Compliance & governance

Governance should be an operating system, not a binder on a shelf.

The ZYK business plan treats China's cybersecurity, data-security, personal-information and generative-AI environment as architecture inputs. Content-v2 separates the legal/compliance framework from ZYK Control, the proposed operational layer that can turn policies into permissions, records and workflows.

Compliance landscape

Design against the institution's actual obligations.

Cybersecurity

The business plan identifies network security, access control, logging, data-location and classified-protection considerations as relevant to architecture and operations.

Data security

Data inventories, classification, handling rules and risk assessment should inform what AI systems can access and where workloads run.

Personal information

Purpose, minimisation, sensitive information, minors, consent where applicable, retention and individual rights should be reflected in system and process design.

Generative AI governance

Content safety, user-information protection, output labelling and other applicable requirements should be reviewed for each deployment and use case.

This site does not determine legal applicability or certify compliance. The regulatory material comes from the consolidated business-plan framing and requires current review by qualified PRC counsel before launch or contractual use.

Readiness before deployment

Map the school before buying hardware.

1. Use cases

Identify the educational and operational workflows the institution actually wants to support.

2. Data flows

Map what information enters each workflow, who can access it, where it is processed and how long it should be retained.

3. Risk & gap analysis

Compare current practices, systems and policies against the requirements identified for the proposed deployment.

4. Roadmap

Prioritise controls, documentation, training, integration and architecture changes before expansion.

Operational governance

Turn policy into system behaviour.

Identity & permissions

Define different access to models, knowledge and tools for students, teachers, leaders and operational teams.

Consent & records

Track consent state and associated records where consent is the appropriate legal basis or institutional requirement.

Audit & incident review

Maintain relevant logs and a structured review process for incidents, policy breaches or problematic outputs.

Retention & deletion

Translate institutional retention decisions into operational workflows rather than leaving data indefinitely by default.

Filtering & labelling

Apply content controls and AI-generated-content labelling settings at institutional level where appropriate.

Approval workflows

Require teacher or administrative review for selected generated materials or higher-risk workflows.

Proposed ZYK assurance programme

Four commercial tiers — clearly separate from government certification.

TierCore requirements in the business planReview concept
BronzeBasic security hardware, access controls and staff trainingAnnual
SilverBronze + data classification, consent system, filtering and security auditBi-annual
GoldSilver + penetration test, disaster-recovery test, data-locality controls and quarterly security reviewQuarterly + annual audit
PlatinumGold + curriculum integration, student AI literacy, case study and conference participationAnnual + quarterly review

These tiers are a proposed ZYK commercial assurance/certification programme from the business plan. They are not government-issued certification, accreditation, regulatory approval or legal assurance.

Professional support

Governance may require more than software.

AI Readiness Assessment

Diagnostic mapping of infrastructure, data flows, risks, use cases and governance gaps.

Compliance implementation support

Support for data classification, workflows, documentation and system controls according to agreed project scope.

DPIA support

Business-plan service concept for impact-assessment support, subject to scope, methodology and appropriate legal/professional review.

Institutional AI Policy Toolkit

A strategic content-v2 concept for acceptable-use policies, staff/student rules, parent communications, consent templates and governance documentation, all requiring legal review before formal use.