Skip to main content

Governance crosswalk

What

This selected crosswalk relates existing rule-inventory controls to external guidance. It is a navigation aid for an adopter's assessment, not certification, a conformance verdict, a complete framework assessment or evidence of effective operation. Numeric control IDs below identify inventory rows, not the separate historical R-number labels.

Why

Security and governance reviewers need a traceable starting point. Each relationship is an S4U editorial judgement; an inventory entry or passing structural check cannot establish that an adopter installed, exercised or measured the control. Every row retains a limit.

Evidence and pinned scope

Sources checked on 2026-09-22:

  • OWASP's Agentic Top 10 announcement, 9 December 2025: ASI01–ASI10 for the 2026 edition. Labels below describe the risks briefly; consult the publisher for full entries.
  • NIST AI RMF Core, AI RMF 1.0 (2023): GOVERN, MAP, MEASURE and MANAGE. The site reports revision work in progress; this map stays pinned to 1.0. NIST- prefixes below are local namespaces for those official function names, not claimed subcategory IDs.
  • ISO's public standard summary, ISO/IEC 42001:2023, edition 1 (December 2023): organizational AI management systems. This public summary supports a standard-level relationship only. No licensed clause text was inspected or reproduced, and clause/annex coverage remains unassessed.
  • FINOS AIR-PREV-018, undated web catalogue checked on the date above: scoped agent access, time limits and separation of duties. This is one selected entry, not coverage of the full FINOS catalogue.

The committed governance/external-items-v1.json pins these IDs, editions, sources and check dates. A changed web page does not silently update the map. CI does not contact publishers or prove source freshness; review changes against the cited primary source before repinning.

Control IDsExternal IDRelationScope and limits
128, 132ASI01related toInstruction/data separation and scoped permission; no claim of complete injection prevention.
131, 132ASI02related toProvenance and effect authorization; tool parameter enforcement depends on the adopter.
115, 132ASI03related toPermission-mode decisions and scoped mandates; no shipped identity federation or runtime access manager.
131ASI04related toTrusted origin and pinned tool versions; advisory provenance does not attest to dependency integrity.
128, 132ASI05related toUntrusted content and effect boundaries; actual process isolation remains host-specific.
70, 71, 72, 128ASI06related toMemory provenance and rechecking claims; no automatic poison detector is supplied.
38, 59, 132ASI07related toExplicit ownership and rechecked authority; transport authentication and replay protection need adopter implementation.
118, 124, 125ASI08related toShared-resource coordination and bounded incident recovery; no runtime cascade circuit breaker is shipped.
3, 36, 132ASI09related toEvidence review and consequence-based decisions; approval fatigue is addressed without measuring individual trust.
59, 118, 132ASI10related toRevocation checks and writer coordination; declarations do not establish effective cancellation or fencing.
41, 82, 132NIST-GOVERNrelated toAdopted profiles, applicable obligations and accountable permission; selected relationships only, not a full subcategory assessment.
15, 121NIST-MAPrelated toDecision context, inception scenarios and threats; broader organizational and societal impacts still need assessment.
4, 78, 137NIST-MEASURErelated toSubject-bound evidence and adverse expectations; software tests are only part of AI risk measurement.
119, 124, 125NIST-MANAGErelated toNamed incident roles, scoped mitigation and learning; no enterprise risk-management system is supplied.
41, 82, 132ISO/IEC-42001:2023related toPolicy, scope and accountability relate at standard level only; clauses, annex controls and certification coverage are unassessed.
115, 118, 132AIR-PREV-018related toScoped authority, coordination and human decisions; adapters must implement and test access restriction, expiry and privilege separation.

The three approval decisions

S4U separates approval of meaning by its accountable business owner, a bounded and expiring execution mandate, and a release decision on verification evidence. See business intent lifecycle and governed factory. These are distinct decisions with different subjects; one does not imply the others.

The consulted OWASP/NIST/FINOS material supports risk, authority and review concerns but does not state this exact S4U three-artifact protocol. FINOS does explicitly discuss separation of duties; this crosswalk does not claim that S4U invented that principle. ISO clause-level comparison is unassessed. The S4U split is an implementation choice, not evidence of superiority or satisfaction of an external requirement.

How to maintain and use it

The methodology maintainer reviews this map at release review and when adopting a changed external edition; an adopter's accountable governance owner assesses actual applicability and retained evidence. Run bash scripts/check-governance-crosswalk.sh after editing the map, pin list or inventory. CI checks that the nonempty mapping table references active inventory rows and pinned IDs with source/date metadata, uses only related to or informs, and covers every item in this deliberately selected pin list. Unknown, retired, duplicate or malformed references fail. It does not assess the meaning of a mapping or scan prose for every possible overclaim.

Cost is one local parse of three committed files, with no model or network use. Repinning, retiring a mapping or changing scope needs source review and the same tests; do not silently renumber inventory controls or replace a missing relationship with a compliance assertion. An adopter can document a different mapping with its rationale and owner; the kit's page does not grant operational authority or impose a new gate on adopter repositories.