Back to Sia Partners A Sia product
Sia RegAI  /  Blog
Practical guides

Working-day notes from the regulatory front line.

Working-day guides — from DORA gap analysis to the EU AI Act, MDR / IVDR, ORSA, and beyond — written from real Sia engagements with GSIBs, insurers, hyperscalers, and pharma. No fluff, no vendor speak. The workflow we'd hand to a compliance lead taking the project on Monday.

All Banking Insurance Utilities Pharma Tech
Featured · 11 min Point of view · Engineering

Thick wrapper vs thin wrapper — why regulatory AI needs a purpose-built system.

Why ChatGPT, Claude, and horizontal AI tools like Harvey can't replace a purpose-built regulatory system. The thick-wrapper case, the five-question test we'd run on any vendor, and what "trained on tens of thousands of SME annotations" actually means.

April 26, 2026 By Sia Read the POV
Buyer's guide · Cross-vertical

Regulatory Change Management Software — A Buyer's Guide.

The eight capabilities that matter, the four categories of vendor, and the seven questions to ask before signing. Honest about where Sia RegAI fits and where it doesn't.

12 min Read
Pharma · FDA Part 11

FDA 21 CFR Part 11 Compliance with AI — Records, Signatures, Audit Trail.

How to add AI to GxP-validated workflows without breaking the validated state. CSA-aligned, audit-trail-grade.

11 min Read
Pharma · MDR / IVDR

EU MDR & IVDR — Automating Technical Documentation.

Annex II structure, Annex VIII classification rules, GSPR matrix, clinical evaluation, post-market surveillance — and where AI cuts drafting time without breaking notified-body acceptance.

10 min Read
Pharma · Pharmacovigilance

Pharmacovigilance Automation — Cutting ICSR & PSUR Cycle Times.

EMA GVP and ICH E2 framework, ICSR triage, MedDRA coding, narrative drafting, signal management, PBRER drafting. Where AI fits without breaking the QPPV's sign-off.

11 min Read
Insurance · Solvency II Pillar II

ORSA in Practice — Automating Solvency II Pillar II.

The three core questions, supervisor expectations, scenario analysis, and where AI compresses the report cycle while the actuarial function and CRO keep the judgment.

10 min Read
Utilities · NERC CIP

NERC CIP Compliance with AI — From CIP-002 Asset Inventory to Audit-Ready Evidence.

The five-phase workflow we run for utilities: BES Cyber System categorization, requirement mapping, evidence gap analysis, policy drafting, audit-pack assembly. Common findings and how to avoid them.

10 min Read
Insurance · NAIC

NAIC Model Laws — US Insurance Compliance for Multi-State Carriers.

The Models that matter (MAR, ORSA, IDSML, AI Model Bulletin) and the multi-state mapping problem. How AI compresses 30+ jurisdictional comparisons into one matrix.

10 min Read
Tech · AI governance

ISO 42001 vs NIST AI RMF — Which AI Governance Framework?

A side-by-side comparison. Certifiable management system vs. operational framework. When to pick one, when to add the other, when to run both.

9 min Read
Buyer's guide · Cross-vertical

GRC vs Regulatory Intelligence — Why They're Not the Same Tool.

GRC stores controls. Regulatory intelligence does the reading, mapping, and drafting. The category-distinction guide for compliance buyers running both.

9 min Read
Tech · EU AI Act

EU AI Act High-Risk Classification — A Decision Tree for AI Builders.

The triage workflow we run with clients. Annex III, the Article 6(3) exception, GPAI. Produces defensible classification memos for every system.

10 min Read
Engineering · Defensibility

Citation Graphs for Compliance — Why Every AI Output Needs Receipts.

The mechanic that turns AI output from "memo" into "audit-ready artifact." The five-property checklist for any vendor that claims defensibility.

9 min Read
Banking · DORA

Automating DORA Gap Analysis: A Practical Guide.

Six phases — scope, obligation extraction, applicability triage, gap analysis, control drafting, evidence pack — from real GSIB engagements.

10 min Read
Banking · AI

EU AI Act for Banks — Obligations, Decoded.

Where banks land in the four risk tiers. What Annex IV documentation actually needs. The August 2026 timeline you can't miss.

9 min Read
Banking · APAC

MAS Notice 626 vs HKMA SPM — Side-by-Side.

70% of obligations map cleanly. The remaining 30% — PEP scope, BO thresholds, STR timing — is where multi-jurisdictional banks burn budget.

8 min Read
Banking · OCC

OCC Heightened Standards: Mapping 12 CFR §30 with AI.

For state-chartered banks moving to OCC supervision, or any large bank under heightened-standards scrutiny. The clause-level mapping playbook from a recent charter conversion.

9 min Read
Insurance · Solvency II / IFRS 17

Solvency II + IFRS 17: Two Frameworks, One Compliance Workflow.

Insurers run Solvency II for capital and IFRS 17 for accounting — and both touch the same products, contracts, and data. How to map them once and serve both.

10 min Read
Tech · NIST AI RMF

NIST AI RMF for Tech: From Govern to Measure in 30 Days.

The four functions (Govern, Map, Measure, Manage), what each one actually demands of an AI-first company, and the pragmatic 30-day onboarding plan we run with hyperscalers.

9 min Read

Want to run Sia RegAI on your own regulation?

A 45-minute walkthrough on a slice of your scope and a sample policy. We bring the platform.