Compliance framework mappings for AI agents
How Praesidia controls and audit evidence map to the frameworks your assessors ask about — SOC 2, the EU AI Act, ISO/IEC 42001, NIST AI RMF, GDPR, and the OWASP Top 10 for LLM applications.
These mappings support your assessment and do not constitute certification. Each page lists the requirement, what Praesidia provides, and the evidence you can produce — plus the responsibilities that stay on your side.
SOC 2
How Praesidia agent identity, guardrails, and tamper-evident audit trails map to SOC 2 criteria CC6, CC7, and CC8, with exportable evidence.
Read the mapping EU AI ActEU AI Act (Regulation (EU) 2024/1689)
How Praesidia risk classification, oversight gates, guardrails, and tamper-evident logging map to EU AI Act Articles 9, 12, 14, 26, 72, and 73.
Read the mapping ISO/IEC 42001ISO/IEC 42001:2023
How Praesidia agent inventory, risk classification, guardrails, and tamper-evident logs map to ISO/IEC 42001 clauses 6 to 9 and Annex A controls.
Read the mapping NIST AI RMFNIST AI Risk Management Framework 1.0
How Praesidia inventory, per-agent risk classification, runtime controls, and audit trail map to NIST AI RMF Govern, Map, Measure, and Manage.
Read the mapping GDPRGeneral Data Protection Regulation (EU) 2016/679
How Praesidia PII redaction, erasure workflow, residency controls, and audit trail map to GDPR Articles 5, 17, 25, 28, 30, 32, 33, and 35 for agents.
Read the mapping OWASP LLM Top 10OWASP Top 10 for LLM Applications 2025
How Praesidia guardrails, per-tool authorization, non-human identity, budgets, and audit trail map to OWASP LLM01 to LLM10 (2025) for AI agents.
Read the mapping