Compliance mappings
What guardlayer evidence export maps each audited decision to. Generated from guardlayer.compliance; see
Audit log and evidence for how to use it.
OWASP Top 10 for LLM Applications 2026
Control
Title
LLM01
Prompt Injection
LLM02
Sensitive Information Disclosure
LLM03
Excessive Agency
LLM06
Unbounded Consumption
LLM08
Hidden Context Exposure
LLM10
Improper Output Handling
OWASP Top 10 for LLM Applications 2025
Control
Title
LLM01
Prompt Injection
LLM02
Sensitive Information Disclosure
LLM05
Improper Output Handling
LLM06
Excessive Agency
LLM07
System Prompt Leakage
LLM10
Unbounded Consumption
OWASP Top 10 for Agentic Applications 2026
Control
Title
ASI01
Agent Goal Hijack
ASI02
Tool Misuse and Exploitation
ASI03
Identity and Privilege Abuse
ASI05
Unexpected Code Execution
ASI06
Memory and Context Poisoning
MITRE ATLAS
Control
Title
AML.T0051
LLM Prompt Injection
AML.T0054
LLM Jailbreak
AML.T0056
Extract LLM System Prompt
AML.T0057
LLM Data Leakage
ISO/IEC 42001:2023 Annex A
Control
Title
A.6.2.6
AI system operation and monitoring
A.6.2.8
AI system recording of event logs
NIST AI RMF 1.0
Control
Title
MEASURE 2.4
Functionality and behavior of the AI system are monitored in production
MEASURE 2.7
AI system security and resilience are evaluated and documented
MANAGE 4.1
Post-deployment monitoring plans are implemented
EU AI Act (Regulation (EU) 2024/1689)
Control
Title
Art. 12
Record-keeping (automatic logging of events)
Art. 14
Human oversight
Art. 15
Accuracy, robustness and cybersecurity
CSA AI Controls Matrix v1.1.1
Control
Title
AIS-09
Input Validation
AIS-10
Output Validation
AIS-11
Agents Security Boundaries
AIS-15
Prompt Differentiation
DSP-10
Sensitive Data Transfer
DSP-17
Sensitive Data Protection
GRC-15
Human supervision
IAM-14
Credentials Management
IAM-18
Agent Access Restriction
LOG-02
Audit Logs Protection
LOG-08
Audit Logs Sanitization
LOG-09
Log Records
LOG-15
Input Monitoring
LOG-16
Output Monitoring
TVM-13
Guardrails
MITRE ATLAS mitigations (v2026.09)
Control
Title
AML.M0020
Generative AI Guardrails
AML.M0024
AI Telemetry Logging
AML.M0028
AI Agent Tools Permissions Configuration
AML.M0029
Human In-the-Loop for AI Agent Actions
AML.M0030
Restrict AI Agent Tool Invocation on Untrusted Data
AML.M0033
Input and Output Validation for AI Agent Components
AML.M0036
Limit AI Workload Resource Consumption
OWASP AI Security Verification Standard (AISVS) 1.0
Control
Title
C2.1.2
Encoded or smuggled input is detected
C2.1.3
Untrusted input is screened for prompt injection; flagged input is blocked
C2.1.4
Input length limits are enforced
C2.1.7
Reserved special tokens can't be injected
C2.1.8
Many-shot jailbreak patterns are detected
C7.3.2
Output disclosing the system prompt or backend data is blocked
C7.3.3
Model output can't trigger outbound requests
C7.3.4
Hidden or encoded content in output is checked
C9.2.1
High-impact agent actions wait for human approval
C9.3.5
Processing of untrusted data can't trigger tool calls
C9.5.1
Agent tool use is restricted by runtime policy
C9.5.3
Access decisions are made by a policy engine, not the model
C9.5.4
Secrets are kept out of the model's context
C12.1.2
Guardrail decisions are recorded for audit
C12.2.1
Known jailbreak and injection attempts are detected and alerted
C12.2.3
Custom rules detect injection and prompt-extraction attempts
UK Code of Practice for the Cyber Security of AI (2025)
Control
Title
2.6
AI system permissions on other systems limited to what's required (shall)
4.1
Capabilities that enable human oversight (should)
4.3
Technical measures where human oversight is a risk control (shall)
5.4
Sensitive data protected against unauthorised access (shall)
5.4.1
Checks and sanitisation applied to data and inputs (shall)
12.1
System and user actions logged for security compliance and investigations (shall)
12.2
Behaviour analysed to detect breaches and unexpected behaviour (should)
ETSI EN 304 223 V2.1.1 (2025-12), baseline cyber security for AI
Control
Title
5.1.2-2
AI system built to withstand adversarial attacks and unexpected input (shall)
5.1.2-6
AI system permissions on other systems limited to what's required (shall)
5.1.4-1
Capabilities that enable human oversight (should)
5.1.4-3
Technical measures where human oversight is a risk control (shall)
5.2.1-4
Sensitive data protected against unauthorised access (shall)
5.2.1-4.1
Checks and sanitisation applied to data and inputs (shall)
5.4.2-1
System and user actions logged for security compliance and investigations (shall)
5.4.2-2
Behaviour analysed to detect breaches and unexpected behaviour (should)
NIST SP 800-53 Rev. 5.2.0
Control
Title
AC-3
Access Enforcement
AC-4
Information Flow Enforcement
AC-6
Least Privilege
AU-2
Event Logging
AU-3
Content of Audit Records
AU-9
Protection of Audit Information
AU-9(3)
Protection of Audit Information
AU-10
Non-repudiation
AU-12
Audit Record Generation
SC-5
Denial-of-service Protection
SC-7
Boundary Protection
SC-7(5)
Boundary Protection
SI-4
System Monitoring
SI-10
Information Input Validation
SI-15
Information Output Filtering
NIST Cybersecurity Framework (CSF) 2.0
Control
Title
DE.AE-06
Information on adverse events is provided to authorized staff and tools
DE.CM-09
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
PR.AA-05
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
PR.DS-01
The confidentiality, integrity, and availability of data-at-rest are protected
PR.DS-02
The confidentiality, integrity, and availability of data-in-transit are protected
PR.DS-10
The confidentiality, integrity, and availability of data-in-use are protected
PR.PS-04
Log records are generated and made available for continuous monitoring
PR.PS-05
Installation and execution of unauthorized software are prevented
ISO/IEC 27001:2022 Annex A
Control
Title
A.5.15
Access control
A.5.33
Protection of records
A.5.34
Privacy and protection of PII
A.8.3
Information access restriction
A.8.11
Data masking
A.8.12
Data leakage prevention
A.8.15
Logging
A.8.16
Monitoring activities
A.8.23
Web filtering
SOC 2: AICPA Trust Services Criteria (2017, points of focus revised 2022)
Control
Title
C1.1
Confidential information is identified and protected
CC6.1
Logical access security over protected assets
CC6.3
Access granted by role, with least privilege
CC6.6
Protection against threats from outside the system boundary
CC6.7
Movement of information restricted to authorised recipients
CC6.8
Unauthorised or malicious software prevented or detected
CC7.2
Components monitored for anomalies indicating malicious acts
CC7.3
Security events evaluated and acted on
HIPAA Security Rule (45 CFR Part 164, Subpart C)
Control
Title
164.308(a)(1)(ii)(D)
Information system activity review
164.308(a)(5)(ii)(B)
Protection from malicious software (addressable)
164.308(a)(6)(ii)
Security incident procedures: response and reporting
164.312(a)(1)
Access control
164.312(b)
Audit controls
164.312(e)(1)
Transmission security
GDPR (Regulation (EU) 2016/679)
Control
Title
Art. 5(1)(c)
Data minimisation
Art. 5(1)(f)
Integrity and confidentiality
Art. 25(1)
Data protection by design
Art. 25(2)
Data protection by default
Art. 32(1)(b)
Security of processing: ongoing confidentiality and integrity
PCI DSS v4.0.1
Control
Title
1.3.2
Outbound traffic restricted to what's necessary
3.4.1
PAN masked when displayed
7.2.5
Application and system account privileges limited to what's necessary
10.2.1
Audit logs enabled and active
10.3.4
Change detection on audit logs
CMMC 2.0 Level 2 (NIST SP 800-171 Rev. 2)
Control
Title
AC.L2-3.1.1
Authorized Access Control
AC.L2-3.1.2
Transaction & Function Control
AC.L2-3.1.3
Control CUI Flow
AC.L2-3.1.5
Least Privilege
AU.L2-3.3.1
System Auditing
AU.L2-3.3.8
Audit Protection
SC.L2-3.13.1
Boundary Protection
SC.L2-3.13.6
Network Communication by Exception
SI.L2-3.14.2
Malicious Code Protection
SI.L2-3.14.6
Monitor Communications for Attacks
FedRAMP 20x Key Security Indicators (Consolidated Rules 2026)
Control
Title
KSI-CNA-RNT
Restricting Network Traffic
KSI-IAM-ELP
Ensuring Least Privilege
KSI-MLA-LET
Logging Event Types
NIS2: Directive (EU) 2022/2555 and Implementing Regulation (EU) 2024/2690
Control
Title
Art. 21(2)(b)
Incident handling
Art. 21(2)(i)
Access control policies
CIR 2024/2690 3.2.1
Activities monitored and logged to detect incidents
CIR 2024/2690 3.2.5
Logs protected from unauthorised access or changes
CIR 2024/2690 11.1.1
Access control policies implemented
DORA: Regulation (EU) 2022/2554 and RTS Delegated Regulation (EU) 2024/1774
Control
Title
Art. 10(1)
Anomalous activities promptly detected
RTS 2024/1774 Art. 11(2)(i)
Data loss and leakage prevention
RTS 2024/1774 Art. 12(1)
Logging procedures, protocols and tools implemented
RTS 2024/1774 Art. 12(2)(d)
Logs protected against tampering, deletion and unauthorised access
RTS 2024/1774 Art. 21(a)
Access rights on need-to-know, need-to-use and least privilege
RTS 2024/1774 Art. 21(d)
Controls and tools to prevent unauthorised access
NYDFS 23 NYCRR Part 500 (as amended November 2023)
Control
Title
500.6(a)(2)
Audit trails designed to detect and respond to cybersecurity events
500.7(a)(1)
Access privileges limited to what's necessary
500.14(a)(1)
Authorised activity monitored; unauthorised access or use detected
500.14(a)(2)
Web traffic and email monitored and filtered to block malicious content
Which decisions map to which controls
Every audited entry is evidence for: iso-42001:A.6.2.6, iso-42001:A.6.2.8, nist-ai-rmf:MEASURE 2.4, nist-ai-rmf:MANAGE 4.1, eu-ai-act:Art. 12, csa-aicm:LOG-09, mitre-atlas-mitigations:AML.M0024, owasp-aisvs-1.0:C12.1.2, uk-ai-cop:12.1, etsi-en-304-223:5.4.2-1, nist-sp-800-53:AU-2, nist-sp-800-53:AU-3, nist-sp-800-53:AU-12, nist-csf-2.0:PR.PS-04, nist-csf-2.0:DE.CM-09, iso-27001:A.8.15, iso-27001:A.8.16, soc2-tsc:CC7.2, hipaa-security:164.312(b), pci-dss-4:10.2.1, cmmc-l2:AU.L2-3.3.1, fedramp-20x:KSI-MLA-LET, nis2:CIR 2024/2690 3.2.1, dora:RTS 2024/1774 Art. 12(1), nydfs-500:500.6(a)(2).
Any detection adds: nist-ai-rmf:MEASURE 2.7, eu-ai-act:Art. 15, csa-aicm:TVM-13, mitre-atlas-mitigations:AML.M0020, uk-ai-cop:12.2, etsi-en-304-223:5.4.2-2, nist-sp-800-53:SI-4, soc2-tsc:CC7.3, hipaa-security:164.308(a)(6)(ii), hipaa-security:164.308(a)(1)(ii)(D), cmmc-l2:SI.L2-3.14.6, nis2:Art. 21(2)(b), dora:Art. 10(1).
A REVIEW verdict adds: eu-ai-act:Art. 14, csa-aicm:GRC-15, uk-ai-cop:4.1, uk-ai-cop:4.3, etsi-en-304-223:5.1.4-1, etsi-en-304-223:5.1.4-3, nist-csf-2.0:DE.AE-06.
Category
Controls
prompt_injection
owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051, owasp-agentic-2026:ASI01
jailbreak
owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0054
goal_hijack
owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051, owasp-agentic-2026:ASI01
obfuscation
owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051
known_attack
owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051
system_prompt_leak
owasp-llm-2026:LLM08, owasp-llm-2025:LLM07, mitre-atlas:AML.T0056, csa-aicm:AIS-10
data_exfiltration
owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, owasp-agentic-2026:ASI02, csa-aicm:DSP-10
secret
owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4
pii
owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4
egress
owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, owasp-agentic-2026:ASI02, csa-aicm:DSP-10, nist-sp-800-53:SC-7, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), iso-27001:A.8.23, soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:SC.L2-3.13.1, fedramp-20x:KSI-CNA-RNT
unsafe_link
owasp-llm-2026:LLM10, owasp-llm-2025:LLM05, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:AIS-10
unsafe_command
owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18, owasp-agentic-2026:ASI05
tool_misuse
owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
resource_abuse
owasp-llm-2026:LLM06, owasp-llm-2025:LLM10, mitre-atlas-mitigations:AML.M0036, nist-sp-800-53:SC-5
policy
(baseline only)
Rule
Extra controls
credential_file
owasp-agentic-2026:ASI03, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:IAM-14, iso-27001:A.8.3
dotenv_file
owasp-agentic-2026:ASI03, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:IAM-14, iso-27001:A.8.3
destructive_command
owasp-agentic-2026:ASI05
persistence
owasp-agentic-2026:ASI05, nist-csf-2.0:PR.PS-05, soc2-tsc:CC6.8, hipaa-security:164.308(a)(5)(ii)(B), cmmc-l2:SI.L2-3.14.2
risky_command
owasp-agentic-2026:ASI03, owasp-agentic-2026:ASI05
egress_metadata_endpoint
owasp-agentic-2026:ASI03
capability_exec
owasp-agentic-2026:ASI05
tool_not_allowed
owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
tool_denied
owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
after_injection
owasp-agentic-2026:ASI01, owasp-agentic-2026:ASI06
trifecta
owasp-agentic-2026:ASI02
egress_not_allowed
nist-sp-800-53:SC-7(5), pci-dss-4:1.3.2, cmmc-l2:SC.L2-3.13.6
sensitive_data_egress
owasp-agentic-2026:ASI02, nist-sp-800-53:AC-4, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:AC.L2-3.1.3
secret_in_egress
owasp-agentic-2026:ASI02, nist-sp-800-53:AC-4, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:AC.L2-3.1.3
fake_special_tokens
owasp-aisvs-1.0:C2.1.7
many_shot_pattern
owasp-aisvs-1.0:C2.1.8
oversized_input
owasp-aisvs-1.0:C2.1.4
token_flooding
owasp-aisvs-1.0:C2.1.4
character_flooding
owasp-aisvs-1.0:C2.1.4
Mapping version 2026.09.17. Control mappings identify runtime evidence relevant to each control. They do not certify compliance with any framework; EU AI Act obligations apply according to the system's risk classification.
CSA AI Controls Matrix control IDs and titles are referenced from the Cloud Security Alliance AI Controls Matrix Version
1.1.1 (© Cloud Security Alliance, all rights reserved); no control text is reproduced. Verified against CSA's official
spreadsheet on 2026-09-27. MITRE ATLAS mitigation names are from MITRE's atlas-data release v2026.09 (Apache-2.0). OWASP
AISVS 1.0 (CC BY-SA 4.0, OWASP Foundation) requirements have no titles: the descriptions here are GuardLayer's own
summaries; cite a requirement as v1.0-C<id>. The UK Code of Practice for the Cyber Security of AI (DSIT and NCSC, January 2025) is
Crown copyright, used under the Open Government Licence v3.0 ;
provision numbers as published on gov.uk, descriptions GuardLayer's own. ETSI EN 304 223 V2.1.1 (2025-12), the European
Standard that supersedes ETSI TS 104 223, is © ETSI with all rights reserved: GuardLayer references provision numbers only
(checked against ETSI's official PDF), with its own descriptions. NIST SP 800-53 Rev. 5.2.0 is a US government work in the
public domain; titles from NIST's OSCAL catalog. NIST CSF 2.0 (public domain): subcategory text from NIST's CSF 2.0
reference export; each CSF subcategory used is consistent with the SP 800-53 families NIST relates it to. ISO/IEC 42001 and ISO/IEC 27001 (© ISO) are referenced by
control number and short title only. SOC 2 Trust Services Criteria (© AICPA) are referenced by criterion ID, checked against
the 2022 revised edition; descriptions are GuardLayer's own.
The HIPAA Security Rule (45 CFR Part 164 Subpart C) is US federal regulation; citations checked against the eCFR as of
2026-09-24 (the rule in force; HHS's January 2025 proposed update is not final). It applies only where the AI system
handles electronic protected health information, and GuardLayer detects common personal identifiers, not health data.
GDPR (Regulation (EU) 2016/679) mappings apply only where personal data is involved; article numbers and titles per the
official text on EUR-Lex. GuardLayer's personal-data detection covers common identifiers, not every category of personal data.
PCI DSS v4.0.1 (© PCI Security Standards Council) is referenced by requirement number, checked against the Council's
published Summary of Changes and practitioner references; descriptions are GuardLayer's own. 10.3.4 expects alerts on
log changes: run guardlayer audit verify on a schedule with alerting. 3.5.1 isn't claimed: the audit log's hash of the
scanned text is unkeyed, and PCI DSS requires keyed hashes for card numbers at rest.
CMMC 2.0 Level 2 practice IDs and titles are from the DoD's CMMC Assessment Guide Level 2 v2.13 (September 2024), which
follows NIST SP 800-171 Rev. 2 (public domain). FedRAMP 20x Key Security Indicators are from FedRAMP's Consolidated Rules
(version 2026.09.13.02); FedRAMP Rev. 5 authorisations use NIST SP 800-53 controls, so use the nist-sp-800-53 evidence.
NIS2: Directive (EU) 2022/2555 Article 21(2) and the annex of Commission Implementing Regulation (EU) 2024/2690 (numbers as
in ENISA's Technical Implementation Guidance v1.0); the annex binds only the entity types it lists (for example cloud,
data-centre and managed service providers).
DORA (Regulation (EU) 2022/2554) Article 10 and the ICT risk-management RTS (Delegated Regulation (EU) 2024/1774): article
numbers checked against the adopted text published by the European Commission. Applies to EU financial entities.
NYDFS 23 NYCRR Part 500: sections as in the Department of Financial Services' published text of the second amendment
(November 2023).