ISO 42001 Readiness
Open route: /iso-42001-readiness
Framework Readiness Library
Scaled Agents™ uses selected public frameworks and standards as readiness, mapping, and evidence-organization references for governed AI workers.
These pages explain how Agent Passports, human oversight, risk classification, runtime permits, control mappings, and evidence trails can support preparation work. They do not create certifications, legal conclusions, audit opinions, regulatory approvals, or guaranteed compliance outcomes.
Context
Framework readiness pages are designed for teams that need common vocabulary and review-preparation context before customer-specific governance, legal, compliance, security, audit, or procurement review.
Each page maps Scaled Agents concepts to preparation patterns such as inventories, ownership, human oversight, risk classification, evidence trails, runtime-control records, management review inputs, and board-level summaries.
Library Structure
The first release covers the public-facing framework references most closely tied to governed AI worker identity, risk management, regulatory screening, AI security, and evidence preparation.
Open route: /iso-42001-readiness
Open route: /framework-readiness/nist-ai-rmf
Open route: /framework-readiness/eu-ai-act
Open route: /framework-readiness/owasp-ai-security
Open route: /framework-readiness/soc-2-evidence
Control Mapping
This matrix keeps the framework family visible without implying that frameworks are interchangeable or that Scaled Agents produces formal compliance outcomes.
| Requirement / concept | Current Scaled Agents capability | Fit | Recommended improvement |
|---|---|---|---|
| Management-system readiness | ISO 42001 readiness page and ISO 27001 integration positioning. | Strong | Add SoA and management-review support in the product roadmap. |
| AI risk-management readiness | Passport, risk classification, Toll Gates, Human Review, monitoring, and evidence records. | Strong | Add NIST AI RMF-specific readiness views and residual-risk summaries. |
| Regulatory screening support | EU AI Act role/risk screening language, transparency and oversight preparation, and Passport report views. | Partial | Add legal-review routing and jurisdiction-specific applicability gates before any customer-specific conclusion. |
| AI security awareness | Prompt risk, tool-use boundaries, connector governance, runtime permits, and evidence trails. | Strong | Add security-review packets for OWASP and adversarial AI threat awareness. |
| Audit evidence organization | Evidence Records, Stamps, lifecycle events, Human Review records, and export-package planning. | Partial | Add customer-safe audit package exports with redaction and scope labels. |
Product Fit
Governed identity, owner, purpose, scope, permissions, review state, lifecycle state, and evidence references.
Decision checkpoints for higher-risk AI worker activity, restricted tool use, sensitive data, and lifecycle movement.
Scoped authority planning for specific action requests before execution or future controlled connector paths.
Traceable records for reviews, decisions, exceptions, remediation, approvals, denials, and lifecycle events.
Framework Readiness Family
Use these pages as orientation aids before customer-specific review, implementation, legal analysis, security assessment, audit work, or management approval.