Compliance · ISO/IEC 27001:2022

ISO 27001for agentic AI

The fourteen ISO 27001:2022 Annex A controls that agent adoption touches, each mapped to the Speakeasy AI Control Plane capability that implements it.

14

Annex A controls mapped

Each id links to the implementation, runtime, and evidence detail in the full reference.

3

Annex A groups covered

Organizational (A.5), people (A.6), and technological (A.8) controls.

170+

Audit event types

Captured with per-call attribution and SIEM export, evidencing the mapped controls.


01 · The mapping

Annex A, control by control

Ids follow the 2022 edition of the standard. Each control links to the per-control detail in the full reference.

A.5

Organizational controls

Governance, inventory, identity, supplier, and incident controls: the clauses that define what an organization knows about its agents and who is accountable for them.

Blocks or holds risky tool calls for human acknowledgement, splits credentials by environment, and routes exceptions through an admin approval queue.

Maintains a live register of agents, tools, MCP servers, and owners as a side effect of use, and discovers unsanctioned servers from live traffic.

Publishes the sanctioned toolsets and surfaces per-user shadow MCP usage with recorded disposition decisions.

Issues every agent a revocable identity with scoped keys, and attributes every tool call to a named user and key.

Records every MCP server as a supplier, with registry provenance, package metadata, and capability scoring for procurement review.

Contains a compromised agent through session revocation, before-and-after audit snapshots, session transcripts, and deployment rollback lineage.

A.6

People controls

The humans who supervise, approve, and rely on agents, and what they need to know to do it safely.

Turns policy warnings into per-person acknowledgements bound to the fingerprint of the exact tool call.

A.8

Technological controls

Access, configuration, deletion, logging, monitoring, network, and environment-separation controls, enforced at the layer agents actually operate on: the tool call.

Enforces access restriction per tool call through toolset grants, roles, and resolved access challenges.

Versions agent configuration as append-only deployments and freezes tool lists to the approved snapshot: upstream changes cannot inject new capabilities, only downgrade to a subset or trigger an approval chain.

Revokes sessions, consents, keys, and grants when an agent is decommissioned, with retention TTLs of 90, 400, and 730 days enforced automatically.

Captures more than 170 audit event types and redacted tool-call logs, with per-call attribution and SIEM export.

Scans prompts and tool calls with Watchdog, scores findings by severity, and blocks spend past budget limits.

Constrains agent egress to deployment-defined destinations and flags exfiltration that rides legitimate tool calls.

Binds credentials to environments, so pointing an agent at production is a deliberate, recorded change.

02 · Certification

Certified and audited

The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.

Visit trust center

AI everywhere.

Control here.