Compliance · ISO/IEC 27001:2022
ISO 27001for agentic AI
The fourteen ISO 27001:2022 Annex A controls that agent adoption touches, each mapped to the Speakeasy AI Control Plane capability that implements it.
14
Annex A controls mapped
Each id links to the implementation, runtime, and evidence detail in the full reference.
3
Annex A groups covered
Organizational (A.5), people (A.6), and technological (A.8) controls.
170+
Audit event types
Captured with per-call attribution and SIEM export, evidencing the mapped controls.
01 · The mapping
Annex A, control by control
Ids follow the 2022 edition of the standard. Each control links to the per-control detail in the full reference.
A.5
Organizational controls
Governance, inventory, identity, supplier, and incident controls: the clauses that define what an organization knows about its agents and who is accountable for them.
Blocks or holds risky tool calls for human acknowledgement, splits credentials by environment, and routes exceptions through an admin approval queue.
Maintains a live register of agents, tools, MCP servers, and owners as a side effect of use, and discovers unsanctioned servers from live traffic.
Publishes the sanctioned toolsets and surfaces per-user shadow MCP usage with recorded disposition decisions.
Issues every agent a revocable identity with scoped keys, and attributes every tool call to a named user and key.
Records every MCP server as a supplier, with registry provenance, package metadata, and capability scoring for procurement review.
Contains a compromised agent through session revocation, before-and-after audit snapshots, session transcripts, and deployment rollback lineage.
A.6
People controls
The humans who supervise, approve, and rely on agents, and what they need to know to do it safely.
Turns policy warnings into per-person acknowledgements bound to the fingerprint of the exact tool call.
A.8
Technological controls
Access, configuration, deletion, logging, monitoring, network, and environment-separation controls, enforced at the layer agents actually operate on: the tool call.
Enforces access restriction per tool call through toolset grants, roles, and resolved access challenges.
Versions agent configuration as append-only deployments and freezes tool lists to the approved snapshot: upstream changes cannot inject new capabilities, only downgrade to a subset or trigger an approval chain.
Revokes sessions, consents, keys, and grants when an agent is decommissioned, with retention TTLs of 90, 400, and 730 days enforced automatically.
Captures more than 170 audit event types and redacted tool-call logs, with per-call attribution and SIEM export.
Scans prompts and tool calls with Watchdog, scores findings by severity, and blocks spend past budget limits.
Constrains agent egress to deployment-defined destinations and flags exfiltration that rides legitimate tool calls.
Binds credentials to environments, so pointing an agent at production is a deliberate, recorded change.
02 · Certification
Certified and audited
The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.
Visit trust center