Organizational AI governance
Policies, management systems, accountability structures, risk ownership and institutional processes.
RESEARCH / GLOBAL CONTROL-LAYER CROSSWALK
A functional crosswalk of major AI governance, risk, access, runtime-control, human-oversight and financial-sector references against the execution boundary.
Execution Control Infrastructure → Human Authority Layer → Execution Boundary → Control Before Consequence.
This record does not rank, replace, or diminish adjacent standards, regulation, governance, security, or agent-control work. It identifies the primary function each reference governs and the distinct control question addressed by Execution Control Infrastructure.
ECI is the category. The Human Authority Layer is the accountable institutional authority requirement ECI is designed to keep effective. The Execution Boundary is the control position. Control Before Consequence is the governing principle.
The question is not whether an upstream framework is strong. The question is whether a specific consequential action is independently cleared before consequence exists.
No single framework is expected to perform every control function. The value of the crosswalk is functional separation.
Policies, management systems, accountability structures, risk ownership and institutional processes.
Identification, assessment, treatment and monitoring of AI-related risk and impact.
Who or what may access a resource, under which permissions, identities and security conditions.
Visibility, policy enforcement, middleware controls and behavioral constraints during operation.
Human control, monitoring, intervention and accountability across the AI system lifecycle.
Independent determination at the execution boundary of whether a consequential action is cleared to become consequence.
The comparison below is deliberately narrow. It describes primary orientation and the relationship to the execution-boundary question. Adjacent frameworks may contain overlapping controls; overlap does not make the categories equivalent.
| Reference | Primary orientation | What it establishes | Relationship to ECI |
|---|---|---|---|
| NIST AI RMF 1.0Voluntary framework · 2023 · revision in progress | AI risk governance and management. | A voluntary, organization-level framework for managing AI risks and trustworthiness considerations across design, development, deployment and use. | Provides the broader risk-management context in which execution controls can be governed. It does not by itself define an independent execution-boundary clearance function for each consequential action. ECI addresses that action-level control position. |
| ISO/IEC 42001:2023Published International Standard | AI management systems. | Organizational policies and procedures for governing AI-related risks and opportunities through a management-system approach. | ECI can sit within an institution's technical control environment under an AI management system. The management system governs organizational practice; ECI governs whether a specific consequential action is independently cleared at execution. |
| ISO/IEC 23894:2023Published International Standard | AI risk management. | Guidance for integrating AI-specific risk management into organizational activities and functions. | Risk analysis can establish why execution controls are required and how their risks should be managed. ECI is the separate control function concerned with the pre-consequence determination on a specific consequential action. |
| ISO/IEC FDIS 42105Human oversight guidance · under development · 2026 | Human control and monitoring of AI systems. | Guidance on human oversight across the AI system lifecycle, applicable across organization types. | This is closely adjacent to OATHOR's authority requirement. ECI addresses the architectural control position through which accountable authority can remain effective at the final boundary before consequential execution. The relationship is complementary, not equivalent. |
| EU AI Act · Article 14Regulation · human oversight for high-risk AI | Legal requirement for effective human oversight. | Requires high-risk AI systems in scope to be designed and developed so natural persons can effectively oversee them, with measures proportionate to risk, autonomy and context. | Article 14 states a regulatory requirement, not a universal control architecture. ECI can be evaluated as one possible technical architecture for making authority effective at execution where relevant. No compliance, certification or regulatory endorsement is implied. |
| NIST SP 800-207Zero Trust Architecture · 2020 | Identity, access and resource protection. | Zero-trust principles centered on protecting resources and making authentication and authorization explicit before access or sessions are established. | ECI is distinct from identity and access control. Even where identity and authorization have established who may act and within what permitted scope, ECI asks a separate question: whether that consequential action is cleared to become consequence now. |
| OWASP Agent Control StandardOpen agent-control standard · September 2026 | Runtime agent transparency and control. | Defines mechanisms for agent platforms to expose middleware hooks and support portable runtime policy enforcement, traceability and control. | This is the closest current runtime-control adjacency. An ACS implementation may provide mechanisms that support an ECI architecture. ECI classification, however, depends on whether the consequential action is subject to an independent, accountable determination at the execution boundary; runtime enforcement alone does not by itself establish that condition. |
| NIST AI Agent Standards InitiativeStandards initiative · February 2026 | Secure, interoperable agent ecosystem. | An initiative intended to foster industry-led standards and protocols for secure, interoperable AI agents and confident adoption. | The initiative is not itself an execution-control standard. It is relevant standards context in which execution-boundary requirements can be mapped as autonomous agents interact with external systems and take consequential actions. |
| FSB Sound Practices for Responsible AI AdoptionConsultation report · June 2026 · not an international standard | Financial-sector AI governance and lifecycle risk. | Proposed sound practices covering organization-wide governance, AI development and deployment risk, and cyber, ICT and third-party risk for financial institutions. | Provides sectoral governance context for financial institutions. ECI addresses the distinct execution-boundary question for consequential financial actions. OATHOR's published consultation response is a participation record only and does not imply FSB endorsement or validation. |
Functional mapping only. Standards, regulation and guidance evolve. This record should be read with the official source text and does not constitute legal, regulatory, certification or compliance advice.
OATHOR's canonical ECI definition already carries a category test. This record preserves it.
Stronger governance, better access control, improved agent guardrails and more effective human oversight all increase the quality of the control environment. They do not remove the need to identify who holds authority when a consequential action reaches the final point at which it can still be stopped.
The durable distinction is functional: permission is not consequence, oversight is not execution clearance, and runtime control is not automatically independent authority.
OATHOR welcomes factual corrections, standards mapping input and institutional scrutiny from standards bodies, research organizations, technology providers, financial institutions and public-sector stakeholders.
External correspondence, inclusion or source citation does not imply endorsement, adoption, validation, certification or partnership. Changes to this record should improve factual accuracy or mapping precision without rewriting the dated category record.
Source status reviewed against official institutional records in September 2026.
AI Risk Management Framework 1.0 · SP 800-207 Zero Trust Architecture · AI Agent Standards Initiative
ISO/IEC 42001:2023 · ISO/IEC 23894:2023 · ISO/IEC FDIS 42105
Sound Practices for Responsible Adoption of Artificial Intelligence — Consultation report