Home The signal Anatomy of an agent Reference architecture Risk-Tiers Guardrail stack Governance in action Best practices Standards and crosswalk Implementation From the field Roadmap Companion toolkit Straight answers Glossary References
08 · Standards register

Fifteen rules, each one enforceable Author opinion

This is the register I would publish and hold teams to. The test for every entry is the same: name the mechanism that enforces it and the evidence it produces. A standard that fails that test is an aspiration, and aspirations do not survive an audit.

ONE CONTROL SET AS-01 … AS-15 enforced by a mechanism producing evidence MAINTAINED ONCE ISO/IEC 42001 i NIST AI RMF i NIST AI 600-1 i EU AI Act i IMDA dimensions i OWASP ASI i provider or deployer changes what applies CLICK A FRAMEWORK FOR WHAT IT IS AND WHERE IT LIVES
IDStandardEnforced byEvidence produced
AS-01Every agent is registered. Identity, accountable owner, purpose, tier, data classes, tools, expiry.Gateway rejects unregistered agent identitiesRegistry record, ownership attestation
AS-02Autonomy is tiered. R0 to R4 assigned by reversibility, blast radius, data sensitivity and regulatory scope.Tier is an attribute of the registry entry; controls attach to the tierRisk assessment, tier decision record
AS-03No standing credentials. Agents receive short-lived, narrowly scoped tokens at the point of use.Tool broker performs the exchange; secret scanning in CIToken issuance log with scope and TTL
AS-04Delegated authority never exceeds the principal. An agent acting for a person inherits that person's entitlements, no more.Policy decision point evaluates the propagated principal scope per callAuthorization decision log
AS-05One authoritative policy system, no ungoverned paths. Policy is authored and versioned once, then enforced at the gateway, tool broker, memory service, retrieval layer, workflow engine, model gateway and egress proxy.Deny-by-default egress plus conformance tests proving every enforcement point evaluates the same bundlePolicy version history, enforcement-point coverage report, exception register
AS-06Writes are idempotent and reversible. Every mutating tool declares an idempotency key and a compensating action.Tool contract test in CI; broker rejects non-conforming toolsContract test results, rollback rehearsal record
AS-07Budgets are bound at start. Steps, tokens, spend and wall clock declared per task and enforced at runtime.Gateway counters; breach halts the run and notifies the ownerPer-task cost and step telemetry
AS-08Untrusted content is screened both ways. Retrieved documents, tool responses and peer messages are treated as hostile input.Input and output guardrail services on the gateway pathScreening verdicts, blocked-event log
AS-09Memory carries provenance. Source, writing task, owning scope and expiry on every durable entry.Memory service schema; writes without provenance are rejectedMemory audit trail, deletion receipts
AS-10Tools and skills are signed and pinned. No unpinned remote definitions, no unreviewed public MCP servers.Private registry with signature verification at load timeSoftware bill of materials, scan results
AS-11Evidence is written before the action. Intent, decision and inputs are logged first; failed logging fails the action.Gateway write-ahead to the append-only decision logTamper-evident decision log
AS-12Releases pass published thresholds. Eval pass rate, injection resistance, cost per task and latency, agreed with the business.CI gate blocks promotion below thresholdEval report attached to the release
AS-13Production is continuously evaluated. Sampled runs scored, drift tracked, judge models re-calibrated against humans.Scheduled sampling jobs with alerting on trend breaksQuality trend, judge agreement rate
AS-14Stop works. Per-agent, per-tool and global kill switches, tested on a schedule.Control plane feature flags with independent operator accessKill-switch test log, incident drill report
AS-15Hard limits are deterministic. Tool and parameter allow-lists, value and rate caps, tenant and data boundaries, egress control and sandboxing are code, not model behaviour. Screening supplements them and never replaces them.Enforcement points reject out-of-envelope calls before executionEnvelope definition, rejected-call log, egress policy

The crosswalk Requirement Mapping is opinion

Maintain one control set and map it outward, so an auditor's question is answered from the same pipeline that runs the platform. Two cautions before you use this. ISO/IEC 42001 is an AI management system standard describing organizational capability, not a technical agent architecture, so these rows connect a technical control to the management-system control it produces evidence for. And EU AI Act duties differ by role, so the provider or deployer column matters as much as the article number.

ID Control ISO/IEC 42001 NIST AI RMF AI 600-1 area EU AI Act Role IMDA OWASP
AS-01Agent registrationA.3.2 · A.4.2 · A.6.2.2GV 1.3 · GV 2.1 · MP 1.1Accountability structuresArt. 11 · 16 · 26(1)P + DD1 · D2ASI03 · ASI10
AS-02Tiered autonomy by use case and actionA.5.2 · A.5.4 · A.6.2.2MP 1.1 · MP 5.1 · MS 1.1Context and risk framingArt. 9PD1ASI03 · ASI08
AS-03No standing credentialsA.6.2.6 + 27001 A.5.15–18GV 6.1 · MG 2.2Access and credential controlsArt. 15PD3ASI03 · ASI05
AS-04Delegated authority never exceeds the principalA.3.2 · A.6.2.6GV 1.3 · MG 2.2Roles and delegationArt. 14 · 26DD2 · D3ASI03 · ASI09
AS-05One authoritative policy system, no ungoverned pathsA.2.2 · A.6.2.6 · A.9.2GV 1.2 · MG 1.3Policy and processArt. 15PD3ASI02 · ASI10
AS-06Idempotent and reversible writesA.6.2.4 · A.6.2.6MG 2.3 · MG 4.1Incident response and recoveryArt. 14(4) · 15PD3ASI02 · ASI08
AS-07Budgets bound at task startA.4.3 · A.6.2.6MG 2.2 · MS 2.6Resource and reliabilityArt. 15PD3ASI08
AS-08Untrusted content screened both waysA.6.2.4 · A.7.4MS 2.7 · MG 2.2Security and resilience testingArt. 15PD3ASI01 · ASI06 · ASI07
AS-09Memory carries provenanceA.6.2.6 · A.7.2 · A.7.5MP 4.1 · MS 2.8 · MG 4.1Provenance and data lineageArt. 10 · 12PD3ASI06
AS-10Tools and skills signed and pinnedA.9.2 · A.9.3GV 6.1 · MP 4.1Third party and supply chainArt. 15 · 25PD3ASI04
AS-11Evidence written before the actionA.5.3 · A.6.2.6MS 1.1 · MG 4.1Monitoring and record-keepingArt. 12 · 19 · 26(6)P + DD2 · D3ASI09 · ASI10
AS-12Releases pass published thresholdsA.6.2.4 · A.6.2.5MS 2.3 · MS 4.2 · MG 1.3Pre-deployment testingArt. 9 · 15 · 17PD1 · D3ASI01 · ASI08
AS-13Production continuously evaluatedCl. 9.1 · A.6.2.6MS 2.4 · MG 4.1Post-deployment monitoringArt. 72 · 26(5)P + DD3ASI06 · ASI08
AS-14Stop worksCl. 10.2 · A.6.2.6MG 2.3 · MG 4.1Incident containmentArt. 14(4)(e) · 26P + DD2 · D3ASI08 · ASI10
AS-15Hard limits are deterministicA.6.2.4 · A.6.2.6MG 2.2 · MS 2.7Technical safeguardsArt. 15PD3ASI02 · ASI03 · ASI05
GV govern · MP map · MS measure · MG manage P provider · D deployer D1–D4 IMDA dimensions Cl. = ISO 42001 main clause
Use this to scope, not to certify. Every row is a starting position for a conversation with your assessor, your counsel and your own Statement of Applicability. Determine your provider or deployer role per system first, because it changes which obligations attach at all. Artifact 03 has the same crosswalk as a spreadsheet with applicability, owner, status and evidence-location columns ready to fill in.
The two controls most often missing from agent designs. AS-11, evidence written before the action rather than after it, and AS-14, a stop that has actually been tested. Both are cheap to build early and close to impossible to retrofit convincingly once an incident has already happened.

Where would you start?

If you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.