AI Governance Notice
How ICS uses Anthropic Claude in compliance research, analysis, and drafting; the data-privacy, cybersecurity, and continuity controls we maintain; and the documentation available to clients and regulators.
Effective date: August 2026
1. Purpose and Scope
International Compliance Solutions LLC ("ICS") is committed to the responsible, ethical, and legally compliant use of artificial intelligence tools in the delivery of its compliance consulting services. This Notice describes how ICS uses AI technology, the controls we maintain to protect client information, and what clients — and their regulators — can expect. It is intended to support client vendor due diligence and may be provided to regulators, examiners, or internal risk and compliance functions upon request.
2. The AI Tool ICS Uses
- ·AI provider: Anthropic PBC (San Francisco, CA, USA).
- ·Product: Claude (claude-sonnet / claude-opus series), a large language model AI assistant.
- ·Access method: Anthropic API and claude.ai enterprise interface.
- ·Data processing location: United States only.
3. How ICS Uses Claude
- ·Regulatory research: identifying and summarizing applicable laws, rules, and guidance from the SEC, FINRA, OCC, FDIC, Federal Reserve, CFTC, state regulators, and other authorities.
- ·Compliance analysis: analyzing how regulatory requirements apply to a client's specific business model, products, or activities.
- ·Document drafting: preparing initial drafts of compliance policies, written supervisory procedures, Form ADV filings, AML programs, privacy notices, codes of ethics, BCPs, and other compliance-related documents.
- ·Template development: creating customized forms for client due diligence, KYC, and recordkeeping.
- ·Training materials: developing compliance training outlines and content.
- ·Administrative support: summarizing research and organizing information for internal work product.
- ·Human review required — always. All AI-generated outputs are reviewed, validated, and approved by qualified ICS professionals before delivery to any client. ICS never transmits raw AI outputs as final work product and retains full professional responsibility for every deliverable, regardless of whether AI tools were used in drafting.
4. Data Privacy and Confidentiality
- ·What we do NOT input into AI: client nonpublic personal information (NPI) or PII; material nonpublic information (MNPI); account numbers, Social Security numbers, or tax IDs; customer records, transaction data, or any other client-specific sensitive information. AI tools are used exclusively with publicly available regulatory information, generic compliance frameworks, or de-identified reference materials.
- ·Zero data retention: ICS maintains a zero-data-retention (ZDR) configuration under its enterprise API agreement with Anthropic. Anthropic does not retain API conversation data beyond the session.
- ·No model training: Anthropic does not use API inputs or outputs to train models without explicit opt-in. ICS does not opt in to any model training program.
- ·Data sharing: Anthropic does not sell user data to third parties.
- ·Sub-processors: AWS and GCP (major U.S. cloud providers). ICS reviews Anthropic's subprocessor list annually.
- ·Data residency: United States only. No international data transfers.
5. Cybersecurity Controls
- ·Anthropic platform: AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls, MFA, and SOC 2 Type II certification. Infrastructure hosted on leading cloud providers with physical security, network segmentation, and continuous monitoring.
- ·API key security: ICS's API credentials are stored securely and never shared externally. Keys are rotated on any personnel change or suspected compromise.
- ·Prompt engineering: ICS uses structured prompt templates that limit unnecessary data disclosure.
- ·Device security: Claude is accessed only from ICS-managed devices with current endpoint protection, over secured network connections.
- ·Access control: AI tool access is limited to personnel who have completed ICS's AI governance training.
- ·Incident response: any suspected AI-related security incident is handled under ICS's Cybersecurity Incident Response Policy and reported to affected clients as required by applicable law.
6. Business Continuity
ICS treats AI tools as efficiency aids, not mission-critical dependencies. All compliance consulting deliverables can be produced by ICS's professional staff without the use of AI. In the event of an AI platform outage or disruption, ICS will continue to meet its contractual obligations using traditional research and drafting methods, with no interruption of client service. Target recovery time: continuation of all client services within 24 hours of any technology disruption.
7. Regulatory Framework Alignment
ICS's AI data handling controls are designed to align with the frameworks applicable to our financial services client base, including GLBA / Regulation S-P, FINRA Rule 4370, OCC Bulletin 2013-29 / SR 23-4, NYDFS 23 NYCRR 500, SEC AI guidance, state insurance privacy regulations, and BSA/AML requirements.
8. Regulatory Examination Support
- ·Upon request, ICS can provide the following to support client examinations and third-party risk management:
- ·This AI Governance Notice and ICS's full AI Governance Policy.
- ·ICS's Vendor Due Diligence & Disclosure Document for the Claude AI platform.
- ·ICS's AI Acceptable Use Guidelines.
- ·Documentation of Anthropic's SOC 2 Type II report (subject to Anthropic's distribution terms).
- ·Written attestation regarding data handling practices applicable to your engagement.
- ·Records of ICS's AI-related policies and employee training.
- ·Full cooperation during examination proceedings.
9. Client Choice
Clients who prefer that AI tools not be used in connection with their work may make that request in writing, and ICS will honor it to the extent operationally practicable.
10. Updates
This Notice is reviewed at least annually and updated as warranted by changes in AI capabilities, regulatory guidance, or ICS's operational practices. Material updates will be reflected in the effective date at the top of this page.
11. Contact
Questions about this Notice, requests for additional documentation, or vendor due diligence inquiries may be directed to Juan Carlos Riera, President — International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134 · +1 (305) 448-0014 · info@ics-compliance.com.
Questions about this document may be directed to info@ics-compliance.com or in writing to International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134.