A regulator's crosswalk: every control, the clause it evidences
27 rows, four standard columns, one clause id per cell. Built for scanning down the column of the instrument you actually enforce.
Published · updated · by Julian Joseph, founder
Get an Agent Trust Gap BriefWhat is this crosswalk for?
A one-row-per-control reference mapping each of the 27 deterministic agent governance controls to the exact clause of OWASP ASI, NIST AI RMF, ISO/IEC 42001, or the EU AI Act it produces file-and-line evidence for.
Why separate columns per standard instead of one combined reference list?
Because a regulator scans for their own instrument. Separating OWASP, NIST, ISO and the EU AI Act into their own columns lets a reader check only the column relevant to the jurisdiction or framework they enforce, without the other three.
How many of the 27 controls cite each standard?
Of 27 controls, OWASP ASI is cited 12 times, NIST AI RMF 19, ISO/IEC 42001 14, and the EU AI Act 9 — most controls cite two or three standards, so these overlap rather than sum to 27.
Which controls have no EU AI Act reference at all?
Eighteen of the 27 controls cite no EU AI Act article — all three Identity & Credentials controls and three of Isolation & Blast Radius's four — because those clauses map more precisely to OWASP's list or ISO's management clauses.
Every control, one row, its exact clause per standard
| Control | Family | Weight | OWASP ASI | NIST AI RMF | ISO/IEC 42001 | EU AI Act |
|---|---|---|---|---|---|---|
id.no_secrets | Agent Identity & Credentials | 6 | OWASP ASI05 | NIST GOVERN-1 | ISO 42001 A.8 | — |
id.env_config | Agent Identity & Credentials | 4 | — | NIST GOVERN-1 | ISO 42001 A.8 | — |
id.distinct_principal | Agent Identity & Credentials | 4 | OWASP ASI06 | NIST MANAGE-2 | — | — |
au.deny_default | Authority & Permission Gates | 7 | OWASP ASI02 | NIST MANAGE-1 | ISO 42001 A.6 | — |
au.explicit_gate | Authority & Permission Gates | 6 | OWASP ASI02 | — | — | EU AI Act Art.14 |
au.bounded_grant | Authority & Permission Gates | 4 | OWASP ASI02 | NIST MANAGE-1 | — | — |
au.budget | Authority & Permission Gates | 3 | OWASP ASI08 | NIST MEASURE-2 | — | — |
is.sandbox | Isolation & Blast Radius | 5 | OWASP ASI06 | — | ISO 42001 A.6 | — |
is.egress | Isolation & Blast Radius | 5 | OWASP ASI04 | NIST MANAGE-2 | — | — |
is.ssrf | Isolation & Blast Radius | 3 | OWASP ASI04 | — | — | — |
is.untrusted_content | Isolation & Blast Radius | 3 | OWASP ASI01 | — | — | EU AI Act Art.15 |
ev.receipts | Evidence & Auditability | 6 | — | NIST MEASURE-1 | ISO 42001 A.9 | EU AI Act Art.12 |
ev.tamper_evidence | Evidence & Auditability | 4 | — | — | ISO 42001 A.9 | EU AI Act Art.12 |
ev.refusals_logged | Evidence & Auditability | 3 | — | NIST MEASURE-1 | — | — |
ev.governance_tests | Evidence & Auditability | 3 | — | NIST MEASURE-2 | ISO 42001 A.9 | — |
sc.pinned_deps | Supply Chain & Integrity | 4 | — | NIST MAP-4 | ISO 42001 A.10 | — |
sc.vuln_scan | Supply Chain & Integrity | 4 | — | NIST MANAGE-3 | ISO 42001 A.10 | — |
sc.integrity | Supply Chain & Integrity | 3 | — | NIST MANAGE-3 | ISO 42001 A.10 | — |
sc.safe_deploy | Supply Chain & Integrity | 3 | — | — | ISO 42001 A.10 | — |
ov.kill_switch | Human Oversight & Recovery | 4 | — | NIST MANAGE-4 | — | EU AI Act Art.14 |
ov.human_gate | Human Oversight & Recovery | 4 | — | NIST GOVERN-2 | — | EU AI Act Art.14 |
ov.rollback | Human Oversight & Recovery | 4 | — | NIST MANAGE-4 | ISO 42001 A.10 | — |
gv.policy_docs | Documented Governance | 3 | — | NIST GOVERN-1 | ISO 42001 A.2 | — |
gv.model_pinned | Documented Governance | 3 | — | NIST MAP-2 | — | EU AI Act Art.13 |
gv.data_handling | Documented Governance | 2 | — | — | ISO 42001 A.7 | EU AI Act Art.10 |
rt.refusal_proof | Evidence & Auditability | 4 | OWASP ASI02 | NIST MEASURE-1 | — | — |
rt.no_real_sends | Authority & Permission Gates | 4 | OWASP ASI02 | — | — | EU AI Act Art.14 |
Source: all 27 Control(...) definitions in /root/apexclaw-audit/aga.py,
introspected directly at build time, 2026-08-24. A dash means that control does not cite that standard directly;
most controls cite two or three of the four. As a share of all 27 controls: NIST appears on 70.4% (19/27),
ISO/IEC 42001 on 51.9% (14/27), OWASP on 44.4% (12/27), and the EU AI Act on 33.3% (9/27) — these overlap
rather than sum to 100%, since most controls cite more than one standard.
How to read this table as a regulator or auditor
Each cell is a specific clause id, not a general topic tag: NIST GOVERN-1,
ISO 42001 A.9, EU AI Act Art.14. A control that cites a clause means the audit reads a
named file for evidence that clause's obligation is met — it does not mean the control is a legal
finding, and it does not mean the underlying system has been certified against any of these standards. ApexClaw
holds no ISO/IEC 42001 certification and makes no certification claim anywhere on this site; see
/trust/. A companion, general-audience version of this same table, with additional context
on how the two figures were computed, is published at
/research/governance-controls-standards-crosswalk/.
Primary standards cited on this page: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.
By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.