Edition 2.1 addition. Primary sources reviewed 2 October 2026.
45 handbook practices, 12 implementation specifications and 112 compendium controls. Selected cross-sector, privacy and financial-services instruments; not an exhaustive inventory of world law.
Use this appendix in three steps: establish the entity, jurisdiction, decision and role in scope; locate the control in the matrix; then read its explanation themes and the cited primary provisions. The spreadsheet explanation table expands every item into separate item–theme–source relationships. The searchable web view at the regulatory map shows these relationships beside the original control and its evidence.
Every relationship is an editorial mapping from the control objective to an inspected provision or guidance domain. It is a contribution to an implementation evidence case, not equivalence, regulator endorsement, proof of compliance or demonstrated control effectiveness. A blank cell means no relationship selected, not an exemption.
The 45 H-prefixed practices, 12 E specifications and 112 original controls retain separate identities. A handbook practice is not a replacement legal requirement. Existing July controls retain their original wording; this current map qualifies their regulatory relevance. Specialist mechanisms such as sandbagging tests, collusion detection, memory repair and external outcome oracles are proposed implementations of broader risk objectives.
K.1 Sources, status and applicability
Source abbreviations in the matrix identify selected relationships. SR~ marks analogy outside agentic scope; IS/IR mark public ISO scope without inspected clauses; EU† requires the specified role and applicability; CO‡ is based on the official enacted summary. All other sources also remain subject to their listed scope. Read the status and scope here before interpreting a cell. Support if applicable means a contribution to a scoped requirement; Upstream provider duty identifies an obligation on a model provider whose evidence an enterprise may request; Guidance alignment means published voluntary or regulator guidance; Industry reference means an industry white paper; Scope-level alignment means public ISO catalogue scope, without inspected clauses or conformity; Domain analogy means transferable discipline outside the instrument’s agentic scope; Draft alignment means preparation against a consultation text. None is a compliance verdict.
| Reference | Version and legal status | When it matters | Timing and limits |
|---|---|---|---|
| R01 · EU: EU AI Act, Regulation (EU) 2024/1689 | Commission consolidated-text explorer, 27 July 2026. Binding law. | EU-market providers, deployers and other covered operators; classify intended use and role first. | Literacy/prohibitions: February 2025 (some new prohibitions December 2026); GPAI: August 2025; Article 50: August 2026; Annex III high-risk Chapter III duties: 2 December 2027; Annex I: 2 August 2028. Article 27 covers specified deployers; Articles 53/55 cover model providers, not every user of a model. Other articles and transitional arrangements have their own dates. The explorer identifies July 2026 amendments; the linked Official Journal is controlling. |
| R02 · GD: GDPR, Regulation (EU) 2016/679 | Official consolidated text: CELEX 02016R0679-20160504; reviewed 2 October 2026. Binding law. | Personal-data processing within Articles 2/3; controller and processor duties differ. | Applicable since 25 May 2018. Article 22 concerns solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards. |
| R03 · DO: DORA, Regulation (EU) 2022/2554 | Core regulation and official rulebook. Binding law. | Financial entities listed in Article 2; check exclusions, proportionality and the simplified framework. | Applicable since 17 January 2025; reporting classifications, clocks and templates also depend on delegated/implementing rules. ICT resilience duties do not by themselves define fairness or AI conformity requirements. This map selects core articles, not every technical standard. |
| R04 · FC: FCA Consumer Duty, PRIN 2A | Live Handbook, including June 2026 updates. Binding rules and guidance. | FCA firms and retail business in the Duty’s scope; account for position in the distribution chain. | Current rules apply to covered business. R paragraphs are rules; G paragraphs explain their application. |
| R05 · PR: PRA model risk management, SS1/23 | April 2026 revision. Supervisory expectations. | UK-incorporated banks, building societies and PRA-designated investment firms with internal-model capital approval; model definition and materiality still matter. | Policy began 17 May 2024; April 2026 revision inspected. Annual self-assessment expectations remain. Branches, firms without internal-model approval, credit unions, insurers and reinsurers are outside the stated scope. For others these disciplines are an analogy, not a new agent-specific mandate. |
| R06 · RB: ECOA / Regulation B | Current CFPB rule text. Binding regulation. | Creditors and covered credit decisions; notification procedures and exceptions vary by application and applicant. | Current §§1002.4 and 1002.9. Use the rule and its official interpretation; do not rely on withdrawn AI circulars. |
| R07 · CA: California CCPA, ADMT and risk assessments | Final approved 2025 text; effective 2026. Binding regulation. | CCPA businesses and covered processing; ADMT significant-decision definition, exemptions and opt-out exceptions are specific. | Regulations effective 1 January 2026. Article 11 ADMT compliance: 1 January 2027. Article 10 risk assessments and cyber-audit schedules differ. An appeal is one qualified opt-out exception; meaningful human involvement has a defined competence, analysis and authority test. |
| R08 · CO: Colorado SB26-189, covered ADMT | Signed 14 May 2026. Enacted law; future duties. | Developers/deployers of ADMT materially influencing specified consequential decisions; statutory exemptions require review. | Covered duties start 1 January 2027. Attorney General implementing rules were proposed in August 2026; proposals are not enacted requirements. This entry maps the General Assembly’s official enacted summary by named duty, not numbered statutory clauses. It does not reuse the superseded SB24-205 impact-assessment regime. |
| R09 · SR: US interagency model risk guidance, SR 26-2 | 17 April 2026; supersedes SR 11-7 and SR 21-8. Supervisory guidance. | Covered banking organisations and qualifying traditional statistical/quantitative and non-generative, non-agentic AI models. | Current guidance. Attachment footnote 3 explicitly excludes generative and agentic AI models. Every agent mapping here is marked analogy. Relevant traditional model components can separately be in scope. Guidance does not establish enforceable standards. |
| R10 · IM: IMDA Model AI Governance Framework for Agentic AI | Version 1.5, 20 May 2026; updated 5 June 2026. Voluntary guidance. | Organisations deploying agents; practical cross-sector design guidance. | Published guidance; not a generally binding AI statute. |
| R11 · SF: MAS / industry SAFR | Version 1.0, July 2026. Voluntary industry white paper. | Agentic financial workflows; runtime authorisation and review design. | Published 3 July 2026. A proposed reference approach, not a new binding MAS rule. |
| R12 · HK: PCPD guidance on agentic AI and personal data | 25 August 2026. Regulator guidance. | Data users processing personal data with agents; underlying PDPO duties remain binding. | Current agent-specific supplement to the 2024 Model Framework. Mappings cite the nine recommendations and checklist. DPP references explain the law discussed by the guidance; this column does not convert every recommendation into a statutory requirement. |
| R13 · NI: NIST AI Risk Management Framework | AI RMF 1.0, January 2023. Voluntary framework. | Organisations managing AI risk across the lifecycle. | Published core framework; a revision initiative or concept note does not replace this baseline. |
| R14 · NG: NIST Generative AI Profile | NIST AI 600-1, July 2024. Voluntary framework. | Generative AI uses, components and supply chains; contextualise the profile to the complete agent workflow. | Published companion to AI RMF 1.0. Risk-area references identify relevant profile topics. They do not assert a specific action ID or a mandatory algorithm. |
| R15 · IS: ISO/IEC 42001 | ISO/IEC 42001:2023. Voluntary standard. | Organisational AI management systems; contract or policy may make adoption an organisational obligation. | Published management-system standard. Only ISO’s public catalogue scope was inspected. All mappings are scope-level alignments; no paid clause text, Annex A conformity or certification verdict is claimed. |
| R16 · IR: ISO/IEC 23894 | ISO/IEC 23894:2023. Voluntary guidance standard. | AI risk-management processes appropriate to organisational context. | Published guidance standard. Public catalogue scope only. Scope-level alignment, not a verified clause-by-clause assessment. |
| R17 · FS: FSB sound practices for responsible AI adoption | 10 June 2026 consultation report. Consultation draft. | Financial institutions; organisation-wide governance and AI lifecycle practices. | Consultation closed July 2026. This map uses the published consultation text, not a presumed final report. Draft alignment supports preparation; it establishes no new binding obligation. |
K.2 Explanation and evidence table
The following are editorial explanations of how the selected controls can contribute to the cited objectives. The evidence examples are proposed implementation artifacts. Source-specific applicability in K.1 remains a condition on every relationship.
| Theme | How the control contributes | Evidence to collect | Primary provision or guidance domain |
|---|---|---|---|
| T01: Accountability and decision rights | Connect decisions about use, residual risk and intervention to named people with authority. A charter alone does not demonstrate operation. | Approved mandate; accountable owner; release and exception decisions; escalation records. | EU: Art 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 5 (Support if applicable); PR: Principle 2 (Support if applicable); FC: PRIN 2A.8 (Support if applicable); IM: §2.2.1 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 2.1, 2.3 (Guidance alignment); IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; FS: Practices 1–3 (Draft alignment) |
| T02: Inventory and configuration records | Identify the deployed system, its dependencies and accountable owner so evidence can be joined to the configuration actually used. | System inventory; versioned manifest; dependency and model records; approval linkage. | EU: Arts 11, 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 8 (Support if applicable); PR: Principle 1 (Support if applicable); IM: §2.2.1 (Guidance alignment); SF: Agent Identity (Industry reference); NI: GOVERN 1.6 (Guidance alignment); SR: VI, model inventory (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2. |
| T03: Impact, legal scope and risk decisions | Assess intended use, affected people, applicable roles and materiality before selecting controls. Record the reason a law applies or does not apply. | Impact assessment; jurisdiction and role decision; risk register; residual-risk owner. | EU: Arts 9, 27 (Support if applicable). Article 9: relevant high-risk provider duties. Article 27: specified deployers, including covered public-service and certain credit/insurance uses; an impact assessment is not required of every deployer.; GD: Art 35 (Support if applicable); PR: Principle 1 (Support if applicable); CA: §§7150, 7152 (Support if applicable); CO: Covered ADMT and consequential-decision scope (Support if applicable); IM: §2.1.1 (Guidance alignment); NI: GOVERN 1.1; MAP 5.1 (Guidance alignment); IR: AI risk-management scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; FS: Practice 5 (Draft alignment) |
| T04: Meaningful human oversight | Reviewers need competence, time, evidence and the authority to change or stop a consequential action. Measure correction rather than counting approvals. | Reviewer test results; workload and response times; held actions; corrections and halt exercises. | EU: Arts 14, 26(2) (Support if applicable). Article 14: high-risk provider oversight design. Article 26(2): high-risk deployer assignment of competent, trained and authorised oversight. Chapter III application dates and transitional rules matter.; GD: Art 22(3) (Support if applicable); CA: §7001(e)(1); §7221(b)(1) (Support if applicable); CO: Meaningful human review and reconsideration (Support if applicable); IM: §2.2.2 (Guidance alignment); SF: Disposition Engine; Considerations for Escalation (Industry reference); HK: Recommendation 8 (Guidance alignment); NI: MAP 3.5; GOVERN 3.2 (Guidance alignment); FS: Practice 10 (Draft alignment) |
| T05: Training and end-user understanding | Demonstrate that operators, reviewers and affected users understand limitations and their responsibilities. Training attendance is incomplete evidence. | Competence rubric; planted cases; accessible instructions; staffing and adoption evidence. | EU: Art 4 (Support if applicable). Article 4: providers and deployers in scope of the AI Act; AI literacy for staff and others operating on their behalf.; DO: Art 13(6) (Support if applicable); IM: §2.4 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 2.2; MAP 3.4 (Guidance alignment) |
| T06: Data purpose and source stewardship | Keep source provenance, permitted use and data quality traceable; additional lawful-basis and rights review is needed when personal data or protected material is involved. | Data/source register; legal basis; provenance; permitted use; quality tests. | EU: Art 10 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 5, 6, 30 (Support if applicable); IM: §2.1.2 (Guidance alignment); HK: Recommendations 1, 5 (Guidance alignment); NI: MAP 2.3; GOVERN 6.1 (Guidance alignment); NG: Data Privacy; Value Chain and Component Integration (Guidance alignment); FS: Practice 7 (Draft alignment) |
| T07: Privacy, retention and deletion | Limit access and reuse to the authorised purpose and retain personal data only as justified. Test deletion and correction through caches, memory and derived records. | Purpose/retention schedule; deletion lineage; access and correction tests; minimisation decisions. | GD: Arts 5(1)(b)–(e), 16, 17, 25 (Support if applicable); CA: §7002 (Support if applicable); IM: §2.1.2 (Guidance alignment); HK: Recommendations 1, 4, 5, 7 (Guidance alignment); NI: MEASURE 2.10 (Guidance alignment); NG: Data Privacy (Guidance alignment) |
| T08: Authority and least privilege | Authenticate the principal and check the actual action and resource before an effect. An authenticated tool call does not establish business authority. | Permission matrix; grant/revocation history; denied cross-tenant and expired-authority outcomes. | GD: Art 32 (Support if applicable); DO: Art 9(4)(c)–(d) (Support if applicable); IM: §2.1.2 (Guidance alignment); SF: Agent Identity; Controls Repository (Industry reference); HK: Recommendation 6(d) (Guidance alignment); NI: MEASURE 2.7; MANAGE 2.4 (Guidance alignment) |
| T09: Secure design and supply-chain integrity | Prevent untrusted inputs, integrations and changed artifacts from bypassing security boundaries. The specified technical mechanism remains an implementation choice. | Threat model; integrity checks; approved artifacts; injection and exfiltration tests. | EU: Art 15 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Art 32 (Support if applicable); DO: Art 9 (Support if applicable); IM: §2.3.1 (Guidance alignment); HK: Recommendation 6(a)–(e) (Guidance alignment); NI: MEASURE 2.7 (Guidance alignment); NG: Information Security; Value Chain and Component Integration (Guidance alignment); FS: Practice 11 (Draft alignment) |
| T10: Memory, state and data accuracy | Trace persistent and derived state, prevent contamination from acquiring authority, and verify that repair reaches descendants. Privacy duties are conditional on personal data. | Memory provenance; state lineage; quarantine; corrected descendants; restore tests. | GD: Arts 5(1)(d), 16, 25 (Support if applicable); IM: §2.3.1 (Guidance alignment); HK: Recommendations 3, 4, 7 (Guidance alignment); NI: MAP 4.2; MEASURE 2.5 (Guidance alignment); NG: Confabulation; Information Integrity (Guidance alignment) |
| T11: Fitness and representative evaluation | Evaluate utility, relevant failure modes and the deployment decision under declared conditions. A test score does not establish fitness outside those conditions. | Evaluation plan; representative cases; configuration; pass/fail decisions; uncertainty and limitations. | EU: Arts 9(6)–(9), 15 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; PR: Principle 3 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 2.1, 2.3, 2.5 (Guidance alignment); SR: IV, model development and use (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment) |
| T12: Adversarial and resilience testing | Challenge the system and its integrations under credible threats. Specialist attacks are proposed ways to test broader robustness expectations, not named legal requirements. | Attack assumptions; coverage; adversarial cases; effect records; residual vulnerabilities. | EU: Art 15(5) (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Arts 24, 25 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 2.7 (Guidance alignment); NG: Information Security (Guidance alignment); FS: Practices 9, 11 (Draft alignment) |
| T13: Independent challenge and assurance | Separate implementation from challenge, review evidence limitations and give reviewers the standing to change the decision. | Independent validation; challenge findings; remediation; audit scope; unresolved limitations. | DO: Art 6(6) (Support if applicable); PR: Principle 4 (Support if applicable); NI: MEASURE 1.3 (Guidance alignment); SR: III, V, effective challenge and validation (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected. |
| T14: Material change and renewed evidence | Detect changes to components, permissions, tasks and suppliers; re-evaluate the affected claims before relying on old approval evidence. | Baseline/candidate comparisons; materiality decisions; notices; regression results; new approvals. | EU: Arts 9(2), 17 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Art 9(4)(e)–(f) (Support if applicable); PR: Principles 3, 4 (Support if applicable); CA: §7155(a)(3) (Support if applicable); CO: Developer material-update notifications (Support if applicable); IM: §2.3.3 (Guidance alignment); NI: GOVERN 1.5; MANAGE 4.2 (Guidance alignment); SR: V, ongoing monitoring (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2. |
| T15: Protected action and assurance evidence | Join identity, policy, decisions and actual effects in protected records. Logging is subject to privacy, confidentiality and retention limits; raw reasoning disclosure is not a universal duty. | Attributable action log; configuration and approval IDs; integrity/access checks; retention schedule. | EU: Arts 12, 19 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 5, 30, 32 (Support if applicable); DO: Arts 9(2), 17(2) (Support if applicable); CO: Compliance records retained at least three years (Support if applicable); SF: Governance Envelope; Audit Log (Industry reference); HK: Recommendation 6(f) (Guidance alignment); NI: MEASURE 2.8; MANAGE 4.1 (Guidance alignment) |
| T16: Monitoring, drift and control decay | Monitor behaviour and outcomes against the tested envelope, including latency, capacity and blind spots. Reopen claims when the environment changes. | Signal definitions; thresholds; measured delay/error; drift cases; reassessment decisions. | EU: Arts 26(5), 72 (Support if applicable). Article 26(5): high-risk deployer monitoring. Article 72: high-risk provider post-market monitoring. Establish the applicable role and article-specific timing.; DO: Art 10 (Support if applicable); PR: Principles 3, 4 (Support if applicable); FC: PRIN 2A.9 (Support if applicable); IM: §2.3.3 (Guidance alignment); HK: Recommendation 8 (Guidance alignment); NI: MEASURE 2.4, 3.1; MANAGE 4.1 (Guidance alignment); SR: V, validation and monitoring (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment) |
| T17: Incident containment and learning | Contain effects and credentials, preserve evidence, investigate mechanisms, and feed corrections into the next operating decision. | Incident classification; containment times; forensic record; root cause; re-entry decision. | EU: Arts 20, 73 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; DO: Arts 11, 13, 17 (Support if applicable); GD: Arts 33, 34 (Support if applicable); IM: §2.3.3 (Guidance alignment); NI: MANAGE 2.3, 4.3 (Guidance alignment); FS: Practices 9, 11 (Draft alignment) |
| T18: Continuity, fallback and recovery | Prove safe operation and effect reconciliation under dependency failure. Recovery must preserve permissions and unresolved business obligations. | Failure matrix; fallback and restore exercises; duplicate/partial-effect reconciliation. | DO: Arts 11, 12 (Support if applicable); PR: Principle 5 (Support if applicable); IM: §2.3.1, §2.3.3 (Guidance alignment); NI: GOVERN 6.2; MANAGE 2.3, 2.4 (Guidance alignment); FS: Practices 11, 12 (Draft alignment) |
| T19: Third-party evidence and contractual duties | Inventory suppliers and processing relationships; secure usable documentation, audit rights, change/incident notice and data handling terms. | Due diligence; contracts; processor terms; provider evidence; dependency register. | EU: Art 25(4) (Support if applicable). High-risk AI system providers and third parties supplying components or services; written arrangements depend on the specified value-chain role.; GD: Art 28 (Support if applicable); DO: Arts 28, 30 (Support if applicable); PR: Principle 3 (Support if applicable); CO: Developer technical documentation (Support if applicable); IM: §2.2.1 (Guidance alignment); HK: Recommendation 9 (Guidance alignment); NI: GOVERN 6.1; MANAGE 3.1 (Guidance alignment); NG: Value Chain and Component Integration (Guidance alignment); FS: Practice 12 (Draft alignment); EU: Art 53(1)(b) (Upstream provider duty). Covered GPAI model providers owe documentation to downstream system providers. An enterprise can request and retain it; model use alone does not make it the obligated model provider. |
| T20: Concentration, exit and retirement | Identify critical dependencies and demonstrate an exit that closes grants, preserves needed evidence, and restores the business process. | Concentration assessment; tested exit; data return/deletion; credential withdrawal; custody decisions. | DO: Arts 28(8), 29, 30 (Support if applicable); GD: Art 28(3)(g) (Support if applicable); IM: §2.3.3 (Guidance alignment); HK: Annex A, Uninstall Stage (Guidance alignment); NI: GOVERN 1.7, 6.2; MANAGE 3.1 (Guidance alignment); FS: Practice 12 (Draft alignment) |
| T21: Fairness across the complete decision path | Measure relevant cohort outcomes, burdens and exclusions across routing and intermediate actions as well as the final decision. Statistical disparity alone is not a complete legal conclusion. | Covered-decision inventory; cohort/trajectory results; uncertainty; alternative-design analysis. | EU: Arts 10(2)(f)–(g), 27 (Support if applicable). Article 10(2)(f)–(g): relevant high-risk provider duties. Article 27: specified deployers, including covered public-service and certain credit/insurance uses; an impact assessment is not required of every deployer.; RB: §1002.4(a), prohibited discrimination (Support if applicable); FC: PRIN 2A.2; 2A.9 (Support if applicable); CA: §7152(a)(5)–(6) (Support if applicable); IM: §2.1.1 (Guidance alignment); NI: MEASURE 2.11; MAP 5.1 (Guidance alignment); NG: Harmful Bias and Homogenization (Guidance alignment) |
| T22: Notices, transparency and actual reasons | Explain the actual decision basis and the agent’s role in terms affected people can use. Generated rationalisations are insufficient evidence of the reasons actually applied. | Decision factors; validated notice; AI disclosure; intelligibility tests; delivered notice record. | EU: Arts 13, 50, 86 (Support if applicable). Article 13: high-risk provider information to deployers. Article 50: transparency for specified systems, content and roles. Article 86: deployers making specified covered decisions. Check each article separately.; GD: Arts 13–15 (Support if applicable); RB: §1002.9(a), (b)(2) and official interpretation (Support if applicable); FC: PRIN 2A.5 (Support if applicable); CA: §§7220, 7222 (Support if applicable); CO: Interaction notice and adverse-outcome disclosure (Support if applicable); IM: §2.4.2 (Guidance alignment); HK: Recommendation 2 (Guidance alignment); NI: MEASURE 2.8, 2.9 (Guidance alignment); FS: Practice 8 (Draft alignment) |
| T23: Contest, correction and remedy | Provide an accessible route to correction or review and investigate recurring harm beyond the person who complained. Rights, exceptions and remedy duties depend on the use and jurisdiction. | Access/correction requests; human reconsideration; complaint results; affected-cohort lookback. | EU: Arts 85, 86 (Support if applicable). Article 85: complaints about infringements. Article 86: explanation for specified individual decisions by deployers. These do not create a universal right to every form of remedy.; GD: Arts 16, 22(3) (Support if applicable); FC: PRIN 2A.6; 2A.10 (Support if applicable); CA: §§7221, 7222 (Support if applicable); CO: Data correction; meaningful human review (Support if applicable); IM: §2.4.2 (Guidance alignment); HK: Recommendation 7 (Guidance alignment); NI: MEASURE 3.3; MANAGE 4.1 (Guidance alignment) |
| T24: Delegation and multi-agent boundaries | Preserve identity, narrower authority, state lineage and containment across agents. Review the whole system rather than assuming individually acceptable components compose safely. | Topology; parent/child authority; joint-outcome tests; propagated revocation and containment. | IM: §2.1.2; §2.3.2 (Guidance alignment); SF: Agent Identity; Controls Repository (Industry reference); HK: Multi-agent risks; Recommendation 6 (Guidance alignment); NI: MAP 4.2; MEASURE 2.7 (Guidance alignment); NG: Value Chain and Component Integration (Guidance alignment) |
| T25: Durable limits and bounded autonomy | Keep action, exposure and time limits outside agent-editable state, including retries and descendants. Proposed budget mechanisms support risk bounding; the sources do not prescribe universal numeric limits. | External limits; consumption ledger; expiry and restart tests; bounded mandate. | IM: §2.1.2 (Guidance alignment); SF: Controls Repository; Table 1, financial limits (Industry reference); NI: GOVERN 1.3; MANAGE 1.3 (Guidance alignment) |
| T26: Management-system and conformity claims | Separate organisational certification, system conformity assessment and evidence of actual control effectiveness. This map cannot establish any of those verdicts. | Applicable conformity route; certificate scope; independent assessment; exclusions; management-system evidence. | EU: Arts 17, 43 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; IS: AI management-system scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; IR: AI risk-management scope (Scope-level alignment). Organisational AI management or risk-management scope only. ISO public catalogue inspected; numbered clauses and conformity were not inspected.; NI: GOVERN 1.4 (Guidance alignment) |
| T27: Independent outcome verification | Check external business state before asserting completion and reconcile uncertain effects. This is a proposed implementation of accuracy and evidence disciplines, not a universally mandated oracle design. | External postconditions; idempotency; state reconciliation; false-completion cases. | EU: Art 15(1) (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; PR: Principle 3 (Support if applicable); IM: §2.3.2 (Guidance alignment); SF: Governance Envelope; Audit Log (Industry reference); NI: MEASURE 2.3, 2.5 (Guidance alignment); NG: Confabulation; Information Integrity (Guidance alignment) |
| T28: Training provenance and protected material | Trace training and retrieved sources and assess protected data or source rights. GPAI model-provider documentation duties do not automatically pass to every agent deployer. | Training/source lineage; rights assessment; extraction tests; supplier documentation. | EU: Art 53(1)(a)–(d) (Upstream provider duty). Article 53 binds covered GPAI model providers. An enterprise using their models can request and retain the documentation; use alone does not make it the obligated model provider.; GD: Arts 5, 15, 30 (Support if applicable); NI: GOVERN 6.1 (Guidance alignment); NG: Intellectual Property; Data Privacy (Guidance alignment) |
| T29: Validity and limitations of evidence | Check measurement grain, labels, oracle quality, independence and uncertainty before relying on a safety or oversight claim. Specialist test methods remain proposed implementations. | Protocol; denominator; independent labels; uncertainty; scope and reproducibility notes. | PR: Principle 4 (Support if applicable); IM: §2.3.2 (Guidance alignment); NI: MEASURE 1.1–1.3; 2.13 (Guidance alignment); SR: V, validation (Domain analogy). Domain analogy only: SR 26-2 explicitly excludes generative and agentic AI models. Assess conventional model components separately; this agent control is not claimed to be required by SR 26-2.; FS: Practice 9 (Draft alignment) |
| T30: Regulatory incident-reporting register | Keep each trigger, recipient, clock and reporting template distinct. Do not apply a single deadline to every AI or ICT incident. | Reportability assessment; jurisdiction/authority; clock start; reports and notification receipts. | EU: Art 73 (Support if applicable). High-risk AI system duties for the provider or other role named in the cited article. Establish classification, role, article-specific application date and transitional rules first.; GD: Arts 33, 34 (Support if applicable); DO: Arts 18–20 (Support if applicable); NI: MANAGE 4.3 (Guidance alignment) |
K.3 Complete control cross-tab
Each cell lists the source abbreviations selected for that specific item. The Theme column connects it to K.2, which supplies the provisions, relationship type and explanation. A blank cell is shown as an em dash and means no relationship selected. It does not establish an exemption. The downloadable cross-tab includes a separate column for every instrument and its exact mapped provision labels.
Handbook practice
| Item and original title | Themes | EU | UK | US | Singapore | Hong Kong | Global |
|---|---|---|---|---|---|---|---|
| H-GOV-01: Named mandate | T01, T03, T25 | EU†, GD, DO | FC, PR | CA, CO‡ | IM, SF | HK | NI, IS, IR, FS |
| H-GOV-02: Impact and legal scope | T03, T21 | EU†, GD | FC, PR | RB, CA, CO‡ | IM | — | NI, NG, IR*, FS |
| H-GOV-03: Decision rights | T01, T04 | EU†, GD, DO | FC, PR | CA, CO‡ | IM, SF | HK | NI, IS*, FS |
| H-GOV-04: Risk and exceptions | T03, T25 | EU†, GD | PR | CA, CO‡ | IM, SF | — | NI, IR*, FS |
| H-GOV-05: Training and adoption | T05, T04 | EU†, GD, DO | — | CA, CO‡ | IM, SF | HK | NI, FS |
| H-DES-01: Configuration identity | T02, T14 | EU†, DO | PR | CA, CO‡, SR~ | IM, SF | — | NI |
| H-DES-02: Independent authority | T08, T09 | EU†, GD, DO | — | — | IM, SF | HK | NI, NG, FS |
| H-DES-03: Data and source purpose | T06, T07 | EU†, GD | — | CA | IM | HK | NI, NG, FS |
| H-DES-04: Memory stewardship | T10, T07 | GD | — | CA | IM | HK | NI, NG |
| H-DES-05: Failure and recovery design | T18, T09 | EU†, GD, DO | PR | — | IM | HK | NI, NG, FS |
| H-EVL-01: Decision and oracle | T11, T27 | EU† | PR | SR~ | IM, SF | — | NI, NG, FS |
| H-EVL-02: Representative tasks | T11, T21 | EU† | FC, PR | RB, CA, SR~ | IM | — | NI, NG, FS |
| H-EVL-03: Adversarial and invariant tests | T12, T08 | EU†, GD, DO | — | — | IM, SF | HK | NI, NG, FS |
| H-EVL-04: Human and monitor validity | T29, T04, T16 | EU†, GD, DO | FC, PR | CA, CO‡, SR~ | IM, SF | HK | NI, FS |
| H-EVL-05: Change interactions | T14, T24 | EU†, DO | PR | CA, CO‡, SR~ | IM, SF | HK | NI, NG |
| H-RUN-01: Commit mediation | T08, T09 | EU†, GD, DO | — | — | IM, SF | HK | NI, NG, FS |
| H-RUN-02: Bounded approval | T08, T04 | EU†, GD, DO | — | CA, CO‡ | IM, SF | HK | NI, FS |
| H-RUN-03: Shared limits and revocation | T25, T24 | — | — | — | IM, SF | HK | NI, NG |
| H-RUN-04: Effect verification | T27, T18 | EU†, DO | PR | — | IM, SF | — | NI, NG, FS |
| H-RUN-05: Human intervention and halt | T04, T17 | EU†, GD, DO | — | CA, CO‡ | IM, SF | HK | NI, FS |
| H-MON-01: Correlated evidence | T15, T27 | EU†, GD, DO | PR | CO‡ | IM, SF | HK | NI, NG |
| H-MON-02: Tested monitor envelope | T16, T29 | EU†, DO | FC, PR | SR~ | IM | HK | NI, FS |
| H-MON-03: Integrity and access | T15, T07 | EU†, GD, DO | — | CA, CO‡ | IM, SF | HK | NI, NG |
| H-MON-04: Drift and evidence expiry | T16, T14 | EU†, DO | FC, PR | CA, CO‡, SR~ | IM | HK | NI, FS |
| H-MON-05: Outcome and incident feedback | T17, T23, T21 | EU†, GD, DO | FC | RB, CA, CO‡ | IM | HK | NI, NG, FS |
| H-MAS-01: Topology necessity | T24, T03 | EU†, GD | PR | CA, CO‡ | IM, SF | HK | NI, NG, IR*, FS |
| H-MAS-02: Constrained delegation | T24, T08, T25 | GD, DO | — | — | IM, SF | HK | NI, NG |
| H-MAS-03: Shared state discipline | T24, T10, T07 | GD | — | CA | IM, SF | HK | NI, NG |
| H-MAS-04: System-level evaluation | T24, T12 | EU†, DO | — | — | IM, SF | HK | NI, NG, FS |
| H-MAS-05: Descendant containment | T24, T17 | EU†, GD, DO | — | — | IM, SF | HK | NI, NG, FS |
| H-TPR-01: Dependency inventory | T19, T02 | EU†, GD, DO | PR | CO‡, SR~ | IM, SF | HK | NI, NG, FS |
| H-TPR-02: Evidence challenge | T19, T29 | EU†, GD, DO | PR | CO‡, SR~ | IM | HK | NI, NG, FS |
| H-TPR-03: Data and rights terms | T19, T07, T28 | EU†, GD, DO | PR | CA, CO‡ | IM | HK | NI, NG, FS |
| H-TPR-04: Change and incident notice | T19, T14, T17 | EU†, GD, DO | PR | CA, CO‡, SR~ | IM | HK | NI, NG, FS |
| H-TPR-05: Exit and continuity | T20, T18 | GD, DO | PR | — | IM | HK | NI, FS |
| H-ASR-01: Claim register | T15, T29 | EU†, GD, DO | PR | CO‡, SR~ | IM, SF | HK | NI, FS |
| H-ASR-02: Evidence validity | T29, T13 | DO | PR | SR~ | IM | — | NI, IS*, FS |
| H-ASR-03: Independent challenge | T13, T01 | EU†, DO | FC, PR | SR~ | IM | HK | NI, IS*, FS |
| H-ASR-04: Operating and recovery proof | T13, T27, T17 | EU†, GD, DO | PR | SR~ | IM, SF | — | NI, NG, IS*, FS |
| H-ASR-05: Retirement and custody | T20, T07 | GD, DO | — | CA | IM | HK | NI, NG, FS |
| H-FCO-01: Decision-path scope | T21, T03 | EU†, GD | FC, PR | RB, CA, CO‡ | IM | — | NI, NG, IR*, FS |
| H-FCO-02: Fairness and burden review | T21, T29 | EU† | FC, PR | RB, CA, SR~ | IM | — | NI, NG, FS |
| H-FCO-03: Actual reasons | T22, T27 | EU†, GD | FC, PR | RB, CA, CO‡ | IM, SF | HK | NI, NG, FS |
| H-FCO-04: Meaningful review | T04, T23 | EU†, GD | FC | CA, CO‡ | IM, SF | HK | NI, FS |
| H-FCO-05: Contest and remedy | T23, T21 | EU†, GD | FC | RB, CA, CO‡ | IM | HK | NI, NG |
Implementation specification
Compendium control
K.4 Important item-specific qualifications
| Item | Interpretation limit |
|---|---|
| GOV-02 | The original certifiable-management-system objective is a design intention, not evidence of readiness or conformity. The ISO mappings use public catalogue scope only; paid clauses and conformity were not inspected. |
| GOV-05 | Institutional model-risk coverage is a proposed governance choice. SR 26-2 expressly excludes generative and agentic AI; review qualifying traditional components separately. |
| DES-02 | Training-source tracing is an implementation aid. EU GPAI documentation duties concern covered model providers; inspect separate copyright and data-protection obligations. |
| RUN-18 | Required action evidence does not imply universal disclosure of raw reasoning traces. Record business-relevant actions and decisions with proportionate data safeguards. Apply defined retention periods, data minimisation, redaction and deletion to trajectory records. GDPR and California relationships describe an editorial evidence contribution, not demonstrated compliance. |
| MON-01 | Attribute each action to a unique executing-agent identity and retain the delegation lineage to the initiating agent and accountable principal. Single-agent attribution alone does not reconstruct responsibility across a multi-agent workflow. |
| MON-02 | Do not interpret record-keeping duties as a general obligation to retain or disclose raw model reasoning. Apply privacy, confidentiality, purpose and retention limits. |
| ASR-01 | An assurance chain can draw on several kinds of evidence. Certification is not a universal legal prerequisite or proof that every agent control works. |
| ASR-05 | AI management-system certification concerns the defined organisational scope. This map does not verify certificate validity, accreditation or individual control effectiveness. ISO mappings use public catalogue scope only; paid clauses and conformity were not inspected. |
| ASR-06 | ISO mappings use public catalogue scope only. Paid clauses and conformity were not inspected; the mapping is not clause-verified conformity evidence. |
| FCO-04 | A disparity measure and alternative-design search inform review; they do not alone determine a legal finding of discrimination or business necessity. |
| FCO-05 | The original guarantee is a design objective, not demonstrated legal sufficiency. For covered credit decisions, verify that notices state the actual, specific principal reasons and satisfy applicable Regulation B requirements; a generated explanation or this mapping does not establish notice adequacy. |
K.5 Working files and review cadence
Download the complete cross-tab, the explanation table, and the regulatory source register. All three are also included in the implementation kit.
This edition records a source review on 2 October 2026. The next monthly review is due 1 November 2026. Monthly reference updates provide supplementary findings; their publication does not silently change this dated legal map. Changed legal text, newly final guidance and applicability decisions require editorial review before the map’s review date advances.