions of non-standard licenses
(the RAIL family, the Llama Community License) are respected, and whether obligations propagate
downstream without being dropped — a tool cannot automatically guarantee any of this. Policy and
human review fill this gap. See<a href="/en/docs/ai-sbom_guide/2-ai-extension/1-license-obligations/">3.5 License Obligations</a>
for details.</p></div><p>The installation and use of each tool is covered with execution screens and command output in
the<a href="/en/docs/ai-sbom_guide/5-tools/">Tools</a> section.</p><h2 id="relationship-to-other-standards">Relationship to Other Standards</h2><div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Relationship to ISO/IEC 5230 and 42001</div><ul><li><strong>ISO/IEC 5230 (License Compliance)</strong>: The AI SBOM Guide inherits the 5230 methodology
directly. Organizations that already have a 5230 program in place can reuse program
foundations such as policy, competence, and resources, and only need to add the AI extension
areas. See the<a href="https://openchain-project.github.io/OpenChain-KWG/guide/iso5230_guide/">ISO/IEC 5230 Compliance Guide</a>.</li><li><strong>ISO/IEC 42001 (AI Management System)</strong>: The technical details of AI SBOM formats (SPDX 3.0 AI
Profile, CycloneDX ML-BOM) and generation tools are covered in the<a href="https://openchain-project.github.io/OpenChain-KWG/guide/iso42001_guide/4-operation/2-ai-sbom/">ISO/IEC 42001 Guide — AI SBOM</a>.
Building on that, this guide focuses on &ldquo;how to operate the compliance program.&rdquo;</li></ul></div><h2 id="original-specification">Original Specification</h2><div class="pageinfo pageinfo-primary"><ul><li><strong>Document</strong>: Artificial Intelligence System Bill of Materials — Compliance Management Guide for
the Supply Chain, Version 1.0</li><li><strong>Published</strong>: OpenChain Project AI Work Group, 2025-10-20</li><li><strong>License</strong>: Creative Commons Attribution 4.0 (CC-BY-4.0)</li><li><strong>Authoritative copy</strong>: Published as PDF and markdown in the OpenChain Reference-Material
repository (<code>AI-SBOM-Compliance/en</code>)</li><li><strong>Announcement</strong>:<a href="https://openchainproject.org/news/2025/10/20/welcoming-the-openchain-ai-system-bill-of-materials-compliance-guide">openchainproject.org</a></li></ul></div>
]]></content:encoded></item></channel></rss>