Standards mapping

Connect each finding to guidance your team already recognises.

Mappings help security, engineering and governance teams communicate. They show which guidance is relevant to a finding; they do not turn a proprietary assessment into certification.

Framework families

Different guidance covers different parts of the system.

Agent behaviour

OWASP Agentic AI guidance

Excessive agency, tool misuse, identity and privilege abuse, memory risks, cascading failures and human-control boundaries.

Model application

OWASP LLM Top 10

Prompt injection, sensitive information disclosure, insecure output handling, excessive agency and supply-chain exposure.

Risk management

NIST AI RMF

Govern, map, measure and manage organisational AI risk with explicit context, accountability and monitoring.

Software assurance

NIST SSDF and SLSA

Secure development, provenance, dependency integrity, build evidence and model or package supply-chain controls.

How mappings appear

The finding remains the source of truth.

A framework label is useful only when scope, evidence, severity and remediation are still visible.

  1. 1

    Identify the assessed system and version

    Record the agent, environment, tools, data and exclusions.

  2. 2

    State the evidence and finding

    Show whether it was declared, observed, reproduced or recorded at runtime.

  3. 3

    Map relevant guidance

    Reference the control or risk category that helps the owner understand the expectation.

  4. 4

    Keep the limitation

    A mapping is not proof of compliance, certification or complete framework coverage.

Trust statement

Framework-aligned does not mean certified.

AgentRiskLayer Security Assessment — assessed against AgentRiskLayer Control Profile vX.Y. This proprietary assessment is not an accredited certification or a guarantee that the system is risk-free.