RESEARCH / GLOBAL CONTROL-LAYER CROSSWALK

Global control frameworks, mapped to the execution boundary.

A functional crosswalk of major AI governance, risk, access, runtime-control, human-oversight and financial-sector references against the execution boundary.

Execution Control Infrastructure → Human Authority Layer → Execution Boundary → Control Before Consequence.

Version 1.0 · September 2026Public research recordSource status reviewed against official records

Convergence makes category boundaries more important.

This record does not rank, replace, or diminish adjacent standards, regulation, governance, security, or agent-control work. It identifies the primary function each reference governs and the distinct control question addressed by Execution Control Infrastructure.

ECI is the category. The Human Authority Layer is the accountable institutional authority requirement ECI is designed to keep effective. The Execution Boundary is the control position. Control Before Consequence is the governing principle.

The question is not whether an upstream framework is strong. The question is whether a specific consequential action is independently cleared before consequence exists.

Different controls answer different questions.

No single framework is expected to perform every control function. The value of the crosswalk is functional separation.

01 / Governance

Organizational AI governance

Policies, management systems, accountability structures, risk ownership and institutional processes.

02 / Risk

Risk and impact management

Identification, assessment, treatment and monitoring of AI-related risk and impact.

03 / Access

Identity and authorization

Who or what may access a resource, under which permissions, identities and security conditions.

04 / Runtime

Agent and runtime controls

Visibility, policy enforcement, middleware controls and behavioral constraints during operation.

05 / Oversight

Human oversight

Human control, monitoring, intervention and accountability across the AI system lifecycle.

06 / Execution

Execution Control Infrastructure

Independent determination at the execution boundary of whether a consequential action is cleared to become consequence.

Global references mapped by control function.

The comparison below is deliberately narrow. It describes primary orientation and the relationship to the execution-boundary question. Adjacent frameworks may contain overlapping controls; overlap does not make the categories equivalent.

ReferencePrimary orientationWhat it establishesRelationship to ECI
NIST AI RMF 1.0Voluntary framework · 2023 · revision in progress AI risk governance and management. A voluntary, organization-level framework for managing AI risks and trustworthiness considerations across design, development, deployment and use. Provides the broader risk-management context in which execution controls can be governed. It does not by itself define an independent execution-boundary clearance function for each consequential action. ECI addresses that action-level control position.
ISO/IEC 42001:2023Published International Standard AI management systems. Organizational policies and procedures for governing AI-related risks and opportunities through a management-system approach. ECI can sit within an institution's technical control environment under an AI management system. The management system governs organizational practice; ECI governs whether a specific consequential action is independently cleared at execution.
ISO/IEC 23894:2023Published International Standard AI risk management. Guidance for integrating AI-specific risk management into organizational activities and functions. Risk analysis can establish why execution controls are required and how their risks should be managed. ECI is the separate control function concerned with the pre-consequence determination on a specific consequential action.
ISO/IEC FDIS 42105Human oversight guidance · under development · 2026 Human control and monitoring of AI systems. Guidance on human oversight across the AI system lifecycle, applicable across organization types. This is closely adjacent to OATHOR's authority requirement. ECI addresses the architectural control position through which accountable authority can remain effective at the final boundary before consequential execution. The relationship is complementary, not equivalent.
EU AI Act · Article 14Regulation · human oversight for high-risk AI Legal requirement for effective human oversight. Requires high-risk AI systems in scope to be designed and developed so natural persons can effectively oversee them, with measures proportionate to risk, autonomy and context. Article 14 states a regulatory requirement, not a universal control architecture. ECI can be evaluated as one possible technical architecture for making authority effective at execution where relevant. No compliance, certification or regulatory endorsement is implied.
NIST SP 800-207Zero Trust Architecture · 2020 Identity, access and resource protection. Zero-trust principles centered on protecting resources and making authentication and authorization explicit before access or sessions are established. ECI is distinct from identity and access control. Even where identity and authorization have established who may act and within what permitted scope, ECI asks a separate question: whether that consequential action is cleared to become consequence now.
OWASP Agent Control StandardOpen agent-control standard · September 2026 Runtime agent transparency and control. Defines mechanisms for agent platforms to expose middleware hooks and support portable runtime policy enforcement, traceability and control. This is the closest current runtime-control adjacency. An ACS implementation may provide mechanisms that support an ECI architecture. ECI classification, however, depends on whether the consequential action is subject to an independent, accountable determination at the execution boundary; runtime enforcement alone does not by itself establish that condition.
NIST AI Agent Standards InitiativeStandards initiative · February 2026 Secure, interoperable agent ecosystem. An initiative intended to foster industry-led standards and protocols for secure, interoperable AI agents and confident adoption. The initiative is not itself an execution-control standard. It is relevant standards context in which execution-boundary requirements can be mapped as autonomous agents interact with external systems and take consequential actions.
FSB Sound Practices for Responsible AI AdoptionConsultation report · June 2026 · not an international standard Financial-sector AI governance and lifecycle risk. Proposed sound practices covering organization-wide governance, AI development and deployment risk, and cyber, ICT and third-party risk for financial institutions. Provides sectoral governance context for financial institutions. ECI addresses the distinct execution-boundary question for consequential financial actions. OATHOR's published consultation response is a participation record only and does not imply FSB endorsement or validation.

Functional mapping only. Standards, regulation and guidance evolve. This record should be read with the official source text and does not constitute legal, regulatory, certification or compliance advice.

The crosswalk applies the existing ECI criteria. It does not create new doctrine.

OATHOR's canonical ECI definition already carries a category test. This record preserves it.

  • 01It must not merely authenticate identity.
  • 02It must not merely approve workflow.
  • 03It must not merely monitor behaviour.
  • 04It must not merely record occurrence.
  • 05It must independently determine, at the execution boundary and before consequence, whether a permissioned, authenticated, approved or prepared action is cleared to become consequence.

Adjacent controls can converge without collapsing into the same category.

Stronger governance, better access control, improved agent guardrails and more effective human oversight all increase the quality of the control environment. They do not remove the need to identify who holds authority when a consequential action reaches the final point at which it can still be stopped.

The durable distinction is functional: permission is not consequence, oversight is not execution clearance, and runtime control is not automatically independent authority.

A versioned reference open to scrutiny.

OATHOR welcomes factual corrections, standards mapping input and institutional scrutiny from standards bodies, research organizations, technology providers, financial institutions and public-sector stakeholders.

External correspondence, inclusion or source citation does not imply endorsement, adoption, validation, certification or partnership. Changes to this record should improve factual accuracy or mapping precision without rewriting the dated category record.

Official source record.

Source status reviewed against official institutional records in September 2026.

Source-context rule. External references are independent. Their inclusion here demonstrates functional context only. It does not imply affiliation, endorsement, adoption, validation or recognition of OATHOR terminology.