Governance crosswalk
What
This selected crosswalk relates existing rule-inventory controls to external guidance. It is a navigation aid for an adopter's assessment, not certification, a conformance verdict, a complete framework assessment or evidence of effective operation. Numeric control IDs below identify inventory rows, not the separate historical R-number labels.
Why
Security and governance reviewers need a traceable starting point. Each relationship is an S4U editorial judgement; an inventory entry or passing structural check cannot establish that an adopter installed, exercised or measured the control. Every row retains a limit.
Evidence and pinned scope
Sources checked on 2026-09-22:
- OWASP's Agentic Top 10 announcement, 9 December 2025: ASI01–ASI10 for the 2026 edition. Labels below describe the risks briefly; consult the publisher for full entries.
- NIST AI RMF Core, AI RMF 1.0 (2023): GOVERN, MAP, MEASURE and MANAGE. The site reports revision work in progress; this map stays pinned to 1.0.
NIST-prefixes below are local namespaces for those official function names, not claimed subcategory IDs. - ISO's public standard summary, ISO/IEC 42001:2023, edition 1 (December 2023): organizational AI management systems. This public summary supports a standard-level relationship only. No licensed clause text was inspected or reproduced, and clause/annex coverage remains unassessed.
- FINOS AIR-PREV-018, undated web catalogue checked on the date above: scoped agent access, time limits and separation of duties. This is one selected entry, not coverage of the full FINOS catalogue.
The committed governance/external-items-v1.json pins these IDs, editions, sources and check
dates. A changed web page does not silently update the map. CI does not contact publishers
or prove source freshness; review changes against the cited primary source before repinning.
Related controls
| Control IDs | External ID | Relation | Scope and limits |
|---|---|---|---|
| 128, 132 | ASI01 | related to | Instruction/data separation and scoped permission; no claim of complete injection prevention. |
| 131, 132 | ASI02 | related to | Provenance and effect authorization; tool parameter enforcement depends on the adopter. |
| 115, 132 | ASI03 | related to | Permission-mode decisions and scoped mandates; no shipped identity federation or runtime access manager. |
| 131 | ASI04 | related to | Trusted origin and pinned tool versions; advisory provenance does not attest to dependency integrity. |
| 128, 132 | ASI05 | related to | Untrusted content and effect boundaries; actual process isolation remains host-specific. |
| 70, 71, 72, 128 | ASI06 | related to | Memory provenance and rechecking claims; no automatic poison detector is supplied. |
| 38, 59, 132 | ASI07 | related to | Explicit ownership and rechecked authority; transport authentication and replay protection need adopter implementation. |
| 118, 124, 125 | ASI08 | related to | Shared-resource coordination and bounded incident recovery; no runtime cascade circuit breaker is shipped. |
| 3, 36, 132 | ASI09 | related to | Evidence review and consequence-based decisions; approval fatigue is addressed without measuring individual trust. |
| 59, 118, 132 | ASI10 | related to | Revocation checks and writer coordination; declarations do not establish effective cancellation or fencing. |
| 41, 82, 132 | NIST-GOVERN | related to | Adopted profiles, applicable obligations and accountable permission; selected relationships only, not a full subcategory assessment. |
| 15, 121 | NIST-MAP | related to | Decision context, inception scenarios and threats; broader organizational and societal impacts still need assessment. |
| 4, 78, 137 | NIST-MEASURE | related to | Subject-bound evidence and adverse expectations; software tests are only part of AI risk measurement. |
| 119, 124, 125 | NIST-MANAGE | related to | Named incident roles, scoped mitigation and learning; no enterprise risk-management system is supplied. |
| 41, 82, 132 | ISO/IEC-42001:2023 | related to | Policy, scope and accountability relate at standard level only; clauses, annex controls and certification coverage are unassessed. |
| 115, 118, 132 | AIR-PREV-018 | related to | Scoped authority, coordination and human decisions; adapters must implement and test access restriction, expiry and privilege separation. |
The three approval decisions
S4U separates approval of meaning by its accountable business owner, a bounded and expiring execution mandate, and a release decision on verification evidence. See business intent lifecycle and governed factory. These are distinct decisions with different subjects; one does not imply the others.
The consulted OWASP/NIST/FINOS material supports risk, authority and review concerns but does not state this exact S4U three-artifact protocol. FINOS does explicitly discuss separation of duties; this crosswalk does not claim that S4U invented that principle. ISO clause-level comparison is unassessed. The S4U split is an implementation choice, not evidence of superiority or satisfaction of an external requirement.
How to maintain and use it
The methodology maintainer reviews this map at release review and when adopting a changed
external edition; an adopter's accountable governance owner assesses actual applicability
and retained evidence. Run bash scripts/check-governance-crosswalk.sh after editing the
map, pin list or inventory. CI checks that the nonempty mapping table references active
inventory rows and pinned IDs with source/date metadata, uses only related to or informs,
and covers every item in this deliberately selected pin list. Unknown, retired, duplicate
or malformed references fail. It does not assess the meaning of a mapping or scan prose
for every possible overclaim.
Cost is one local parse of three committed files, with no model or network use. Repinning, retiring a mapping or changing scope needs source review and the same tests; do not silently renumber inventory controls or replace a missing relationship with a compliance assertion. An adopter can document a different mapping with its rationale and owner; the kit's page does not grant operational authority or impose a new gate on adopter repositories.