Governance requirements

Agent governance requirements

Future tenants will arrive through different standards universes, but the control objective is remarkably consistent: an agent should not turn its own proposal into authority. Its actions need accountable ownership, bounded access, human intervention where appropriate, and evidence that can be inspected after the event.

This is a practical control mapping, not legal advice, a certification claim or a statement that Agent Control Room makes an organisation compliant. Applicability depends on your role, use case, risk classification and wider control environment.

Read the implementation boundary on Security and the complete decision lifecycle on How it works.

Scope

Five frameworks, one control problem

The frameworks have different legal and assurance roles. The mapping below uses their current published editions and keeps those differences explicit.

EU AI Act

European Union law

The mapping focuses on high-risk-system risk management, records, transparency and human oversight, plus deployer duties. Whether the Act applies — and whether an organisation is a provider or deployer — requires a separate legal classification.

Current consolidated Regulation (EU) 2024/1689 (opens in a new tab)

ISO/IEC 42001:2023

Certifiable AI management-system standard

Covers an organisation-wide AI management system: policy, responsibilities, risk and impact processes, lifecycle controls, operation, monitoring, suppliers and continual improvement.

ISO overview of ISO/IEC 42001 (opens in a new tab)

NIST AI RMF 1.0

Voluntary, use-case-agnostic framework

Organises AI risk work into Govern, Map, Measure and Manage. It is not a checklist, and NIST is currently revising version 1.0; the references here identify relevant outcomes rather than claim conformance.

NIST AI RMF Core (opens in a new tab)

ISO/IEC 27001:2022

Certifiable information-security management-system standard

Provides the security-management foundation around governed agents, including access, identity, logging, monitoring, cryptography, cloud services, suppliers and incident management.

ISO overview of ISO/IEC 27001 (opens in a new tab)

SOC 2 Trust Services Criteria

Assurance criteria used in CPA examinations

This page concentrates on CC6 logical access and CC7 system operations and monitoring. These are criteria for evaluating controls, not a product certification that a feature can confer.

AICPA Trust Services Criteria (opens in a new tab)

Control map

The requirements, mapped to execution

Rather than repeat the same product feature under five headings, the sections below group the recurring requirements. Each separates the framework expectation, the contribution Agent Control Room can make, and the work the customer still owns.

01 · Accountability

Governance, ownership and AI-system inventory

  • ISO/IEC 42001: clauses 5–6 and Annex A.2–A.4
  • NIST AI RMF: GOVERN 1–4, including GOVERN 1.6 inventory
  • EU AI Act: Articles 9 and 26
  • ISO/IEC 27001: organisational controls in Annex A.5

What the frameworks expect

Organisations need defined accountability, policies and roles, an inventory of relevant AI systems, and a risk-based process for deciding how those systems may be used.

Agent Control Room contributes

  • A workspace declares its agents, their owners, the actions they may request, and the policies that govern those actions.
  • Member, workspace-administrator and platform-administrator roles are distinct and checked on the server.
  • Machine-readable system records and dated evidence exports can feed an AI inventory, CMDB or assurance review.

The customer retains

  • Define the AI policy, risk appetite, accountable executives, system classification and wider inventory.
  • Decide which agent actions must be governed and ensure every relevant execution path actually asks Agent Control Room before acting.

02 · Risk control

Risk-based control of agent actions

  • EU AI Act: Article 9 risk management
  • ISO/IEC 42001: clauses 6 and 8; Annex A.6 and A.9
  • NIST AI RMF: GOVERN 1, MAP 1–3 and MANAGE 1–2
  • SOC 2: CC3 risk assessment and CC5 control activities (adjacent to CC6–CC7)

What the frameworks expect

Risk decisions should be translated into repeatable controls appropriate to the purpose and context of the system, with unsafe or unsupported conditions handled deliberately.

Agent Control Room contributes

  • Ordered rules return only allow, refuse or ask a person first. A workspace with no saved rules refuses every request.
  • Each action can define a typed context contract. Missing, malformed, stale or disallowed required context is Not decided before a rule runs; it never falls through to permission.
  • Unknown actions and unregistered agents are refused, and local rules remain the authority even when an optional external reading is used.

The customer retains

  • Perform the risk and impact assessments, set acceptance criteria, write and review the rules, and test them against foreseeable misuse.
  • Govern model quality, bias, robustness, safety and system-level behaviour outside the action-enforcement layer.

03 · Human oversight

Meaningful intervention before an action

  • EU AI Act: Article 14 human oversight and Article 26(2) deployer oversight
  • ISO/IEC 42001: Annex A.3 roles and A.9 responsible use
  • NIST AI RMF: GOVERN 3 and MANAGE 2

What the frameworks expect

People assigned to oversight need authority, competence and a practical means to understand, intervene in or stop relevant operation rather than merely review it afterwards.

Agent Control Room contributes

  • Ask a person first creates an approval record before any grant exists. The caller must wait and later claim the approved decision for the identical step.
  • A rule can prevent an agent's registered owner from approving that agent's work; blocked attempts are enforced on the server and audited.
  • Approval, claim and grant windows expire. Administrators can refuse requests, revoke access and pause the entire workspace at the next governed step.

The customer retains

  • Choose the actions and thresholds that require a person, appoint competent and sufficiently independent reviewers, and give them time and information to challenge the step.
  • Provide any stop or rollback mechanism needed after work has already executed outside Agent Control Room.

04 · Access

Identity, least privilege and segregation

  • ISO/IEC 27001 Annex A: 5.15–5.18 and 8.2–8.5
  • SOC 2: CC6.1–CC6.3 and CC6.6–CC6.7
  • ISO/IEC 42001: Annex A.3 and A.4

What the frameworks expect

Human and machine identities should be authenticated, authorised to the minimum necessary scope, isolated from other tenants, and removable when access is no longer justified.

Agent Control Room contributes

  • Each request resolves to one workspace before data is read; membership and workspace scope are enforced again at the data layer.
  • Human sessions and machine API credentials are separate. Keys are workspace-bound, scope-limited, optionally network-restricted and stored only as hashes.
  • Domain and SSO enforcement, idle and absolute session limits, revocation, and edge-verified network allow-lists support the access boundary.

The customer retains

  • Operate joiner, mover, leaver and periodic access-review processes; configure the identity provider, MFA and conditional-access controls.
  • Keep policy-decision keys in trusted server-side enforcement services — never in an agent, model prompt or browser.

05 · Evidence

Traceability, records and understandable decisions

  • EU AI Act: Articles 12, 13, 19 and 26(6)
  • ISO/IEC 42001: clauses 7.5, 9 and Annex A.8
  • NIST AI RMF: GOVERN 1.4, MEASURE 2 and MANAGE 4
  • ISO/IEC 27001: A.8.15 logging and A.8.16 monitoring
  • SOC 2: CC7.2–CC7.5

What the frameworks expect

Relevant operation should be recorded so authorised reviewers can understand what happened, monitor controls, investigate anomalies and demonstrate that oversight operated as designed.

Agent Control Room contributes

  • Decision evidence preserves the agent, action, resource reference, payload fingerprint, outcome, rule, context validation, provenance, timing and any approval lifecycle.
  • A separate workspace audit trail records security, configuration, policy and governance activity; administrators can inspect recent decisions and export bounded evidence.
  • Detailed evidence can live in a workspace-specific bucket, including customer-owned Google Cloud, while the operational database keeps only the control records it needs.

The customer retains

  • Set legal and contractual retention periods, protect and review exported records, connect them to incident and assurance processes, and maintain the rest of the AI system's logs.
  • Provide transparency to end users or affected persons where required; ACR explains its decision layer, not the underlying model or customer service.

06 · Operations

Monitoring, limits and response

  • NIST AI RMF: MEASURE 2–4 and MANAGE 1–4
  • ISO/IEC 42001: clauses 8–10 and Annex A.6
  • ISO/IEC 27001: A.5.24–5.28 and A.8.15–8.16
  • SOC 2: CC7 system operations

What the frameworks expect

Controls should be monitored, deviations investigated and risks treated throughout operation, with evidence supporting incident response, correction and continual improvement.

Agent Control Room contributes

  • Per-agent, per-action rate windows and cooldowns are claimed atomically when a grant is issued; concurrent requests cannot each pass a stale counter.
  • Refusal, expiry, revocation, approval activity and safe retries remain visible in decision and audit records.
  • The security-posture export and system records expose the enforcement layer for periodic review and change tracking.

The customer retains

  • Operate active alerting, anomaly detection, incident classification, communications, recovery exercises and continual-improvement governance.
  • Measure the underlying model and complete agent system for accuracy, bias, robustness, drift and harmful impacts; ACR does not perform those evaluations.

07 · Trusted context

Declared facts, provenance and transparency

  • EU AI Act: Article 13 transparency to deployers
  • ISO/IEC 42001: Annex A.7 data and A.8 information for interested parties
  • NIST AI RMF: MAP 1–3 and MEASURE 2

What the frameworks expect

Operators need enough information about purpose, inputs, limits and expected use to apply controls correctly and judge whether the evidence supporting an action is suitable.

Agent Control Room contributes

  • The workspace publishes its exact action vocabulary, payload-binding notes and context expectations for integrators to read rather than guess.
  • A context fact can require an approved asserter and a recent observation time. The decision record shows whether those declared checks passed.
  • The payload itself stays in the supervised application; ACR receives a one-way fingerprint and the context facts deliberately supplied for the decision.

The customer retains

  • Derive facts from authoritative systems and decide which values are suitable to send. assertedBy and observedAt are caller claims: ACR checks them against the contract but does not authenticate the source or prove the event occurred.
  • Maintain instructions, limitations and user-facing disclosures for the complete AI system.

08 · Third parties

External policy evidence remains subordinate

  • ISO/IEC 42001: Annex A.10 third-party and customer relationships
  • ISO/IEC 27001: A.5.19–5.23 supplier and cloud-service controls
  • NIST AI RMF: GOVERN 6 third-party risks

What the frameworks expect

Third-party services, dependencies and evidence should be governed without transferring accountability or silently weakening the organisation's own controls.

Agent Control Room contributes

  • The optional ACR–Complyee pairing records a Policy Library reading as advisory evidence or applies it as a restrictive gate to a step local rules already allowed.
  • A Complyee reading can preserve, hold or refuse that local allow. It cannot create permission, loosen a refusal or replace a required human decision.
  • A missing or inconclusive gate reading fails closed according to the workspace's configured choice: ask a person first or refuse.

The customer retains

  • Assess Complyee as the customer's own provider, configure the pairing and actions deliberately, and govern the context and plain-language action description eligible for consultation.
  • Maintain an operational pairing wherever gated actions depend on it and review the recorded reading as evidence, not independent verification of caller-supplied facts.

Execution safeguards

Where the enforcement pattern goes further

Most frameworks state control outcomes rather than prescribing one software design. Agent Control Room adds a set of execution-level safeguards that are more specific than many baseline formulations.

One step, one decision

A grant covers one registered agent, one declared action and one exact payload fingerprint. It is not a general permission for a workflow or session.

Authority outside the model

The model can propose work but cannot issue, approve or verify the grant that permits execution.

Payload-bound grants

Signed grants are short-lived and bound to the payload fingerprint. Approval grants are single-use; changed work needs a new decision.

Fail-closed context

An undeclared action, unknown agent or incomplete enforced context cannot inherit a broad default allow.

Stateful controls made explicit

Approval state, idempotency, revocation, rate windows and cooldown claims are recorded around deterministic rule evaluation rather than hidden inside model behaviour.

Downgrade-only external gate

Optional Complyee evidence can support, hold or refuse a locally allowed step. It can never become a second source of permission.

Application

How to use this mapping

Treat the page as a starting point for a control owner, security reviewer or auditor — not as a completed assessment.

  1. 01Identify the framework, legal role and system boundary that apply to the use case.
  2. 02Select the agent actions whose consequences justify an external decision before execution.
  3. 03Map the customer's organisational, model, data and incident controls around ACR's enforcement controls.
  4. 04Test the complete path — including refusal, missing context, human hold, expiry and unavailable dependencies — before relying on it.
  5. 05Retain and review the resulting evidence under the customer's own assurance and records policy.

Discuss your control mapping

We can walk your governance, security or audit team through the decision path and the evidence it produces. Your advisers remain responsible for deciding which obligations apply and whether the complete system meets them. Write to hello@agent-cr.com.