I am not sure if I understand your requirement. Compliance rules are created for assessment of a state of machine and not for enforcements such as making AD group to be part of local Administrators group.
You should probably look into VCM 'Console' slider and then navigate to Windows | Security | Local Groups and edit the groups to reflect what you want.
You can also create a compliance rule on Local Group data class to check if a particular member is part of a group.
Please let me know if I understood your requirement correctly.