Skip to content

Compliance mappings

What guardlayer evidence export maps each audited decision to. Generated from guardlayer.compliance; see Audit log and evidence for how to use it.

OWASP Top 10 for LLM Applications 2026

Control Title
LLM01 Prompt Injection
LLM02 Sensitive Information Disclosure
LLM03 Excessive Agency
LLM06 Unbounded Consumption
LLM08 Hidden Context Exposure
LLM10 Improper Output Handling

OWASP Top 10 for LLM Applications 2025

Control Title
LLM01 Prompt Injection
LLM02 Sensitive Information Disclosure
LLM05 Improper Output Handling
LLM06 Excessive Agency
LLM07 System Prompt Leakage
LLM10 Unbounded Consumption

OWASP Top 10 for Agentic Applications 2026

Control Title
ASI01 Agent Goal Hijack
ASI02 Tool Misuse and Exploitation
ASI03 Identity and Privilege Abuse
ASI05 Unexpected Code Execution
ASI06 Memory and Context Poisoning

MITRE ATLAS

Control Title
AML.T0051 LLM Prompt Injection
AML.T0054 LLM Jailbreak
AML.T0056 Extract LLM System Prompt
AML.T0057 LLM Data Leakage

ISO/IEC 42001:2023 Annex A

Control Title
A.6.2.6 AI system operation and monitoring
A.6.2.8 AI system recording of event logs

NIST AI RMF 1.0

Control Title
MEASURE 2.4 Functionality and behavior of the AI system are monitored in production
MEASURE 2.7 AI system security and resilience are evaluated and documented
MANAGE 4.1 Post-deployment monitoring plans are implemented

EU AI Act (Regulation (EU) 2024/1689)

Control Title
Art. 12 Record-keeping (automatic logging of events)
Art. 14 Human oversight
Art. 15 Accuracy, robustness and cybersecurity

CSA AI Controls Matrix v1.1.1

Control Title
AIS-09 Input Validation
AIS-10 Output Validation
AIS-11 Agents Security Boundaries
AIS-15 Prompt Differentiation
DSP-10 Sensitive Data Transfer
DSP-17 Sensitive Data Protection
GRC-15 Human supervision
IAM-14 Credentials Management
IAM-18 Agent Access Restriction
LOG-02 Audit Logs Protection
LOG-08 Audit Logs Sanitization
LOG-09 Log Records
LOG-15 Input Monitoring
LOG-16 Output Monitoring
TVM-13 Guardrails

MITRE ATLAS mitigations (v2026.09)

Control Title
AML.M0020 Generative AI Guardrails
AML.M0024 AI Telemetry Logging
AML.M0028 AI Agent Tools Permissions Configuration
AML.M0029 Human In-the-Loop for AI Agent Actions
AML.M0030 Restrict AI Agent Tool Invocation on Untrusted Data
AML.M0033 Input and Output Validation for AI Agent Components
AML.M0036 Limit AI Workload Resource Consumption

OWASP AI Security Verification Standard (AISVS) 1.0

Control Title
C2.1.2 Encoded or smuggled input is detected
C2.1.3 Untrusted input is screened for prompt injection; flagged input is blocked
C2.1.4 Input length limits are enforced
C2.1.7 Reserved special tokens can't be injected
C2.1.8 Many-shot jailbreak patterns are detected
C7.3.2 Output disclosing the system prompt or backend data is blocked
C7.3.3 Model output can't trigger outbound requests
C7.3.4 Hidden or encoded content in output is checked
C9.2.1 High-impact agent actions wait for human approval
C9.3.5 Processing of untrusted data can't trigger tool calls
C9.5.1 Agent tool use is restricted by runtime policy
C9.5.3 Access decisions are made by a policy engine, not the model
C9.5.4 Secrets are kept out of the model's context
C12.1.2 Guardrail decisions are recorded for audit
C12.2.1 Known jailbreak and injection attempts are detected and alerted
C12.2.3 Custom rules detect injection and prompt-extraction attempts

UK Code of Practice for the Cyber Security of AI (2025)

Control Title
2.6 AI system permissions on other systems limited to what's required (shall)
4.1 Capabilities that enable human oversight (should)
4.3 Technical measures where human oversight is a risk control (shall)
5.4 Sensitive data protected against unauthorised access (shall)
5.4.1 Checks and sanitisation applied to data and inputs (shall)
12.1 System and user actions logged for security compliance and investigations (shall)
12.2 Behaviour analysed to detect breaches and unexpected behaviour (should)

ETSI EN 304 223 V2.1.1 (2025-12), baseline cyber security for AI

Control Title
5.1.2-2 AI system built to withstand adversarial attacks and unexpected input (shall)
5.1.2-6 AI system permissions on other systems limited to what's required (shall)
5.1.4-1 Capabilities that enable human oversight (should)
5.1.4-3 Technical measures where human oversight is a risk control (shall)
5.2.1-4 Sensitive data protected against unauthorised access (shall)
5.2.1-4.1 Checks and sanitisation applied to data and inputs (shall)
5.4.2-1 System and user actions logged for security compliance and investigations (shall)
5.4.2-2 Behaviour analysed to detect breaches and unexpected behaviour (should)

NIST SP 800-53 Rev. 5.2.0

Control Title
AC-3 Access Enforcement
AC-4 Information Flow Enforcement
AC-6 Least Privilege
AU-2 Event Logging
AU-3 Content of Audit Records
AU-9 Protection of Audit Information
AU-9(3) Protection of Audit Information
AU-10 Non-repudiation
AU-12 Audit Record Generation
SC-5 Denial-of-service Protection
SC-7 Boundary Protection
SC-7(5) Boundary Protection
SI-4 System Monitoring
SI-10 Information Input Validation
SI-15 Information Output Filtering

NIST Cybersecurity Framework (CSF) 2.0

Control Title
DE.AE-06 Information on adverse events is provided to authorized staff and tools
DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
PR.PS-04 Log records are generated and made available for continuous monitoring
PR.PS-05 Installation and execution of unauthorized software are prevented

ISO/IEC 27001:2022 Annex A

Control Title
A.5.15 Access control
A.5.33 Protection of records
A.5.34 Privacy and protection of PII
A.8.3 Information access restriction
A.8.11 Data masking
A.8.12 Data leakage prevention
A.8.15 Logging
A.8.16 Monitoring activities
A.8.23 Web filtering

SOC 2: AICPA Trust Services Criteria (2017, points of focus revised 2022)

Control Title
C1.1 Confidential information is identified and protected
CC6.1 Logical access security over protected assets
CC6.3 Access granted by role, with least privilege
CC6.6 Protection against threats from outside the system boundary
CC6.7 Movement of information restricted to authorised recipients
CC6.8 Unauthorised or malicious software prevented or detected
CC7.2 Components monitored for anomalies indicating malicious acts
CC7.3 Security events evaluated and acted on

HIPAA Security Rule (45 CFR Part 164, Subpart C)

Control Title
164.308(a)(1)(ii)(D) Information system activity review
164.308(a)(5)(ii)(B) Protection from malicious software (addressable)
164.308(a)(6)(ii) Security incident procedures: response and reporting
164.312(a)(1) Access control
164.312(b) Audit controls
164.312(e)(1) Transmission security

GDPR (Regulation (EU) 2016/679)

Control Title
Art. 5(1)(c) Data minimisation
Art. 5(1)(f) Integrity and confidentiality
Art. 25(1) Data protection by design
Art. 25(2) Data protection by default
Art. 32(1)(b) Security of processing: ongoing confidentiality and integrity

PCI DSS v4.0.1

Control Title
1.3.2 Outbound traffic restricted to what's necessary
3.4.1 PAN masked when displayed
7.2.5 Application and system account privileges limited to what's necessary
10.2.1 Audit logs enabled and active
10.3.4 Change detection on audit logs

CMMC 2.0 Level 2 (NIST SP 800-171 Rev. 2)

Control Title
AC.L2-3.1.1 Authorized Access Control
AC.L2-3.1.2 Transaction & Function Control
AC.L2-3.1.3 Control CUI Flow
AC.L2-3.1.5 Least Privilege
AU.L2-3.3.1 System Auditing
AU.L2-3.3.8 Audit Protection
SC.L2-3.13.1 Boundary Protection
SC.L2-3.13.6 Network Communication by Exception
SI.L2-3.14.2 Malicious Code Protection
SI.L2-3.14.6 Monitor Communications for Attacks

FedRAMP 20x Key Security Indicators (Consolidated Rules 2026)

Control Title
KSI-CNA-RNT Restricting Network Traffic
KSI-IAM-ELP Ensuring Least Privilege
KSI-MLA-LET Logging Event Types

NIS2: Directive (EU) 2022/2555 and Implementing Regulation (EU) 2024/2690

Control Title
Art. 21(2)(b) Incident handling
Art. 21(2)(i) Access control policies
CIR 2024/2690 3.2.1 Activities monitored and logged to detect incidents
CIR 2024/2690 3.2.5 Logs protected from unauthorised access or changes
CIR 2024/2690 11.1.1 Access control policies implemented

DORA: Regulation (EU) 2022/2554 and RTS Delegated Regulation (EU) 2024/1774

Control Title
Art. 10(1) Anomalous activities promptly detected
RTS 2024/1774 Art. 11(2)(i) Data loss and leakage prevention
RTS 2024/1774 Art. 12(1) Logging procedures, protocols and tools implemented
RTS 2024/1774 Art. 12(2)(d) Logs protected against tampering, deletion and unauthorised access
RTS 2024/1774 Art. 21(a) Access rights on need-to-know, need-to-use and least privilege
RTS 2024/1774 Art. 21(d) Controls and tools to prevent unauthorised access

NYDFS 23 NYCRR Part 500 (as amended November 2023)

Control Title
500.6(a)(2) Audit trails designed to detect and respond to cybersecurity events
500.7(a)(1) Access privileges limited to what's necessary
500.14(a)(1) Authorised activity monitored; unauthorised access or use detected
500.14(a)(2) Web traffic and email monitored and filtered to block malicious content

Which decisions map to which controls

Every audited entry is evidence for: iso-42001:A.6.2.6, iso-42001:A.6.2.8, nist-ai-rmf:MEASURE 2.4, nist-ai-rmf:MANAGE 4.1, eu-ai-act:Art. 12, csa-aicm:LOG-09, mitre-atlas-mitigations:AML.M0024, owasp-aisvs-1.0:C12.1.2, uk-ai-cop:12.1, etsi-en-304-223:5.4.2-1, nist-sp-800-53:AU-2, nist-sp-800-53:AU-3, nist-sp-800-53:AU-12, nist-csf-2.0:PR.PS-04, nist-csf-2.0:DE.CM-09, iso-27001:A.8.15, iso-27001:A.8.16, soc2-tsc:CC7.2, hipaa-security:164.312(b), pci-dss-4:10.2.1, cmmc-l2:AU.L2-3.3.1, fedramp-20x:KSI-MLA-LET, nis2:CIR 2024/2690 3.2.1, dora:RTS 2024/1774 Art. 12(1), nydfs-500:500.6(a)(2). Any detection adds: nist-ai-rmf:MEASURE 2.7, eu-ai-act:Art. 15, csa-aicm:TVM-13, mitre-atlas-mitigations:AML.M0020, uk-ai-cop:12.2, etsi-en-304-223:5.4.2-2, nist-sp-800-53:SI-4, soc2-tsc:CC7.3, hipaa-security:164.308(a)(6)(ii), hipaa-security:164.308(a)(1)(ii)(D), cmmc-l2:SI.L2-3.14.6, nis2:Art. 21(2)(b), dora:Art. 10(1). A REVIEW verdict adds: eu-ai-act:Art. 14, csa-aicm:GRC-15, uk-ai-cop:4.1, uk-ai-cop:4.3, etsi-en-304-223:5.1.4-1, etsi-en-304-223:5.1.4-3, nist-csf-2.0:DE.AE-06.

Category Controls
prompt_injection owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051, owasp-agentic-2026:ASI01
jailbreak owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0054
goal_hijack owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051, owasp-agentic-2026:ASI01
obfuscation owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051
known_attack owasp-llm-2026:LLM01, owasp-llm-2025:LLM01, mitre-atlas:AML.T0051
system_prompt_leak owasp-llm-2026:LLM08, owasp-llm-2025:LLM07, mitre-atlas:AML.T0056, csa-aicm:AIS-10
data_exfiltration owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, owasp-agentic-2026:ASI02, csa-aicm:DSP-10
secret owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4
pii owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4
egress owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, owasp-agentic-2026:ASI02, csa-aicm:DSP-10, nist-sp-800-53:SC-7, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), iso-27001:A.8.23, soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:SC.L2-3.13.1, fedramp-20x:KSI-CNA-RNT
unsafe_link owasp-llm-2026:LLM10, owasp-llm-2025:LLM05, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:AIS-10
unsafe_command owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18, owasp-agentic-2026:ASI05
tool_misuse owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
resource_abuse owasp-llm-2026:LLM06, owasp-llm-2025:LLM10, mitre-atlas-mitigations:AML.M0036, nist-sp-800-53:SC-5
policy (baseline only)
Rule Extra controls
credential_file owasp-agentic-2026:ASI03, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:IAM-14, iso-27001:A.8.3
dotenv_file owasp-agentic-2026:ASI03, owasp-llm-2026:LLM02, owasp-llm-2025:LLM02, mitre-atlas:AML.T0057, csa-aicm:DSP-17, uk-ai-cop:5.4, etsi-en-304-223:5.2.1-4, csa-aicm:IAM-14, iso-27001:A.8.3
destructive_command owasp-agentic-2026:ASI05
persistence owasp-agentic-2026:ASI05, nist-csf-2.0:PR.PS-05, soc2-tsc:CC6.8, hipaa-security:164.308(a)(5)(ii)(B), cmmc-l2:SI.L2-3.14.2
risky_command owasp-agentic-2026:ASI03, owasp-agentic-2026:ASI05
egress_metadata_endpoint owasp-agentic-2026:ASI03
capability_exec owasp-agentic-2026:ASI05
tool_not_allowed owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
tool_denied owasp-llm-2026:LLM03, owasp-llm-2025:LLM06, owasp-agentic-2026:ASI02, csa-aicm:AIS-11, csa-aicm:IAM-18
after_injection owasp-agentic-2026:ASI01, owasp-agentic-2026:ASI06
trifecta owasp-agentic-2026:ASI02
egress_not_allowed nist-sp-800-53:SC-7(5), pci-dss-4:1.3.2, cmmc-l2:SC.L2-3.13.6
sensitive_data_egress owasp-agentic-2026:ASI02, nist-sp-800-53:AC-4, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:AC.L2-3.1.3
secret_in_egress owasp-agentic-2026:ASI02, nist-sp-800-53:AC-4, nist-csf-2.0:PR.DS-02, iso-27001:A.8.12, dora:RTS 2024/1774 Art. 11(2)(i), soc2-tsc:CC6.7, hipaa-security:164.312(e)(1), cmmc-l2:AC.L2-3.1.3
fake_special_tokens owasp-aisvs-1.0:C2.1.7
many_shot_pattern owasp-aisvs-1.0:C2.1.8
oversized_input owasp-aisvs-1.0:C2.1.4
token_flooding owasp-aisvs-1.0:C2.1.4
character_flooding owasp-aisvs-1.0:C2.1.4

Mapping version 2026.09.17. Control mappings identify runtime evidence relevant to each control. They do not certify compliance with any framework; EU AI Act obligations apply according to the system's risk classification.

CSA AI Controls Matrix control IDs and titles are referenced from the Cloud Security Alliance AI Controls Matrix Version 1.1.1 (© Cloud Security Alliance, all rights reserved); no control text is reproduced. Verified against CSA's official spreadsheet on 2026-09-27. MITRE ATLAS mitigation names are from MITRE's atlas-data release v2026.09 (Apache-2.0). OWASP AISVS 1.0 (CC BY-SA 4.0, OWASP Foundation) requirements have no titles: the descriptions here are GuardLayer's own summaries; cite a requirement as v1.0-C<id>. The UK Code of Practice for the Cyber Security of AI (DSIT and NCSC, January 2025) is Crown copyright, used under the Open Government Licence v3.0; provision numbers as published on gov.uk, descriptions GuardLayer's own. ETSI EN 304 223 V2.1.1 (2025-12), the European Standard that supersedes ETSI TS 104 223, is © ETSI with all rights reserved: GuardLayer references provision numbers only (checked against ETSI's official PDF), with its own descriptions. NIST SP 800-53 Rev. 5.2.0 is a US government work in the public domain; titles from NIST's OSCAL catalog. NIST CSF 2.0 (public domain): subcategory text from NIST's CSF 2.0 reference export; each CSF subcategory used is consistent with the SP 800-53 families NIST relates it to. ISO/IEC 42001 and ISO/IEC 27001 (© ISO) are referenced by control number and short title only. SOC 2 Trust Services Criteria (© AICPA) are referenced by criterion ID, checked against the 2022 revised edition; descriptions are GuardLayer's own. The HIPAA Security Rule (45 CFR Part 164 Subpart C) is US federal regulation; citations checked against the eCFR as of 2026-09-24 (the rule in force; HHS's January 2025 proposed update is not final). It applies only where the AI system handles electronic protected health information, and GuardLayer detects common personal identifiers, not health data. GDPR (Regulation (EU) 2016/679) mappings apply only where personal data is involved; article numbers and titles per the official text on EUR-Lex. GuardLayer's personal-data detection covers common identifiers, not every category of personal data. PCI DSS v4.0.1 (© PCI Security Standards Council) is referenced by requirement number, checked against the Council's published Summary of Changes and practitioner references; descriptions are GuardLayer's own. 10.3.4 expects alerts on log changes: run guardlayer audit verify on a schedule with alerting. 3.5.1 isn't claimed: the audit log's hash of the scanned text is unkeyed, and PCI DSS requires keyed hashes for card numbers at rest. CMMC 2.0 Level 2 practice IDs and titles are from the DoD's CMMC Assessment Guide Level 2 v2.13 (September 2024), which follows NIST SP 800-171 Rev. 2 (public domain). FedRAMP 20x Key Security Indicators are from FedRAMP's Consolidated Rules (version 2026.09.13.02); FedRAMP Rev. 5 authorisations use NIST SP 800-53 controls, so use the nist-sp-800-53 evidence. NIS2: Directive (EU) 2022/2555 Article 21(2) and the annex of Commission Implementing Regulation (EU) 2024/2690 (numbers as in ENISA's Technical Implementation Guidance v1.0); the annex binds only the entity types it lists (for example cloud, data-centre and managed service providers). DORA (Regulation (EU) 2022/2554) Article 10 and the ICT risk-management RTS (Delegated Regulation (EU) 2024/1774): article numbers checked against the adopted text published by the European Commission. Applies to EU financial entities. NYDFS 23 NYCRR Part 500: sections as in the Department of Financial Services' published text of the second amendment (November 2023).