Skip to content
BlueprintPage 45
45GOVERNANCE

Compliance & Governance Mapping

NIST AI RMF supports AI risk management; ISO/IEC 42001 defines an AI management system; EU AI Act obligations continue to phase into enforcement in 2026.

Priority
P1
Phase
Phase 2
Primary owner
GRC / Legal / Product
Status
Blueprint

Objective

Agent Trust Cloud should help customers operationalize AI governance frameworks without presenting itself as legal advice or automatic compliance certification. The product can map controls and evidence to recognized frameworks and regulations, while customers remain responsible for applicability and legal interpretation.

What to build

  • Control mapping library for NIST AI RMF, ISO/IEC 42001, NIST zero trust concepts and common security-control frameworks.
  • EU AI Act workflow support for inventory, documentation, risk records and incident/evidence processes where relevant.
  • Customer-specific internal AI policy mappings.
  • Gap dashboard: required control, implemented technical control, owner, evidence and exception.

Implementation decisions

  • Version framework mappings and show source/version dates.
  • Separate “technical evidence available” from “compliant” conclusions.
  • Allow customers/partners to add legal interpretation notes and applicability decisions.
  • Build exportable control/evidence packages for audit workflows.

Definition of done

  • Customers can map agent classes to required controls and evidence.
  • Framework updates can be applied without rewriting core policies.
  • Product wording does not promise certification or legal compliance automatically.

Success metrics

  • Mapped controls
  • Evidence coverage
  • Open governance gaps
  • Framework update latency

CURRENT BASELINE

NIST AI RMF supports AI risk management; ISO/IEC 42001 defines an AI management system; EU AI Act obligations continue to phase into enforcement in 2026.