Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 31 of 31

Appendix K. Regulatory cross-tab and implementation evidence

Edition 2.1 addition. Primary sources reviewed 2 October 2026.

45 handbook practices, 12 implementation specifications and 112 compendium controls. Selected cross-sector, privacy and financial-services instruments; not an exhaustive inventory of world law.

Use this appendix in three steps: establish the entity, jurisdiction, decision and role in scope; locate the control in the matrix; then read its explanation themes and the cited primary provisions. The spreadsheet explanation table expands every item into separate item–theme–source relationships. The searchable web view at the regulatory map shows these relationships beside the original control and its evidence.

Every relationship is an editorial mapping from the control objective to an inspected provision or guidance domain. It is a contribution to an implementation evidence case, not equivalence, regulator endorsement, proof of compliance or demonstrated control effectiveness. A blank cell means no relationship selected, not an exemption.

The 45 H-prefixed practices, 12 E specifications and 112 original controls retain separate identities. A handbook practice is not a replacement legal requirement. Existing July controls retain their original wording; this current map qualifies their regulatory relevance. Specialist mechanisms such as sandbagging tests, collusion detection, memory repair and external outcome oracles are proposed implementations of broader risk objectives.

K.1 Sources, status and applicability

Source abbreviations in the matrix identify selected relationships. SR~ marks analogy outside agentic scope; IS/IR mark public ISO scope without inspected clauses; EU† requires the specified role and applicability; CO‡ is based on the official enacted summary. All other sources also remain subject to their listed scope. Read the status and scope here before interpreting a cell. Support if applicable means a contribution to a scoped requirement; Upstream provider duty identifies an obligation on a model provider whose evidence an enterprise may request; Guidance alignment means published voluntary or regulator guidance; Industry reference means an industry white paper; Scope-level alignment means public ISO catalogue scope, without inspected clauses or conformity; Domain analogy means transferable discipline outside the instrument’s agentic scope; Draft alignment means preparation against a consultation text. None is a compliance verdict.

Evidence table: Reference, Version and legal status, When it matters, Timing and limits
ReferenceVersion and legal statusWhen it mattersTiming and limits
R01 · EU: EU AI Act, Regulation (EU) 2024/1689Commission consolidated-text explorer, 27 July 2026. Binding law.EU-market providers, deployers and other covered operators; classify intended use and role first.Literacy/prohibitions: February 2025 (some new prohibitions December 2026); GPAI: August 2025; Article 50: August 2026; Annex III high-risk Chapter III duties: 2 December 2027; Annex I: 2 August 2028. Article 27 covers specified deployers; Articles 53/55 cover model providers, not every user of a model. Other articles and transitional arrangements have their own dates. The explorer identifies July 2026 amendments; the linked Official Journal is controlling.
R02 · GD: GDPR, Regulation (EU) 2016/679Official consolidated text: CELEX 02016R0679-20160504; reviewed 2 October 2026. Binding law.Personal-data processing within Articles 2/3; controller and processor duties differ.Applicable since 25 May 2018. Article 22 concerns solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards.
R03 · DO: DORA, Regulation (EU) 2022/2554Core regulation and official rulebook. Binding law.Financial entities listed in Article 2; check exclusions, proportionality and the simplified framework.Applicable since 17 January 2025; reporting classifications, clocks and templates also depend on delegated/implementing rules. ICT resilience duties do not by themselves define fairness or AI conformity requirements. This map selects core articles, not every technical standard.
R04 · FC: FCA Consumer Duty, PRIN 2ALive Handbook, including June 2026 updates. Binding rules and guidance.FCA firms and retail business in the Duty’s scope; account for position in the distribution chain.Current rules apply to covered business. R paragraphs are rules; G paragraphs explain their application.
R05 · PR: PRA model risk management, SS1/23April 2026 revision. Supervisory expectations.UK-incorporated banks, building societies and PRA-designated investment firms with internal-model capital approval; model definition and materiality still matter.Policy began 17 May 2024; April 2026 revision inspected. Annual self-assessment expectations remain. Branches, firms without internal-model approval, credit unions, insurers and reinsurers are outside the stated scope. For others these disciplines are an analogy, not a new agent-specific mandate.
R06 · RB: ECOA / Regulation BCurrent CFPB rule text. Binding regulation.Creditors and covered credit decisions; notification procedures and exceptions vary by application and applicant.Current §§1002.4 and 1002.9. Use the rule and its official interpretation; do not rely on withdrawn AI circulars.
R07 · CA: California CCPA, ADMT and risk assessmentsFinal approved 2025 text; effective 2026. Binding regulation.CCPA businesses and covered processing; ADMT significant-decision definition, exemptions and opt-out exceptions are specific.Regulations effective 1 January 2026. Article 11 ADMT compliance: 1 January 2027. Article 10 risk assessments and cyber-audit schedules differ. An appeal is one qualified opt-out exception; meaningful human involvement has a defined competence, analysis and authority test.
R08 · CO: Colorado SB26-189, covered ADMTSigned 14 May 2026. Enacted law; future duties.Developers/deployers of ADMT materially influencing specified consequential decisions; statutory exemptions require review.Covered duties start 1 January 2027. Attorney General implementing rules were proposed in August 2026; proposals are not enacted requirements. This entry maps the General Assembly’s official enacted summary by named duty, not numbered statutory clauses. It does not reuse the superseded SB24-205 impact-assessment regime.
R09 · SR: US interagency model risk guidance, SR 26-217 April 2026; supersedes SR 11-7 and SR 21-8. Supervisory guidance.Covered banking organisations and qualifying traditional statistical/quantitative and non-generative, non-agentic AI models.Current guidance. Attachment footnote 3 explicitly excludes generative and agentic AI models. Every agent mapping here is marked analogy. Relevant traditional model components can separately be in scope. Guidance does not establish enforceable standards.
R10 · IM: IMDA Model AI Governance Framework for Agentic AIVersion 1.5, 20 May 2026; updated 5 June 2026. Voluntary guidance.Organisations deploying agents; practical cross-sector design guidance.Published guidance; not a generally binding AI statute.
R11 · SF: MAS / industry SAFRVersion 1.0, July 2026. Voluntary industry white paper.Agentic financial workflows; runtime authorisation and review design.Published 3 July 2026. A proposed reference approach, not a new binding MAS rule.
R12 · HK: PCPD guidance on agentic AI and personal data25 August 2026. Regulator guidance.Data users processing personal data with agents; underlying PDPO duties remain binding.Current agent-specific supplement to the 2024 Model Framework. Mappings cite the nine recommendations and checklist. DPP references explain the law discussed by the guidance; this column does not convert every recommendation into a statutory requirement.
R13 · NI: NIST AI Risk Management FrameworkAI RMF 1.0, January 2023. Voluntary framework.Organisations managing AI risk across the lifecycle.Published core framework; a revision initiative or concept note does not replace this baseline.
R14 · NG: NIST Generative AI ProfileNIST AI 600-1, July 2024. Voluntary framework.Generative AI uses, components and supply chains; contextualise the profile to the complete agent workflow.Published companion to AI RMF 1.0. Risk-area references identify relevant profile topics. They do not assert a specific action ID or a mandatory algorithm.
R15 · IS: ISO/IEC 42001ISO/IEC 42001:2023. Voluntary standard.Organisational AI management systems; contract or policy may make adoption an organisational obligation.Published management-system standard. Only ISO’s public catalogue scope was inspected. All mappings are scope-level alignments; no paid clause text, Annex A conformity or certification verdict is claimed.
R16 · IR: ISO/IEC 23894ISO/IEC 23894:2023. Voluntary guidance standard.AI risk-management processes appropriate to organisational context.Published guidance standard. Public catalogue scope only. Scope-level alignment, not a verified clause-by-clause assessment.
R17 · FS: FSB sound practices for responsible AI adoption10 June 2026 consultation report. Consultation draft.Financial institutions; organisation-wide governance and AI lifecycle practices.Consultation closed July 2026. This map uses the published consultation text, not a presumed final report. Draft alignment supports preparation; it establishes no new binding obligation.

K.2 Explanation and evidence table

The following are editorial explanations of how the selected controls can contribute to the cited objectives. The evidence examples are proposed implementation artifacts. Source-specific applicability in K.1 remains a condition on every relationship.

Evidence table: Theme, How the control contributes, Evidence to collect, Primary provision or guidance domain
ThemeHow the control contributesEvidence to collectPrimary provision or guidance domain
T01: Accountability and decision rightsConnect decisions about use, residual risk and intervention to named people with authority. A charter alone does not demonstrate operation.Approved mandate; accountable owner; release and exception decisions; escalation records.EU: Art 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 5 (Support if applicable); PR: Principle 2 (Support if applicable); FC: PRIN 2A.8 (Support if applicable); IM: §2.2.1 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 2.1, 2.3 (Guidance alignment); IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; FS: Practices 1–3 (Draft alignment)
T02: Inventory and configuration recordsIdentify the deployed system, its dependencies and accountable owner so evidence can be joined to the configuration actually used.System inventory; versioned manifest; dependency and model records; approval linkage.EU: Arts 11, 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 8 (Support if applicable); PR: Principle 1 (Support if applicable); IM: §2.2.1 (Guidance alignment); SF: Agent Identity (Industry reference); NI: GOVERN 1.6 (Guidance alignment); SR: VI, model inventory (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.
T03: Impact, legal scope and risk decisionsAssess intended use, affected people, applicable roles and materiality before selecting controls. Record the reason a law applies or does not apply.Impact assessment; jurisdiction and role decision; risk register; residual-risk owner.EU: Arts 9, 27 (Support if applicable). Article 9: relevant high-risk provider duties. Article 27: specified deployers, including covered public-service and certain credit/insurance uses; an impact assessment is not required of every deployer.; GD: Art 35 (Support if applicable); PR: Principle 1 (Support if applicable); CA: §§7150, 7152 (Support if applicable); CO: Covered ADMT and consequential-decision scope (Support if applicable); IM: §2.1.1 (Guidance alignment); NI: GOVERN 1.1; MAP 5.1 (Guidance alignment); IR: AI risk-management scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; FS: Practice 5 (Draft alignment)
T04: Meaningful human oversightReviewers need competence, time, evidence and the authority to change or stop a consequential action. Measure correction rather than counting approvals.Reviewer test results; workload and response times; held actions; corrections and halt exercises.EU: Arts 14, 26(2) (Support if applicable). Article 14: high-risk provider oversight design. Article 26(2): high-risk deployer assignment of competent, trained and authorised oversight. Chapter III application dates and transitional rules matter.; GD: Art 22(3) (Support if applicable); CA: §7001(e)(1); §7221(b)(1) (Support if applicable); CO: Meaningful human review and reconsideration (Support if applicable); IM: §2.2.2 (Guidance alignment); SF: Disposition Engine; Considerations for Escalation (Industry reference); HK: Recommendation 8 (Guidance alignment); NI: MAP 3.5; GOVERN 3.2 (Guidance alignment); FS: Practice 10 (Draft alignment)
T05: Training and end-user understandingDemonstrate that operators, reviewers and affected users understand limitations and their responsibilities. Training attendance is incomplete evidence.Competence rubric; planted cases; accessible instructions; staffing and adoption evidence.EU: Art 4 (Support if applicable). Article 4: providers and deployers in scope of the AI Act; AI literacy for staff and others operating on their behalf.; DO: Art 13(6) (Support if applicable); IM: §2.4 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 2.2; MAP 3.4 (Guidance alignment)
T06: Data purpose and source stewardshipKeep source provenance, permitted use and data quality traceable; additional lawful-basis and rights review is needed when personal data or protected material is involved.Data/source register; legal basis; provenance; permitted use; quality tests.EU: Art 10 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 5, 6, 30 (Support if applicable); IM: §2.1.2 (Guidance alignment); HK: Recommendations 1, 5 (Guidance alignment); NI: MAP 2.3; GOVERN 6.1 (Guidance alignment); NG: Data Privacy; Value Chain and Component Integration (Guidance alignment); FS: Practice 7 (Draft alignment)
T07: Privacy, retention and deletionLimit access and reuse to the authorised purpose and retain personal data only as justified. Test deletion and correction through caches, memory and derived records.Purpose/retention schedule; deletion lineage; access and correction tests; minimisation decisions.GD: Arts 5(1)(b)–(e), 16, 17, 25 (Support if applicable); CA: §7002 (Support if applicable); IM: §2.1.2 (Guidance alignment); HK: Recommendations 1, 4, 5, 7 (Guidance alignment); NI: MEASURE 2.10 (Guidance alignment); NG: Data Privacy (Guidance alignment)
T08: Authority and least privilegeAuthenticate the principal and check the actual action and resource before an effect. An authenticated tool call does not establish business authority.Permission matrix; grant/revocation history; denied cross-tenant and expired-authority outcomes.GD: Art 32 (Support if applicable); DO: Art 9(4)(c)–(d) (Support if applicable); IM: §2.1.2 (Guidance alignment); SF: Agent Identity; Controls Repository (Industry reference); HK: Recommendation 6(d) (Guidance alignment); NI: MEASURE 2.7; MANAGE 2.4 (Guidance alignment)
T09: Secure design and supply-chain integrityPrevent untrusted inputs, integrations and changed artifacts from bypassing security boundaries. The specified technical mechanism remains an implementation choice.Threat model; integrity checks; approved artifacts; injection and exfiltration tests.EU: Art 15 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Art 32 (Support if applicable); DO: Art 9 (Support if applicable); IM: §2.3.1 (Guidance alignment); HK: Recommendation 6(a)–(e) (Guidance alignment); NI: MEASURE 2.7 (Guidance alignment); NG: Information Security; Value Chain and Component Integration (Guidance alignment); FS: Practice 11 (Draft alignment)
T10: Memory, state and data accuracyTrace persistent and derived state, prevent contamination from acquiring authority, and verify that repair reaches descendants. Privacy duties are conditional on personal data.Memory provenance; state lineage; quarantine; corrected descendants; restore tests.GD: Arts 5(1)(d), 16, 25 (Support if applicable); IM: §2.3.1 (Guidance alignment); HK: Recommendations 3, 4, 7 (Guidance alignment); NI: MAP 4.2; MEASURE 2.5 (Guidance alignment); NG: Confabulation; Information Integrity (Guidance alignment)
T11: Fitness and representative evaluationEvaluate utility, relevant failure modes and the deployment decision under declared conditions. A test score does not establish fitness outside those conditions.Evaluation plan; representative cases; configuration; pass/fail decisions; uncertainty and limitations.EU: Arts 9(6)–(9), 15 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; PR: Principle 3 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 2.1, 2.3, 2.5 (Guidance alignment); SR: IV, model development and use (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment)
T12: Adversarial and resilience testingChallenge the system and its integrations under credible threats. Specialist attacks are proposed ways to test broader robustness expectations, not named legal requirements.Attack assumptions; coverage; adversarial cases; effect records; residual vulnerabilities.EU: Art 15(5) (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Arts 24, 25 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 2.7 (Guidance alignment); NG: Information Security (Guidance alignment); FS: Practices 9, 11 (Draft alignment)
T13: Independent challenge and assuranceSeparate implementation from challenge, review evidence limitations and give reviewers the standing to change the decision.Independent validation; challenge findings; remediation; audit scope; unresolved limitations.DO: Art 6(6) (Support if applicable); PR: Principle 4 (Support if applicable); NI: MEASURE 1.3 (Guidance alignment); SR: III, V, effective challenge and validation (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.
T14: Material change and renewed evidenceDetect changes to components, permissions, tasks and suppliers; re-evaluate the affected claims before relying on old approval evidence.Baseline/candidate comparisons; materiality decisions; notices; regression results; new approvals.EU: Arts 9(2), 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 9(4)(e)–(f) (Support if applicable); PR: Principles 3, 4 (Support if applicable); CA: §7155(a)(3) (Support if applicable); CO: Developer material-update notifications (Support if applicable); IM: §2.3.3 (Guidance alignment); NI: GOVERN 1.5; MANAGE 4.2 (Guidance alignment); SR: V, ongoing monitoring (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.
T15: Protected action and assurance evidenceJoin identity, policy, decisions and actual effects in protected records. Logging is subject to privacy, confidentiality and retention limits; raw reasoning disclosure is not a universal duty.Attributable action log; configuration and approval IDs; integrity/access checks; retention schedule.EU: Arts 12, 19 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 5, 30, 32 (Support if applicable); DO: Arts 9(2), 17(2) (Support if applicable); CO: Compliance records retained at least three years (Support if applicable); SF: Governance Envelope; Audit Log (Industry reference); HK: Recommendation 6(f) (Guidance alignment); NI: MEASURE 2.8; MANAGE 4.1 (Guidance alignment)
T16: Monitoring, drift and control decayMonitor behaviour and outcomes against the tested envelope, including latency, capacity and blind spots. Reopen claims when the environment changes.Signal definitions; thresholds; measured delay/error; drift cases; reassessment decisions.EU: Arts 26(5), 72 (Support if applicable). Article 26(5): high-risk deployer monitoring. Article 72: high-risk provider post-market monitoring. Establish the applicable role and article-specific timing.; DO: Art 10 (Support if applicable); PR: Principles 3, 4 (Support if applicable); FC: PRIN 2A.9 (Support if applicable); IM: §2.3.3 (Guidance alignment); HK: Recommendation 8 (Guidance alignment); NI: MEASURE 2.4, 3.1; MANAGE 4.1 (Guidance alignment); SR: V, validation and monitoring (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment)
T17: Incident containment and learningContain effects and credentials, preserve evidence, investigate mechanisms, and feed corrections into the next operating decision.Incident classification; containment times; forensic record; root cause; re-entry decision.EU: Arts 20, 73 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Arts 11, 13, 17 (Support if applicable); GD: Arts 33, 34 (Support if applicable); IM: §2.3.3 (Guidance alignment); NI: MANAGE 2.3, 4.3 (Guidance alignment); FS: Practices 9, 11 (Draft alignment)
T18: Continuity, fallback and recoveryProve safe operation and effect reconciliation under dependency failure. Recovery must preserve permissions and unresolved business obligations.Failure matrix; fallback and restore exercises; duplicate/partial-effect reconciliation.DO: Arts 11, 12 (Support if applicable); PR: Principle 5 (Support if applicable); IM: §2.3.1, §2.3.3 (Guidance alignment); NI: GOVERN 6.2; MANAGE 2.3, 2.4 (Guidance alignment); FS: Practices 11, 12 (Draft alignment)
T19: Third-party evidence and contractual dutiesInventory suppliers and processing relationships; secure usable documentation, audit rights, change/incident notice and data handling terms.Due diligence; contracts; processor terms; provider evidence; dependency register.EU: Art 25(4) (Support if applicable). High-risk AI system providers and third parties supplying components or services; written arrangements depend on the specified value-chain role.; GD: Art 28 (Support if applicable); DO: Arts 28, 30 (Support if applicable); PR: Principle 3 (Support if applicable); CO: Developer technical documentation (Support if applicable); IM: §2.2.1 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 6.1; MANAGE 3.1 (Guidance alignment); NG: Value Chain and Component Integration (Guidance alignment); FS: Practice 12 (Draft alignment); EU: Art 53(1)(b) (Upstream provider duty). Covered GPAI model providers owe documentation to downstream system providers. An enterprise can request and retain it; model use alone does not make it the obligated model provider.
T20: Concentration, exit and retirementIdentify critical dependencies and demonstrate an exit that closes grants, preserves needed evidence, and restores the business process.Concentration assessment; tested exit; data return/deletion; credential withdrawal; custody decisions.DO: Arts 28(8), 29, 30 (Support if applicable); GD: Art 28(3)(g) (Support if applicable); IM: §2.3.3 (Guidance alignment); HK: Annex A, Uninstall Stage (Guidance alignment); NI: GOVERN 1.7, 6.2; MANAGE 3.1 (Guidance alignment); FS: Practice 12 (Draft alignment)
T21: Fairness across the complete decision pathMeasure relevant cohort outcomes, burdens and exclusions across routing and intermediate actions as well as the final decision. Statistical disparity alone is not a complete legal conclusion.Covered-decision inventory; cohort/trajectory results; uncertainty; alternative-design analysis.EU: Arts 10(2)(f)–(g), 27 (Support if applicable). Article 10(2)(f)–(g): relevant high-risk provider duties. Article 27: specified deployers, including covered public-service and certain credit/insurance uses; an impact assessment is not required of every deployer.; RB: §1002.4(a), prohibited discrimination (Support if applicable); FC: PRIN 2A.2; 2A.9 (Support if applicable); CA: §7152(a)(5)–(6) (Support if applicable); IM: §2.1.1 (Guidance alignment); NI: MEASURE 2.11; MAP 5.1 (Guidance alignment); NG: Harmful Bias and Homogenization (Guidance alignment)
T22: Notices, transparency and actual reasonsExplain the actual decision basis and the agent’s role in terms affected people can use. Generated rationalisations are insufficient evidence of the reasons actually applied.Decision factors; validated notice; AI disclosure; intelligibility tests; delivered notice record.EU: Arts 13, 50, 86 (Support if applicable). Article 13: high-risk provider information to deployers. Article 50: transparency for specified systems, content and roles. Article 86: deployers making specified covered decisions. Check each article separately.; GD: Arts 13–15 (Support if applicable); RB: §1002.9(a), (b)(2) and official interpretation (Support if applicable); FC: PRIN 2A.5 (Support if applicable); CA: §§7220, 7222 (Support if applicable); CO: Interaction notice and adverse-outcome disclosure (Support if applicable); IM: §2.4.2 (Guidance alignment); HK: Recommendation 2 (Guidance alignment); NI: MEASURE 2.8, 2.9 (Guidance alignment); FS: Practice 8 (Draft alignment)
T23: Contest, correction and remedyProvide an accessible route to correction or review and investigate recurring harm beyond the person who complained. Rights, exceptions and remedy duties depend on the use and jurisdiction.Access/correction requests; human reconsideration; complaint results; affected-cohort lookback.EU: Arts 85, 86 (Support if applicable). Article 85: complaints about infringements. Article 86: explanation for specified individual decisions by deployers. These do not create a universal right to every form of remedy.; GD: Arts 16, 22(3) (Support if applicable); FC: PRIN 2A.6; 2A.10 (Support if applicable); CA: §§7221, 7222 (Support if applicable); CO: Data correction; meaningful human review (Support if applicable); IM: §2.4.2 (Guidance alignment); HK: Recommendation 7 (Guidance alignment); NI: MEASURE 3.3; MANAGE 4.1 (Guidance alignment)
T24: Delegation and multi-agent boundariesPreserve identity, narrower authority, state lineage and containment across agents. Review the whole system rather than assuming individually acceptable components compose safely.Topology; parent/child authority; joint-outcome tests; propagated revocation and containment.IM: §2.1.2; §2.3.2 (Guidance alignment); SF: Agent Identity; Controls Repository (Industry reference); HK: Multi-agent risks; Recommendation 6 (Guidance alignment); NI: MAP 4.2; MEASURE 2.7 (Guidance alignment); NG: Value Chain and Component Integration (Guidance alignment)
T25: Durable limits and bounded autonomyKeep action, exposure and time limits outside agent-editable state, including retries and descendants. Proposed budget mechanisms support risk bounding; the sources do not prescribe universal numeric limits.External limits; consumption ledger; expiry and restart tests; bounded mandate.IM: §2.1.2 (Guidance alignment); SF: Controls Repository; Table 1, financial limits (Industry reference); NI: GOVERN 1.3; MANAGE 1.3 (Guidance alignment)
T26: Management-system and conformity claimsSeparate organisational certification, system conformity assessment and evidence of actual control effectiveness. This map cannot establish any of those verdicts.Applicable conformity route; certificate scope; independent assessment; exclusions; management-system evidence.EU: Arts 17, 43 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; IR: AI risk-management scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; NI: GOVERN 1.4 (Guidance alignment)
T27: Independent outcome verificationCheck external business state before asserting completion and reconcile uncertain effects. This is a proposed implementation of accuracy and evidence disciplines, not a universally mandated oracle design.External postconditions; idempotency; state reconciliation; false-completion cases.EU: Art 15(1) (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; PR: Principle 3 (Support if applicable); IM: §2.3.2 (Guidance alignment); SF: Governance Envelope; Audit Log (Industry reference); NI: MEASURE 2.3, 2.5 (Guidance alignment); NG: Confabulation; Information Integrity (Guidance alignment)
T28: Training provenance and protected materialTrace training and retrieved sources and assess protected data or source rights. GPAI model-provider documentation duties do not automatically pass to every agent deployer.Training/source lineage; rights assessment; extraction tests; supplier documentation.EU: Art 53(1)(a)–(d) (Upstream provider duty). Article 53 binds covered GPAI model providers. An enterprise using their models can request and retain the documentation; use alone does not make it the obligated model provider.; GD: Arts 5, 15, 30 (Support if applicable); NI: GOVERN 6.1 (Guidance alignment); NG: Intellectual Property; Data Privacy (Guidance alignment)
T29: Validity and limitations of evidenceCheck measurement grain, labels, oracle quality, independence and uncertainty before relying on a safety or oversight claim. Specialist test methods remain proposed implementations.Protocol; denominator; independent labels; uncertainty; scope and reproducibility notes.PR: Principle 4 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 1.1–1.3; 2.13 (Guidance alignment); SR: V, validation (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment)
T30: Regulatory incident-reporting registerKeep each trigger, recipient, clock and reporting template distinct. Do not apply a single deadline to every AI or ICT incident.Reportability assessment; jurisdiction/authority; clock start; reports and notification receipts.EU: Art 73 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 33, 34 (Support if applicable); DO: Arts 18–20 (Support if applicable); NI: MANAGE 4.3 (Guidance alignment)

K.3 Complete control cross-tab

Each cell lists the source abbreviations selected for that specific item. The Theme column connects it to K.2, which supplies the provisions, relationship type and explanation. A blank cell is shown as an em dash and means no relationship selected. It does not establish an exemption. The downloadable cross-tab includes a separate column for every instrument and its exact mapped provision labels.

Handbook practice

Evidence table: Item and original title, Themes, EU, UK, US, Singapore, Hong Kong, Global
Item and original titleThemesEUUKUSSingaporeHong KongGlobal
H-GOV-01: Named mandateT01, T03, T25EU†, GD, DOFC, PRCA, CO‡IM, SFHKNI, IS, IR, FS
H-GOV-02: Impact and legal scopeT03, T21EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
H-GOV-03: Decision rightsT01, T04EU†, GD, DOFC, PRCA, CO‡IM, SFHKNI, IS*, FS
H-GOV-04: Risk and exceptionsT03, T25EU†, GDPRCA, CO‡IM, SF—NI, IR*, FS
H-GOV-05: Training and adoptionT05, T04EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
H-DES-01: Configuration identityT02, T14EU†, DOPRCA, CO‡, SR~IM, SF—NI
H-DES-02: Independent authorityT08, T09EU†, GD, DO——IM, SFHKNI, NG, FS
H-DES-03: Data and source purposeT06, T07EU†, GD—CAIMHKNI, NG, FS
H-DES-04: Memory stewardshipT10, T07GD—CAIMHKNI, NG
H-DES-05: Failure and recovery designT18, T09EU†, GD, DOPR—IMHKNI, NG, FS
H-EVL-01: Decision and oracleT11, T27EU†PRSR~IM, SF—NI, NG, FS
H-EVL-02: Representative tasksT11, T21EU†FC, PRRB, CA, SR~IM—NI, NG, FS
H-EVL-03: Adversarial and invariant testsT12, T08EU†, GD, DO——IM, SFHKNI, NG, FS
H-EVL-04: Human and monitor validityT29, T04, T16EU†, GD, DOFC, PRCA, CO‡, SR~IM, SFHKNI, FS
H-EVL-05: Change interactionsT14, T24EU†, DOPRCA, CO‡, SR~IM, SFHKNI, NG
H-RUN-01: Commit mediationT08, T09EU†, GD, DO——IM, SFHKNI, NG, FS
H-RUN-02: Bounded approvalT08, T04EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
H-RUN-03: Shared limits and revocationT25, T24———IM, SFHKNI, NG
H-RUN-04: Effect verificationT27, T18EU†, DOPR—IM, SF—NI, NG, FS
H-RUN-05: Human intervention and haltT04, T17EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
H-MON-01: Correlated evidenceT15, T27EU†, GD, DOPRCO‡IM, SFHKNI, NG
H-MON-02: Tested monitor envelopeT16, T29EU†, DOFC, PRSR~IMHKNI, FS
H-MON-03: Integrity and accessT15, T07EU†, GD, DO—CA, CO‡IM, SFHKNI, NG
H-MON-04: Drift and evidence expiryT16, T14EU†, DOFC, PRCA, CO‡, SR~IMHKNI, FS
H-MON-05: Outcome and incident feedbackT17, T23, T21EU†, GD, DOFCRB, CA, CO‡IMHKNI, NG, FS
H-MAS-01: Topology necessityT24, T03EU†, GDPRCA, CO‡IM, SFHKNI, NG, IR*, FS
H-MAS-02: Constrained delegationT24, T08, T25GD, DO——IM, SFHKNI, NG
H-MAS-03: Shared state disciplineT24, T10, T07GD—CAIM, SFHKNI, NG
H-MAS-04: System-level evaluationT24, T12EU†, DO——IM, SFHKNI, NG, FS
H-MAS-05: Descendant containmentT24, T17EU†, GD, DO——IM, SFHKNI, NG, FS
H-TPR-01: Dependency inventoryT19, T02EU†, GD, DOPRCO‡, SR~IM, SFHKNI, NG, FS
H-TPR-02: Evidence challengeT19, T29EU†, GD, DOPRCO‡, SR~IMHKNI, NG, FS
H-TPR-03: Data and rights termsT19, T07, T28EU†, GD, DOPRCA, CO‡IMHKNI, NG, FS
H-TPR-04: Change and incident noticeT19, T14, T17EU†, GD, DOPRCA, CO‡, SR~IMHKNI, NG, FS
H-TPR-05: Exit and continuityT20, T18GD, DOPR—IMHKNI, FS
H-ASR-01: Claim registerT15, T29EU†, GD, DOPRCO‡, SR~IM, SFHKNI, FS
H-ASR-02: Evidence validityT29, T13DOPRSR~IM—NI, IS*, FS
H-ASR-03: Independent challengeT13, T01EU†, DOFC, PRSR~IMHKNI, IS*, FS
H-ASR-04: Operating and recovery proofT13, T27, T17EU†, GD, DOPRSR~IM, SF—NI, NG, IS*, FS
H-ASR-05: Retirement and custodyT20, T07GD, DO—CAIMHKNI, NG, FS
H-FCO-01: Decision-path scopeT21, T03EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
H-FCO-02: Fairness and burden reviewT21, T29EU†FC, PRRB, CA, SR~IM—NI, NG, FS
H-FCO-03: Actual reasonsT22, T27EU†, GDFC, PRRB, CA, CO‡IM, SFHKNI, NG, FS
H-FCO-04: Meaningful reviewT04, T23EU†, GDFCCA, CO‡IM, SFHKNI, FS
H-FCO-05: Contest and remedyT23, T21EU†, GDFCRB, CA, CO‡IMHKNI, NG

Implementation specification

Evidence table: Item and original title, Themes, EU, UK, US, Singapore, Hong Kong, Global
Item and original titleThemesEUUKUSSingaporeHong KongGlobal
E01: Join the deployed configuration to its approval evidenceT02, T14, T15EU†, GD, DOPRCA, CO‡, SR~IM, SFHKNI
E02: Enforce authority at the consequential-effect boundaryT08, T04, T09EU†, GD, DO—CA, CO‡IM, SFHKNI, NG, FS
E03: Verify completion from external business stateT27, T18EU†, DOPR—IM, SF—NI, NG, FS
E04: Preserve relevant safety state across the workflowT25, T10, T24GD——IM, SFHKNI, NG
E05: Evaluate delayed influence and repair its descendantsT10, T07, T12EU†, GD, DO—CAIMHKNI, NG, FS
E06: Validate affected interactions before approving changeT14, T11, T24EU†, DOPRCA, CO‡, SR~IM, SFHKNI, NG, FS
E07: Limit monitor assurance to demonstrated operating conditionsT16, T29EU†, DOFC, PRSR~IMHKNI, FS
E08: Prove protocol and adapter enforcement coverageT09, T08, T19EU†, GD, DOPRCO‡IM, SFHKNI, NG, FS
E09: Test multi-agent outcomes across threat and topologyT24, T12EU†, DO——IM, SFHKNI, NG, FS
E10: Measure customer outcomes across the complete decision pathT21, T23EU†, GDFCRB, CA, CO‡IMHKNI, NG
E11: Demonstrate human correction competence and approval integrityT04, T08, T29EU†, GD, DOPRCA, CO‡, SR~IM, SFHKNI, FS
E12: Link assurance claims to protected operational evidenceT15, T13, T29EU†, GD, DOPRCO‡, SR~IM, SFHKNI, IS*, FS

Compendium control

Evidence table: Item and original title, Themes, EU, UK, US, Singapore, Hong Kong, Global
Item and original titleThemesEUUKUSSingaporeHong KongGlobal
GOV-01: Board-Approved AI & Autonomy Governance CharterT01, T25EU†, DOFC, PR—IM, SFHKNI, IS*, FS
GOV-02: Enterprise AI Management System (AIMS)T26, T01EU†, DOFC, PR—IMHKNI, IS, IR, FS
GOV-03: Agent Inventory & RegistrationT02EU†, DOPRSR~IM, SF—NI
GOV-04: Named Accountable Owner per AgentT01, T02EU†, DOFC, PRSR~IM, SFHKNI, IS*, FS
GOV-05: Agentic Systems Within Model Risk Management ScopeT03, T13EU†, GD, DOPRCA, CO‡, SR~IM—NI, IS, IR, FS
GOV-06: Independent Validation & Effective Challenge for AgentsT13, T29DOPRSR~IM—NI, IS*, FS
GOV-07: Autonomy Tier Framework in the Risk AppetiteT25, T03EU†, GDPRCA, CO‡IM, SF—NI, IR*, FS
GOV-08: Autonomy Promotion & Demotion GatesT14, T25EU†, DOPRCA, CO‡, SR~IM, SF—NI
GOV-09: Three-Lines Responsibility Assignment for Agentic AIT01, T13EU†, DOFC, PRSR~IMHKNI, IS*, FS
GOV-10: AI Impact Assessment Before Deployment and PromotionT03, T21EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
GOV-11: Governance Records & Regulator-Ready DocumentationT15, T02EU†, GD, DOPRCO‡, SR~IM, SFHKNI
GOV-12: Data Quality Management Accountability for Agent-Consumed DataT06, T10EU†, GD——IMHKNI, NG, FS
GOV-13: Evidentiary Standards for Oversight & Monitoring ClaimsT29, T16EU†, DOFC, PRSR~IMHKNI, FS
GOV-14: AI Ethics & Escalation Body with Anti-Decoy SafeguardsT01, T04, T03EU†, GD, DOFC, PRCA, CO‡IM, SFHKNI, IS, IR, FS
DES-01: Agent Data Inventory and Governance PlanT06, T02EU†, GD, DOPRSR~IM, SFHKNI, NG, FS
DES-02: Training-Data Provenance Instrumentation and Post-Hoc AuditabilityT28EU†, GD————NI, NG
DES-03: Poisoning-Resistant Data AcquisitionT09, T06, T12EU†, GD, DO——IMHKNI, NG, FS
DES-04: Memorization and Training-Data Extraction Risk ControlsT07, T28, T12EU†, GD, DO—CAIMHKNI, NG, FS
DES-05: AI System Impact Assessment as a Design GateT03, T14EU†, GD, DOPRCA, CO‡, SR~IM—NI, IR*, FS
DES-06: Human-Rights and Customer-Impact Assessment for High-Stakes Agentic ScopeT03, T21EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
DES-07: Agent Identity, Ownership, and Lifecycle by DesignT02, T08EU†, GD, DOPRSR~IM, SFHKNI
DES-08: Least-Privilege Tool and Permission ScopingT08, T07GD, DO—CAIM, SFHKNI, NG
DES-09: Short-Lived, Delegation-Bounded Credential ArchitectureT08, T24GD, DO——IM, SFHKNI, NG
DES-10: User-Level Permission Model: Specify, Derive, EnforceT08, T04EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
DES-11: Environmental Constraints as an Oversight SubstrateT09, T16EU†, GD, DOFC, PRSR~IMHKNI, NG, FS
DES-12: Secure Development and Attestation for the Agent StackT09, T19EU†, GD, DOPRCO‡IMHKNI, NG, FS
DES-13: Model, Artifact, and Tool Provenance: Signing and Integrity VerificationT09, T02, T14EU†, GD, DOPRCA, CO‡, SR~IM, SFHKNI, NG, FS
DES-14: Memory and Context Architecture as Designed Control SurfacesT10, T07GD—CAIMHKNI, NG
EVL-01: Documented Pre-Deployment Evaluation Plan per Agent SystemT11, T29EU†PRSR~IM—NI, FS
EVL-02: Multi-Dimensional Capability & Fitness EvaluationT11EU†PRSR~IM—NI, FS
EVL-03: Dangerous-Capability Evaluation ProgrammeT12, T03EU†, GD, DOPRCA, CO‡IM—NI, NG, IR*, FS
EVL-04: Full-Capability Elicitation StandardT12, T29EU†, DOPRSR~IM—NI, NG, FS
EVL-05: Sandbagging & Evaluation-Awareness TestingT12, T29EU†, DOPRSR~IM—NI, NG, FS
EVL-06: Construct & Ecological Validity ReviewT29, T11EU†PRSR~IM—NI, FS
EVL-07: Benchmark Integrity: Verifier Hardening & Contamination ControlT29, T09EU†, GD, DOPRSR~IMHKNI, NG, FS
EVL-08: Trajectory-Level Evaluation EvidenceT15, T11EU†, GD, DOPRCO‡, SR~IM, SFHKNI, FS
EVL-09: Cross-Benchmark CorroborationT29, T11EU†PRSR~IM—NI, FS
EVL-10: Adversarial Red-Teaming of Agentic SystemsT12EU†, DO——IM—NI, NG, FS
EVL-11: Control Evaluations Under Assumed SubversionT12, T09EU†, GD, DO——IMHKNI, NG, FS
EVL-12: Propensity, Sabotage & Misbehavior EvaluationT12, T11EU†, DOPRSR~IM—NI, NG, FS
EVL-13: Privacy & Data-Leakage Evaluation of Agent Tool-ChainsT07, T12, T24EU†, GD, DO—CAIM, SFHKNI, NG, FS
EVL-14: Independent & Third-Party EvaluationT13, T19EU†, GD, DOPRCO‡, SR~IMHKNI, NG, IS*, FS
EVL-15: Pre-Committed Pass/Fail Thresholds & Go/No-Go Deployment GateT11, T01EU†, DOFC, PRSR~IMHKNI, IS*, FS
EVL-16: Continuous Re-Evaluation TriggersT14, T16EU†, DOFC, PRCA, CO‡, SR~IMHKNI, FS
RUN-01: Designated Oversight Mode per Agent DeploymentT04, T03EU†, GDPRCA, CO‡IM, SFHKNI, IR*, FS
RUN-02: Structured Adversarial Review at Approval GatesT04, T29EU†, GDPRCA, CO‡, SR~IM, SFHKNI, FS
RUN-03: Oversight Triggers Wired to Observable SignalsT04, T16EU†, GD, DOFC, PRCA, CO‡, SR~IM, SFHKNI, FS
RUN-04: Graduated Autonomy with Deferral (Act-or-Ask)T25, T04EU†, GD—CA, CO‡IM, SFHKNI, FS
RUN-05: AI-Control Protocol as the Deployment BaselineT09, T12EU†, GD, DO——IMHKNI, NG, FS
RUN-06: Trusted Monitoring of Untrusted Agent ActionsT16, T09EU†, GD, DOFC, PRSR~IMHKNI, NG, FS
RUN-07: Untrusted Monitoring with Collusion SafeguardsT16, T24, T29EU†, DOFC, PRSR~IM, SFHKNI, NG, FS
RUN-08: Resample and Defer-to-Trusted Protocols for Suspicious ActionsT04, T18EU†, GD, DOPRCA, CO‡IM, SFHKNI, FS
RUN-09: Adaptive Deployment Against Distributed ThreatsT16, T25EU†, DOFC, PRSR~IM, SFHKNI, FS
RUN-10: Adversarial Validation of the Monitoring StackT12, T29, T16EU†, DOFC, PRSR~IMHKNI, NG, FS
RUN-11: Sandboxed Execution and Environment ContainmentT09, T08EU†, GD, DO——IM, SFHKNI, NG, FS
RUN-12: Kill Switch: Tested Emergency Shutdown per AgentT04, T17EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
RUN-13: Graceful Degradation and Fallback Operating ModesT18DOPR—IM—NI, FS
RUN-14: Hard Budget, Turn, and Spend GuardsT25———IM, SF—NI
RUN-15: Call-Time Tool Gating and Permission EnforcementT08GD, DO——IM, SFHKNI
RUN-16: Chain-Aware Compositional Tool Policies with Taint TrackingT08, T10, T24GD, DO——IM, SFHKNI, NG
RUN-17: Approval Workflows for Consequential ActionsT04, T08EU†, GD, DO—CA, CO‡IM, SFHKNI, FS
RUN-18: Runtime Trajectory and Reasoning-Trace CaptureT15, T07EU†, GD, DO—CA, CO‡IM, SFHKNI, NG
MON-01: Complete, Attributable Agent Action LoggingT15, T24EU†, GD, DO—CO‡IM, SFHKNI, NG
MON-02: Reasoning-Trace Capture & RetentionT15, T07EU†, GD, DO—CA, CO‡IM, SFHKNI, NG
MON-03: Agent Observability Platform & Telemetry TaxonomyT16, T15EU†, GD, DOFC, PRCO‡, SR~IM, SFHKNI, FS
MON-04: Statistical Drift & Performance-Degradation DetectionT16, T14EU†, DOFC, PRCA, CO‡, SR~IMHKNI, FS
MON-05: Behavioral Baselining & Goal-Drift MonitoringT16, T25EU†, DOFC, PRSR~IM, SFHKNI, FS
MON-06: Tool-Use & Environment Anomaly DetectionT16, T09EU†, GD, DOFC, PRSR~IMHKNI, NG, FS
MON-07: AI-Supervised Monitoring of Agents (Hierarchical Oversight)T16, T24, T29EU†, DOFC, PRSR~IM, SFHKNI, NG, FS
MON-08: Monitoring-Latency Budget (Detect-to-Respond SLO)T16, T04EU†, GD, DOFC, PRCA, CO‡, SR~IM, SFHKNI, FS
MON-09: Agentic Incident Classification & Severity TaxonomyT17, T30EU†, GD, DO——IM—NI, FS
MON-10: Agentic Incident Response & ContainmentT17, T24EU†, GD, DO——IM, SFHKNI, NG, FS
MON-11: Regulatory Incident-Reporting Obligations RegisterT30EU†, GD, DO————NI
MON-12: Safeguard Re-Verification & Feedback into Re-EvaluationT16, T14, T29EU†, DOFC, PRCA, CO‡, SR~IMHKNI, FS
MAS-01: Multi-Agent System Inventory and Topology RegistrationT24, T02EU†, DOPRSR~IM, SFHKNI, NG
MAS-02: Unique Agent Identity with Attributable Action LoggingT24, T15, T08EU†, GD, DO—CO‡IM, SFHKNI, NG
MAS-03: Authenticated Delegation with Bounded Authority ChainsT24, T08GD, DO——IM, SFHKNI, NG
MAS-04: Short-Lived, Dynamically Issued Agent CredentialsT24, T08GD, DO——IM, SFHKNI, NG
MAS-05: Action- and Artifact-Level Monitoring Primacy over Message-Log ReviewT24, T15, T27EU†, GD, DOPRCO‡IM, SFHKNI, NG
MAS-06: Trusted Monitor over Multi-Agent Work ProductsT24, T16, T29EU†, DOFC, PRSR~IM, SFHKNI, NG, FS
MAS-07: Persistent-State and Cross-Session Sabotage ReviewT24, T10, T12EU†, GD, DO——IM, SFHKNI, NG, FS
MAS-08: Collusion Detection Instrumentation (Ensembled, Never Assumed Solved)T24, T12, T29EU†, DOPRSR~IM, SFHKNI, NG, FS
MAS-09: Deployment-Rule Red-Teaming (Institutional Configuration as an Attack Surface)T24, T12, T03EU†, GD, DOPRCA, CO‡IM, SFHKNI, NG, IR*, FS
MAS-10: Cascade and Propagation Containment; Multi-Agent Necessity JustificationT24, T17, T03EU†, GD, DOPRCA, CO‡IM, SFHKNI, NG, IR*, FS
TPR-01: Model-Provider Due Diligence and Third-Party AI Risk ClassificationT19, T03EU†, GD, DOPRCA, CO‡IMHKNI, NG, IR*, FS
TPR-02: Vendor Concentration and Systemic Dependency ManagementT20GD, DO——IMHKNI, FS
TPR-03: Upstream Model and Weight Change ManagementT14, T19EU†, GD, DOPRCA, CO‡, SR~IMHKNI, NG, FS
TPR-04: Vendor Evaluation Evidence: Demand, Verify, and Do Not Rely Solely on First-Party ClaimsT19, T29, T13EU†, GD, DOPRCO‡, SR~IMHKNI, NG, IS*, FS
TPR-05: Documentation Artifacts for Third-Party Models and DatasetsT19, T28EU†, GD, DOPRCO‡IMHKNI, NG, FS
TPR-06: Third-Party Tool and MCP-Server Supply-Chain SecurityT19, T09, T08EU†, GD, DOPRCO‡IM, SFHKNI, NG, FS
TPR-07: API Dependency Resilience, Degradation, and ExitT18, T20GD, DOPR—IMHKNI, FS
TPR-08: Contractual Controls, Secure Access Tiers, and the Third-Party Assurance EcosystemT19, T08, T07EU†, GD, DOPRCA, CO‡IM, SFHKNI, NG, FS
ASR-01: Documented layered assurance stackT26, T13, T15EU†, GD, DOPRCO‡, SR~SFHKNI, IS, IR
ASR-02: AI impact assessment as a first-line gateT03EU†, GDPRCA, CO‡IM—NI, IR*, FS
ASR-03: Independent internal audit of agentic AIT13, T01EU†, DOFC, PRSR~IMHKNI, IS*, FS
ASR-04: End-to-end internal algorithmic audit methodologyT13, T29DOPRSR~IM—NI, IS*, FS
ASR-05: Accredited certification of the AI management systemT26EU†————NI, IS, IR
ASR-06: Conformity-assessment readiness for regulated high-risk usesT26, T03EU†, GDPRCA, CO‡IM—NI, IS, IR, FS
ASR-07: Frontier-safety-framework vendor diligenceT19, T29EU†, GD, DOPRCO‡, SR~IMHKNI, NG, FS
ASR-08: Vendor safety-framework change monitoringT19, T14EU†, GD, DOPRCA, CO‡, SR~IMHKNI, NG, FS
ASR-09: Transparency artifacts as mandatory audit evidenceT15, T19, T02EU†, GD, DOPRCO‡, SR~IM, SFHKNI, NG, FS
ASR-10: Assurance evidence repositoryT15, T13EU†, GD, DOPRCO‡, SR~SFHKNI, IS*
FCO-01: Covered-Decision Inventory and Fairness ScopingT21, T03EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
FCO-02: Constrained Decision Policy for Covered ActionsT21, T08, T06EU†, GD, DOFCRB, CAIM, SFHKNI, NG, FS
FCO-03: Trajectory-Level Disparate-Impact TestingT21, T11EU†FC, PRRB, CA, SR~IM—NI, NG, FS
FCO-04: Less-Discriminatory-Alternative Search and Business-Necessity FileT21, T03EU†, GDFC, PRRB, CA, CO‡IM—NI, NG, IR*, FS
FCO-05: Specific and Accurate Adverse-Action Reasons for Agentic DecisionsT22EU†, GDFCRB, CA, CO‡IMHKNI, FS
FCO-06: Decision Reproducibility and Trajectory Evidence CaptureT15, T22, T27EU†, GD, DOFC, PRRB, CA, CO‡IM, SFHKNI, NG, FS
FCO-07: Production Fairness Monitoring for Agentic FlowsT21, T16EU†, DOFC, PRRB, CA, SR~IMHKNI, NG, FS
FCO-08: Complaint Handling and Human Reopening of Agentic DecisionsT23, T04EU†, GDFCCA, CO‡IM, SFHKNI, FS
FCO-09: Cohort Remediation and Fairness LookbacksT23, T21EU†, GDFCRB, CA, CO‡IMHKNI, NG
FCO-10: Vulnerable-Customer Safeguards in Agent InteractionsT21, T05, T23EU†, GD, DOFCRB, CA, CO‡IMHKNI, NG

K.4 Important item-specific qualifications

Evidence table: Item, Interpretation limit
ItemInterpretation limit
GOV-02The original certifiable-management-system objective is a design intention, not evidence of readiness or conformity. The ISO mappings use public catalogue scope only; paid clauses and conformity were not inspected.
GOV-05Institutional model-risk coverage is a proposed governance choice. SR 26-2 expressly excludes generative and agentic AI; review qualifying traditional components separately.
DES-02Training-source tracing is an implementation aid. EU GPAI documentation duties concern covered model providers; inspect separate copyright and data-protection obligations.
RUN-18Required action evidence does not imply universal disclosure of raw reasoning traces. Record business-relevant actions and decisions with proportionate data safeguards. Apply defined retention periods, data minimisation, redaction and deletion to trajectory records. GDPR and California relationships describe an editorial evidence contribution, not demonstrated compliance.
MON-01Attribute each action to a unique executing-agent identity and retain the delegation lineage to the initiating agent and accountable principal. Single-agent attribution alone does not reconstruct responsibility across a multi-agent workflow.
MON-02Do not interpret record-keeping duties as a general obligation to retain or disclose raw model reasoning. Apply privacy, confidentiality, purpose and retention limits.
ASR-01An assurance chain can draw on several kinds of evidence. Certification is not a universal legal prerequisite or proof that every agent control works.
ASR-05AI management-system certification concerns the defined organisational scope. This map does not verify certificate validity, accreditation or individual control effectiveness. ISO mappings use public catalogue scope only; paid clauses and conformity were not inspected.
ASR-06ISO mappings use public catalogue scope only. Paid clauses and conformity were not inspected; the mapping is not clause-verified conformity evidence.
FCO-04A disparity measure and alternative-design search inform review; they do not alone determine a legal finding of discrimination or business necessity.
FCO-05The original guarantee is a design objective, not demonstrated legal sufficiency. For covered credit decisions, verify that notices state the actual, specific principal reasons and satisfy applicable Regulation B requirements; a generated explanation or this mapping does not establish notice adequacy.

K.5 Working files and review cadence

Download the complete cross-tab, the explanation table, and the regulatory source register. All three are also included in the implementation kit.

This edition records a source review on 2 October 2026. The next monthly review is due 1 November 2026. Monthly reference updates provide supplementary findings; their publication does not silently change this dated legal map. Changed legal text, newly final guidance and applicability decisions require editorial review before the map’s review date advances.