27 governance controls, mapped to OWASP, NIST, ISO and the EU AI Act
A full reference table, introspected directly from the control definitions rather than transcribed by hand.
Published · updated · by Julian Joseph, founder
Get an Agent Trust Gap BriefWhat are the 27 governance controls, and where do they come from?
They are the full control set in aga.py (Agent Governance Audit, AGA/1.0) — a deterministic audit of an agent system's source, config and deployment, distinct from the website-facing ARB rubric. Every control reads a named file and line.
How are the 27 controls grouped?
Into 7 families, each with a fixed weight in the overall score summing to 100: Authority & Permission Gates carries the most weight at 20, Documented Governance the least at 8.
| Family | Weight in overall score | Controls |
|---|---|---|
| Agent Identity & Credentials | 14 | 3 |
| Authority & Permission Gates | 20 | 5 |
| Isolation & Blast Radius | 16 | 4 |
| Evidence & Auditability | 16 | 5 |
| Supply Chain & Integrity | 14 | 4 |
| Human Oversight & Recovery | 12 | 3 |
| Documented Governance | 8 | 3 |
Source: FAMILIES and run_controls() in /root/apexclaw-audit/aga.py, introspected at build time.
Which published standard is cited most across the 27 controls?
NIST, appearing in 19 of the 54 total standard references across all 27 controls — more than OWASP, ISO/IEC 42001 or the EU AI Act individually, each cited fewer times.
| Standard | References across 27 controls |
|---|---|
| OWASP | 12 |
| NIST | 19 |
| ISO | 14 |
| EU AI Act | 9 |
Are any of the 27 controls unscoreable without a running system?
Two: rt.refusal_proof and rt.no_real_sends. Both require evidence from a live run — an observed refusal, or observed zero unauthorized external effects — and return UNKNOWN, removed from the denominator, without it.
Is this the same audit that scores apexclawai.com's own website?
No. This is AGA, which reads an agent system's source tree. The website-facing rubric is a separate one, published at methodology.json — different engine, different check list, different target. As of 2026-08-26, methodology.json reflects ARB/1.1 (49 checks, live default engine); the 27 controls on this page are aga.py's AGA/1.0 control set, unchanged since 2026-08-24.
How the 54 standard references break down by percentage
Of the 54 total standard references across all 27 controls, NIST accounts for 35.2%, ISO/IEC 42001 for 25.9%, OWASP for 22.2%, and the EU AI Act for 16.7% — the four add to 100% of the references, since every control cites at least one and most cite two or three.
Family weights as a share of the overall AGA score: Authority & Permission Gates 20%, Isolation & Blast Radius and Evidence & Auditability 16% each, Agent Identity & Credentials and Supply Chain & Integrity 14% each, Human Oversight & Recovery 12%, Documented Governance 8% — summing to 100%.
All 27 controls, mapped to their standards
| ID | Family | Title | Weight | Standards referenced | |
|---|---|---|---|---|---|
id.no_secrets | Agent Identity & Credentials | No credentials committed to the tree | 6 | OWASP ASI05, ISO 42001 A.8, NIST GOVERN-1 | |
id.env_config | Agent Identity & Credentials | Secrets loaded from environment, not literals | 4 | ISO 42001 A.8, NIST GOVERN-1 | |
id.distinct_principal | Agent Identity & Credentials | Agent runs as its own principal, not root | 4 | OWASP ASI06, NIST MANAGE-2 | |
au.deny_default | Authority & Permission Gates | Tool authority is deny-by-default | 7 | OWASP ASI02, NIST MANAGE-1, ISO 42001 A.6 | |
au.explicit_gate | Authority & Permission Gates | Actions pass an explicit authorization gate | 6 | OWASP ASI02, EU AI Act Art.14 | |
au.bounded_grant | Authority & Permission Gates | Grants are bounded: single-use or expiring | 4 | OWASP ASI02, NIST MANAGE-1 | |
au.budget | Authority & Permission Gates | Spend, rate or resource budget enforced | 3 | OWASP ASI08, NIST MEASURE-2 | |
is.sandbox | Isolation & Blast Radius | Process sandboxing declared | 5 | OWASP ASI06, ISO 42001 A.6 | |
is.egress | Isolation & Blast Radius | Outbound network is restricted | 5 | OWASP ASI04, NIST MANAGE-2 | |
is.ssrf | Isolation & Blast Radius | Server-side request forgery is blocked | 3 | OWASP ASI04 | |
is.untrusted_content | Isolation & Blast Radius | Untrusted content is isolated from the reasoning path | 3 | OWASP ASI01, EU AI Act Art.15 | |
ev.receipts | Evidence & Auditability | Every action emits a durable record | 6 | EU AI Act Art.12, NIST MEASURE-1, ISO 42001 A.9 | |
ev.tamper_evidence | Evidence & Auditability | Records are tamper-evident | 4 | EU AI Act Art.12, ISO 42001 A.9 | |
ev.refusals_logged | Evidence & Auditability | Refusals are recorded, not only successes | 3 | NIST MEASURE-1 | |
ev.governance_tests | Evidence & Auditability | Governance paths carry tests | 3 | NIST MEASURE-2, ISO 42001 A.9 | |
sc.pinned_deps | Supply Chain & Integrity | Dependencies are pinned by a lockfile | 4 | ISO 42001 A.10, NIST MAP-4 | |
sc.vuln_scan | Supply Chain & Integrity | A dependency vulnerability scan runs | 4 | ISO 42001 A.10, NIST MANAGE-3 | |
sc.integrity | Supply Chain & Integrity | Running code can be proven to match reviewed code | 3 | ISO 42001 A.10, NIST MANAGE-3 | |
sc.safe_deploy | Supply Chain & Integrity | Deployment has no destructive default | 3 | ISO 42001 A.10 | |
ov.kill_switch | Human Oversight & Recovery | A kill switch exists | 4 | EU AI Act Art.14, NIST MANAGE-4 | |
ov.human_gate | Human Oversight & Recovery | Irreversible actions require a human | 4 | EU AI Act Art.14, NIST GOVERN-2 | |
ov.rollback | Human Oversight & Recovery | A documented rollback path exists | 4 | ISO 42001 A.10, NIST MANAGE-4 | |
gv.policy_docs | Documented Governance | Security and governance policy is published | 3 | ISO 42001 A.2, NIST GOVERN-1 | |
gv.model_pinned | Documented Governance | Model version is pinned and recorded | 3 | EU AI Act Art.13, NIST MAP-2 | |
gv.data_handling | Documented Governance | Data retention and personal data handling is stated | 2 | ISO 42001 A.7, EU AI Act Art.10 | |
rt.refusal_proof | Evidence & Auditability | Observed refusal of an unauthorized action | 4 | OWASP ASI02, NIST MEASURE-1 | runtime |
rt.no_real_sends | Authority & Permission Gates | Observed zero unauthorized external effects | 4 | OWASP ASI02, EU AI Act Art.14 | runtime |
Source: /root/apexclaw-audit/aga.py, all 27 Control(...) definitions introspected directly at build time, 2026-08-24. "runtime" marks the 2 controls that score UNKNOWN without live evidence.
Method note
Primary standards cited across the table: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.
By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.