Skip to content
Open access

Mapping C3P Control Objectives to ISO/IEC 42001 Requirements for AI Lifecycle Governance

Jul 2026 · Universal Library of Innovative Research and Studies · 0 citations · 9 references

TL;DR

The central finding is that the same four points generalize without modification to AI coding agents and to general agentic workflows, where a defined purpose, an auditable trail, verification, and safe delivery produce tamper-evident evidence at every stage.

Abstract

This article examines how the four control objectives of the Continuous Compliance Control Protocol align with the requirements of ISO/IEC 42001 for managing an artificial intelligence system across its lifecycle, and how they generalize to autonomous agents. Organizations adopt artificial intelligence in regulated settings faster than they build the mechanisms that continuously prove governance, and a management system standard states what must be governed, while leaving open how durable evidence is produced as systems run. A baseline mapping establishes that the four control points meet the requirements of the standard for a conventional, human-in-the-loop deployment. The central finding is that the same four points generalize without modification to AI coding agents and to general agentic workflows, where a defined purpose, an auditable trail, verification, and safe delivery produce tamper-evident evidence at every stage. That evidence assembles into a chain of custody for the agent that supplies exactly the documentation an ISO/IEC 42001 audit expects. The work serves compliance leaders, audit professionals, and engineering teams who govern autonomous artificial intelligence.

Read PDF

Similar papers

Open access Jul 2026

The Model Context Protocol and Enterprise Tool Orchestration: Architectural Patterns for Connecting AI Agents to Production Systems at Scale

Autonomous AI agents operating in enterprise environments require both standardized connectivity to production tools and a governance architecture for doing so safely. The Model Context Protocol (MCP), introduced in November 2024 and transferred to the Agentic AI Foundation under the Linux Foundation in December 2025, has reached 97 million monthly SDK downloads and adoption across all major AI providers within sixteen months of launch. The specification addresses connectivity; it does not address governance. Enterprise architects deploying agents in regulated, mission-critical environments face a structural gap: no architectural guidance exists for permission enforcement, risk-tiered execution, or audit trail requirements at the MCP protocol layer. This article reports three contributions derived from an eighteen-month production deployment connecting autonomous agents to fourteen enterprise systems across 270 globally distributed data centers. First, a three-tier integration pattern taxonomy maps tool risk profiles to appropriate governance mechanisms. Second, a permission manifest architecture embeds role-based access control (RBAC), rate limiting, and scope constraints into MCP server registration — making safety a protocol-level property rather than an application-level afterthought. Third, empirical measurement confirms a 73 percent reduction in per-tool engineering effort and complete cross-platform portability across three AI providers. These patterns provide enterprise architects with a validated governance framework for production MCP deployment.

Satish Chandra, Guruvelli · 0 citations
2026

Governing Agentic AI in Enterprise Operations: Architectural “Rails” for Safe, Deterministic, and Compliant Autonomous Systems

This paper argues that the introduction of agentic AI requires a substantial expansion of traditional enterprise architecture principles to address new behavioral, security, and governance risks emerging from non-deterministic AI systems interacting with heterogeneous operational platforms-ERP, HCM, CLM, asset management, workflow engines, and domain-specific applications.

Elizabeth Koumpan, Vimal Dimpi · 0 citations
Open access 2026

Deliver cross-process automation across Finance, HR, Procurement by orchestrating actions across diverse systems -powered by AI & governed workflows

This research demonstrates that when designed with ergonomics, human values, and socio‑technical principles at the center, agentic AI become powerful enablers of human‑centric, resilient, and adaptive enterprises.

Elizabeth Koumpan, Laurentiu Gabriel Ghergu, Łukasz Strack et al. · 0 citations
Preprint Jul 2026

Stop Shipping AI Agents on Faith: Capability Is Not Production Readiness

AI agents are moving into production workflows where they retrieve information, call tools, maintain state, and act on behalf of users or organizations, but many release decisions still rely on capability signals, demos, or behavioral tests that do not show whether an agent is ready to operate under production constraints. Capability is therefore not production readiness. This paper introduces the ProofAgent Index (PAI), a governance readiness index for AI agents. PAI combines four dimensions of deployment evidence: Evaluation, Context, Compliance, and Governance. Evaluation measures observed behavior, Context measures the operating environment that shapes that behavior, Compliance measures alignment with applicable rules and controls, and Governance measures whether the organization can authorize, monitor, audit, and control the agent during operation. PAI is implemented inside ProofAgent Harness, an open source infrastructure for auditable AI agent evaluation and governance. Validation across two heavily regulated domains, healthcare and finance, shows that PAI carries held out readiness signal and separates higher risk from lower risk configurations. The results show that context engineering strongly changes reliability, capability improves behavior but does not determine readiness, and governance evidence must remain visible rather than averaged away. PAI reframes agent release from a faith based deployment decision into an auditable readiness decision.

Fouad Bousetouane · 0 citations
Book Open access Jul 2026

Dependency-Aware Over-the-Air Framework for Reliable Software-Defined Vehicle Updates

A dependency-aware OTA orchestration framework that addresses challenges in improving update success rates, efficiency in execution time and update requests through optimized scheduling, and feasibility in maintaining system-wide integrity by successfully reconciling stringent safety requirements and diverse update sensitivity constraints is proposed.

Juyeon Park, In-Young Ko · 0 citations
Conference Open access 2026

Managing Cybersecurity Compliance with Structured Guidance and Integrated Audit Support

: As cybersecurity regulations such as ISO/IEC 27001 and the NIS2 Directive continue to expand in scope and complexity, organizations face growing challenges in translating regulatory obligations into actionable security policies and audit-ready evidence. Conventional compliance approaches rely on manual interpretation of regulatory texts, fragmented documentation repositories, and ad hoc audit preparation, introducing operational bottlenecks and exposing organizations to non-compliance risks. This paper presents a compliance management platform that operationalizes regulatory requirements through structured, expert-guided control implementation. It combines NLP extraction with human-supervised annotation to convert regulatory texts into machine-readable frameworks, enabling multi-framework management (ISO/IEC 27001:2022 and NIS2), control mapping, evidence tracking, and role-based audit workflows. In a task-based usability study with twelve participants, the platform scored 83.3 on the System Usability Scale (SUS), rated “excellent,” indicating that embedded guidance can reduce expertise barriers in cybersecurity compliance management.

Mariana Andrade, João Rafael Almeida, J. Oliveira · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.