Policy-to-code · Asenion ControlGen

Policy-to-code, made context-aware

Asenion ControlGen transforms compliance requirements into reusable control objectives, then contextualizes them into organization-specific, machine-executable controls that can be verified and evidenced. Every control is versioned and cited back to the clause it implements.

Schedule a Call

30 minutes with our AI compliance team. Bring a regulation or policy you need to operationalize.

The Asenion control architecture

From policy to provable control

Asenion has developed a methodology and system for transforming heterogeneous compliance requirements into reusable control objectives, then contextualizing and operationalizing those objectives into organization-specific controls that can be verified and evidenced.

Authoritative sources
Regulations · Standards · Frameworks · Internal policies
Policy-aware
Requirements and obligations: what the source requires
Context-aware
Jurisdiction · Use case · Users · Data · Environment: where and under what conditions it applies
Intent-aware
Organizational policy · Risk appetite · Business requirements: what you want to achieve and why
Control objective
The required compliance outcome, normalized and testable
Control
What you will implement to achieve that outcome
Verification
Verification that the control works
Evidence
Proof for auditors, regulators and the board

Policy-aware tells you what the source requires. Context-aware tells you where and under what conditions it applies. Intent-aware tells you what your organization wants to achieve, and why. Context captures the circumstances; intent captures the organization’s purpose and desired outcome. Control objectives turn both into a reusable, testable outcome, and controls define what you will implement to achieve it.

That is where compliance becomes operational, and where years of experience matter. Anyone can ask an LLM to generate a control. Knowing whether that control is actually fit for purpose for a particular organization is a very different problem.

For more than a decade, Asenion’s work has been focused on that problem: translating the language of regulation, policy and risk into controls that can be implemented, verified and evidenced in real organizations.

From the language of compliance to the language of machines.

Worked example

One requirement, every layer

Hiring AI used in the U.S., traced from the authoritative source to the evidence an auditor will ask for.

Layer
Question it answers
Example
Requirement
What does the authoritative source require?
Automated hiring tools must not discriminate, and employers must be able to defend their decisions under Title VII, the ADA and state laws.
Context
Where and under what conditions does this apply?
Hiring AI in the U.S., including New York City and California
Intent
What does the organization want to achieve, and why?
Human review must remain meaningful before an employment decision.
Control objective
What outcome must the control achieve?
Ensure employment decisions are not made solely by automated AI output.
Control
What will we implement to achieve that outcome?
Require documented human approval before rejecting a candidate.
Verification
How do we know the control works?
Verify that a rejection cannot occur without human approval.
Evidence
How do we prove it?
Approval records, system logs and bias audit results

Intent and control objective are not the same thing

Intent

Organization-specific

“We want meaningful human oversight before AI influences a hiring decision, so every candidate is treated fairly.”

Control objective

Normalized, testable and reusable

“Ensure human oversight is required before an AI-assisted employment decision is finalized.” Different organizations can arrive at the same control objective from different intent.

Same objective, different controls

Control objective: ensure human approval is required before an AI-assisted hiring decision.

Company A

Two-person approval for every candidate rejection.

Company B

One qualified recruiter must review and approve each AI recommendation.

Company C

AI can rank candidates but cannot execute the final rejection.

How policy-to-code works

From policy text to machine-readable controls

Regulations and policies are written for people. ControlGen's policy-to-code approach turns them into control objectives and operational controls that can be assessed, verified and consulted at runtime.

Traceable

Built from the source text

ControlGen works from the requirement itself and cites the clause each control implements, so every control traces back to its source.

Any requirement

Regulations, standards and your own policies

Start from the EU AI Act, ISO/IEC 42001 or NIST AI RMF, or bring your internal AI, model risk, privacy and security policies and bespoke requirements.

Operational

Classified by how it is governed

Each control is classified by how it must be governed, so it lands in the right place: an assessment question, a quantitative verification or runtime guidance.

Auditable

Versioned with tamper-resistant history

Controls are versioned with a tamper-resistant history, so you can show which version applied, when it changed and why.

Expert-led

Your experts stay in charge

ControlGen assists your policy, risk and compliance teams. They review and approve controls before anything is put to work.

Inside every policy-to-code control

Controls built to be answered, verified and evidenced

A ControlGen control is more than a sentence. It carries what your teams need to act on it and what auditors need to check it.

The right kind of answer

Controls can take multiple-choice, checkbox, text, test-score, document-upload or card-based answers, so each requirement is captured in the form that proves it.

Citations back to the clause

Every control links to the requirement it implements, so reviewers can see exactly why it exists.

Conditional and assignable

Controls can show only when they apply to a use case, and can be assigned to the right owner in your review workflow.

Grouped for scoring

Controls roll up into control bundles, such as data governance or transparency, that contribute to an overall policy score.

Part of the Asenion AI Control System

Policy-to-code, from authoring to runtime

The controls ControlGen produces are packaged as Policy Packs, then assessed, verified and witnessed across the AI lifecycle.

Package

Asenion Policy Packs

Controls are organized into ready-to-use packs for a regulation, standard or your own policy.

Explore Policy Packs →
Assess · Verify

Assessed and tested

The same controls drive lifecycle assessments in Asenion Assess and pre-deployment verificaqtion in Asenion Verify.

Explore Asenion Assess →
Witness

Consulted at runtime

AI agents consult the applicable controls before they act, and Asenion Witness records what happened.

Explore Asenion Witness →
Policy-to-code FAQ

Policy-to-code, explained

What is policy-to-code?

Policy-to-code turns the written text of a regulation, standard or internal policy into structured, machine-readable controls. Those controls can then be assessed, verified and applied to AI systems and agents, instead of living only in documents.

How is it different from policy-as-code?

Policy-as-code usually means engineers hand-writing technical rules for infrastructure. Policy-to-code starts from compliance requirements and produces controls that compliance, risk and engineering teams share, each cited back to its source clause.

Which requirements can ControlGen convert?

AI regulations such as the EU AI Act, standards such as ISO/IEC 42001 and NIST AI RMF, industry frameworks, contracts, and your own AI, model risk, privacy and security policies.

Who approves the controls?

Your people. ControlGen assists your policy, risk and compliance teams, who review and approve every control before it is used in assessments, verification or runtime guardrails.

What are context-aware controls?

Controls that reflect where and under what conditions a requirement applies (the jurisdiction, use case, users, data and environment) and what your organization wants to achieve, and why (its policies, risk appetite and business requirements). ControlGen uses both to turn reusable control objectives into organization-specific controls.

Can’t an LLM just generate controls?

Anyone can ask an LLM to generate a control. Knowing whether that control is fit for purpose is a different problem. ControlGen encodes more than a decade of Asenion experience translating regulation, policy and risk into controls that can be implemented, verified and evidenced, and your experts approve every control.

What is a control objective?

The normalized, testable outcome a control must achieve, such as “ensure employment decisions are not made solely by automated AI output.” Intent is organization-specific; the control objective is reusable. Different organizations can share the same objective and implement it with different controls.

How do Policy Packs and ControlGen work together?

ControlGen turns compliance source material into structured, reusable compliance knowledge. Policy Packs package that knowledge for repeatable use across AI systems and organizations.

See policy-to-code on one of your policies

In 30 minutes we'll take a regulation, standard or internal policy you care about and show the control objectives and controls ControlGen produces from it.

Schedule a Call

No preparation needed.