---
title: "AI governance controls crosswalk"
description: "Open AI governance controls read from the framework side: each EU AI Act obligation, ISO/IEC 42001 clause, NIST AI RMF or OWASP id, with its controls."
canonical: https://aigovernanceengineer.com/controls/crosswalk
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-26
---

# AI governance controls crosswalk

> Open AI governance controls read from the framework side: each EU AI Act obligation, ISO/IEC 42001 clause, NIST AI RMF or OWASP id, with its controls.

Each mapping is illustrative, not a claim of conformity: it is this project's reading of the framework's public text.

The open control profiles (https://aigovernanceengineer.com/controls) map each control to the obligations, standards and threat catalogues it answers; this document turns those mappings around. It is generated from the control registry: 469 mappings across 30 frameworks. A framework with no mapping has no table. NIST SP 800-53 rows are control families; each row names the specific controls cited.

AIUC-1: This site is not affiliated with AIUC and holds no AIUC certificate; ids read on AIUC-1's public pages. Each mapping is this project's reading of the requirement text, not AIUC's.

## EU AI Act (post-Omnibus)

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-eu-ai-act
- Source: https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- Note: Rows of this site's obligation register (AIGE-OBL-*) for EU AI Act; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-EUAIA-ART4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4) | EU AI Act Art. 4 AI literacy | [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| [AIGE-OBL-EUAIA-ART4A](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) | EU AI Act Art. 4a lawful basis for special-category data in bias detection | [AIGE-CTL-DATA-007](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-007) Special-Category Data Conditions; [AIGE-CTL-DEPLOY-009](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009) Fairness monitored by group in production |
| [AIGE-OBL-EUAIA-ART5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) | EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) | [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension |
| [AIGE-OBL-EUAIA-ART9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) | EU AI Act Art. 9 risk management system | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs; [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation; [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences |
| [AIGE-OBL-EUAIA-ART10](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) | EU AI Act Art. 10 data and data governance | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version; [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source; [AIGE-CTL-DATA-008](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008) Fitness-for-Purpose Checks Before Admission; [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity; [AIGE-CTL-DATA-010](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010) Lineage from Training Runs to Admitted Sources |
| [AIGE-OBL-EUAIA-ART11](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11) | EU AI Act Art. 11 technical documentation (Annex IV) | [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [AIGE-OBL-EUAIA-ART12](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12) | EU AI Act Art. 12 record-keeping and logging | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback; [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record; [AIGE-CTL-ASSURE-006](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006) Control Observations Filed Against Control Ids; [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL; [AIGE-CTL-ASSURE-008](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008) Evidence Retention as Code |
| [AIGE-OBL-EUAIA-ART13](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13) | EU AI Act Art. 13 transparency and information to deployers | [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-DEPLOY-002](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002) Instructions for use held and followed |
| [AIGE-OBL-EUAIA-ART14](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) | EU AI Act Art. 14 human oversight | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop |
| [AIGE-OBL-EUAIA-ART15](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) | EU AI Act Art. 15 accuracy, robustness and cybersecurity | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation; [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-006](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006) Control Observations Filed Against Control Ids; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models |
| [AIGE-OBL-EUAIA-ART15-4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15-4) | EU AI Act Art. 15(4) feedback loops in systems that continue to learn | [AIGE-CTL-DEPLOY-009](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009) Fairness monitored by group in production |
| [AIGE-OBL-EUAIA-ART17](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17) | EU AI Act Art. 17 quality management system | [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record; [AIGE-CTL-ASSURE-006](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006) Control Observations Filed Against Control Ids; [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL |
| [AIGE-OBL-EUAIA-ART18](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18) | EU AI Act Art. 18 documentation keeping | [AIGE-CTL-ASSURE-008](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008) Evidence Retention as Code |
| [AIGE-OBL-EUAIA-ART19](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19) | EU AI Act Art. 19 automatically generated logs kept by the provider | [AIGE-CTL-ASSURE-008](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008) Evidence Retention as Code |
| [AIGE-OBL-EUAIA-ART20](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art20) | EU AI Act Art. 20 corrective actions and duty of information | [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension |
| [AIGE-OBL-EUAIA-ART25](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) | EU AI Act Art. 25 responsibilities along the AI value chain | [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs; [AIGE-CTL-DEPLOY-007](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-007) Re-assessment when a change goes beyond what was foreseen |
| [AIGE-OBL-EUAIA-ART26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) | EU AI Act Art. 26 deployer obligations for high-risk systems | [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use; [AIGE-CTL-DEPLOY-002](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002) Instructions for use held and followed |
| [AIGE-OBL-EUAIA-ART26-2](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2) | EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority | [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop |
| [AIGE-OBL-EUAIA-ART26-5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5) | EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider | [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences; [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks; [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension |
| [AIGE-OBL-EUAIA-ART26-6](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6) | EU AI Act Art. 26(6) deployer retention of automatically generated logs | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-DEPLOY-010](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010) Deployer log retention |
| [AIGE-OBL-EUAIA-ART49-71](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71) | EU AI Act Art. 49/71 registration of high-risk systems in the EU database | [AIGE-CTL-DEPLOY-013](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013) Shadow AI discovery and registry reconciliation |
| [AIGE-OBL-EUAIA-ART50](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) | EU AI Act Art. 50 transparency for certain AI systems | [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| [AIGE-OBL-EUAIA-ART53](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) | EU AI Act Art. 53 GPAI provider obligations | [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [AIGE-OBL-EUAIA-ART53-1C](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c) | EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations | [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source |
| [AIGE-OBL-EUAIA-ART55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) | EU AI Act Art. 55 GPAI models with systemic risk | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| [AIGE-OBL-EUAIA-ART72](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72) | EU AI Act Art. 72 post-market monitoring | [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record; [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store; [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences |
| [AIGE-OBL-EUAIA-ART73](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73) | EU AI Act Art. 73 serious-incident reporting | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks |

## GPAI Code of Practice

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-gpai-code-of-practice
- Source: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- Note: Rows of this site's obligation register (AIGE-OBL-*) for GPAI Code; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-GPAICOP-SAFETY-C9](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-c9) | Safety and Security Commitment 9: serious-incident reporting | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation |

## General Data Protection Regulation (EU) 2016/679

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-gdpr
- Source: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Note: Rows of this site's obligation register (AIGE-OBL-*) for GDPR; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-GDPR-ART5-1B](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b) | GDPR Art. 5(1)(b) and 6(4) purpose limitation | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source; [AIGE-CTL-DATA-005](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-005) Purpose Match Before Reuse of Data |
| [AIGE-OBL-GDPR-ART6](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art6) | GDPR Art. 6 lawful basis per processing moment | [AIGE-CTL-DATA-004](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-004) Lawful Basis and Assessment per Processing Stage |
| [AIGE-OBL-GDPR-ART7](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7) | GDPR Art. 7 conditions for consent and its withdrawal | [AIGE-CTL-DATA-011](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011) Rights Changes Propagated to Affected Models |
| [AIGE-OBL-GDPR-ART9](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art9) | GDPR Art. 9 special categories, incl. inferred sensitive data | [AIGE-CTL-DATA-007](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-007) Special-Category Data Conditions |
| [AIGE-OBL-GDPR-ART15-17-21](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21) | GDPR Arts. 15–17 and 21 data subject rights against trained models | [AIGE-CTL-DATA-011](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011) Rights Changes Propagated to Affected Models |
| [AIGE-OBL-GDPR-ART25](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25) | GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default | [AIGE-CTL-DATA-006](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-006) Personal Data Screening and Minimisation |
| [AIGE-OBL-GDPR-ART30](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art30) | GDPR Art. 30 records of processing activities | [AIGE-CTL-DATA-007](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-007) Special-Category Data Conditions |
| [AIGE-OBL-GDPR-ART33-34](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34) | GDPR Arts. 33–34 personal data breach notification | [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks |
| [AIGE-OBL-GDPR-ART35-36](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art35-36) | GDPR Arts. 35–36 DPIA and prior consultation | [AIGE-CTL-DATA-004](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-004) Lawful Basis and Assessment per Processing Stage |

## Directive (EU) 2019/790 on copyright in the Digital Single Market

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-eu-dsm
- Source: https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng
- Note: Rows of this site's obligation register (AIGE-OBL-*) for DSM Directive; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-DSM-ART4-3](https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3) | DSM Directive Art. 4(3) text-and-data-mining reservations | [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source; [AIGE-CTL-DATA-011](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011) Rights Changes Propagated to Affected Models |

## ISO/IEC 42001

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-iso-42001
- Note: Rows of this site's obligation register (AIGE-OBL-*) for ISO 42001; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-ISO42001-A6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) | A.6 AI system life cycle | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation; [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| [AIGE-OBL-ISO42001-A7](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) | A.7 Data for AI systems | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version; [AIGE-CTL-DATA-008](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008) Fitness-for-Purpose Checks Before Admission; [AIGE-CTL-DATA-010](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010) Lineage from Training Runs to Admitted Sources |
| [AIGE-OBL-ISO42001-A8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) | A.8 Information for interested parties | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| [AIGE-OBL-ISO42001-A9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) | A.9 Use of AI systems | [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| [AIGE-OBL-ISO42001-A10](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10) | A.10 Third-party and customer relationships | [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models |

## NIST AI RMF

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-nist-ai-rmf
- Source: https://www.nist.gov/itl/ai-risk-management-framework
- Note: Rows of this site's obligation register (AIGE-OBL-*) for NIST AI RMF; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-NISTRMF-GOVERN](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) | GOVERN | [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store; [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL |
| [AIGE-OBL-NISTRMF-MANAGE](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) | MANAGE | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record; [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store; [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| [AIGE-OBL-NISTRMF-MAP](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) | MAP | [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [AIGE-OBL-NISTRMF-MEASURE](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) | MEASURE | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan |

## NIST AI Agent Standards Initiative

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-nist-ai-agent-standards
- Source: https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure
- Note: Rows of this site's obligation register (AIGE-OBL-*) for NIST Agents; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-NIST-AGENTS](https://aigovernanceengineer.com/obligations/aige-obl-nist-agents) | NIST AI Agent Standards Initiative (2026) | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary |

## NIST AI 600-1 Generative AI Profile

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-nist-ai-600-1
- Source: https://doi.org/10.6028/NIST.AI.600-1
- Note: Rows of this site's obligation register (AIGE-OBL-*) for NIST AI 600-1; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-NIST-AI600-1](https://aigovernanceengineer.com/obligations/aige-obl-nist-ai600-1) | NIST AI 600-1 Generative AI Profile | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks |

## CSA AI Controls Matrix (AICM) v1.1

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-csa-aicm
- Source: https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1
- Note: Rows of this site's obligation register (AIGE-OBL-*) for CSA AICM; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-CSA-AICM](https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm) | AICM v1.1: 247 control objectives across 18 domains | [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [AIGE-OBL-CSA-AICM-AGENTIC](https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic) | AICM agent controls with the CSA Agentic Trust Framework and AARM specification | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary |

## OWASP Top 10 for Agentic Applications 2026

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-owasp-agentic-top-10
- Source: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
- Note: Rows of this site's obligation register (AIGE-OBL-*) for OWASP Agentic; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-OWASP-AGENTIC](https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic) | Top 10 for Agentic Applications 2026 | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation; [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |

## OWASP Top 10 for LLM Applications 2026

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-owasp-llm-top-10
- Source: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
- Note: Rows of this site's obligation register (AIGE-OBL-*) for OWASP LLM; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-OWASP-LLM](https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm) | Top 10 for LLM Applications 2026 | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models |

## OWASP Agent Control Standard (ACS)

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-owasp-acs
- Source: https://genai.owasp.org/resource/agent-control-standard-acs/
- Note: Rows of this site's obligation register (AIGE-OBL-*) for OWASP ACS; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-OWASP-ACS](https://aigovernanceengineer.com/obligations/aige-obl-owasp-acs) | Agent Control Standard (ACS) | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |

## OWASP AIBOM

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-owasp-aibom
- Source: https://genai.owasp.org/initiatives/ai-sbom-initiative/
- Note: Rows of this site's obligation register (AIGE-OBL-*) for OWASP AIBOM; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-OWASP-AIBOM](https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom) | AIBOM | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |

## Singapore Model AI Governance Framework for Agentic AI

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-sg-agentic-framework
- Source: https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf
- Note: Rows of this site's obligation register (AIGE-OBL-*) for Singapore Agentic; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-SG-AGENTIC-CHECKPOINTS](https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-checkpoints) | Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary) | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |
| [AIGE-OBL-SG-AGENTIC-IDENTITY](https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity) | Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary) | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |

## TC260 AI Safety Governance Framework 3.0

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-cn-tc260-framework
- Source: https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf
- Note: Rows of this site's obligation register (AIGE-OBL-*) for TC260 Framework 3.0; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-CN-TC260-AGENTS](https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents) | TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14) | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions |

## ETSI EN 304 223

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#obligations-etsi-en-304-223
- Source: https://www.etsi.org/newsroom/press-releases/2627-etsi-releases-world-leading-standard-for-securing-ai/
- Note: Rows of this site's obligation register (AIGE-OBL-*) for ETSI EN 304 223; each links to its register page.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [AIGE-OBL-ETSI-304223](https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223) | ETSI EN 304 223 baseline cyber-security for AI models and systems | [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox |

## ISO/IEC 42001:2023 Annex A

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#iso42001
- Source: https://www.iso.org/standard/81230.html
- Note: Annex A reference controls, by their short titles.

| Clause or id | Name | Controls |
| --- | --- | --- |
| A.6.2.2 | AI system requirements and specification | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary |
| A.6.2.4 | AI system verification and validation | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan |
| A.6.2.5 | AI system deployment | [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use; [AIGE-CTL-DEPLOY-004](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004) Go-live decision with conditions as code; [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria; [AIGE-CTL-DEPLOY-006](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006) Pinned versions and a tested path back |
| A.6.2.6 | AI system operation and monitoring | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences; [AIGE-CTL-DEPLOY-009](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009) Fairness monitored by group in production; [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension |
| A.6.2.8 | AI system recording of event logs | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback; [AIGE-CTL-DEPLOY-010](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010) Deployer log retention |
| A.7.2 | Data for development and enhancement of AI system | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version |
| A.7.4 | Quality of data for AI systems | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-008](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008) Fitness-for-Purpose Checks Before Admission |
| A.7.5 | Data provenance | [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version; [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source; [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity; [AIGE-CTL-DATA-010](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010) Lineage from Training Runs to Admitted Sources; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| A.8.2 | System documentation and information for users | [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs; [AIGE-CTL-DEPLOY-002](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002) Instructions for use held and followed |
| A.8.4 | Communication of incidents | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks |
| A.9.2 | Processes for responsible use of AI systems | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| A.9.4 | Intended use of the AI system | [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs; [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use |
| A.10.3 | Suppliers | [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |

## NIST AI Risk Management Framework (AI RMF 1.0)

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#nist-ai-rmf
- Source: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- Note: Subcategories, with their text as NIST AI 100-1 prints it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| GOVERN 1.6 | Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. | [AIGE-CTL-DEPLOY-013](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013) Shadow AI discovery and registry reconciliation |
| GOVERN 1.7 | Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. | [AIGE-CTL-DEPLOY-015](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-015) Retirement runbook with access and data removal |
| GOVERN 2.2 | The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements. | [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| GOVERN 6.1 | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights. | [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| MAP 1.1 | Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. | [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs; [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use |
| MAP 2.3 | Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version; [AIGE-CTL-DATA-008](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008) Fitness-for-Purpose Checks Before Admission |
| MAP 3.3 | Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization. | [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| MAP 3.5 | Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. | [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop |
| MAP 4.1 | Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights. | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source |
| MAP 4.2 | Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |
| MEASURE 2.1 | Test sets, metrics, and details about the tools used during TEVV are documented. | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation |
| MEASURE 2.3 | AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold; [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan; [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria |
| MEASURE 2.4 | The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production. | [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences |
| MEASURE 2.7 | AI system security and resilience – as identified in the MAP function – are evaluated and documented. | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| MEASURE 2.10 | Privacy risk of the AI system – as identified in the MAP function – is examined and documented. | [AIGE-CTL-DATA-004](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-004) Lawful Basis and Assessment per Processing Stage |
| MEASURE 2.11 | Fairness and bias – as identified in the MAP function – are evaluated and results are documented. | [AIGE-CTL-DEPLOY-009](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009) Fairness monitored by group in production |
| MEASURE 2.13 | Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks |
| MEASURE 3.1 | Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts. | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences |
| MANAGE 1.1 | A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. | [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use; [AIGE-CTL-DEPLOY-004](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004) Go-live decision with conditions as code; [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria |
| MANAGE 1.4 | Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. | [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| MANAGE 2.4 | Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria; [AIGE-CTL-DEPLOY-006](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006) Pinned versions and a tested path back; [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension |
| MANAGE 3.1 | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. | [AIGE-CTL-DEPLOY-006](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006) Pinned versions and a tested path back; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| MANAGE 3.2 | Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. | [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| MANAGE 4.1 | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. | [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store; [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences |
| MANAGE 4.3 | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks |

## OWASP Top 10 for LLM Applications 2026

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#owasp-llm
- Source: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
- Note: Version 2026 (published 3 Aug 2026); ids as the catalogue prints them.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [LLM02:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM02_SensitiveInformationDisclosure.md) | Sensitive Information Disclosure | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| [LLM03:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM03_ExcessiveAgency.md) | Excessive Agency | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary |
| [LLM04:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM04_SupplyChain.md) | Supply Chain | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [LLM05:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM05_DataModelPoisoning.md) | Data and Model Poisoning | [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time; [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity |
| [LLM06:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM06_UnboundedConsumption.md) | Unbounded Consumption | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions |
| [LLM10:2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM10_ImproperOutputHandling.md) | Improper Output Handling | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |

## OWASP Top 10 for Agentic Applications 2026

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#owasp-asi
- Source: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
- Note: Version 2026 (published 9 Dec 2025); ids as the catalogue prints them.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [ASI01](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Agent Goal Hijack | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold |
| [ASI02](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Tool Misuse and Exploitation | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold |
| [ASI03](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Identity and Privilege Abuse | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity; [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28); [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials; [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation |
| [ASI04](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Agentic Supply Chain Vulnerabilities | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models |
| [ASI05](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Unexpected Code Execution (RCE) | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox |
| [ASI06](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Memory & Context Poisoning | [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback |
| [ASI07](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Insecure Inter-Agent Communication | [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary |
| [ASI08](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Cascading Failures | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops; [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs |
| [ASI09](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Human-Agent Trust Exploitation | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed |
| [ASI10](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) | Rogue Agents | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions; [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry; [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker; [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch; [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed; [AIGE-CTL-DEPLOY-013](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013) Shadow AI discovery and registry reconciliation |

## MITRE ATLAS techniques

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#mitre-atlas
- Source: https://atlas.mitre.org/
- Note: Version data release v2026.09 (15 Sep 2026); ids as the catalogue prints them.

| Clause or id | Name | Controls |
| --- | --- | --- |
| AML.M0007 | Sanitize Training Data (mitigation) | [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity |
| AML.M0025 | Maintain AI Dataset Provenance (mitigation) | [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity |
| [AML.T0010](https://atlas.mitre.org/techniques/AML.T0010) | AI Supply Chain Compromise | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load; [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| [AML.T0034](https://atlas.mitre.org/techniques/AML.T0034) | Cost Harvesting | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions |
| AML.T0083 | Credentials from AI Agent Configuration (not yet a row of the threat bridge) | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |
| [AML.T0086](https://atlas.mitre.org/techniques/AML.T0086) | Exfiltration via AI Agent Tool Invocation | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control |
| [AML.T0110](https://atlas.mitre.org/techniques/AML.T0110) | AI Agent Tool Poisoning | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation |

## NIST SP 800-53 Rev. 5

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#nist-sp-800-53
- Source: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- Note: One row per control family; each row names the specific controls cited from it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| AC | AC-3 Access Enforcement; AC-6 Least Privilege | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |
| AU | AU-2 Event Logging; AU-9 Protection of Audit Information; AU-12 Audit Record Generation | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation |
| CM | CM-2 Baseline Configuration; CM-3 Configuration Change Control; CM-6 Configuration Settings | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation |
| IA | IA-5 Authenticator Management | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |
| IR | IR-4 Incident Handling | [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation |
| SA | SA-11 Developer Testing and Evaluation | [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks |
| SC | SC-7 Boundary Protection; SC-7(5) Deny by default, allow by exception | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control |
| SI | SI-4 System Monitoring | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity |

## AIUC-1

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#aiuc1
- Source: https://standard.aiuc-1.com/
- Note: This site is not affiliated with AIUC and holds no AIUC certificate; ids read on AIUC-1's public pages. Each mapping is this project's reading of the requirement text, not AIUC's.

| Clause or id | Name | Controls |
| --- | --- | --- |
| [A006](https://standard.aiuc-1.com/data-and-privacy/prevent-pii-leakage) | Prevent PII leakage (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter |
| [A008](https://standard.aiuc-1.com/data-and-privacy/prevent-secrets-leakage) | Prevent leakage of credentials and secrets (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation; [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter |
| [B006](https://standard.aiuc-1.com/security/enforce-contextual-access-controls) | Prevent unauthorized AI agent actions (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary; [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control; [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-012](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-012) Trajectory anomaly detection; [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox |
| [C002](https://standard.aiuc-1.com/safety/conduct-pre-deployment-testing) | Conduct pre-deployment testing (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-AGENT-013](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-013) Independent trajectory evals; [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold |
| [D003](https://standard.aiuc-1.com/reliability/restrict-unsafe-tool-calls) | Restrict unsafe tool calls (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation; [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default; [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call; [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets; [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed |
| [E004](https://standard.aiuc-1.com/accountability/assign-accountability) | Assign accountability (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-AGENT-028](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-028) Prompts under change control |
| [E008](https://standard.aiuc-1.com/accountability/review-internal-processes) | Review internal processes (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-ASSURE-009](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009) Internal Audit Answered from the Evidence Store |
| [E010](https://standard.aiuc-1.com/accountability/establish-ai-acceptable-use-policy) | Establish AI acceptable use policy (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use |
| [E015](https://standard.aiuc-1.com/accountability/log-model-activity) | Log AI system activity (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity; [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation; [AIGE-CTL-AGENT-004](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-004) Traces; [AIGE-CTL-AGENT-029](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-029) Telemetry on the OpenTelemetry GenAI conventions; [AIGE-CTL-ASSURE-008](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008) Evidence Retention as Code; [AIGE-CTL-DEPLOY-010](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010) Deployer log retention |
| [E016](https://standard.aiuc-1.com/accountability/implement-ai-disclosure-mechanisms) | Implement AI disclosure mechanisms (Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.) | [AIGE-CTL-AGENT-031](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-031) Tell people they are dealing with an AI system |

## EU AI Act

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-eu-ai-act
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| Art. 14(4)(e) | stop procedure | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions |

## IETF RFC 8693

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-ietf-rfc-8693
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| act claim | delegation names the acting party; never impersonation | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |

## ISO/IEC 42001:2023

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-iso-iec-42001-2023
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| 9 | Performance evaluation: one evidence store answering internal audit (clause heading as chapter 22 names it) | [AIGE-CTL-ASSURE-009](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009) Internal Audit Answered from the Evidence Store |
| 9.1 | Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas) | [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record; [AIGE-CTL-ASSURE-006](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006) Control Observations Filed Against Control Ids |

## MCP specification 2026-07-28

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-mcp-specification-2026-07-28
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| Authorization, Token Handling | audience validation; no token passthrough | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |

## MITRE ATLAS mitigation

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-mitre-atlas-mitigation
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| AML.M0013 | Code Signing | [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| AML.M0014 | Verify AI Artifacts | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load |
| AML.M0016 | Vulnerability Scanning | [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models |
| AML.M0023 | AI Bill of Materials | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation; [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build |
| AML.M0024 | AI Telemetry Logging | [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity |
| AML.M0028 | AI Agent Tools Permissions Configuration | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |
| AML.M0029 | Human In-the-Loop for AI Agent Actions | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |
| AML.M0030 | Restrict AI Agent Tool Invocation on Untrusted Data | [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation |
| AML.M0032 | Segmentation of AI Agent Components | [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control |
| AML.M0036 | Limit AI Workload Resource Consumption | [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions |

## NIST SP 800-218A

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-nist-sp-800-218a
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| PS.1.3 | Protect model weights and configuration parameters | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation |
| PS.3.2 | Keep provenance data for every component of a release | [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation |

## SPIFFE

- Anchor: https://aigovernanceengineer.com/controls/crosswalk#other-spiffe
- Note: Named in the controls' other mappings; this site keeps no index of it.

| Clause or id | Name | Controls |
| --- | --- | --- |
| SVID | short-lived workload identity documents | [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation |

## By profile

Each control of a profile with the ids it maps to, framework by framework.

### Evaluation Environment Control Profile

Profile page: https://aigovernanceengineer.com/controls/evaluation-environment

| Control | Ids per framework |
| --- | --- |
| [AIGE-CTL-EVAL-001](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001) Authorization Boundary | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; Singapore Model AI Governance Framework for Agentic AI: AIGE-OBL-SG-AGENTIC-IDENTITY; ISO/IEC 42001:2023 Annex A: A.6.2.2, A.9.2; NIST AI Risk Management Framework (AI RMF 1.0): MAP 4.2; OWASP Top 10 for LLM Applications 2026: LLM03:2026; OWASP Top 10 for Agentic Applications 2026: ASI02, ASI03; NIST SP 800-53 Rev. 5: AC-3, AC-6; AIUC-1: B006 |
| [AIGE-CTL-EVAL-002](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002) Network Egress Control | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; OWASP Top 10 for LLM Applications 2026: AIGE-OBL-OWASP-LLM; ISO/IEC 42001:2023 Annex A: A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.7; OWASP Top 10 for LLM Applications 2026: LLM02:2026; OWASP Top 10 for Agentic Applications 2026: ASI02; MITRE ATLAS techniques: AML.T0086; NIST SP 800-53 Rev. 5: SC-7, SC-7(5); AIUC-1: B006; MITRE ATLAS mitigation: AML.M0032 |
| [AIGE-CTL-EVAL-003](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003) Credential Isolation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; Singapore Model AI Governance Framework for Agentic AI: AIGE-OBL-SG-AGENTIC-IDENTITY; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.9.2; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.7; OWASP Top 10 for Agentic Applications 2026: ASI03; MITRE ATLAS techniques: AML.T0083; NIST SP 800-53 Rev. 5: AC-6, IA-5; AIUC-1: A008; IETF RFC 8693: act claim; MCP specification 2026-07-28: Authorization, Token Handling; SPIFFE: SVID |
| [AIGE-CTL-EVAL-004](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004) Tool and Action Mediation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; OWASP Agent Control Standard (ACS): AIGE-OBL-OWASP-ACS; Singapore Model AI Governance Framework for Agentic AI: AIGE-OBL-SG-AGENTIC-CHECKPOINTS; ISO/IEC 42001:2023 Annex A: A.9.2; NIST AI Risk Management Framework (AI RMF 1.0): MAP 4.2; OWASP Top 10 for LLM Applications 2026: LLM10:2026; OWASP Top 10 for Agentic Applications 2026: ASI01, ASI02, ASI05, ASI09; AIUC-1: B006, D003; MITRE ATLAS mitigation: AML.M0028, AML.M0029, AML.M0030 |
| [AIGE-CTL-EVAL-005](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005) Monitoring Integrity | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12; NIST AI RMF: AIGE-OBL-NISTRMF-MEASURE; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 3.1; OWASP Top 10 for Agentic Applications 2026: ASI10; NIST SP 800-53 Rev. 5: AU-2, AU-9, AU-12, SI-4; AIUC-1: E015; MITRE ATLAS mitigation: AML.M0024 |
| [AIGE-CTL-EVAL-006](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006) Stop Conditions | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; TC260 AI Safety Governance Framework 3.0: AIGE-OBL-CN-TC260-AGENTS; ISO/IEC 42001:2023 Annex A: A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 2.4; OWASP Top 10 for LLM Applications 2026: LLM06:2026; OWASP Top 10 for Agentic Applications 2026: ASI08, ASI10; MITRE ATLAS techniques: AML.T0034; EU AI Act: Art. 14(4)(e); MITRE ATLAS mitigation: AML.M0036 |
| [AIGE-CTL-EVAL-007](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007) Incident Evidence Preservation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART26-6, AIGE-OBL-EUAIA-ART73; GPAI Code of Practice: AIGE-OBL-GPAICOP-SAFETY-C9; ISO/IEC 42001: AIGE-OBL-ISO42001-A8; ISO/IEC 42001:2023 Annex A: A.6.2.8, A.8.4; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 4.3; NIST SP 800-53 Rev. 5: AU-9, IR-4; AIUC-1: E015 |
| [AIGE-CTL-EVAL-008](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008) Harness and Configuration Attestation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; ISO/IEC 42001: AIGE-OBL-ISO42001-A6; OWASP AIBOM: AIGE-OBL-OWASP-AIBOM; ISO/IEC 42001:2023 Annex A: A.6.2.4; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.1; OWASP Top 10 for LLM Applications 2026: LLM04:2026; OWASP Top 10 for Agentic Applications 2026: ASI04; MITRE ATLAS techniques: AML.T0010, AML.T0110; NIST SP 800-53 Rev. 5: CM-2, CM-3, CM-6; MITRE ATLAS mitigation: AML.M0014, AML.M0023; NIST SP 800-218A: PS.1.3, PS.3.2 |
| [AIGE-CTL-EVAL-009](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009) Evaluation Validity Checks | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART9, AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART55; ISO/IEC 42001: AIGE-OBL-ISO42001-A6; NIST AI RMF: AIGE-OBL-NISTRMF-MEASURE; NIST AI 600-1 Generative AI Profile: AIGE-OBL-NIST-AI600-1; ISO/IEC 42001:2023 Annex A: A.6.2.4; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.3, MEASURE 2.13; NIST SP 800-53 Rev. 5: SA-11 |

### Agent Runtime Control Profile

Profile page: https://aigovernanceengineer.com/controls/agent-runtime

| Control | Ids per framework |
| --- | --- |
| [AIGE-CTL-AGENT-001](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001) Registry entry | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART26, AIGE-OBL-EUAIA-ART72; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8; OWASP Top 10 for Agentic Applications 2026: ASI10 |
| [AIGE-CTL-AGENT-002](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002) Its own identity | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5; OWASP Top 10 for Agentic Applications 2026: ASI03 |
| [AIGE-CTL-AGENT-003](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-003) Read-only tools | None yet |
| [AIGE-CTL-AGENT-004](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-004) Traces | AIUC-1: E015 |
| [AIGE-CTL-AGENT-005](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005) Tool allow-list, deny by default | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.9.2; OWASP Top 10 for Agentic Applications 2026: ASI02; AIUC-1: B006, D003 |
| [AIGE-CTL-AGENT-006](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-006) Checkpoint before every write | None yet |
| [AIGE-CTL-AGENT-007](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007) Runtime guardrail on every tool call | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.4, A.6.2.6, A.9.2; OWASP Top 10 for Agentic Applications 2026: ASI01, ASI02; AIUC-1: D003 |
| [AIGE-CTL-AGENT-008](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008) Execution budgets | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6; OWASP Top 10 for Agentic Applications 2026: ASI08; AIUC-1: D003 |
| [AIGE-CTL-AGENT-009](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009) Approval log, bound to the call | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART13, AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART50; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.8.2, A.9.2; OWASP Top 10 for Agentic Applications 2026: ASI09 |
| [AIGE-CTL-AGENT-010](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010) Per-agent circuit breaker | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART26, AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 2.4; OWASP Top 10 for Agentic Applications 2026: ASI08, ASI10 |
| [AIGE-CTL-AGENT-011](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011) Drilled kill switch | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART26, AIGE-OBL-EUAIA-ART72; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 2.4; OWASP Top 10 for Agentic Applications 2026: ASI10 |
| [AIGE-CTL-AGENT-012](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-012) Trajectory anomaly detection | AIUC-1: B006 |
| [AIGE-CTL-AGENT-013](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-013) Independent trajectory evals | AIUC-1: C002 |
| [AIGE-CTL-AGENT-014](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-014) Reversible, bounded actions only | None yet |
| [AIGE-CTL-AGENT-015](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015) Checkpoints on irreversible actions, failing closed | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART13, AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART50; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.8.2, A.9.2; OWASP Top 10 for Agentic Applications 2026: ASI02, ASI09; AIUC-1: D003 |
| [AIGE-CTL-AGENT-016](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016) Code runs only in a sandbox | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ETSI EN 304 223: AIGE-OBL-ETSI-304223; ISO/IEC 42001:2023 Annex A: A.6.2.5, A.6.2.6; OWASP Top 10 for Agentic Applications 2026: ASI05; AIUC-1: B006 |
| [AIGE-CTL-AGENT-017](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017) Output and egress filter | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.9.2; OWASP Top 10 for Agentic Applications 2026: ASI02; AIUC-1: A006, A008 |
| [AIGE-CTL-AGENT-018](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018) MCP server admission gate | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART25; ISO/IEC 42001: AIGE-OBL-ISO42001-A10; OWASP AIBOM: AIGE-OBL-OWASP-AIBOM; ISO/IEC 42001:2023 Annex A: A.7.5, A.10.3; OWASP Top 10 for Agentic Applications 2026: ASI04 |
| [AIGE-CTL-AGENT-019](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019) Local MCP servers sandboxed | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART25, AIGE-OBL-EUAIA-ART26, AIGE-OBL-EUAIA-ART72; ISO/IEC 42001: AIGE-OBL-ISO42001-A10; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; OWASP AIBOM: AIGE-OBL-OWASP-AIBOM; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8, A.7.5, A.10.3; OWASP Top 10 for Agentic Applications 2026: ASI04, ASI10 |
| [AIGE-CTL-AGENT-020](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020) MCP authorisation (spec 2026-07-28) | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5; OWASP Top 10 for Agentic Applications 2026: ASI03 |
| [AIGE-CTL-AGENT-021](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021) Replace long-lived secrets with short-lived credentials | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5; OWASP Top 10 for Agentic Applications 2026: ASI03 |
| [AIGE-CTL-AGENT-022](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022) Delegation, never impersonation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5; OWASP Top 10 for Agentic Applications 2026: ASI03 |
| [AIGE-CTL-AGENT-023](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023) Memory write gate and rollback | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART15; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.6, A.6.2.8; OWASP Top 10 for Agentic Applications 2026: ASI06 |
| [AIGE-CTL-AGENT-024](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-024) Retention and erasure for personal data in memory | None yet |
| [AIGE-CTL-AGENT-025](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025) Accountability across hops | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5, A.6.2.6; OWASP Top 10 for Agentic Applications 2026: ASI07, ASI08 |
| [AIGE-CTL-AGENT-026](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026) Stopping third-party agents at your boundary | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; NIST AI Agent Standards Initiative: AIGE-OBL-NIST-AGENTS; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM-AGENTIC; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.5; OWASP Top 10 for Agentic Applications 2026: ASI07 |
| [AIGE-CTL-AGENT-027](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-027) Data classes recorded, with the DPIA linked | None yet |
| [AIGE-CTL-AGENT-028](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-028) Prompts under change control | AIUC-1: E004 |
| [AIGE-CTL-AGENT-029](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-029) Telemetry on the OpenTelemetry GenAI conventions | AIUC-1: E015 |
| [AIGE-CTL-AGENT-030](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-030) EU AI Act hooks for a high-risk purpose | None yet |
| [AIGE-CTL-AGENT-031](https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-031) Tell people they are dealing with an AI system | AIUC-1: E016 |

### Data Admission and Privacy Control Profile

Profile page: https://aigovernanceengineer.com/controls/data-admission-and-privacy

| Control | Ids per framework |
| --- | --- |
| [AIGE-CTL-DATA-001](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001) Dataset Admission Gate at Read Time | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10; General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART5-1B; ISO/IEC 42001: AIGE-OBL-ISO42001-A7; ISO/IEC 42001:2023 Annex A: A.7.2, A.7.4, A.7.5; NIST AI Risk Management Framework (AI RMF 1.0): MAP 2.3, MAP 4.1; OWASP Top 10 for LLM Applications 2026: LLM05:2026 |
| [AIGE-CTL-DATA-002](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002) Dataset Card for Every Admitted Version | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10; ISO/IEC 42001: AIGE-OBL-ISO42001-A7; ISO/IEC 42001:2023 Annex A: A.7.2, A.7.5; NIST AI Risk Management Framework (AI RMF 1.0): MAP 2.3 |
| [AIGE-CTL-DATA-003](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003) Training-Data Rights Ledger Row per Source | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10, AIGE-OBL-EUAIA-ART53-1C; General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART5-1B; Directive (EU) 2019/790 on copyright in the Digital Single Market: AIGE-OBL-DSM-ART4-3; ISO/IEC 42001:2023 Annex A: A.7.5; NIST AI Risk Management Framework (AI RMF 1.0): GOVERN 6.1, MAP 4.1 |
| [AIGE-CTL-DATA-004](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-004) Lawful Basis and Assessment per Processing Stage | General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART6, AIGE-OBL-GDPR-ART35-36; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.10 |
| [AIGE-CTL-DATA-005](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-005) Purpose Match Before Reuse of Data | General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART5-1B |
| [AIGE-CTL-DATA-006](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-006) Personal Data Screening and Minimisation | General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART25 |
| [AIGE-CTL-DATA-007](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-007) Special-Category Data Conditions | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART4A; General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART9, AIGE-OBL-GDPR-ART30 |
| [AIGE-CTL-DATA-008](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008) Fitness-for-Purpose Checks Before Admission | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10; ISO/IEC 42001: AIGE-OBL-ISO42001-A7; ISO/IEC 42001:2023 Annex A: A.7.4; NIST AI Risk Management Framework (AI RMF 1.0): MAP 2.3 |
| [AIGE-CTL-DATA-009](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009) Signed Snapshot Integrity | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10; OWASP Top 10 for LLM Applications 2026: AIGE-OBL-OWASP-LLM; ISO/IEC 42001:2023 Annex A: A.7.5; OWASP Top 10 for LLM Applications 2026: LLM05:2026; MITRE ATLAS techniques: AML.M0007, AML.M0025 |
| [AIGE-CTL-DATA-010](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010) Lineage from Training Runs to Admitted Sources | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART10; ISO/IEC 42001: AIGE-OBL-ISO42001-A7; ISO/IEC 42001:2023 Annex A: A.7.5 |
| [AIGE-CTL-DATA-011](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011) Rights Changes Propagated to Affected Models | General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART7, AIGE-OBL-GDPR-ART15-17-21; Directive (EU) 2019/790 on copyright in the Digital Single Market: AIGE-OBL-DSM-ART4-3 |
| [AIGE-CTL-DATA-012](https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012) Registered Downstream Consumers of Outputs | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART9, AIGE-OBL-EUAIA-ART25, AIGE-OBL-EUAIA-ART50; ISO/IEC 42001: AIGE-OBL-ISO42001-A8, AIGE-OBL-ISO42001-A9; ISO/IEC 42001:2023 Annex A: A.8.2, A.9.4; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 1.4, MAP 1.1, MAP 3.3; OWASP Top 10 for LLM Applications 2026: LLM10:2026; OWASP Top 10 for Agentic Applications 2026: ASI08 |

### Assurance and Evidence Control Profile

Profile page: https://aigovernanceengineer.com/controls/assurance-and-evidence

| Control | Ids per framework |
| --- | --- |
| [AIGE-CTL-ASSURE-001](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001) Test Plan Frozen Before Evaluation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART9; ISO/IEC 42001: AIGE-OBL-ISO42001-A6; NIST AI RMF: AIGE-OBL-NISTRMF-MEASURE; ISO/IEC 42001:2023 Annex A: A.6.2.4; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.1 |
| [AIGE-CTL-ASSURE-002](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002) Release Blocked Below the Eval Threshold | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART55; NIST AI RMF: AIGE-OBL-NISTRMF-MEASURE; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; ISO/IEC 42001:2023 Annex A: A.6.2.4; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.3; OWASP Top 10 for Agentic Applications 2026: ASI01, ASI02; AIUC-1: C002 |
| [AIGE-CTL-ASSURE-003](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003) Signed Test Report Against the Plan | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART9, AIGE-OBL-EUAIA-ART11; ISO/IEC 42001: AIGE-OBL-ISO42001-A6; NIST AI RMF: AIGE-OBL-NISTRMF-MEASURE; ISO/IEC 42001:2023 Annex A: A.6.2.4; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.3 |
| [AIGE-CTL-ASSURE-004](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004) Common Signed Evidence Record | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART17, AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; ISO/IEC 42001:2023: 9.1 |
| [AIGE-CTL-ASSURE-005](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005) Live Control Status from the Assurance Store | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-GOVERN, AIGE-OBL-NISTRMF-MANAGE; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 4.1 |
| [AIGE-CTL-ASSURE-006](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006) Control Observations Filed Against Control Ids | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART17; ISO/IEC 42001:2023: 9.1 |
| [AIGE-CTL-ASSURE-007](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007) Machine-Readable Evidence in OSCAL | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART17, AIGE-OBL-EUAIA-ART72; NIST AI RMF: AIGE-OBL-NISTRMF-GOVERN, AIGE-OBL-NISTRMF-MANAGE |
| [AIGE-CTL-ASSURE-008](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008) Evidence Retention as Code | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART12, AIGE-OBL-EUAIA-ART18, AIGE-OBL-EUAIA-ART19; AIUC-1: E015 |
| [AIGE-CTL-ASSURE-009](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009) Internal Audit Answered from the Evidence Store | AIUC-1: E008; ISO/IEC 42001:2023: 9 |
| [AIGE-CTL-ASSURE-010](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010) Model Artefacts Signed at Build and Verified Before Load | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15, AIGE-OBL-EUAIA-ART55; ISO/IEC 42001: AIGE-OBL-ISO42001-A6, AIGE-OBL-ISO42001-A10; NIST AI RMF: AIGE-OBL-NISTRMF-MANAGE; OWASP Top 10 for Agentic Applications 2026: AIGE-OBL-OWASP-AGENTIC; OWASP Top 10 for LLM Applications 2026: AIGE-OBL-OWASP-LLM; ISO/IEC 42001:2023 Annex A: A.6.2.5, A.10.3; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 3.2, MEASURE 2.7; OWASP Top 10 for LLM Applications 2026: LLM04:2026; OWASP Top 10 for Agentic Applications 2026: ASI04; MITRE ATLAS techniques: AML.T0010; MITRE ATLAS mitigation: AML.M0013, AML.M0014 |
| [AIGE-CTL-ASSURE-011](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011) Safe Model Formats and Digest-Pinned Third-Party Models | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART15; ISO/IEC 42001: AIGE-OBL-ISO42001-A10; OWASP Top 10 for LLM Applications 2026: AIGE-OBL-OWASP-LLM; ISO/IEC 42001:2023 Annex A: A.10.3; OWASP Top 10 for LLM Applications 2026: LLM04:2026; OWASP Top 10 for Agentic Applications 2026: ASI04; MITRE ATLAS techniques: AML.T0010; MITRE ATLAS mitigation: AML.M0016 |
| [AIGE-CTL-ASSURE-012](https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012) AI Bill of Materials per Build | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART11, AIGE-OBL-EUAIA-ART53; NIST AI RMF: AIGE-OBL-NISTRMF-MAP; CSA AI Controls Matrix (AICM) v1.1: AIGE-OBL-CSA-AICM; OWASP AIBOM: AIGE-OBL-OWASP-AIBOM; ISO/IEC 42001:2023 Annex A: A.7.5, A.10.3; OWASP Top 10 for LLM Applications 2026: LLM04:2026; MITRE ATLAS techniques: AML.T0010; MITRE ATLAS mitigation: AML.M0023 |

### Deployment and Monitoring Control Profile

Profile page: https://aigovernanceengineer.com/controls/deployment-and-monitoring

| Control | Ids per framework |
| --- | --- |
| [AIGE-CTL-DEPLOY-001](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001) Deployment decision record before use | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART26; ISO/IEC 42001:2023 Annex A: A.6.2.5, A.9.4; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 1.1, MAP 1.1 |
| [AIGE-CTL-DEPLOY-002](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002) Instructions for use held and followed | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART13, AIGE-OBL-EUAIA-ART26; ISO/IEC 42001:2023 Annex A: A.8.2 |
| [AIGE-CTL-DEPLOY-003](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003) Oversight by trained people with authority to stop | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART4, AIGE-OBL-EUAIA-ART14, AIGE-OBL-EUAIA-ART26-2; ISO/IEC 42001:2023 Annex A: A.9.2; NIST AI Risk Management Framework (AI RMF 1.0): MAP 3.5 |
| [AIGE-CTL-DEPLOY-004](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004) Go-live decision with conditions as code | ISO/IEC 42001:2023 Annex A: A.6.2.5; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 1.1 |
| [AIGE-CTL-DEPLOY-005](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005) Staged rollout with pre-registered rollback criteria | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART26-5; ISO/IEC 42001:2023 Annex A: A.6.2.5, A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 1.1, MANAGE 2.4, MEASURE 2.3 |
| [AIGE-CTL-DEPLOY-006](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006) Pinned versions and a tested path back | ISO/IEC 42001:2023 Annex A: A.6.2.5; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 2.4, MANAGE 3.1 |
| [AIGE-CTL-DEPLOY-007](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-007) Re-assessment when a change goes beyond what was foreseen | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART25 |
| [AIGE-CTL-DEPLOY-008](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008) Monitoring plan with thresholds, owners and consequences | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART9, AIGE-OBL-EUAIA-ART26-5, AIGE-OBL-EUAIA-ART72; ISO/IEC 42001:2023 Annex A: A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 4.1, MEASURE 2.4, MEASURE 3.1 |
| [AIGE-CTL-DEPLOY-009](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009) Fairness monitored by group in production | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART4A, AIGE-OBL-EUAIA-ART15-4; ISO/IEC 42001:2023 Annex A: A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MEASURE 2.11 |
| [AIGE-CTL-DEPLOY-010](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010) Deployer log retention | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART26-6; ISO/IEC 42001:2023 Annex A: A.6.2.8; AIUC-1: E015 |
| [AIGE-CTL-DEPLOY-011](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011) Serious incident reporting clocks | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART26-5, AIGE-OBL-EUAIA-ART73; General Data Protection Regulation (EU) 2016/679: AIGE-OBL-GDPR-ART33-34; ISO/IEC 42001:2023 Annex A: A.8.4; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 4.3 |
| [AIGE-CTL-DEPLOY-012](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012) Deactivation triggers, degraded modes and suspension | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART5, AIGE-OBL-EUAIA-ART20, AIGE-OBL-EUAIA-ART26-5; ISO/IEC 42001:2023 Annex A: A.6.2.6; NIST AI Risk Management Framework (AI RMF 1.0): MANAGE 2.4 |
| [AIGE-CTL-DEPLOY-013](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013) Shadow AI discovery and registry reconciliation | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART49-71; NIST AI Risk Management Framework (AI RMF 1.0): GOVERN 1.6; OWASP Top 10 for Agentic Applications 2026: ASI10 |
| [AIGE-CTL-DEPLOY-014](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014) Sanctioned AI gateway for staff use | EU AI Act (post-Omnibus): AIGE-OBL-EUAIA-ART4; ISO/IEC 42001:2023 Annex A: A.9.2, A.10.3; NIST AI Risk Management Framework (AI RMF 1.0): GOVERN 2.2, GOVERN 6.1, MANAGE 3.1; OWASP Top 10 for LLM Applications 2026: LLM02:2026; AIUC-1: E010 |
| [AIGE-CTL-DEPLOY-015](https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-015) Retirement runbook with access and data removal | NIST AI Risk Management Framework (AI RMF 1.0): GOVERN 1.7 |

## Machine-readable

- The crosswalk as JSON: the `crosswalk` key of https://aigovernanceengineer.com/api/v1/controls.json (schema: https://aigovernanceengineer.com/api/v1/schemas/controls.json)
- Page: https://aigovernanceengineer.com/controls/crosswalk

## Propose a mapping

Propose or correct a mapping through the framework mapping form: https://github.com/losanchos5/aige/issues/new?template=framework-mapping.yml
