Standards and guidance
AI Agent Security Standards & Regulatory References
Certification schemes, management system standards, risk frameworks and laws serve different purposes.
Standards and guidance
AIUC-1
An AI security, safety and reliability certification scheme maintained by AIUC.
OWASP Top 10 for Agentic Applications
A risk taxonomy and mitigation resource for agentic applications, rather than a certification scheme.
ETSI AI cybersecurity baseline
ETSI EN 304 223 sets baseline cybersecurity requirements for AI systems and models across their lifecycle.
EU AI Act
The AI Act establishes requirements according to the role, system classification and use case. Article 15 concerns accuracy, robustness and cybersecurity of high-risk AI systems.
ISO/IEC 42001
A management system standard for organisations that provide or use AI.
NIST AI Risk Management Framework
A voluntary framework for managing AI risks; its core functions are Govern, Map, Measure and Manage.
SOC 2 and ISO/IEC 27001
SOC 2 is an examination and reporting framework; ISO/IEC 27001 is an information security management system standard.
Regulatory references
DORA
Confirm applicability for the actual entity and use case.
NIS2
Confirm applicability for the actual entity and use case.
PRA SS1/23
Confirm applicability for the actual entity and use case.
MAS AI Risk Management Guidelines
Confirm applicability for the actual entity and use case.
What a mapping means
A mapping links agreed requirements to controls, evidence and gaps. It does not claim accreditation, endorsement, a certificate or legal compliance. We record the source and version used. External reviewers and the client’s advisers make the relevant decisions.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.