Getting Audit-Ready with Finite State: A CISO’s Guide to Regulatory Compliance