Six things an auditor will ask about your agents
These are the questions ISO/IEC 42001, the NIST AI RMF, the EU AI Act and the OWASP guidance for LLM applications converge on. The pack answers each one with a document you can hand over. Framework references are in our own words; licensed standard text is never reproduced.
Inventory
Every agent, the model behind it, the tools it can call, the data it reaches, and who owns it.
Permissions and tool scope
What each agent may read, write, send or spend, and whether anyone has reviewed that scope since it was set.
Input trust
How the agent treats content it did not author: pasted documents, inbound email, web pages, other agents' output.
Human oversight
Who can stop an agent, how quickly, whether the stop is logged, and what the agent does when the stop mechanism itself is unavailable.
Audit trail and attribution
One record per invocation, including refusals, tied to the exact instruction version that produced the output.
Change and incidents
How model swaps, instruction edits and rollbacks are approved, and what happens when an agent misbehaves in production.
How it works
- Describe your agents. A 20-minute intake for a handful of agents, or the spreadsheet template for dozens or hundreds. Identical configurations are grouped into classes, so 200 seats of the same Copilot setup are assessed once, not 200 times.
- Get a score per agent class. Each class is rated on autonomy, tool access, data sensitivity and blast radius. You see which ones matter and why, with the specific gap named and the number of instances affected. Every point deducted has a named contributor.
- Receive the policy set. An AI Agent Governance Policy, an acceptable-use standard for agents, and a human-oversight and kill-switch procedure, written for your organisation rather than a template with your name pasted in.
We run this on ourselves
RiskWoven is itself an estate of twenty-one AI agents. The controls below are ones we operate in production and attest to publicly. The most recent attestation, covering the deployment of 7 September 2026, is summarised on the trust page. The observations in the table were made against the 4 September deployment and have not been re-run since; the attestation says so.
| Control | What was observed |
|---|---|
| Kill switch | Disabling an agent returned 503 with the operator's reason and made zero model calls. Re-enabling restored it within one request. |
| Refusals logged | The refusal was written to the audit trail naming the switch that caused it. |
| Instruction pinning | Any change to an agent's instructions without a version bump fails the test suite, so the version recorded on each audit row is meaningful. |
| Independent review | Every customer-facing output passes a reviewer that never sees the producer's instructions before it is released. |
| Tenant isolation | Seventeen cross-organisation probes from a real second account, zero exposure. |
The attestation also records what was not verified. That is the standard we hold ourselves to and the standard the pack applies to you.
What you receive
- Agent inventory (your AIBOM): agents grouped into classes, with every instance, model, tool, data source, owner and purpose
- Per-class risk assessment with a named contributor for every point deducted
- Gap list across the six areas, ordered by exposure
- AI Agent Governance Policy
- Acceptable-use standard for agents and the people who deploy them
- Human-oversight and kill-switch procedure
- Framework crosswalk showing which clause each document supports
Pricing
AI Agent Governance Pack is $499 one-time, delivered as editable documents you own, covering up to 25 agent classes.
Already planning ISO/IEC 42001 or NIST AI RMF readiness? It is available with the Readiness Bundle for $1,299 instead of $1,398. The Readiness Bundle is on sale today.
A subscription that keeps your agent inventory current as you add and retire agents is not yet open. Buyers of either pack get the launch price when it is.
Straight answers
We only use ChatGPT and Copilot. Do we have agents?
If any of those tools has been given access to your email, files, calendar or a company system, or if anyone has built an automation on top of them, yes. The inventory step will tell you how many.
We have hundreds of agents. Does this still work?
Yes. Agents that share a model, tools, data sources and autonomy level are grouped into a class and scored once; your inventory records every instance and owner underneath. Hundreds of agents are usually a few dozen classes. The pack covers 25 classes; beyond that, email us for a quote. Automatic discovery of agents across Microsoft 365, Zapier, n8n and similar platforms is part of the subscription that follows, not the pack.
Is this the same as the AI Risk Assessment?
No. The AI Risk Assessment covers your use of AI as a whole. This pack covers the specific problem of software that acts on your behalf: what it may do, who watches it, and how you prove both.
Does it satisfy the EU AI Act?
It produces the transparency and oversight evidence that Article 50 and Article 14 call for. Transparency duties for customer-facing AI have applied since August 2026; high-risk system obligations land in December 2027. The pack prepares the inventory you will need for that classification. Where an obligation turns on your jurisdiction or circumstances, you need a lawyer.
Do you reproduce ISO standard text?
No. Documents reference clauses and paraphrase their intent. If you need the standards themselves, buy them from ISO or your national body.
Who reviews the output?
Every document passes an independent review stage before you see it. A professional review by a person is available separately, from $600, scoped per document.