Skip to content
Preprint

Operationalizing Regulations into Code: A Model to Enhance Governance and Compliance in LLM Selection for Software Engineering

Aug 2026 · 0 citations · 18 references
Computer Science

TL;DR

The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering projects.

Abstract

Integrating Large Language Models (LLMs) into the Software Development Life Cycle (SDLC) can improve developer productivity, but it also introduces security, privacy, and compliance risks during model selection. Regulations and frameworks such as the EU AI Act, the NIST AI Risk Management Framework (RMF), the General Data Protection Regulation (GDPR), the Lei Geral de Prote\c{c}\~ao de Dados (LGPD), and ISO/IEC 42001 establish obligations that are often difficult to translate into operational criteria for technical decision-making. This paper proposes a model to support governance and compliance in LLM selection for software engineering projects. The model is developed through Design Science Research (DSR) and is structured in three layers: (i) regulatory requirements, (ii) organizational governance capabilities, instantiated by a multi-criteria decision matrix with knock-out and weighted scoring criteria, and (iii) productivity and sustainability outcomes, operationalized by the LLM governance assessment protocol (PAG-LLM). A regulatory feedback loop connects operational results back to the normative layer, enabling iterative refinement of the model. A pilot evaluation with 20 adversarial scenarios based on Common Weakness Enumeration (CWE) and the OWASP Top 10 suggests distinct risk profiles between commercial cloud-based LLMs and local open-source LLMs. The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering projects.

View source

Similar papers

#small language model Open access Sep 2026

Shipping Safer LLM Features in SMEs: A OnePage Checklist Mapped to NIST AI RMF and ISO/IEC 23894/42001

It is concluded that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection.

Mohamed Riyaz M. Meera Rawuthar, Ahmad M. Al-Ali · 0 citations
Review Open access Sep 2026

Assessing CI/CD Pipeline Governance Maturity Using the ITIL v4 Framework: A Case Study of an Indonesian Digital Wallet

Background: Digital wallet services depend on frequent software delivery while operating under stringent requirements for availability, security, and accountability. In such environments, extensive CI/CD automation does not necessarily imply an equally mature governance framework. Objective: This study assesses the ext...

Garvin Moses Tanuwihardjo, Sfenrianto Sfenrianto · 0 citations
Open access Jun 2025

ESG-as-Code: A Deterministic Rule-Based Framework for Automated ESG Compliance Validation

Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United...

Isaiah Oluwsegun Owolabi · 0 citations
Open access Sep 2026

Auditing the coverage of software quality & security & compliance requirements throughout the software development life cycle: A holistic approach

In recent years, due to the widespread adoption of Agile and DevSecOps approaches to software development, the increasing number of abuses and malicious actions targeting information technology-based resources and the accelerating need for software applications to adhere compliance requirements with certain standards,...

Zhelyana Doneva Georgieva, R. Doneva, Silvia Gaftandzhieva · 0 citations
Open access Aug 2026

Good Governance Practices of COBIT 2019 and ITIL v4 for Sustainable Service Management in Museum Electronic-Based Government System

This study proposes an integrated COBIT 2019 and ITIL v4 approach, embedding good governance principles for sustainable service management in Museum Electronic-Based Government System (SPBE) and addressing the gap between governance conditions and public interests.

Fauzia Dhiyaa' Farros, D. Nugraheni · 0 citations
Review Open access Aug 2026

Mapping IT Reference Frameworks for Governance, Service Management, and Quality Assurance: A Scoping Review

Evidence on IT reference frameworks across organizational and sectoral contexts is characterized, indicating that integration is concentrated around recurring interfaces among strategic governance, service operation, quality and assurance controls, enterprise architecture, and evidence feedback.

Alejandro Quintero Sánchez, J. Gómez-Rodríguez, L. A. Flores-Chaires et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.