<a href="https://colab.research.google.com/github/micah-shull/AI_Agents/blob/main/708_ComplianceSentinel_V2_DataGen.ipynb" target="_parent"><img src="https://colab.research.google.com/assets/colab-badge.svg" alt="Open In Colab"/></a>



This is where Compliance Sentinel v2 becomes *portfolio-worthy*: the data itself should feel like something a Fortune-500 risk office would operate.

Below is a **V2 Data Strategy** that:

* supports CEO-level dashboards
* enables trend analysis + escalation logic
* powers financial risk modeling
* demonstrates governance maturity
* fits your MVP-first ‚Üí v2-expansion philosophy
* plugs cleanly into your orchestrator pattern

---

# **Compliance Sentinel v2 ‚Äî Data Strategy**

## üéØ Design Goals for V2 Data

V2 data should enable the agent to answer:

* Which AI systems are riskiest?
* Which departments create the most exposure?
* Are things improving or deteriorating over time?
* What triggered executive escalation?
* How fast are humans remediating issues?
* What is our regulatory exposure in dollars?
* Which vendors or models are repeat offenders?
* What evidence would a regulator request?

That means:

‚úÖ multi-system coverage
‚úÖ historical snapshots
‚úÖ varied severity
‚úÖ closed vs open cases
‚úÖ financial modeling
‚úÖ human workflows
‚úÖ escalation events
‚úÖ audit artifacts
‚úÖ portfolio rollups

---

---

# üìÅ Proposed V2 Dataset Set (MVP Scope)

For V2 I recommend **6‚Äì8 core datasets** instead of just raw logs.

Think of these as your agent‚Äôs ‚Äúcontrol plane.‚Äù

---

## **1. `ai_system_registry_v2.json`**

Master list of all AI systems under governance.

**Purpose**

* what exists
* who owns it
* what regulations apply
* deployment status
* risk tier

**Fields**

```json
{
  "system_id": "ai_marketing_01",
  "system_name": "Marketing Copy Generator",
  "business_unit": "Marketing",
  "owner_role": "CMO",
  "vendor": "internal_llm",
  "deployment_stage": "production",
  "regulated_domains": ["gdpr"],
  "data_types_processed": ["personal_data"],
  "baseline_risk_tier": "medium"
}
```

---

---

## **2. `ai_output_events_v2.json`**

Every AI output observed.

**Purpose**

* ingestion layer
* raw material for evaluation
* audit trace root

**Fields**

```json
{
  "event_id": "evt_20260201_0009",
  "timestamp": "2026-02-01T10:33:00Z",
  "system_id": "ai_support_02",
  "model_name": "gpt-like-4",
  "output_type": "email",
  "content_snippet": "The patient SSN is 123-45-6789...",
  "contains_sensitive_data": true,
  "customer_region": "EU",
  "channel": "email"
}
```

---

---

## **3. `policy_rules_v2.json`**

Codified regulatory + internal rules.

**Purpose**

* deterministic evaluation
* explainability
* statute mapping

**Fields**

```json
{
  "policy_id": "gdpr_pii_exposure",
  "regulation": "GDPR",
  "article": "Article 32",
  "description": "Personal identifiers must not appear in outbound messages.",
  "severity": "high",
  "default_fine_range_usd": [500000, 20000000],
  "requires_escalation": true
}
```

---

---

## **4. `compliance_findings_v2.json`**

Results of evaluation.

**Purpose**

* violation tracking
* severity scoring
* trend modeling
* case creation

**Fields**

```json
{
  "finding_id": "cf_9002",
  "event_id": "evt_20260201_0009",
  "system_id": "ai_support_02",
  "policy_id": "gdpr_pii_exposure",
  "severity": "critical",
  "risk_score": 94.2,
  "repeat_offender": true,
  "status": "open",
  "detected_at": "2026-02-01T10:34:10Z"
}
```

---

---

## **5. `financial_exposure_models_v2.json`**

How risk becomes dollars.

**Purpose**

* CEO-level translation
* board metrics
* portfolio totals

**Fields**

```json
{
  "finding_id": "cf_9002",
  "estimated_fine_usd": 4500000,
  "legal_cost_estimate": 800000,
  "remediation_cost": 120000,
  "brand_risk_multiplier": 1.4,
  "total_estimated_exposure": 7280000
}
```

---

---

## **6. `human_review_actions_v2.json`**

Human-in-the-loop system.

**Purpose**

* oversight proof
* SLA metrics
* accountability

**Fields**

```json
{
  "review_id": "rev_3009",
  "finding_id": "cf_9002",
  "reviewer_role": "Privacy Officer",
  "decision": "confirm_violation",
  "remediation_required": true,
  "resolution_deadline": "2026-02-05",
  "closed_at": null
}
```

---

---

## **7. `escalation_events_v2.json`**

Executive trigger log.

**Purpose**

* CRO/CEO alerts
* governance maturity
* board decks

**Fields**

```json
{
  "escalation_id": "esc_1001",
  "finding_id": "cf_9002",
  "trigger_reason": "exposure_threshold_exceeded",
  "notified_roles": ["CRO", "CLO"],
  "escalated_at": "2026-02-01T10:40:00Z",
  "severity": "critical"
}
```

---

---

## **8. `portfolio_snapshots_v2.json`**

Periodic rollups.

**Purpose**

* trend charts
* historical tracking
* executive dashboards

**Fields**

```json
{
  "snapshot_date": "2026-02-01",
  "systems_monitored": 14,
  "open_cases": 9,
  "critical_cases": 3,
  "total_estimated_exposure": 21800000,
  "avg_time_to_close_days": 4.6,
  "portfolio_risk_score": 82.3
}
```

---

# üìä What This Enables in the Agent

With this data, Compliance Sentinel v2 can now:

‚úÖ rank systems by risk
‚úÖ show exposure by department
‚úÖ trigger executive alerts
‚úÖ detect worsening trends
‚úÖ identify chronic violators
‚úÖ prove remediation loops
‚úÖ compute ROI of governance
‚úÖ compare vendors/models
‚úÖ generate board decks
‚úÖ export regulator packages

---

---

# üß† MVP vs V2 Philosophy

We keep this disciplined:

### **MVP V2 (first pass)**

Start with:

* ai_system_registry
* ai_output_events
* compliance_findings
* financial_exposure
* portfolio_snapshots

That‚Äôs enough to:

* run the orchestrator
* generate executive reports
* fire escalation triggers
* compute exposure totals

---

### **Later V2+ Enhancements**

Add:

* human_review_actions
* escalation_events
* historical trend series
* vendor comparisons
* remediation effectiveness
* policy changes over time

---

---

# üöÄ Why This Is So Strong for Your Portfolio

This data strategy screams:

* enterprise AI governance
* regulatory systems engineering
* risk analytics
* compliance ops
* board reporting
* orchestrator architecture
* portfolio intelligence

It matches *exactly* the persona you‚Äôve been building:

> **‚ÄúI design AI systems the CEO can actually run.‚Äù**




# ai_system_registry_v2.json

In [None]:
[
  {
    "system_id": "ai_marketing_01",
    "system_name": "Marketing Copy Generator",
    "business_unit": "Marketing",
    "owner_role": "Chief Marketing Officer",
    "vendor": "internal_llm",
    "model_family": "enterprise_gpt",
    "deployment_stage": "production",
    "regulated_domains": ["gdpr"],
    "data_types_processed": ["personal_data"],
    "geographic_scope": ["EU", "US"],
    "baseline_risk_tier": "medium",
    "last_audit_date": "2026-01-10",
    "status": "active"
  },
  {
    "system_id": "ai_support_02",
    "system_name": "Customer Support Email Assistant",
    "business_unit": "Customer Support",
    "owner_role": "Chief Customer Officer",
    "vendor": "openai_like_api",
    "model_family": "gpt-4-class",
    "deployment_stage": "production",
    "regulated_domains": ["gdpr", "hipaa"],
    "data_types_processed": ["personal_data", "health_data"],
    "geographic_scope": ["US"],
    "baseline_risk_tier": "high",
    "last_audit_date": "2026-01-02",
    "status": "active"
  },
  {
    "system_id": "ai_legal_01",
    "system_name": "Contract Drafting Assistant",
    "business_unit": "Legal",
    "owner_role": "Chief Legal Officer",
    "vendor": "internal_llm",
    "model_family": "legal_finetune_v3",
    "deployment_stage": "production",
    "regulated_domains": ["gdpr"],
    "data_types_processed": ["personal_data", "financial_data"],
    "geographic_scope": ["EU", "US"],
    "baseline_risk_tier": "high",
    "last_audit_date": "2026-01-18",
    "status": "active"
  },
  {
    "system_id": "ai_hr_01",
    "system_name": "Recruiting Recommendation Engine",
    "business_unit": "Human Resources",
    "owner_role": "Chief Human Resources Officer",
    "vendor": "third_party_vendor_x",
    "model_family": "resume_ranker_v2",
    "deployment_stage": "pilot",
    "regulated_domains": ["eeoc", "gdpr"],
    "data_types_processed": ["personal_data", "demographic_data"],
    "geographic_scope": ["US", "EU"],
    "baseline_risk_tier": "high",
    "last_audit_date": "2025-12-20",
    "status": "restricted"
  },
  {
    "system_id": "ai_finance_01",
    "system_name": "Financial Narrative Generator",
    "business_unit": "Finance",
    "owner_role": "Chief Financial Officer",
    "vendor": "internal_llm",
    "model_family": "finance_gpt_v1",
    "deployment_stage": "production",
    "regulated_domains": ["sox"],
    "data_types_processed": ["financial_data"],
    "geographic_scope": ["US"],
    "baseline_risk_tier": "medium",
    "last_audit_date": "2026-01-05",
    "status": "active"
  },
  {
    "system_id": "ai_underwriting_01",
    "system_name": "Loan Underwriting Explanation Bot",
    "business_unit": "Risk",
    "owner_role": "Chief Risk Officer",
    "vendor": "third_party_vendor_y",
    "model_family": "xgb_explainer",
    "deployment_stage": "production",
    "regulated_domains": ["fair_lending", "gdpr"],
    "data_types_processed": ["financial_data", "personal_data"],
    "geographic_scope": ["EU", "US"],
    "baseline_risk_tier": "high",
    "last_audit_date": "2026-01-12",
    "status": "active"
  },
  {
    "system_id": "ai_research_01",
    "system_name": "Internal Research Assistant",
    "business_unit": "R&D",
    "owner_role": "Chief Technology Officer",
    "vendor": "open_source_llm",
    "model_family": "llama_like_70b",
    "deployment_stage": "sandbox",
    "regulated_domains": [],
    "data_types_processed": ["public_data"],
    "geographic_scope": ["US"],
    "baseline_risk_tier": "low",
    "last_audit_date": null,
    "status": "experimental"
  },
  {
    "system_id": "ai_sales_01",
    "system_name": "Sales Proposal Generator",
    "business_unit": "Sales",
    "owner_role": "Chief Revenue Officer",
    "vendor": "openai_like_api",
    "model_family": "gpt-4-class",
    "deployment_stage": "production",
    "regulated_domains": ["gdpr"],
    "data_types_processed": ["personal_data", "financial_data"],
    "geographic_scope": ["EU", "US"],
    "baseline_risk_tier": "medium",
    "last_audit_date": "2026-01-08",
    "status": "active"
  },
  {
    "system_id": "ai_health_ops_01",
    "system_name": "Clinical Operations Assistant",
    "business_unit": "Healthcare Operations",
    "owner_role": "Chief Medical Officer",
    "vendor": "third_party_vendor_z",
    "model_family": "clinical_llm_v2",
    "deployment_stage": "production",
    "regulated_domains": ["hipaa"],
    "data_types_processed": ["health_data", "personal_data"],
    "geographic_scope": ["US"],
    "baseline_risk_tier": "critical",
    "last_audit_date": "2025-12-28",
    "status": "under_review"
  },
  {
    "system_id": "ai_procurement_01",
    "system_name": "Vendor Due Diligence Copilot",
    "business_unit": "Procurement",
    "owner_role": "Chief Procurement Officer",
    "vendor": "internal_llm",
    "model_family": "enterprise_gpt",
    "deployment_stage": "pilot",
    "regulated_domains": ["gdpr"],
    "data_types_processed": ["vendor_data", "financial_data"],
    "geographic_scope": ["EU", "US"],
    "baseline_risk_tier": "medium",
    "last_audit_date": "2026-01-15",
    "status": "active"
  }
]


# ai_output_events_v2.json

In [None]:
[
  {
    "event_id": "evt_20260201_0001",
    "timestamp": "2026-02-01T08:12:41Z",
    "system_id": "ai_marketing_01",
    "model_name": "enterprise_gpt_v4",
    "output_type": "email_campaign_copy",
    "channel": "email",
    "content_snippet": "Dear Maria Lopez, thanks for signing up for our service...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["personal_data"],
    "customer_region": "EU",
    "language": "en",
    "preliminary_risk_signal": "medium"
  },
  {
    "event_id": "evt_20260201_0002",
    "timestamp": "2026-02-01T08:22:09Z",
    "system_id": "ai_support_02",
    "model_name": "gpt-4-class",
    "output_type": "support_email",
    "channel": "email",
    "content_snippet": "Your medical claim for policy #44812 was denied...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["health_data", "personal_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "high"
  },
  {
    "event_id": "evt_20260201_0003",
    "timestamp": "2026-02-01T08:35:18Z",
    "system_id": "ai_sales_01",
    "model_name": "gpt-4-class",
    "output_type": "proposal_draft",
    "channel": "crm_export",
    "content_snippet": "The contract value for ACME Corp is projected at $4.2M...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["financial_data"],
    "customer_region": "EU",
    "language": "en",
    "preliminary_risk_signal": "medium"
  },
  {
    "event_id": "evt_20260201_0004",
    "timestamp": "2026-02-01T09:01:44Z",
    "system_id": "ai_legal_01",
    "model_name": "legal_finetune_v3",
    "output_type": "contract_clause",
    "channel": "document_system",
    "content_snippet": "The borrower SSN shall be recorded as 987-65-4321...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["personal_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "critical"
  },
  {
    "event_id": "evt_20260201_0005",
    "timestamp": "2026-02-01T09:18:02Z",
    "system_id": "ai_research_01",
    "model_name": "llama_like_70b",
    "output_type": "internal_summary",
    "channel": "internal_tool",
    "content_snippet": "Recent studies published by the CDC show...",
    "contains_sensitive_data": false,
    "sensitive_data_types": [],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "low"
  },
  {
    "event_id": "evt_20260201_0006",
    "timestamp": "2026-02-01T09:40:29Z",
    "system_id": "ai_health_ops_01",
    "model_name": "clinical_llm_v2",
    "output_type": "patient_message",
    "channel": "patient_portal",
    "content_snippet": "Patient John D., DOB 02/11/1975, diagnosis code E11...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["health_data", "personal_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "critical"
  },
  {
    "event_id": "evt_20260201_0007",
    "timestamp": "2026-02-01T10:03:55Z",
    "system_id": "ai_underwriting_01",
    "model_name": "xgb_explainer",
    "output_type": "loan_decision_explanation",
    "channel": "customer_portal",
    "content_snippet": "Your income of $72,000 and credit history were factors...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["financial_data", "personal_data"],
    "customer_region": "EU",
    "language": "en",
    "preliminary_risk_signal": "high"
  },
  {
    "event_id": "evt_20260201_0008",
    "timestamp": "2026-02-01T10:21:17Z",
    "system_id": "ai_hr_01",
    "model_name": "resume_ranker_v2",
    "output_type": "candidate_evaluation",
    "channel": "hr_system",
    "content_snippet": "Applicant scored lower due to age and education level...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["demographic_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "high"
  },
  {
    "event_id": "evt_20260201_0009",
    "timestamp": "2026-02-01T10:47:03Z",
    "system_id": "ai_procurement_01",
    "model_name": "enterprise_gpt_v4",
    "output_type": "vendor_risk_summary",
    "channel": "procurement_portal",
    "content_snippet": "Vendor Delta Ltd processes EU customer addresses...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["vendor_data", "personal_data"],
    "customer_region": "EU",
    "language": "en",
    "preliminary_risk_signal": "medium"
  },
  {
    "event_id": "evt_20260201_0010",
    "timestamp": "2026-02-01T11:05:42Z",
    "system_id": "ai_finance_01",
    "model_name": "finance_gpt_v1",
    "output_type": "earnings_commentary",
    "channel": "internal_report",
    "content_snippet": "Projected revenue shortfall for Q3 is estimated at $18.2M...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["financial_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "medium"
  },
  {
    "event_id": "evt_20260202_0011",
    "timestamp": "2026-02-02T08:14:11Z",
    "system_id": "ai_support_02",
    "model_name": "gpt-4-class",
    "output_type": "support_chat",
    "channel": "chat",
    "content_snippet": "Please confirm your SSN so we can process the claim...",
    "contains_sensitive_data": true,
    "sensitive_data_types": ["personal_data"],
    "customer_region": "US",
    "language": "en",
    "preliminary_risk_signal": "critical"
  },
  {
    "event_id": "evt_20260202_0012",
    "timestamp": "2026-02-02T09:02:55Z",
    "system_id": "ai_marketing_01",
    "model_name": "enterprise_gpt_v4",
    "output_type": "landing_page_copy",
    "channel": "web",
    "content_snippet": "Join thousands of customers across Europe who trust us...",
    "contains_sensitive_data": false,
    "sensitive_data_types": [],
    "customer_region": "EU",
    "language": "en",
    "preliminary_risk_signal": "low"
  }
]


# compliance_findings_v2.json

In [None]:
[
  {
    "finding_id": "cf_9001",
    "event_id": "evt_20260201_0001",
    "system_id": "ai_marketing_01",
    "policy_id": "gdpr_marketing_pii",
    "regulation": "GDPR",
    "article": "Article 6",
    "violation_type": "unauthorized_personalization",
    "severity": "medium",
    "risk_score": 62.4,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T08:13:10Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9002",
    "event_id": "evt_20260201_0002",
    "system_id": "ai_support_02",
    "policy_id": "hipaa_phi_email",
    "regulation": "HIPAA",
    "article": "Privacy Rule",
    "violation_type": "phi_in_outbound_email",
    "severity": "high",
    "risk_score": 88.9,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T08:22:41Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9003",
    "event_id": "evt_20260201_0004",
    "system_id": "ai_legal_01",
    "policy_id": "gdpr_ssn_exposure",
    "regulation": "GDPR",
    "article": "Article 32",
    "violation_type": "national_identifier_exposure",
    "severity": "critical",
    "risk_score": 97.1,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T09:02:10Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9004",
    "event_id": "evt_20260201_0006",
    "system_id": "ai_health_ops_01",
    "policy_id": "hipaa_phi_portal",
    "regulation": "HIPAA",
    "article": "Security Rule",
    "violation_type": "phi_exposure_in_portal",
    "severity": "critical",
    "risk_score": 99.0,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T09:41:05Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9005",
    "event_id": "evt_20260201_0007",
    "system_id": "ai_underwriting_01",
    "policy_id": "fair_lending_disclosure",
    "regulation": "Fair Lending",
    "article": "ECOA",
    "violation_type": "sensitive_attribute_usage",
    "severity": "high",
    "risk_score": 90.3,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T10:04:30Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9006",
    "event_id": "evt_20260201_0008",
    "system_id": "ai_hr_01",
    "policy_id": "eeoc_bias_signal",
    "regulation": "EEOC",
    "article": "Title VII",
    "violation_type": "discriminatory_scoring",
    "severity": "high",
    "risk_score": 89.7,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T10:05:11Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9007",
    "event_id": "evt_20260201_0010",
    "system_id": "ai_finance_01",
    "policy_id": "sox_forward_statements",
    "regulation": "SOX",
    "article": "Section 404",
    "violation_type": "unaudited_forward_looking_statement",
    "severity": "medium",
    "risk_score": 61.2,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T11:06:22Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9008",
    "event_id": "evt_20260202_0011",
    "system_id": "ai_support_02",
    "policy_id": "gdpr_ssn_request",
    "regulation": "GDPR",
    "article": "Article 5",
    "violation_type": "requesting_sensitive_identifier",
    "severity": "critical",
    "risk_score": 96.4,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-02T08:14:49Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9009",
    "event_id": "evt_20260202_0012",
    "system_id": "ai_marketing_01",
    "policy_id": "gdpr_web_copy_review",
    "regulation": "GDPR",
    "article": "Article 25",
    "violation_type": "privacy_by_design_review_required",
    "severity": "low",
    "risk_score": 28.5,
    "repeat_offender": false,
    "status": "closed",
    "detected_at": "2026-02-02T09:03:20Z",
    "closed_at": "2026-02-02T10:12:00Z"
  }
]


# compliance_findings_v2.json

In [None]:
[
  {
    "finding_id": "cf_9001",
    "event_id": "evt_20260201_0001",
    "system_id": "ai_marketing_01",
    "policy_id": "gdpr_marketing_pii",
    "regulation": "GDPR",
    "article": "Article 6",
    "violation_type": "unauthorized_personalization",
    "severity": "medium",
    "risk_score": 62.4,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T08:13:10Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9002",
    "event_id": "evt_20260201_0002",
    "system_id": "ai_support_02",
    "policy_id": "hipaa_phi_email",
    "regulation": "HIPAA",
    "article": "Privacy Rule",
    "violation_type": "phi_in_outbound_email",
    "severity": "high",
    "risk_score": 88.9,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T08:22:41Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9003",
    "event_id": "evt_20260201_0004",
    "system_id": "ai_legal_01",
    "policy_id": "gdpr_ssn_exposure",
    "regulation": "GDPR",
    "article": "Article 32",
    "violation_type": "national_identifier_exposure",
    "severity": "critical",
    "risk_score": 97.1,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T09:02:10Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9004",
    "event_id": "evt_20260201_0006",
    "system_id": "ai_health_ops_01",
    "policy_id": "hipaa_phi_portal",
    "regulation": "HIPAA",
    "article": "Security Rule",
    "violation_type": "phi_exposure_in_portal",
    "severity": "critical",
    "risk_score": 99.0,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T09:41:05Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9005",
    "event_id": "evt_20260201_0007",
    "system_id": "ai_underwriting_01",
    "policy_id": "fair_lending_disclosure",
    "regulation": "Fair Lending",
    "article": "ECOA",
    "violation_type": "sensitive_attribute_usage",
    "severity": "high",
    "risk_score": 90.3,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T10:04:30Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9006",
    "event_id": "evt_20260201_0008",
    "system_id": "ai_hr_01",
    "policy_id": "eeoc_bias_signal",
    "regulation": "EEOC",
    "article": "Title VII",
    "violation_type": "discriminatory_scoring",
    "severity": "high",
    "risk_score": 89.7,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-01T10:05:11Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9007",
    "event_id": "evt_20260201_0010",
    "system_id": "ai_finance_01",
    "policy_id": "sox_forward_statements",
    "regulation": "SOX",
    "article": "Section 404",
    "violation_type": "unaudited_forward_looking_statement",
    "severity": "medium",
    "risk_score": 61.2,
    "repeat_offender": false,
    "status": "open",
    "detected_at": "2026-02-01T11:06:22Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9008",
    "event_id": "evt_20260202_0011",
    "system_id": "ai_support_02",
    "policy_id": "gdpr_ssn_request",
    "regulation": "GDPR",
    "article": "Article 5",
    "violation_type": "requesting_sensitive_identifier",
    "severity": "critical",
    "risk_score": 96.4,
    "repeat_offender": true,
    "status": "open",
    "detected_at": "2026-02-02T08:14:49Z",
    "closed_at": null
  },
  {
    "finding_id": "cf_9009",
    "event_id": "evt_20260202_0012",
    "system_id": "ai_marketing_01",
    "policy_id": "gdpr_web_copy_review",
    "regulation": "GDPR",
    "article": "Article 25",
    "violation_type": "privacy_by_design_review_required",
    "severity": "low",
    "risk_score": 28.5,
    "repeat_offender": false,
    "status": "closed",
    "detected_at": "2026-02-02T09:03:20Z",
    "closed_at": "2026-02-02T10:12:00Z"
  }
]


# financial_exposure_models_v2.json

In [None]:
[
  {
    "finding_id": "cf_9001",
    "estimated_fine_usd": 750000,
    "legal_cost_estimate_usd": 180000,
    "remediation_cost_usd": 90000,
    "brand_risk_multiplier": 1.15,
    "base_exposure_usd": 1020000,
    "total_estimated_exposure_usd": 1173000,
    "confidence_level": 0.72,
    "model_assumptions": "Single-instance GDPR marketing PII exposure; limited distribution; rapid containment."
  },
  {
    "finding_id": "cf_9002",
    "estimated_fine_usd": 2800000,
    "legal_cost_estimate_usd": 600000,
    "remediation_cost_usd": 140000,
    "brand_risk_multiplier": 1.30,
    "base_exposure_usd": 3540000,
    "total_estimated_exposure_usd": 4602000,
    "confidence_level": 0.81,
    "model_assumptions": "HIPAA PHI emailed externally; repeat offender; moderate customer reach."
  },
  {
    "finding_id": "cf_9003",
    "estimated_fine_usd": 5200000,
    "legal_cost_estimate_usd": 950000,
    "remediation_cost_usd": 210000,
    "brand_risk_multiplier": 1.45,
    "base_exposure_usd": 6360000,
    "total_estimated_exposure_usd": 9222000,
    "confidence_level": 0.87,
    "model_assumptions": "SSN included in legal draft; systemic control gap; US jurisdiction."
  },
  {
    "finding_id": "cf_9004",
    "estimated_fine_usd": 6100000,
    "legal_cost_estimate_usd": 1200000,
    "remediation_cost_usd": 320000,
    "brand_risk_multiplier": 1.50,
    "base_exposure_usd": 7620000,
    "total_estimated_exposure_usd": 11430000,
    "confidence_level": 0.90,
    "model_assumptions": "HIPAA exposure via patient portal; critical system; potential breach notification obligations."
  },
  {
    "finding_id": "cf_9005",
    "estimated_fine_usd": 3400000,
    "legal_cost_estimate_usd": 720000,
    "remediation_cost_usd": 160000,
    "brand_risk_multiplier": 1.25,
    "base_exposure_usd": 4280000,
    "total_estimated_exposure_usd": 5350000,
    "confidence_level": 0.79,
    "model_assumptions": "Fair lending disclosure issue; EU customers; underwriting explanations."
  },
  {
    "finding_id": "cf_9006",
    "estimated_fine_usd": 3000000,
    "legal_cost_estimate_usd": 650000,
    "remediation_cost_usd": 190000,
    "brand_risk_multiplier": 1.28,
    "base_exposure_usd": 3840000,
    "total_estimated_exposure_usd": 4915000,
    "confidence_level": 0.83,
    "model_assumptions": "EEOC bias signal in HR pilot system; demographic inference; potential class-action risk."
  },
  {
    "finding_id": "cf_9007",
    "estimated_fine_usd": 900000,
    "legal_cost_estimate_usd": 200000,
    "remediation_cost_usd": 85000,
    "brand_risk_multiplier": 1.10,
    "base_exposure_usd": 1185000,
    "total_estimated_exposure_usd": 1303500,
    "confidence_level": 0.70,
    "model_assumptions": "SOX forward-looking commentary without audit approval; contained internally."
  },
  {
    "finding_id": "cf_9008",
    "estimated_fine_usd": 4700000,
    "legal_cost_estimate_usd": 880000,
    "remediation_cost_usd": 230000,
    "brand_risk_multiplier": 1.40,
    "base_exposure_usd": 5810000,
    "total_estimated_exposure_usd": 8134000,
    "confidence_level": 0.88,
    "model_assumptions": "GDPR sensitive identifier request; repeated behavior; US system serving EU data."
  }
]


# portfolio_snapshots_v2.json

In [None]:
[
  {
    "snapshot_date": "2026-01-30",
    "systems_monitored": 10,
    "open_cases": 4,
    "closed_cases": 2,
    "critical_cases": 1,
    "high_cases": 2,
    "medium_cases": 1,
    "low_cases": 2,
    "total_estimated_exposure_usd": 6400000,
    "avg_time_to_close_days": 5.8,
    "repeat_offender_systems": 2,
    "executive_escalations": 1,
    "portfolio_risk_score": 58.4,
    "trend_vs_prior_period": "stable"
  },
  {
    "snapshot_date": "2026-01-31",
    "systems_monitored": 10,
    "open_cases": 6,
    "closed_cases": 2,
    "critical_cases": 2,
    "high_cases": 3,
    "medium_cases": 1,
    "low_cases": 2,
    "total_estimated_exposure_usd": 11800000,
    "avg_time_to_close_days": 5.4,
    "repeat_offender_systems": 3,
    "executive_escalations": 2,
    "portfolio_risk_score": 71.2,
    "trend_vs_prior_period": "worsening"
  },
  {
    "snapshot_date": "2026-02-01",
    "systems_monitored": 10,
    "open_cases": 9,
    "closed_cases": 3,
    "critical_cases": 3,
    "high_cases": 4,
    "medium_cases": 1,
    "low_cases": 1,
    "total_estimated_exposure_usd": 21800000,
    "avg_time_to_close_days": 4.6,
    "repeat_offender_systems": 4,
    "executive_escalations": 3,
    "portfolio_risk_score": 82.3,
    "trend_vs_prior_period": "worsening"
  },
  {
    "snapshot_date": "2026-02-02",
    "systems_monitored": 10,
    "open_cases": 7,
    "closed_cases": 5,
    "critical_cases": 2,
    "high_cases": 3,
    "medium_cases": 1,
    "low_cases": 1,
    "total_estimated_exposure_usd": 16400000,
    "avg_time_to_close_days": 3.9,
    "repeat_offender_systems": 3,
    "executive_escalations": 2,
    "portfolio_risk_score": 69.7,
    "trend_vs_prior_period": "improving"
  },
  {
    "snapshot_date": "2026-02-03",
    "systems_monitored": 10,
    "open_cases": 6,
    "closed_cases": 6,
    "critical_cases": 2,
    "high_cases": 2,
    "medium_cases": 1,
    "low_cases": 1,
    "total_estimated_exposure_usd": 13850000,
    "avg_time_to_close_days": 3.5,
    "repeat_offender_systems": 2,
    "executive_escalations": 1,
    "portfolio_risk_score": 63.9,
    "trend_vs_prior_period": "improving"
  }
]


# escalation_events_v2.json

In [None]:
[
    {
      "escalation_id": "esc_2001",
      "finding_id": "cf_9003",
      "system_id": "ai_legal_01",
      "trigger_type": "severity_threshold",
      "trigger_reason": "critical_ssn_exposure",
      "trigger_details": "GDPR Article 32 violation with national identifier in production legal system.",
      "exposure_threshold_usd": 5000000,
      "actual_exposure_usd": 9222000,
      "severity": "critical",
      "notified_roles": ["Chief Legal Officer", "Chief Risk Officer"],
      "escalated_at": "2026-02-01T09:05:00Z",
      "acknowledged": true,
      "acknowledged_by_role": "Chief Legal Officer",
      "acknowledged_at": "2026-02-01T09:18:00Z",
      "status": "active"
    },
    {
      "escalation_id": "esc_2002",
      "finding_id": "cf_9004",
      "system_id": "ai_health_ops_01",
      "trigger_type": "severity_threshold",
      "trigger_reason": "hipaa_phi_exposure",
      "trigger_details": "PHI exposed in patient portal; breach notification assessment required.",
      "exposure_threshold_usd": 5000000,
      "actual_exposure_usd": 11430000,
      "severity": "critical",
      "notified_roles": ["Chief Medical Officer", "Chief Compliance Officer", "Chief Risk Officer"],
      "escalated_at": "2026-02-01T09:43:00Z",
      "acknowledged": true,
      "acknowledged_by_role": "Chief Compliance Officer",
      "acknowledged_at": "2026-02-01T09:58:00Z",
      "status": "active"
    },
    {
      "escalation_id": "esc_2003",
      "finding_id": "cf_9002",
      "system_id": "ai_support_02",
      "trigger_type": "repeat_offender",
      "trigger_reason": "multiple_hipaa_violations",
      "trigger_details": "Customer Support system triggered second HIPAA PHI email incident within 48 hours.",
      "exposure_threshold_usd": 2500000,
      "actual_exposure_usd": 4602000,
      "severity": "high",
      "notified_roles": ["Chief Customer Officer", "Chief Risk Officer"],
      "escalated_at": "2026-02-01T08:30:00Z",
      "acknowledged": true,
      "acknowledged_by_role": "Chief Risk Officer",
      "acknowledged_at": "2026-02-01T08:47:00Z",
      "status": "active"
    },
    {
      "escalation_id": "esc_2004",
      "finding_id": "cf_9008",
      "system_id": "ai_support_02",
      "trigger_type": "severity_threshold",
      "trigger_reason": "gdpr_sensitive_identifier_request",
      "trigger_details": "Support chatbot requested SSN from EU subject; critical GDPR breach.",
      "exposure_threshold_usd": 5000000,
      "actual_exposure_usd": 8134000,
      "severity": "critical",
      "notified_roles": ["Chief Privacy Officer", "Chief Risk Officer", "Chief Legal Officer"],
      "escalated_at": "2026-02-02T08:17:00Z",
      "acknowledged": false,
      "acknowledged_by_role": null,
      "acknowledged_at": null,
      "status": "pending_acknowledgement"
    },
    {
      "escalation_id": "esc_2005",
      "finding_id": "cf_9006",
      "system_id": "ai_hr_01",
      "trigger_type": "regulatory_category",
      "trigger_reason": "eeoc_bias_signal",
      "trigger_details": "Discriminatory scoring detected in recruiting pilot system; potential Title VII exposure.",
      "exposure_threshold_usd": 3000000,
      "actual_exposure_usd": 4915000,
      "severity": "high",
      "notified_roles": ["Chief Human Resources Officer", "Chief Compliance Officer"],
      "escalated_at": "2026-02-01T10:07:00Z",
      "acknowledged": true,
      "acknowledged_by_role": "Chief Human Resources Officer",
      "acknowledged_at": "2026-02-01T10:25:00Z",
      "status": "active"
    },
    {
      "escalation_id": "esc_2006",
      "finding_id": "cf_9005",
      "system_id": "ai_underwriting_01",
      "trigger_type": "risk_score_threshold",
      "trigger_reason": "fair_lending_violation",
      "trigger_details": "Underwriting explanation references sensitive attributes; ECOA flagged.",
      "exposure_threshold_usd": 4000000,
      "actual_exposure_usd": 5350000,
      "severity": "high",
      "notified_roles": ["Chief Risk Officer", "Chief Lending Officer"],
      "escalated_at": "2026-02-01T10:06:00Z",
      "acknowledged": true,
      "acknowledged_by_role": "Chief Risk Officer",
      "acknowledged_at": "2026-02-01T10:20:00Z",
      "status": "active"
    }
  ]


# human_review_actions_v2.json

In [None]:
[
  {
    "review_id": "rev_3001",
    "finding_id": "cf_9003",
    "system_id": "ai_legal_01",
    "reviewer_role": "Senior Privacy Counsel",
    "decision": "confirm_violation",
    "severity_confirmed": "critical",
    "remediation_required": true,
    "assigned_team": "Legal Ops",
    "resolution_deadline": "2026-02-04",
    "review_started_at": "2026-02-01T09:12:00Z",
    "review_completed_at": "2026-02-01T10:02:00Z",
    "closed_at": null,
    "sla_hours": 24
  },
  {
    "review_id": "rev_3002",
    "finding_id": "cf_9004",
    "system_id": "ai_health_ops_01",
    "reviewer_role": "Chief Privacy Officer",
    "decision": "confirm_violation",
    "severity_confirmed": "critical",
    "remediation_required": true,
    "assigned_team": "Clinical IT Security",
    "resolution_deadline": "2026-02-03",
    "review_started_at": "2026-02-01T09:50:00Z",
    "review_completed_at": "2026-02-01T10:25:00Z",
    "closed_at": null,
    "sla_hours": 12
  },
  {
    "review_id": "rev_3003",
    "finding_id": "cf_9002",
    "system_id": "ai_support_02",
    "reviewer_role": "HIPAA Compliance Officer",
    "decision": "confirm_violation",
    "severity_confirmed": "high",
    "remediation_required": true,
    "assigned_team": "Customer Support Engineering",
    "resolution_deadline": "2026-02-03",
    "review_started_at": "2026-02-01T08:35:00Z",
    "review_completed_at": "2026-02-01T09:05:00Z",
    "closed_at": null,
    "sla_hours": 24
  },
  {
    "review_id": "rev_3004",
    "finding_id": "cf_9006",
    "system_id": "ai_hr_01",
    "reviewer_role": "Employment Counsel",
    "decision": "confirm_violation",
    "severity_confirmed": "high",
    "remediation_required": true,
    "assigned_team": "HR Analytics",
    "resolution_deadline": "2026-02-05",
    "review_started_at": "2026-02-01T10:12:00Z",
    "review_completed_at": "2026-02-01T10:45:00Z",
    "closed_at": null,
    "sla_hours": 48
  },
  {
    "review_id": "rev_3005",
    "finding_id": "cf_9005",
    "system_id": "ai_underwriting_01",
    "reviewer_role": "Fair Lending Officer",
    "decision": "confirm_violation",
    "severity_confirmed": "high",
    "remediation_required": true,
    "assigned_team": "Risk Model Governance",
    "resolution_deadline": "2026-02-04",
    "review_started_at": "2026-02-01T10:15:00Z",
    "review_completed_at": "2026-02-01T10:40:00Z",
    "closed_at": null,
    "sla_hours": 24
  },
  {
    "review_id": "rev_3006",
    "finding_id": "cf_9007",
    "system_id": "ai_finance_01",
    "reviewer_role": "Internal Audit Director",
    "decision": "confirm_violation",
    "severity_confirmed": "medium",
    "remediation_required": false,
    "assigned_team": "Finance Controls",
    "resolution_deadline": null,
    "review_started_at": "2026-02-01T11:10:00Z",
    "review_completed_at": "2026-02-01T11:35:00Z",
    "closed_at": "2026-02-02T09:15:00Z",
    "sla_hours": 48
  },
  {
    "review_id": "rev_3007",
    "finding_id": "cf_9009",
    "system_id": "ai_marketing_01",
    "reviewer_role": "Privacy Analyst",
    "decision": "no_violation",
    "severity_confirmed": "low",
    "remediation_required": false,
    "assigned_team": "Marketing Ops",
    "resolution_deadline": null,
    "review_started_at": "2026-02-02T09:10:00Z",
    "review_completed_at": "2026-02-02T09:30:00Z",
    "closed_at": "2026-02-02T09:30:00Z",
    "sla_hours": 24
  }
]


# remediation_actions_v2.json

In [None]:
[
  {
    "remediation_id": "rem_5001",
    "finding_id": "cf_9003",
    "system_id": "ai_legal_01",
    "action_type": "disable_feature",
    "description": "Disabled auto-insertion of personal identifiers in legal drafting templates.",
    "owner_team": "Legal Engineering",
    "executive_approved": true,
    "approved_by_role": "Chief Legal Officer",
    "started_at": "2026-02-01T10:30:00Z",
    "completed_at": null,
    "status": "in_progress",
    "estimated_risk_reduction_pct": 45,
    "post_action_exposure_usd": 5072100
  },
  {
    "remediation_id": "rem_5002",
    "finding_id": "cf_9004",
    "system_id": "ai_health_ops_01",
    "action_type": "system_restriction",
    "description": "Restricted outbound PHI in patient portal until encryption and redaction controls are deployed.",
    "owner_team": "Clinical IT Security",
    "executive_approved": true,
    "approved_by_role": "Chief Compliance Officer",
    "started_at": "2026-02-01T10:40:00Z",
    "completed_at": null,
    "status": "in_progress",
    "estimated_risk_reduction_pct": 60,
    "post_action_exposure_usd": 4572000
  },
  {
    "remediation_id": "rem_5003",
    "finding_id": "cf_9002",
    "system_id": "ai_support_02",
    "action_type": "prompt_update",
    "description": "Updated support prompts to prohibit requesting SSNs or PHI.",
    "owner_team": "Customer Support Engineering",
    "executive_approved": false,
    "approved_by_role": null,
    "started_at": "2026-02-01T09:10:00Z",
    "completed_at": null,
    "status": "awaiting_approval",
    "estimated_risk_reduction_pct": 30,
    "post_action_exposure_usd": 3221400
  },
  {
    "remediation_id": "rem_5004",
    "finding_id": "cf_9006",
    "system_id": "ai_hr_01",
    "action_type": "model_retraining",
    "description": "Retraining resume scoring model with bias-mitigated dataset and fairness constraints.",
    "owner_team": "HR Analytics",
    "executive_approved": true,
    "approved_by_role": "Chief Human Resources Officer",
    "started_at": "2026-02-01T10:55:00Z",
    "completed_at": null,
    "status": "in_progress",
    "estimated_risk_reduction_pct": 50,
    "post_action_exposure_usd": 2457500
  },
  {
    "remediation_id": "rem_5005",
    "finding_id": "cf_9005",
    "system_id": "ai_underwriting_01",
    "action_type": "guardrail_deployment",
    "description": "Added sensitive attribute redaction and explanation filtering to underwriting outputs.",
    "owner_team": "Risk Model Governance",
    "executive_approved": true,
    "approved_by_role": "Chief Risk Officer",
    "started_at": "2026-02-01T10:30:00Z",
    "completed_at": "2026-02-02T08:15:00Z",
    "status": "completed",
    "estimated_risk_reduction_pct": 55,
    "post_action_exposure_usd": 2407500
  },
  {
    "remediation_id": "rem_5006",
    "finding_id": "cf_9007",
    "system_id": "ai_finance_01",
    "action_type": "workflow_control",
    "description": "Added audit approval gate for forward-looking financial commentary.",
    "owner_team": "Finance Controls",
    "executive_approved": true,
    "approved_by_role": "Chief Financial Officer",
    "started_at": "2026-02-01T11:50:00Z",
    "completed_at": "2026-02-02T09:10:00Z",
    "status": "completed",
    "estimated_risk_reduction_pct": 70,
    "post_action_exposure_usd": 391050
  }
]
