Transparent coverage

Every technical finding maps to recognised guidance.

Mappings provide traceability, not certification. A mapped finding shows why a control matters and where remediation supports a broader framework.

OWASP Agentic & AI Agent Security

Tool misuse, excessive agency, memory poisoning, human approval, output validation, data protection, monitoring and resource limits.

OWASP LLM Top 10

Supply-chain exposure, improper output handling and unbounded consumption are mapped directly from observed technical evidence.

NIST AI RMF

GOVERN, MEASURE and MANAGE references connect technical findings with risk ownership, evaluation and treatment activities.

SLSA and NIST SSDF

CI/CD, immutable dependencies, build integrity, repository governance and vulnerability-reporting controls.

How coverage appears in evidence

FindingObserved riskExample mapping
ARL-MCP-001Shell-capable agent toolOWASP Agentic: Tool Misuse
ARL-AI-008Unscoped persistent memoryOWASP Agentic: Memory Poisoning
ARL-CICD-001Broad workflow permissionsNIST AI RMF GOVERN 1.7
ARL-DEP-001Missing dependency lockfileSLSA Build

The complete machine-readable mapping is published in the Inspector policy catalogue and embedded in SARIF rules.

Open complete policy catalogue Run a scan
Honest scope: AgentRiskLayer does not currently claim ISO 42001, EU AI Act, SOC 2 or any other certification. Those require organisation-specific legal, governance and audit evidence beyond this automated technical assessment.