POLICY-ML: Policy-as-Code Enforcement for Compliance, Auditability, and Trust Across Data and Machine Learning Pipelines

Authors

  • Sunil Kumar Vytla

DOI:

https://doi.org/10.22399/ijcesen.5393

Keywords:

Policy-as-Code, MLOps, Compliance Enforcement, Open Policy Agent, CI/CD Governance, Machine Learning Pipelines

Abstract

Manual governance and post-deployment validation remain persistent weaknesses in enterprise data and machine learning delivery pipelines. This paper introduces POLICY-ML, a policy-as-code enforcement framework for expressing and executing access governance, lineage rules, deployment approvals, and compliance evidence requirements across CI/CD and MLOps workflows. POLICY-ML is different from governance control plane architectures that coordinate controls across the whole enterprise. Instead, it focuses on policy definition, enforcement logic, and pipeline-level execution mechanisms that make governance directly enforceable within delivery workflows. The framework operationalizes governable checkpoints using policy engines, including OPA, Rego, and Cedar across the data and model lifecycle. Operational experience in executable policy enforcement across enterprise AI delivery systems reduces compliance violations by 60–78%, improves audit evidence completeness by 39–49 percentage points, and cuts compliance reporting effort by 55–65% compared with manual or legacy validation workflows.

References

[1] Andrei Paleye, et al., "Challenges in Deploying Machine Learning: A Survey of Case Studies," ACM Computing Surveys, 2022. DOI: https://doi.org/10.1145/353337 DOI: https://doi.org/10.1145/3533378

[2] Dominik Kreuzberger, et al., "Machine Learning Operations (MLOps): Overview, Definition, and Architecture," IEEE Access, 2023. DOI: 10.1109/ACCESS.2023.3262138

[3] Georgios Symeonidis, et al., "MLOps - Definitions, Tools and Challenges," 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC), 2022. DOI: 10.1109/CCWC54503.2022.9720902 DOI: https://doi.org/10.1109/CCWC54503.2022.9720902

[4] Shreya Shankar, et al., “Operationalizing Machine Learning: An Interview Study,” arXiv, 2022. DOI: https://doi.org/10.48550/arXiv.2209.09125

[5] OASIS, “eXtensible Access Control Markup Language (XACML) Version 3.0,” OASIS Standard, 2013. Available: https://docs.oasis-open.org/xacml/3.0/xacml-3.0core-spec-os-en. html

[6] Open Policy Agent Authors, “Open Policy Agent Documentation: Policy-Based Control for Cloud Native Environments,” Cloud Native Computing Foundation (CNCF), 2022. Available: https://www.openpolicyagent.org/docs/latest/

[7] Haftay Gebreslasie Abreha, et al. "Federated Learning in Edge Computing: A Systematic Survey," Sensors (Basel), 2022. Available: https://pme.ncbi.nlm.nih.gov/articles/PMC8780 479/

[8] Georgiana Copil, et al, "rSYBL: A Framework for Specifying and Controlling Cloud Services Elasticity,"ACM Transactions on Internet Technology (TOIT), 2016. DOI: https://doi.org/10.1145/2925990 DOI: https://doi.org/10.1145/2925990

[9] Cedric Renggli, et al., "Continuous Integration of Machine Learning Models with ease.ml/ci: Towards a Rigorous Yet Practical Treatment," arXiv, 2019. DOI: https://doi.org/10.48550/arXiv.1903.00278

[10] European Commission, “Proposal for a Regulation of the European Parliament and of the Council Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act),” COM(2021) 206 final, Brussels, 21 April 2021. Available: https://eur-lex.europa.eu/legal-content/EN/TXT/ 2uri=celex:52021PC0206

[11] NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” 2023. DOI: 10.6028/NIST.AL100- DOI: https://doi.org/10.6028/NIST.AI.100-1.jpn

[12] ISOMEC JTC 1/SC 42, “ISO/IEC TR 24030:2021 Information Technology — Artificial Intelligence (AI) — Use Cases,” International Organization for Standardization, 2021. Available: https://www.iso.org/standard/77608. html

[13] Saleema Amershi, et al. "Software Engineering for Machine Learning: A Case Study," 2019 IEEE/ACM 4lst International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), 2019. DOI: https://ieeexplore.ieee.org/document/8804457 DOI: https://doi.org/10.1109/ICSE-SEIP.2019.00042

[14] Sasu Makinen, et al., “Who Needs MLOps: What Data Scientists Seek to Accomplish and How Can MLOps Help?” arXiv, 2021. DOI: https://doi.org/10.48550/arXiv.2103.08942 DOI: https://doi.org/10.1109/WAIN52551.2021.00024

[15] European Commission, “Ethics Guidelines for Trustworthy Artificial Intelligence,” Brussels, 2019. Available: https://digital-strategy.ec.europa.eu/en/library/eth ics-guidelines-trustworthy-ai

[16] Cynthia Rudin, “Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Interpretable Models Instead,” arXiv, 2018. DOI: https://doi.org/10.48550/arXiv.1811.10154 DOI: https://doi.org/10.1038/s42256-019-0048-x

[17] Inioluwa Deborah Raji, et al., “Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing,” arXiv, 2020. Available: https://doi.org/10.48550/arXiv.2001.00973

[18] Margaret Mitchell, et al., “Model Cards for Model Reporting,” ACM Digital Library, 2019. DOI: https://doi.org/10.1145/3287560.328759

[19] Timnit Gebru, et al., “Datasheets for Datasets,” Communications of the ACM, vol. 64, no. 12, pp. 86-92, 2021. DOI: https://doi.org/10.1145/3458723 DOI: https://doi.org/10.1145/3458723

[20] D. Sculley, et al., “Hidden Technical Debt in Machine Learning Systems,” Advances in Neural Information Processing Systems, 2015. Available: https://proceedings.neurips.cc/paper/2015/file/86df7dcefd896fcaf2674f757a2463eba-Paper.pdf

[21] Elizamary Nascimento, et al., “Software Engineering for Artificial Intelligence and Machine Learning Software: A Systematic Literature Review,” arXiv, 2020. DOI: https://doi.org/10.48550/arXiv.2011.03751

[22] Janis Klaise, et al., “Monitoring and Explainability of Models in Production,” arXiv, 2020. DOI: https://doi.org/10.48550/arXiv.2007.06299

[23] Shreya Shankar and Aditya Parameswaran, “Towards Observability for Production Machine Learning Pipelines,” arXiv, 2022. DOI: https://doi.org/10.48550/arXiv.2108.13557 DOI: https://doi.org/10.14778/3565838.3565853

[24] Miles Brundage, et al., “Toward Trustworthy AI Development: Mechanisms for Supporting Verifiable Claims,” arXiv, 2020. Available: https://doi.org/10.48550/arXiv.2004.07213

[25] Dominik Kreuzberger, et al., “Machine Learning Operations (MLOps): Overview, Definition, and Architecture,” arXiv, 2022. DOI: https://doi.org/10.48550/arXiv.2205.02302 DOI: https://doi.org/10.1109/ACCESS.2023.3262138

[26] HashiCorp, “Sentinel: Policy as Code Framework,” 2022. Available: https://developer.hashicorp.com/sentinel

[27] Kubernetes Authors, “Policy: Kubernetes Documentation,” The Kubernetes Project. Available: https://kubernetes.io/docs/concepts/policy/

[28] Raghu Gollapudi, “Operational Drift And Risk-Bounded Decision-Making In Production Database Systems,” JOURNAL OF INTERNATIONAL CRISIS AND RISK COMMUNICATION RESEARCH, — 2023. Available: https://jicrer.com/index.php/jicrer/article/view/37 62/3176

[29] Raghu Gollapudi, “Backup Integrity and Recovery Readiness Assessmen for High-Availability Databases,” Computer Fraud and Security, 2023. Available: https://computerfraudsecurity.com/index.php/jou mal/article/view/1031/739 DOI: https://doi.org/10.52710/cfs.1031

Downloads

Published

2024-03-30

How to Cite

Sunil Kumar Vytla. (2024). POLICY-ML: Policy-as-Code Enforcement for Compliance, Auditability, and Trust Across Data and Machine Learning Pipelines. International Journal of Computational and Experimental Science and Engineering, 10(4). https://doi.org/10.22399/ijcesen.5393

Issue

Section

Research Article