Status: informative. Nothing in this appendix creates a requirement. Conformance with the Agent Estate Standard is determined solely by Section 7.
Verified: July 2026. Several frameworks referenced here revise frequently. AIUC-1 updates quarterly. The IMDA framework moved from v1.0 to v1.5 within four months of release. Verify against the current published version of any framework before relying on a mapping.
Between January and February 2026, four significant agentic AI frameworks published within six weeks of each other. A reasonable question follows: does an enterprise that has adopted one of them need this Standard as well?
The answer turns on what each framework is for.
The frameworks listed here assess whether an agent should be allowed to operate. They address risk, safety, security, identity and compliance. They are the right instruments for those questions and this Standard does not attempt to replace any of them.
This Standard addresses whether an agent is still worth operating, and who answers for it. Accountability by name, economics per outcome, promotion evidence, review cadence, retirement.
Both questions have to be answered. Neither answers the other.
Each table shows where a requirement of this Standard supports an obligation or control area in the named framework. A mapping means the Standard's requirement produces evidence that is useful to the other framework. It does not mean satisfying one satisfies the other.
Mappings are stated at the level the source framework publishes at. Where a framework publishes numbered articles or clauses, those are cited. Where a framework publishes dimensions or pillars, those are cited.
Four functions: Govern, Map, Measure, Manage.
| AI RMF function | Supported by |
|---|---|
| Govern | Section 3 (four roles), 5.1 (estate review with decision rights), 7.2.1 (named Business Owner), 7.2.4 (accountabilities assigned) |
| Map | Section 2 (Agent Record), 2.2 (identity block), 7.1 (register coverage), Section 4 (control surfaces) |
| Measure | 4.2 (numeric thresholds), Section 6 (cost per successful outcome), 6.2 (negative unit economics test) |
| Manage | 5.2 (promotion gates), 5.3 (review cadence), 5.5 (retirement), 7.3.7 (evidenced retirement or demotion) |
What the Standard adds: AI RMF is risk-management guidance without a certification path and without a defined unit of management. This Standard supplies the unit, being the Agent Record, and the cadence that operates on it.
Three pillars: industry-led standards, open-source protocol development, and security and identity research. The associated NCCoE concept paper addresses agent identity and authorisation, covering authentication, authorisation, auditing, non-repudiation and prompt injection mitigation.
| Initiative area | Supported by |
|---|---|
| Agent identity | 2.2 field 1 (organisation-assigned persistent ID, independent of vendor identifier) |
| Authorisation | 2.3 field 13 (autonomy level), optional field for systems and data accessed |
| Auditing and non-repudiation | 7.3.8 (records traceable without reconstruction), 5.1.4 (decisions recorded within five working days) |
| Lifecycle | 5.2 (promotion), 5.5 (retirement including credential revocation) |
What the Standard adds: the Initiative addresses identity and security. It does not address business accountability or economics. Field 1 of the Agent Record is deliberately specified to survive platform migration, which vendor-assigned identity does not.
Certifiable through accredited bodies. Targets the management system rather than agent behaviour.
| ISO/IEC 42001 area | Supported by |
|---|---|
| Clause 5, leadership and roles | Section 3 (four roles), 3.7 (named individuals per agent) |
| Clause 6, planning and objectives | 2.3 field 10 (stated outcome), field 11 (baseline), 6.4 (operating cost planning) |
| Clause 8, operation | Section 5 in full (promotion, review, reconciliation, retirement) |
| Clause 9, performance evaluation | Section 4 (control surfaces and triggers), Section 6 (estate economics), 5.1 (estate review) |
| Clause 10, improvement | 5.5.2 (retirement criteria revision with recorded reason), CC change control |
| AI system lifecycle controls | 5.2 (promotion gates), 5.5 (retirement) |
| AI system impact assessment | 2.3 fields 10 to 14, 5.2.2 (promotion evidence) |
What the Standard adds: ISO/IEC 42001 requires a management system and leaves the operational unit undefined. An organisation can hold 42001 certification and still be unable to name the owner of a given agent. This Standard makes the agent the unit and the owner a required field.
Article numbers refer to Regulation (EU) 2024/1689. Applicability depends on risk classification and on whether the organisation is a provider or a deployer.
| EU AI Act obligation | Supported by |
|---|---|
| Art. 9, risk management system | Section 4 (control surfaces), 4.1 to 4.3 (triggers per surface) |
| Art. 12, record-keeping and logging | Section 2 (Agent Record), 2.7 (record integrity), 7.3.8 (traceable records) |
| Art. 14, human oversight | 2.3 field 13 (autonomy level), field 14 (escalation point), 5.1.2 (authority to demote) |
| Art. 15, accuracy and robustness | 4.2 (numeric thresholds), 1.6 (successful outcome definition excluding reworked output) |
| Art. 17, quality management system | Section 5 (operating cadence), Section 3 (roles) |
| Art. 26, deployer obligations | 7.2.1 (named Business Owner), 2.3 field 14 (escalation), 5.3 (review cadence) |
| Art. 72, post-market monitoring | 5.3 (review cadence), 5.4 (reconciliation), 4.4 (trigger monitoring) |
What the Standard adds: the Act imposes obligations without specifying the operating rhythm that discharges them. Requirement 5.3.3, review within ten working days of a detected trigger breach, is the kind of operational specificity the Act assumes and does not provide.
Launched 22 January 2026, revised to v1.5 on 20 May 2026. Voluntary and non-binding. Four dimensions.
| IMDA dimension | Supported by |
|---|---|
| 1. Assessing and bounding risks upfront | 5.2 (promotion gates), 5.2.2 (promotion evidence requirements), 2.3 field 13 (autonomy level) |
| 2. Making humans meaningfully accountable | 7.2.1 (Business Owner as named individual), 3.7 (accountabilities assigned), 7.2.5 (zero orphans) |
| 3. Implementing technical controls and processes | Section 4 (five control surfaces), 4.2 (numeric thresholds), 5.5.3 (credential revocation on retirement) |
| 4. Enabling end-user responsibility | 2.3 field 14 (escalation point with stated response time), 2.2 field 3 (purpose stated in non-specialist terms) |
Alignment note. Dimension 2 is the closest external alignment to this Standard's Level 2. IMDA states the principle that humans must be meaningfully accountable. This Standard states the requirement that makes it verifiable: field 9 must hold a named individual, and a team, role, committee or distribution list must not be recorded in it.
v1.5 adds treatment of agent sprawl and multi-agent systemic risk. Sections 5.4 (reconciliation) and 7.1.4 (stated coverage figure) address the measurement side of sprawl directly.
A certification standard for AI agents, issued by the Artificial Intelligence Underwriting Company. Six control domains, updated quarterly, certificates valid twelve months with quarterly technical retesting.
| AIUC-1 domain | Supported by |
|---|---|
| Accountability | 7.2 in full (Level 2), Section 3 (roles) |
| Reliability | 4.2 (thresholds), 1.6 (successful outcome definition), 5.3.3 (triggered review) |
| Safety | 5.1.2 (authority to demote or retire), 2.3 field 14 (escalation) |
| Security | Not addressed. Out of scope per this Standard's Scope statement. |
| Data and Privacy | Not addressed. Optional field for data classification only. |
| Society | Not addressed. |
Relationship. AIUC-1 certifies the agent or the vendor supplying it. This Standard addresses the estate operating it. An enterprise could hold AIUC-1 certification for every purchased agent and still have no register, no named owners and no retirement decisions. The two operate at different levels and the overlap is limited to the Accountability and Reliability domains.
Applies to APRA-regulated entities in Australia. Effective 1 July 2025.
| CPS 230 area | Supported by |
|---|---|
| Identification of critical operations | 5.3.2 and 5.3.4 (materiality threshold defined and stated), 2.2 field 7 (business unit) |
| Operational risk profile | Section 4 (control surfaces), 4.1 (triggers per surface per agent) |
| Tolerance levels | 4.2 (thresholds expressed as values), 6.2 (negative unit economics test) |
| Monitoring and escalation | 4.4 (trigger monitoring), 2.3 field 14 (escalation point and response time) |
| Register of material arrangements | Section 2 (Agent Record), Section 7.1 (register with stated coverage) |
| Board and management accountability | Section 3 (roles), 5.1 (estate review with decision rights) |
Note for regulated entities. Where agents perform work inside a critical operation, the materiality threshold required by 5.3.4 should be set to align with the entity's existing critical operations definition rather than defined independently. Two thresholds that disagree will produce two answers to the same question.
The practical version of this appendix. If an organisation already holds or follows the framework in the left column, the right column states what this Standard adds that the framework does not require.
| If you already have | This Standard still adds |
|---|---|
| An agent registry (Agent 365, Workday ASOR, ServiceNow) | Fields 9 to 19. Business ownership by name, stated outcome and baseline, cost per successful outcome, promotion evidence, review triggers, retirement criteria. No registry holds any of these. |
| ISO/IEC 42001 certification | The agent as the unit of management, a named owner per agent, and cost per successful outcome. A certified management system does not require either. |
| NIST AI RMF adoption | A defined register, a promotion gate, a review cadence with authority to retire, and an evidenced retirement. |
| EU AI Act compliance | The operating rhythm. The Act states what must be true. It does not state the cadence, the forum, or who holds the decision. |
| IMDA MGF conformance | The verifiable form of Dimension 2. Accountability recorded as a named individual, with the orphan count required to be zero. |
| AIUC-1 certification | Everything above the individual agent. The estate, the register, the economics and the retirement decision. |
| CPS 230 compliance | Agent-level granularity inside the critical operation, and the economics test that CPS 230 does not contemplate. |
It does not confer compliance with any framework listed here.
It does not substitute for a risk assessment, a conformity assessment, a security review or a data protection impact assessment.
It does not address whether an agent is safe, secure, lawful or fair to deploy. Those questions come first and are answered elsewhere.
It addresses what happens after the agent is running, which is the question none of the frameworks above were built to answer.