Governance & Compliance Focus
Compliance Interpretation AI Agent
Designing a lightweight AI tool to map Victorian regulations to content with clarity and strategic insight
6+
Role & Task Requirements Analysed
3
AI Reasoning Flows Designed
3
User Guidance Patterns Defined
10+
Test Runs Conducted
Project Details
Client
Governance & Compliance (Demonstration for portfolio)
Duration
3 hours
Skillset
AI Workflow, Governance Mapping, UX, Structured Reasoning, Ethical Design
Tools & Stakeholders
Tools
Lindy (AI Agent Builder)
Perplexity (Scanning, scraping and analysis of sources)
Copilot (Prompt Design & Iteration)
Regulation Documentation (Publicly Available Sources)
MS Word (Research Notes & Report Structuring)
Key Stakeholders (Hypothetical/Contextual)
-
Information Governance Lead
-
Records & Archives Advisors
-
Privacy & Risk Specialists
-
IT Architects
-
Compliance & Assurance Teams
Case study details
Compliance teams often struggle to interpret dense Victorian regulations and map them to organisational practices. Public‑facing content rarely makes obligations explicit, and internal teams must manually compare standards like the PDP Act, PROV Standards, and VPDSS against what the organisation communicates externally.
The challenge was to create a lightweight AI agent that could support this interpretive work by extracting obligations, analysing public content, and presenting a clear, structured comparison. This needed to be done without access to internal systems, using only publicly available information, job‑description insights, and my own governance experience.
The goal was not to automate compliance, but to demonstrate how AI can clarify complexity, support uplift conversations, and model responsible, transparent AI behaviour through a quick live prototype.

Here’s how the journey unfolded:
1. Research
With no direct access to internal SMEs, I conducted self‑directed research:
-
Analysed the job description for an Information Compliance Lead
-
Reviewed 8+ Victorian regulatory and governance sources
-
Synthesised common obligations across PROV, VPDSS, PDP Act, and public‑sector guidance
-
Mapped typical governance workflows based on my experience in compliance‑adjacent roles
-
Identified the core user need: “Help me understand what the regulation requires and how our content aligns.”
-
This formed the foundation for the agent’s reasoning structure.
2. Designing the AI Agent Flow
The design work focused on AI reasoning flows and user guidance steps.
I created 3+ structured flows that defined:
-
How the agent prompts the user
-
What inputs are required
-
How scraping is handled (only when URLs are provided)
-
How obligations are extracted
-
How public content is summarised
-
How alignment is mapped and scored
-
How the final report is structured
This created a logic‑first design, ensuring the agent behaves predictably and transparently. The AI agent can be accessed here, although that require creation of a free account in Lindy: https://chat.lindy.ai/eva-olssons-workspace-2/lindy/chat-696c2bbbe1a9415565fd21e6
Below are screenshots from the detailed flow views of the agent in Lindy, including the user's user interface when interacting with the agent, and the report it generated.
3. Prompt Refinement & Ethical Safeguard
To stabilise the agent’s behaviour and reduce unnecessary credit usage in Lindy, I completed 10+ refinement cycles in Copilot. This allowed me to iterate quickly on the agent’s reasoning structure, guardrails, and output format before transferring the final version into Lindy.
The refinement work focused on:
-
Strengthening ethical safeguards
-
Ensuring the agent never provides legal advice
-
Making source transparency explicit
-
Clarifying how scraping works (only when URLs are provided)
-
Improving the userflow and input prompts
-
Ensuring the agent explains its output structure before analysing
-
Reducing ambiguity in scoring and interpretation
-
Creating a predictable, repeatable workflow
Below is an excerpt of the actual system prompt used in the agent — included here to demonstrate the level of structure, clarity, and ethical design embedded into the workflow.
You are an AI assistant that interprets Victorian information governance regulations and compares them to public-facing organisational content. You extract obligations, summarise content, map alignment, identify gaps, and provide plain-language insights. You support strategic compliance thinking, not legal advice. Always begin by showing the userflow: ## How to Use This Agent 1. Provide the regulation or standard text (or a URL for scraping) 2. Provide the public-facing content you want analysed (or a URL for scraping) 3. (Optional) Ask for a STAR example 4. I will then generate a structured compliance interpretation report Then show the output preview: ## Your Report Will Include: - Extracted Obligations - Summary of Public Content - Obligation Mapping Table (with scoring) - Plain-Language Interpretation - Strategic Summary - STAR Example (optional) - References - Source Transparency Notes Ask for inputs: "To begin, please provide: - Regulation text or URL - Public-facing content or URL - (Optional) Request a STAR example" Do NOT begin analysis until the user provides the required inputs. When analysing: - Extract obligations - Summarise public content - Map alignment using a 0–2 scoring model - Provide plain-language interpretation - Provide a strategic summary - Include references and transparency notes Ethical guardrails: - Never provide legal advice - Never fabricate regulatory text - Never scrape without a URL - Distinguish explicit evidence from inference - Be transparent about sources and limitations
My efforts
-
Conducted regulatory and governance research
-
Designed AI reasoning flows and user guidance steps
-
Built structured workflows for obligation extraction and mapping
-
Embedded ethical safeguards and transparency notes
-
Iterated the prompt and output structure for clarity and usability
-
Ensured the agent behaves predictably and avoids legal overreach

This prototype showed that an AI‑supported compliance interpretation workflow is feasible, fast to design, and easy to test. The entire concept — research, flows, prompt refinement, and this case study — took only 2–3 hours, proving how lightweight prototypes can quickly demonstrate capability without heavy investment.
The agent also highlighted clear time‑saving potential. A human would spend hours reading regulations, extracting obligations, reviewing content, comparing alignment, and writing a report. The agent completes the same workflow in seconds, making it an opportunity worth exploring further.
The work also revealed several future directions, for example:
-
Building the agent in other models
-
Refining the scoring system (the current 0–2 scale is a first draft) to better reflect risk, confidence, and impact
-
Design a tracking system and dashboard that reports on compliance over time, make predictions, and report on outliers
-
Making the report layout more concise, with linked references instead of inline citations
-
Connecting outputs to content owners to ensure accountability and trigger follow-up actions
-
Embedding the agent into Microsoft 365 workflows, including SharePoint and Microsoft Purview, to track obligations, assign actions, and maintain transparent audit trails
-
Including ownership metadata and transparency notes to clarify responsibility if something goes wrong
-
Enabling agents to notify stakeholders, escalate issues, or launch remediation workflow
Overall, this early test validated the concept and opened the door to deeper exploration of how AI can support governance and compliance teams with clarity, speed, and structure





