ApexClaw
HomeGovernance › Regulator crosswalk
GOVERNANCE

A regulator's crosswalk: every control, the clause it evidences

27 rows, four standard columns, one clause id per cell. Built for scanning down the column of the instrument you actually enforce.

Published · updated · by , founder

Get an Agent Trust Gap Brief

What is this crosswalk for?

A one-row-per-control reference mapping each of the 27 deterministic agent governance controls to the exact clause of OWASP ASI, NIST AI RMF, ISO/IEC 42001, or the EU AI Act it produces file-and-line evidence for.

Why separate columns per standard instead of one combined reference list?

Because a regulator scans for their own instrument. Separating OWASP, NIST, ISO and the EU AI Act into their own columns lets a reader check only the column relevant to the jurisdiction or framework they enforce, without the other three.

How many of the 27 controls cite each standard?

Of 27 controls, OWASP ASI is cited 12 times, NIST AI RMF 19, ISO/IEC 42001 14, and the EU AI Act 9 — most controls cite two or three standards, so these overlap rather than sum to 27.

Which controls have no EU AI Act reference at all?

Eighteen of the 27 controls cite no EU AI Act article — all three Identity & Credentials controls and three of Isolation & Blast Radius's four — because those clauses map more precisely to OWASP's list or ISO's management clauses.

Every control, one row, its exact clause per standard

ControlFamilyWeight OWASP ASINIST AI RMFISO/IEC 42001EU AI Act
id.no_secretsAgent Identity & Credentials6OWASP ASI05NIST GOVERN-1ISO 42001 A.8
id.env_configAgent Identity & Credentials4NIST GOVERN-1ISO 42001 A.8
id.distinct_principalAgent Identity & Credentials4OWASP ASI06NIST MANAGE-2
au.deny_defaultAuthority & Permission Gates7OWASP ASI02NIST MANAGE-1ISO 42001 A.6
au.explicit_gateAuthority & Permission Gates6OWASP ASI02EU AI Act Art.14
au.bounded_grantAuthority & Permission Gates4OWASP ASI02NIST MANAGE-1
au.budgetAuthority & Permission Gates3OWASP ASI08NIST MEASURE-2
is.sandboxIsolation & Blast Radius5OWASP ASI06ISO 42001 A.6
is.egressIsolation & Blast Radius5OWASP ASI04NIST MANAGE-2
is.ssrfIsolation & Blast Radius3OWASP ASI04
is.untrusted_contentIsolation & Blast Radius3OWASP ASI01EU AI Act Art.15
ev.receiptsEvidence & Auditability6NIST MEASURE-1ISO 42001 A.9EU AI Act Art.12
ev.tamper_evidenceEvidence & Auditability4ISO 42001 A.9EU AI Act Art.12
ev.refusals_loggedEvidence & Auditability3NIST MEASURE-1
ev.governance_testsEvidence & Auditability3NIST MEASURE-2ISO 42001 A.9
sc.pinned_depsSupply Chain & Integrity4NIST MAP-4ISO 42001 A.10
sc.vuln_scanSupply Chain & Integrity4NIST MANAGE-3ISO 42001 A.10
sc.integritySupply Chain & Integrity3NIST MANAGE-3ISO 42001 A.10
sc.safe_deploySupply Chain & Integrity3ISO 42001 A.10
ov.kill_switchHuman Oversight & Recovery4NIST MANAGE-4EU AI Act Art.14
ov.human_gateHuman Oversight & Recovery4NIST GOVERN-2EU AI Act Art.14
ov.rollbackHuman Oversight & Recovery4NIST MANAGE-4ISO 42001 A.10
gv.policy_docsDocumented Governance3NIST GOVERN-1ISO 42001 A.2
gv.model_pinnedDocumented Governance3NIST MAP-2EU AI Act Art.13
gv.data_handlingDocumented Governance2ISO 42001 A.7EU AI Act Art.10
rt.refusal_proofEvidence & Auditability4OWASP ASI02NIST MEASURE-1
rt.no_real_sendsAuthority & Permission Gates4OWASP ASI02EU AI Act Art.14

Source: all 27 Control(...) definitions in /root/apexclaw-audit/aga.py, introspected directly at build time, 2026-08-24. A dash means that control does not cite that standard directly; most controls cite two or three of the four. As a share of all 27 controls: NIST appears on 70.4% (19/27), ISO/IEC 42001 on 51.9% (14/27), OWASP on 44.4% (12/27), and the EU AI Act on 33.3% (9/27) — these overlap rather than sum to 100%, since most controls cite more than one standard.

How to read this table as a regulator or auditor

Each cell is a specific clause id, not a general topic tag: NIST GOVERN-1, ISO 42001 A.9, EU AI Act Art.14. A control that cites a clause means the audit reads a named file for evidence that clause's obligation is met — it does not mean the control is a legal finding, and it does not mean the underlying system has been certified against any of these standards. ApexClaw holds no ISO/IEC 42001 certification and makes no certification claim anywhere on this site; see /trust/. A companion, general-audience version of this same table, with additional context on how the two figures were computed, is published at /research/governance-controls-standards-crosswalk/.

Primary standards cited on this page: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.

By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.