ApexClaw
Home › Standards
Standards

A control crosswalk maps what you actually do to govern agents against every framework you will be asked about.

Buyers, auditors and regulators each arrive with a different framework. The underlying controls barely change — identity, authorization, approval, evidence, revocation. This table maps twelve controls across the four frameworks that matter in 2026, so one governance model answers all four conversations.

Get an Agent Trust Gap Brief

The control crosswalk

One row per control. Each column is a framework a buyer, auditor or regulator may hold you to. Mappings are our interpretation for planning purposes, published so they can be checked and argued with — not an assertion of compliance and not legal advice.

ControlOWASP Agentic 2026NIST AI RMFISO/IEC 42001EU AI Act
Agent identity & ownership
Every agent has a cryptographic identity and a named human owner
ASI03 Identity & Privilege AbuseGOVERN 2.1 — roles and responsibilitiesA.9.2 — roles, responsibilities and authoritiesArt. 26 — deployer obligations, human oversight assignment
Least privilege / scoped tools
Agents hold only the tool permissions their mission requires
ASI02 Tool Misuse & ExploitationMAP 5.1 — context and constraintsA.6.1 — AI system impact assessmentArt. 14 — human oversight design
Deterministic policy gate
A deny-by-default check runs before execution, not after
ASI01 Agent Goal HijackMANAGE 2.2 — mechanisms to supersede or deactivateA.8.2 — system operation controlsArt. 9 — risk management system
Payload-bound human approval
Consequential actions need single-use, expiring approval tied to an exact payload
ASI09 Human–Agent Trust ExploitationMANAGE 2.1 — documented decision authorityA.9.3 — human oversightArt. 14(4) — ability to intervene or interrupt
Signed execution receipts
Each consequential action emits a signed, hash-chained record
ASI04 Agentic Supply ChainMEASURE 2.8 — traceability and transparencyA.7.3 — records of AI system operationArt. 12 — automatic logging / record-keeping
Replay & reconstruction
Any action can be reconstructed end to end for review
ASI08 Cascading FailuresMEASURE 2.13 — monitoring and incident trackingA.8.4 — event logging and reviewArt. 19 — log retention
Revocation & kill switch
One agent, or all agents, can be stopped immediately
ASI10 Rogue AgentsMANAGE 2.4 — deactivation mechanismsA.8.5 — incident responseArt. 14(4)(e) — stop button
Autonomy budget / spend ceiling
Hard, fail-closed limits on actions, rate and spend
ASI02 Tool Misuse & ExploitationMANAGE 1.3 — risk tolerance and limitsA.6.2 — resource and operational limitsArt. 9(2) — foreseeable misuse mitigation
Memory & context integrity
Agent memory and retrieved context are validated before use
ASI06 Memory & Context PoisoningMEASURE 2.7 — robustness and securityA.7.2 — data quality and provenanceArt. 10 — data governance
Inter-agent authorization
Agent-to-agent calls are authenticated and scoped
ASI07 Insecure Inter-Agent CommunicationMAP 4.1 — third-party and dependency riskA.10.2 — third-party and supplier controlsArt. 25 — value-chain responsibilities
Sandboxed execution
Generated or tool-invoked code runs isolated and non-privileged
ASI05 Unexpected Code ExecutionMANAGE 2.3 — incident containmentA.8.3 — operational securityArt. 15 — accuracy, robustness, cybersecurity
Independent verification
Consequential controls are verified by something other than the actor
MEASURE 3.1 — independent assessmentA.9.4 — internal auditArt. 17 — quality management system

Interpretation  These mappings are ApexClaw's reading of published framework text, last verified 2026-08-06. Frameworks evolve; check the primary sources below before relying on any row.

What each framework actually is

OWASP Top 10 for Agentic Applications 2026

Published 9 December 2025. Ten risks, ASI01–ASI10, specific to systems where agents plan, hold memory, call tools and coordinate. Extends rather than replaces the LLM Top 10. The closest thing to a shared vocabulary this category has.

The ten risks →

NIST AI RMF

A voluntary, risk-based framework organised as Govern, Map, Measure, Manage. No certification exists. Notable in the US: Texas TRAIGA provides an affirmative defence for organisations that comply with it.

NIST for agents →

ISO/IEC 42001

An auditable AI management system standard with genuine third-party certification via a two-stage audit. Management-system shaped rather than agent-shaped.

EU AI Act

Binding law. The Digital Omnibus deferred Annex III high-risk obligations to December 2027, but most transparency and deployer obligations took effect 2 August 2026.

What still applies →

The honest gap

None of the three major frameworks — EU AI Act, NIST AI RMF, ISO/IEC 42001 — was designed for agentic systems. They were written for models and management systems, not for software that plans, holds memory, calls tools and spends money on your behalf. Singapore's January 2026 framework is reported to be the only governance document that addresses autonomous agents directly.

That gap is why this crosswalk exists and why it is published rather than sold. A control model everyone can check is worth more to this category than one nobody can see.

Primary sources: OWASP Top 10 for Agentic Applications 2026 · EU AI Act vs NIST AI RMF vs ISO/IEC 42001 comparison · EU AI Act Digital Omnibus deadline changes · CSA: NIST standards for autonomous systems. Last verified 2026-08-06. Not legal advice.

Common questions

Which AI standards can you be certified against?

ISO/IEC 42001 offers accredited third-party certification. NIST AI RMF and the OWASP Agentic Top 10 have no certification path.

What is a control crosswalk?

A mapping showing how one control satisfies requirements across several frameworks, so evidence is produced once and reused.

Does the EU AI Act require certification?

High-risk systems face conformity assessment. It is a legal obligation rather than a framework you opt into.

Is the OWASP Agentic Top 10 a standard?

It is a risk taxonomy and the closest thing to shared vocabulary the category has. It is not certifiable.

Where should we start?

NIST AI RMF for structure, because it costs nothing and other regimes point back at it.

Standards do not name agents; they bind their effects. The crosswalk exists so a team can prove one control set answers every regime at once.
Julian Joseph, founder of ApexClaw