Resources · Reading list
The sources that formed the discipline.
A working bibliography, not a canon. 35 sources across 6 themes, each annotated in one line, each with a verified URL and a verification tag drawn from the book's research digest.
Verification tags: primary — the source itself; secondary — a reliable account of it; reported — awaiting a primary confirmation.
- 01
Foundational texts (the form and the method)
- GRC Engineering Manifesto verified: primary
the parent discipline's founding statement; the structural and philosophical model for this book
- "What is GRC Engineering" (Ayoub Fandi) verified: primary
the clearest definition of the parent method and the source of the "green dashboard over a broken control is theatre" test
- The Agile Manifesto verified: primary
the "X over Y" value grammar and the signatory model this book borrows
- The Twelve-Factor App verified: primary
the template for a numbered, practitioner-facing body of practice with a "who should read this" framing
- CSIRO Responsible AI Pattern Catalogue verified: primary
the pattern template (chapter 05) and proof that responsible-AI practice can be written as reusable patterns
- privacypatterns.org verified: primary
the precedent for translating a legal principle (privacy by design) into engineering patterns under CC BY
-
- 02
Regulation and standards
- EU AI Act + Digital Omnibus explorer verified: primary
the consolidated, navigable text of the Act as amended; the primary obligation source for chapter 08
- GPAI Code of Practice verified: primary
the Commission's code for general-purpose AI, including the safety and security chapter that requires model evaluations
- "ISO/IEC 42001 and the AI Act: why certification is not yet a presumption of conformity" verified: secondary
the key relationship between the AIMS standard (and 42005/42006) and the Act
- JTC 21 harmonised-standards tracker verified: secondary
the live status of the European standards that would grant a presumption of conformity; as of the book's date, none is OJ-cited
- NIST AI Risk Management Framework 1.0 verified: primary
the Govern/Map/Measure/Manage functions used as a mapping target throughout
-
the emerging reference for non-human identity, the precondition of agent governance
- NIST CAISI AI Agent Standards Initiative verified: primary
the effort to make agent interoperability and security standard, not per-vendor
- OWASP GenAI Security Project verified: primary
the home of the Top 10 for LLM Applications, the Top 10 for Agentic Applications, the AIBOM project and the AI Maturity Assessment
- CSA AI Controls Matrix and STAR for AI verified: primary
the control framework and assurance programme mapped to ISO 42001 and NIST AI RMF (chapters 07-08)
- MITRE ATLAS verified: primary
the adversarial tactics-and-techniques knowledge base for AI, including agent techniques, that threat models draw on
- NSA CSI, "MCP: Security Design Considerations" verified: primary
government guidance on securing the Model Context Protocol that connects agents to tools
- "California's SB 53: the first frontier-AI law explained" (FPF) verified: secondary
the clearest read on SB 53 and, in the same source family, New York's RAISE Act
-
- 03
Papers (machine-readable evidence and agent governance)
- "Making AI Compliance Evidence Machine-Readable" (arXiv 2604.13767) verified: primary
extends OSCAL for AI and argues frameworks specify *what* to assure but no executable *how*
- "Audit-as-code" (Frontiers in AI) verified: primary
an assured-readiness score with proceed/remediate/block gates; audit output as a build artefact
- Policy Cards (arXiv 2510.24383) verified: primary
JSON-schema, machine-readable runtime governance artefacts for agents
- TAIP (arXiv 2603.03340) verified: primary
treats NIST TEVV outputs as AI assurance objects
- AI Trust OS (arXiv 2604.04749) verified: primary
an operating-system framing for continuous AI trust and assurance
- AAGATE (arXiv 2510.25863) verified: primary
a NIST AI RMF-aligned agent governance platform design
-
- 04
Reports (the market and the profession)
- IAPP AI Governance Profession Report 2025 (with Credo AI) verified: primary
where the function sits and how it is staffed; the profession's baseline census
- IAPP Salary & Jobs Report 2025-26 verified: primary
the salary bands that anchor chapter 06, including the technical-AI-governance premium
- IAPP AI Governance Vendor Report 2026 verified: primary
the four vendor categories and the claim that AI governance "is not a single function, discipline or technology"
- State of GRC 2026 verified: primary
the practitioner survey behind the "spreadsheet is still the #1 GRC tool" reality the discipline reacts against
- Gartner Magic Quadrant for AI Governance Platforms 2026 (via IBM) verified: secondary
the first MQ for the category and its inclusion criteria (discovery, registry, policy, evidence)
- HiddenLayer Threat Report 2026 verified: reported
the source of the reported "~1 in 8 AI breaches involve autonomous agents" figure; read as reported
-
- 05
Tools (illustrative categories, not endorsements)
- Inspect AI (UK AI Security Institute) verified: primary
an open eval framework, the reference example for evals-as-evidence and eval gates
- awesome-ai-agent-governance verified: primary
a curated index that catalogues the tool categories this book names — eval frameworks (promptfoo, DeepEval, Ragas, Giskard, Garak), policy engines (OPA/Rego, Cedar), guardrails (NeMo Guardrails, Guardrails AI, LlamaFirewall), observability (Langfuse, Arize Phoenix) and AIBOM formats (CycloneDX ML-BOM, SPDX 3.0)
-
- 06
Communities and newsletters
- GRC Engineer (grcengineer.com) verified: primary
the parent community's hub; the analyst-vs-engineer framing and the role definitions this book adapts
- blog.grc.engineering, "GRC Engineering in 2026" (Justin Pagano) verified: primary
the forward view: policy-as- code guardrails in CI/CD, trust operations centres, agentic extensions
- IAPP (iapp.org) verified: primary
the professional body whose reports, certifications and events map the AI governance profession
-