The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering projects.
Abstract
Integrating Large Language Models (LLMs) into the Software Development Life Cycle (SDLC) can improve developer productivity, but it also introduces security, privacy, and compliance risks during model selection. Regulations and frameworks such as the EU AI Act, the NIST AI Risk Management Framework (RMF), the General Data Protection Regulation (GDPR), the Lei Geral de Prote\c{c}\~ao de Dados (LGPD), and ISO/IEC 42001 establish obligations that are often difficult to translate into operational criteria for technical decision-making. This paper proposes a model to support governance and compliance in LLM selection for software engineering projects. The model is developed through Design Science Research (DSR) and is structured in three layers: (i) regulatory requirements, (ii) organizational governance capabilities, instantiated by a multi-criteria decision matrix with knock-out and weighted scoring criteria, and (iii) productivity and sustainability outcomes, operationalized by the LLM governance assessment protocol (PAG-LLM). A regulatory feedback loop connects operational results back to the normative layer, enabling iterative refinement of the model. A pilot evaluation with 20 adversarial scenarios based on Common Weakness Enumeration (CWE) and the OWASP Top 10 suggests distinct risk profiles between commercial cloud-based LLMs and local open-source LLMs. The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering projects.
It is concluded that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection.
Mohamed Riyaz M. Meera Rawuthar, Ahmad M. Al-Ali· International Journal of Inn...· 0 citations
Background: Digital wallet services depend on frequent software delivery while operating under stringent requirements for availability, security, and accountability. In such environments, extensive CI/CD automation does not necessarily imply an equally mature governance framework.
Objective: This study assesses the ext...
Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United...
In recent years, due to the widespread adoption of Agile and DevSecOps approaches to software development, the increasing number of abuses and malicious actions targeting information technology-based resources and the accelerating need for software applications to adhere compliance requirements with certain standards,...
Zhelyana Doneva Georgieva, R. Doneva, Silvia Gaftandzhieva· International Journal on Inf...· 0 citations
This study proposes an integrated COBIT 2019 and ITIL v4 approach, embedding good governance principles for sustainable service management in Museum Electronic-Based Government System (SPBE) and addressing the gap between governance conditions and public interests.
Fauzia Dhiyaa' Farros, D. Nugraheni· Scientific Journal of Inform...· 0 citations
Evidence on IT reference frameworks across organizational and sectoral contexts is characterized, indicating that integration is concentrated around recurring interfaces among strategic governance, service operation, quality and assurance controls, enterprise architecture, and evidence feedback.
Alejandro Quintero Sánchez, J. Gómez-Rodríguez, L. A. Flores-Chaires et al.· Information· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.