The Agent Estate Standard · v1.0

Framework Mappings


This is Appendix C of The Agent Estate Standard v1.0. Read the full Standard.

Appendix C: Regulatory and Framework Mappings

Status: informative. Nothing in this appendix creates a requirement. Conformance with the Agent Estate Standard is determined solely by Section 7.

Verified: July 2026. Several frameworks referenced here revise frequently. AIUC-1 updates quarterly. The IMDA framework moved from v1.0 to v1.5 within four months of release. Verify against the current published version of any framework before relying on a mapping.


C.1 Why this appendix exists

Between January and February 2026, four significant agentic AI frameworks published within six weeks of each other. A reasonable question follows: does an enterprise that has adopted one of them need this Standard as well?

The answer turns on what each framework is for.

The frameworks listed here assess whether an agent should be allowed to operate. They address risk, safety, security, identity and compliance. They are the right instruments for those questions and this Standard does not attempt to replace any of them.

This Standard addresses whether an agent is still worth operating, and who answers for it. Accountability by name, economics per outcome, promotion evidence, review cadence, retirement.

Both questions have to be answered. Neither answers the other.


C.2 How to read the mappings

Each table shows where a requirement of this Standard supports an obligation or control area in the named framework. A mapping means the Standard's requirement produces evidence that is useful to the other framework. It does not mean satisfying one satisfies the other.

Mappings are stated at the level the source framework publishes at. Where a framework publishes numbered articles or clauses, those are cited. Where a framework publishes dimensions or pillars, those are cited.


C.3 NIST AI Risk Management Framework (AI 100-1)

Four functions: Govern, Map, Measure, Manage.

AI RMF functionSupported by
GovernSection 3 (four roles), 5.1 (estate review with decision rights), 7.2.1 (named Business Owner), 7.2.4 (accountabilities assigned)
MapSection 2 (Agent Record), 2.2 (identity block), 7.1 (register coverage), Section 4 (control surfaces)
Measure4.2 (numeric thresholds), Section 6 (cost per successful outcome), 6.2 (negative unit economics test)
Manage5.2 (promotion gates), 5.3 (review cadence), 5.5 (retirement), 7.3.7 (evidenced retirement or demotion)

What the Standard adds: AI RMF is risk-management guidance without a certification path and without a defined unit of management. This Standard supplies the unit, being the Agent Record, and the cadence that operates on it.


C.4 NIST AI Agent Standards Initiative (CAISI, February 2026)

Three pillars: industry-led standards, open-source protocol development, and security and identity research. The associated NCCoE concept paper addresses agent identity and authorisation, covering authentication, authorisation, auditing, non-repudiation and prompt injection mitigation.

Initiative areaSupported by
Agent identity2.2 field 1 (organisation-assigned persistent ID, independent of vendor identifier)
Authorisation2.3 field 13 (autonomy level), optional field for systems and data accessed
Auditing and non-repudiation7.3.8 (records traceable without reconstruction), 5.1.4 (decisions recorded within five working days)
Lifecycle5.2 (promotion), 5.5 (retirement including credential revocation)

What the Standard adds: the Initiative addresses identity and security. It does not address business accountability or economics. Field 1 of the Agent Record is deliberately specified to survive platform migration, which vendor-assigned identity does not.


C.5 ISO/IEC 42001:2023, AI Management Systems

Certifiable through accredited bodies. Targets the management system rather than agent behaviour.

ISO/IEC 42001 areaSupported by
Clause 5, leadership and rolesSection 3 (four roles), 3.7 (named individuals per agent)
Clause 6, planning and objectives2.3 field 10 (stated outcome), field 11 (baseline), 6.4 (operating cost planning)
Clause 8, operationSection 5 in full (promotion, review, reconciliation, retirement)
Clause 9, performance evaluationSection 4 (control surfaces and triggers), Section 6 (estate economics), 5.1 (estate review)
Clause 10, improvement5.5.2 (retirement criteria revision with recorded reason), CC change control
AI system lifecycle controls5.2 (promotion gates), 5.5 (retirement)
AI system impact assessment2.3 fields 10 to 14, 5.2.2 (promotion evidence)

What the Standard adds: ISO/IEC 42001 requires a management system and leaves the operational unit undefined. An organisation can hold 42001 certification and still be unable to name the owner of a given agent. This Standard makes the agent the unit and the owner a required field.


C.6 EU AI Act

Article numbers refer to Regulation (EU) 2024/1689. Applicability depends on risk classification and on whether the organisation is a provider or a deployer.

EU AI Act obligationSupported by
Art. 9, risk management systemSection 4 (control surfaces), 4.1 to 4.3 (triggers per surface)
Art. 12, record-keeping and loggingSection 2 (Agent Record), 2.7 (record integrity), 7.3.8 (traceable records)
Art. 14, human oversight2.3 field 13 (autonomy level), field 14 (escalation point), 5.1.2 (authority to demote)
Art. 15, accuracy and robustness4.2 (numeric thresholds), 1.6 (successful outcome definition excluding reworked output)
Art. 17, quality management systemSection 5 (operating cadence), Section 3 (roles)
Art. 26, deployer obligations7.2.1 (named Business Owner), 2.3 field 14 (escalation), 5.3 (review cadence)
Art. 72, post-market monitoring5.3 (review cadence), 5.4 (reconciliation), 4.4 (trigger monitoring)

What the Standard adds: the Act imposes obligations without specifying the operating rhythm that discharges them. Requirement 5.3.3, review within ten working days of a detected trigger breach, is the kind of operational specificity the Act assumes and does not provide.


C.7 Singapore IMDA Model AI Governance Framework for Agentic AI

Launched 22 January 2026, revised to v1.5 on 20 May 2026. Voluntary and non-binding. Four dimensions.

IMDA dimensionSupported by
1. Assessing and bounding risks upfront5.2 (promotion gates), 5.2.2 (promotion evidence requirements), 2.3 field 13 (autonomy level)
2. Making humans meaningfully accountable7.2.1 (Business Owner as named individual), 3.7 (accountabilities assigned), 7.2.5 (zero orphans)
3. Implementing technical controls and processesSection 4 (five control surfaces), 4.2 (numeric thresholds), 5.5.3 (credential revocation on retirement)
4. Enabling end-user responsibility2.3 field 14 (escalation point with stated response time), 2.2 field 3 (purpose stated in non-specialist terms)

Alignment note. Dimension 2 is the closest external alignment to this Standard's Level 2. IMDA states the principle that humans must be meaningfully accountable. This Standard states the requirement that makes it verifiable: field 9 must hold a named individual, and a team, role, committee or distribution list must not be recorded in it.

v1.5 adds treatment of agent sprawl and multi-agent systemic risk. Sections 5.4 (reconciliation) and 7.1.4 (stated coverage figure) address the measurement side of sprawl directly.


C.8 AIUC-1

A certification standard for AI agents, issued by the Artificial Intelligence Underwriting Company. Six control domains, updated quarterly, certificates valid twelve months with quarterly technical retesting.

AIUC-1 domainSupported by
Accountability7.2 in full (Level 2), Section 3 (roles)
Reliability4.2 (thresholds), 1.6 (successful outcome definition), 5.3.3 (triggered review)
Safety5.1.2 (authority to demote or retire), 2.3 field 14 (escalation)
SecurityNot addressed. Out of scope per this Standard's Scope statement.
Data and PrivacyNot addressed. Optional field for data classification only.
SocietyNot addressed.

Relationship. AIUC-1 certifies the agent or the vendor supplying it. This Standard addresses the estate operating it. An enterprise could hold AIUC-1 certification for every purchased agent and still have no register, no named owners and no retirement decisions. The two operate at different levels and the overlap is limited to the Accountability and Reliability domains.


C.9 APRA CPS 230, Operational Risk Management

Applies to APRA-regulated entities in Australia. Effective 1 July 2025.

CPS 230 areaSupported by
Identification of critical operations5.3.2 and 5.3.4 (materiality threshold defined and stated), 2.2 field 7 (business unit)
Operational risk profileSection 4 (control surfaces), 4.1 (triggers per surface per agent)
Tolerance levels4.2 (thresholds expressed as values), 6.2 (negative unit economics test)
Monitoring and escalation4.4 (trigger monitoring), 2.3 field 14 (escalation point and response time)
Register of material arrangementsSection 2 (Agent Record), Section 7.1 (register with stated coverage)
Board and management accountabilitySection 3 (roles), 5.1 (estate review with decision rights)

Note for regulated entities. Where agents perform work inside a critical operation, the materiality threshold required by 5.3.4 should be set to align with the entity's existing critical operations definition rather than defined independently. Two thresholds that disagree will produce two answers to the same question.


C.10 Reverse map: what remains after compliance

The practical version of this appendix. If an organisation already holds or follows the framework in the left column, the right column states what this Standard adds that the framework does not require.

If you already haveThis Standard still adds
An agent registry (Agent 365, Workday ASOR, ServiceNow)Fields 9 to 19. Business ownership by name, stated outcome and baseline, cost per successful outcome, promotion evidence, review triggers, retirement criteria. No registry holds any of these.
ISO/IEC 42001 certificationThe agent as the unit of management, a named owner per agent, and cost per successful outcome. A certified management system does not require either.
NIST AI RMF adoptionA defined register, a promotion gate, a review cadence with authority to retire, and an evidenced retirement.
EU AI Act complianceThe operating rhythm. The Act states what must be true. It does not state the cadence, the forum, or who holds the decision.
IMDA MGF conformanceThe verifiable form of Dimension 2. Accountability recorded as a named individual, with the orphan count required to be zero.
AIUC-1 certificationEverything above the individual agent. The estate, the register, the economics and the retirement decision.
CPS 230 complianceAgent-level granularity inside the critical operation, and the economics test that CPS 230 does not contemplate.

C.11 What this Standard does not claim

It does not confer compliance with any framework listed here.

It does not substitute for a risk assessment, a conformity assessment, a security review or a data protection impact assessment.

It does not address whether an agent is safe, secure, lawful or fair to deploy. Those questions come first and are answered elsewhere.

It addresses what happens after the agent is running, which is the question none of the frameworks above were built to answer.



← The full Standard (v1.0)