Body of Knowledge · Chapter 10
10. Reading list
The sources that formed the discipline, curated and annotated — each with a verified URL and a one-line note on why it matters.
This is a working bibliography, not a canon. Entries are grouped by theme and annotated in one line.
URLs are given inline with a verification tag (primary, secondary, reported) so the chapter is
self-documenting; every URL is either drawn from the book’s research digest or verified for this
edition. Tools are named as category examples, illustrative and not endorsements.
Foundational texts (the form and the method)
- GRC Engineering Manifesto — the parent discipline’s founding statement; the structural and
philosophical model for this book.
https://grc.engineering/(verified: primary) - “What is GRC Engineering” (Ayoub Fandi) — the clearest definition of the parent method and the
source of the “green dashboard over a broken control is theatre” test.
https://grcengineer.com/what-is-grc-engineering/(verified: primary) - The Agile Manifesto — the “X over Y” value grammar and the signatory model this book borrows.
https://agilemanifesto.org/(verified: primary) - The Twelve-Factor App — the template for a numbered, practitioner-facing body of practice with a
“who should read this” framing.
https://12factor.net/(verified: primary) - CSIRO Responsible AI Pattern Catalogue — the pattern template (chapter 05) and proof that
responsible-AI practice can be written as reusable patterns.
https://research.csiro.au/ss/science/projects/responsible-ai-pattern-catalogue/(verified: primary) - privacypatterns.org — the precedent for translating a legal principle (privacy by design) into
engineering patterns under CC BY.
https://privacypatterns.org/(verified: primary)
Regulation and standards
- EU AI Act + Digital Omnibus explorer — the consolidated, navigable text of the Act as amended;
the primary obligation source for chapter 08.
https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/(verified: primary) - GPAI Code of Practice — the Commission’s code for general-purpose AI, including the safety and
security chapter that requires model evaluations.
https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai(verified: primary) - “ISO/IEC 42001 and the AI Act: why certification is not yet a presumption of conformity” — the
key relationship between the AIMS standard (and 42005/42006) and the Act.
https://lawandtechnology.eu/en/iso-iec-42001-and-the-ai-act-why-certification-is-not-yet-a-presumption-of-conformity/(verified: secondary) - JTC 21 harmonised-standards tracker — the live status of the European standards that would grant
a presumption of conformity; as of the book’s date, none is OJ-cited.
https://kla.digital/blog/jtc-21-standards-tracker(verified: secondary) - NIST AI Risk Management Framework 1.0 — the Govern/Map/Measure/Manage functions used as a
mapping target throughout.
https://www.nist.gov/itl/ai-risk-management-framework(verified: primary) - NIST NCCoE, “Software and AI Agent Identity and Authorization” (concept paper) — the emerging
reference for non-human identity, the precondition of agent governance.
https://www.nccoe.nist.gov/news-insights/new-concept-paper-identity-and-authority-software-agents(verified: primary) - NIST CAISI AI Agent Standards Initiative — the effort to make agent interoperability and
security standard, not per-vendor.
https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure(verified: primary) - OWASP GenAI Security Project — the home of the Top 10 for LLM Applications, the Top 10 for
Agentic Applications, the AIBOM project and the AI Maturity Assessment.
https://genai.owasp.org/(verified: primary) - CSA AI Controls Matrix and STAR for AI — the control framework and assurance programme mapped to
ISO 42001 and NIST AI RMF (chapters 07-08).
https://cloudsecurityalliance.org/star/ai(verified: primary) - MITRE ATLAS — the adversarial tactics-and-techniques knowledge base for AI, including agent
techniques, that threat models draw on.
https://atlas.mitre.org/(verified: primary) - NSA CSI, “MCP: Security Design Considerations” — government guidance on securing the Model
Context Protocol that connects agents to tools.
https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496698/(verified: primary) - “California’s SB 53: the first frontier-AI law explained” (FPF) — the clearest read on SB 53 and,
in the same source family, New York’s RAISE Act.
https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/(verified: secondary)
Papers (machine-readable evidence and agent governance)
- “Making AI Compliance Evidence Machine-Readable” (arXiv 2604.13767) — extends
OSCALfor AI and argues frameworks specify what to assure but no executable how.https://arxiv.org/html/2604.13767v1(verified: primary) - “Audit-as-code” (Frontiers in AI) — an assured-readiness score with proceed/remediate/block
gates; audit output as a build artefact.
https://pubmed.ncbi.nlm.nih.gov/41837238/(verified: primary) - Policy Cards (arXiv 2510.24383) — JSON-schema, machine-readable runtime governance artefacts for
agents.
https://arxiv.org/abs/2510.24383(verified: primary) - TAIP (arXiv 2603.03340) — treats NIST TEVV outputs as AI assurance objects.
https://arxiv.org/abs/2603.03340(verified: primary) - AI Trust OS (arXiv 2604.04749) — an operating-system framing for continuous AI trust and
assurance.
https://arxiv.org/abs/2604.04749(verified: primary) - AAGATE (arXiv 2510.25863) — a NIST AI RMF-aligned agent governance platform design.
https://arxiv.org/abs/2510.25863(verified: primary)
Reports (the market and the profession)
- IAPP AI Governance Profession Report 2025 (with Credo AI) — where the function sits and how it is
staffed; the profession’s baseline census.
https://iapp.org/resources/article/ai-governance-profession-report/(verified: primary) - IAPP Salary & Jobs Report 2025-26 — the salary bands that anchor chapter 06, including the
technical-AI-governance premium.
https://iapp.org/resources/article/salary-survey-summary/(verified: primary) - IAPP AI Governance Vendor Report 2026 — the four vendor categories and the claim that AI
governance “is not a single function, discipline or technology”.
https://iapp.org/resources/article/ai-governance-vendor-report(verified: primary) - State of GRC 2026 — the practitioner survey behind the “spreadsheet is still the #1 GRC tool”
reality the discipline reacts against.
https://grcengineer.com/report/(verified: primary) - Gartner Magic Quadrant for AI Governance Platforms 2026 (via IBM) — the first MQ for the
category and its inclusion criteria (discovery, registry, policy, evidence).
https://www.ibm.com/new/announcements/ibm-recognized-as-a-leader-in-gartner-magic-quadrant-for-ai-governance-platforms(verified: secondary) - HiddenLayer Threat Report 2026 — the source of the reported “~1 in 8 AI breaches involve
autonomous agents” figure; read as reported.
https://www.hiddenlayer.com/report-and-guide/threatreport2026(verified: reported)
Tools (illustrative categories, not endorsements)
- Inspect AI (UK AI Security Institute) — an open eval framework, the reference example for
evals-as-evidence and eval gates.
https://github.com/UKGovernmentBEIS/inspect_ai(verified: primary) - awesome-ai-agent-governance — a curated index that catalogues the tool categories this book
names — eval frameworks (promptfoo, DeepEval, Ragas, Giskard, Garak), policy engines (OPA/Rego,
Cedar), guardrails (NeMo Guardrails, Guardrails AI, LlamaFirewall), observability (Langfuse, Arize
Phoenix) and AIBOM formats (CycloneDX ML-BOM, SPDX 3.0).
https://github.com/systempromptio/awesome-ai-agent-governance(verified: primary)
Communities and newsletters
- GRC Engineer (grcengineer.com) — the parent community’s hub; the analyst-vs-engineer framing and
the role definitions this book adapts.
https://grcengineer.com/(verified: primary) - blog.grc.engineering, “GRC Engineering in 2026” (Justin Pagano) — the forward view: policy-as-
code guardrails in CI/CD, trust operations centres, agentic extensions.
https://blog.grc.engineering/p/grc-engineering-in-2026(verified: primary) - IAPP (iapp.org) — the professional body whose reports, certifications and events map the AI
governance profession.
https://iapp.org/(verified: primary)
Maps to: this chapter makes no normative claim; the standards and frameworks it lists are treated in full in chapters 04, 05, 07 and 08. Mappings elsewhere in the book are illustrative, not a claim of conformity.
Sources
The reading list is its own source set: each entry above carries its URL and a verification tag
inline, and every URL is recorded as a row in this chapter’s section of sources/SOURCES.md. Items
whose URL could not be drawn from the research digest or verified for this edition were left out — most
notably the International AI Safety Report 2026, cited elsewhere in the digest but without a URL that
resolved at the time of writing.