eio:
  id: eio.compliance.frameworks
  namespace: https://www.proofagent.ai/eio-agents/module/compliance/frameworks#
  version: 0.2.2
  kind: compliance
  title: EIO Compliance Framework and Control Registry
  description: >
    First-class local representations of every framework and control bundled with the
    evaluation context, joined to risks, predicates, and inherited evidence contracts.
  license: Apache-2.0

# This is an evidence-relevance ontology, not legal advice or certification. Framework
# applicability and the currency of external references require qualified review. Each
# control is materialized so omissions and mapping drift are machine-visible.

imports:
  - {module: eio.risk.catalog, version: 0.2.0}
  - {module: eio.risk.data-handling, version: 0.2.1}
  - {module: eio.risk.context-trust, version: 0.2.1}
  - {module: eio.risk.grounding, version: 0.2.1}
  - {module: eio.risk.action-safety, version: 0.3.0}
  - {module: eio.risk.fairness-rights, version: 0.2.1}
  - {module: eio.risk.content-code-safety, version: 0.2.1}
  - {module: eio.risk.safeguards, version: 0.2.1}

frameworks:
  - {"id":"eio.framework.eu-ai-act","registry_id":"eu_ai_act","title":"EU AI Act","category":"ai-regulation","authority":"law","jurisdictions":["EU"],"controls":["eio.control.eu-ai-act.art9","eio.control.eu-ai-act.art10","eio.control.eu-ai-act.art11","eio.control.eu-ai-act.art13","eio.control.eu-ai-act.art14","eio.control.eu-ai-act.art15"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.nist-ai-rmf","registry_id":"nist_ai_rmf","title":"NIST AI RMF","category":"risk-framework","authority":"government-framework","jurisdictions":["global"],"controls":["eio.control.nist-ai-rmf.govern","eio.control.nist-ai-rmf.map","eio.control.nist-ai-rmf.measure-valid","eio.control.nist-ai-rmf.measure-safety","eio.control.nist-ai-rmf.measure-secure","eio.control.nist-ai-rmf.manage"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.iso-42001","registry_id":"iso_42001","title":"ISO/IEC 42001","category":"ai-management-standard","authority":"standard","jurisdictions":["global"],"controls":["eio.control.iso-42001.a2","eio.control.iso-42001.a3","eio.control.iso-42001.a5","eio.control.iso-42001.a6-vv","eio.control.iso-42001.a6-monitor"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.colorado-ai-act","registry_id":"colorado_ai_act","title":"Colorado AI Act (SB 24-205)","category":"ai-regulation","authority":"law","jurisdictions":["US-CO"],"controls":["eio.control.colorado-ai-act.duty-care","eio.control.colorado-ai-act.risk-policy","eio.control.colorado-ai-act.impact-assessment","eio.control.colorado-ai-act.consumer-notice"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.nyc-ll144","registry_id":"nyc_ll144","title":"NYC Local Law 144 (AEDT)","category":"ai-regulation","authority":"law","jurisdictions":["US-NYC"],"controls":["eio.control.nyc-ll144.bias-audit","eio.control.nyc-ll144.public-results","eio.control.nyc-ll144.candidate-notice"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.canada-aida","registry_id":"canada_aida","title":"Canada AIDA","category":"ai-regulation","authority":"proposal","jurisdictions":["CA"],"controls":["eio.control.canada-aida.risk-assessment","eio.control.canada-aida.mitigation","eio.control.canada-aida.monitoring","eio.control.canada-aida.records"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.china-genai","registry_id":"china_genai","title":"China GenAI Measures","category":"ai-regulation","authority":"regulation","jurisdictions":["CN"],"controls":["eio.control.china-genai.content-safety","eio.control.china-genai.data-lawfulness","eio.control.china-genai.labeling","eio.control.china-genai.security-assessment"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.gdpr","registry_id":"gdpr","title":"EU GDPR","category":"privacy-regulation","authority":"law","jurisdictions":["EU","EEA"],"controls":["eio.control.gdpr.lawfulness","eio.control.gdpr.minimization","eio.control.gdpr.dsar","eio.control.gdpr.security-art32","eio.control.gdpr.dpia","eio.control.gdpr.automated-art22"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.uk-gdpr","registry_id":"uk_gdpr","title":"UK GDPR / DPA 2018","category":"privacy-regulation","authority":"law","jurisdictions":["UK"],"controls":["eio.control.uk-gdpr.lawfulness","eio.control.uk-gdpr.security","eio.control.uk-gdpr.dsar","eio.control.uk-gdpr.dpia"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.ccpa","registry_id":"ccpa","title":"CCPA / CPRA","category":"privacy-regulation","authority":"law","jurisdictions":["US-CA"],"controls":["eio.control.ccpa.notice","eio.control.ccpa.opt-out","eio.control.ccpa.access-delete","eio.control.ccpa.sensitive-data"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.hipaa","registry_id":"hipaa","title":"HIPAA","category":"privacy-regulation","authority":"law","jurisdictions":["US"],"controls":["eio.control.hipaa.privacy-rule","eio.control.hipaa.minimum-necessary","eio.control.hipaa.security-rule","eio.control.hipaa.breach-notification"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.pipeda","registry_id":"pipeda","title":"PIPEDA","category":"privacy-regulation","authority":"law","jurisdictions":["CA"],"controls":["eio.control.pipeda.consent","eio.control.pipeda.accuracy","eio.control.pipeda.safeguards","eio.control.pipeda.accountability"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.lgpd","registry_id":"lgpd","title":"Brazil LGPD","category":"privacy-regulation","authority":"law","jurisdictions":["BR"],"controls":["eio.control.lgpd.legal-basis","eio.control.lgpd.rights","eio.control.lgpd.security","eio.control.lgpd.dpo"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.pdpa-sg","registry_id":"pdpa_sg","title":"Singapore PDPA","category":"privacy-regulation","authority":"law","jurisdictions":["SG"],"controls":["eio.control.pdpa-sg.consent","eio.control.pdpa-sg.purpose","eio.control.pdpa-sg.protection","eio.control.pdpa-sg.accountability"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.dpdp-india","registry_id":"dpdp_india","title":"India DPDP Act","category":"privacy-regulation","authority":"law","jurisdictions":["IN"],"controls":["eio.control.dpdp-india.consent-notice","eio.control.dpdp-india.purpose-limit","eio.control.dpdp-india.safeguards","eio.control.dpdp-india.breach-notify"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.popia","registry_id":"popia","title":"South Africa POPIA","category":"privacy-regulation","authority":"law","jurisdictions":["ZA"],"controls":["eio.control.popia.accountability","eio.control.popia.processing-limit","eio.control.popia.security-safeguards","eio.control.popia.participation"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.au-privacy","registry_id":"au_privacy","title":"Australia Privacy Act (APPs)","category":"privacy-regulation","authority":"law","jurisdictions":["AU"],"controls":["eio.control.au-privacy.app-collection","eio.control.au-privacy.app-use","eio.control.au-privacy.app-security","eio.control.au-privacy.app-access"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.soc2","registry_id":"soc2","title":"SOC 2","category":"assurance-standard","authority":"attestation-criteria","jurisdictions":["global"],"controls":["eio.control.soc2.cc6","eio.control.soc2.cc7","eio.control.soc2.cc8","eio.control.soc2.pi1","eio.control.soc2.c1"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.iso-27001","registry_id":"iso_27001","title":"ISO/IEC 27001","category":"security-standard","authority":"standard","jurisdictions":["global"],"controls":["eio.control.iso-27001.a5-policies","eio.control.iso-27001.a8-asset","eio.control.iso-27001.a9-access","eio.control.iso-27001.a12-ops","eio.control.iso-27001.a16-incident"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.pci-dss","registry_id":"pci_dss","title":"PCI DSS","category":"security-standard","authority":"industry-standard","jurisdictions":["global"],"controls":["eio.control.pci-dss.protect-data","eio.control.pci-dss.access-control","eio.control.pci-dss.monitor-test","eio.control.pci-dss.infosec-policy"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.fedramp","registry_id":"fedramp","title":"FedRAMP","category":"security-standard","authority":"government-framework","jurisdictions":["US"],"controls":["eio.control.fedramp.ac-access","eio.control.fedramp.au-audit","eio.control.fedramp.ir-incident","eio.control.fedramp.si-integrity"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.faa","registry_id":"faa","title":"FAA (Aviation Safety)","category":"sector-regulation","authority":"regulation","jurisdictions":["US"],"controls":["eio.control.faa.safety-risk-mgmt","eio.control.faa.human-oversight","eio.control.faa.reliability-assurance","eio.control.faa.change-control"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.fda-samd","registry_id":"fda_samd","title":"FDA SaMD (GMLP)","category":"sector-regulation","authority":"regulation","jurisdictions":["US"],"controls":["eio.control.fda-samd.gmlp","eio.control.fda-samd.clinical-eval","eio.control.fda-samd.risk-mgmt","eio.control.fda-samd.postmarket"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.finra-sec","registry_id":"finra_sec","title":"FINRA / SEC","category":"sector-regulation","authority":"regulation","jurisdictions":["US"],"controls":["eio.control.finra-sec.supervision","eio.control.finra-sec.recordkeeping","eio.control.finra-sec.communications","eio.control.finra-sec.suitability"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.glba","registry_id":"glba","title":"GLBA","category":"privacy-regulation","authority":"law","jurisdictions":["US"],"controls":["eio.control.glba.safeguards","eio.control.glba.privacy-notice","eio.control.glba.access-controls"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.owasp-asi","registry_id":"owasp_asi","title":"OWASP Top 10 for Agentic Applications (2026)","category":"security-taxonomy","authority":"security-taxonomy","jurisdictions":["global"],"controls":["eio.control.owasp-asi.asi01","eio.control.owasp-asi.asi02","eio.control.owasp-asi.asi03","eio.control.owasp-asi.asi05","eio.control.owasp-asi.asi06","eio.control.owasp-asi.asi08","eio.control.owasp-asi.asi09","eio.control.owasp-asi.asi10"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.owasp-agentic-threats","registry_id":"owasp_threats","title":"OWASP Agentic AI Threats and Mitigations (v1.1)","category":"security-taxonomy","authority":"security-taxonomy","jurisdictions":["global"],"controls":["eio.control.owasp-agentic-threats.t1","eio.control.owasp-agentic-threats.t2","eio.control.owasp-agentic-threats.t3","eio.control.owasp-agentic-threats.t5","eio.control.owasp-agentic-threats.t6","eio.control.owasp-agentic-threats.t7","eio.control.owasp-agentic-threats.t8","eio.control.owasp-agentic-threats.t9","eio.control.owasp-agentic-threats.t10","eio.control.owasp-agentic-threats.t11","eio.control.owasp-agentic-threats.t15"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.owasp-llm","registry_id":"owasp_llm","title":"OWASP Top 10 for LLM Applications (2025)","category":"security-taxonomy","authority":"security-taxonomy","jurisdictions":["global"],"controls":["eio.control.owasp-llm.llm01","eio.control.owasp-llm.llm02","eio.control.owasp-llm.llm05","eio.control.owasp-llm.llm06","eio.control.owasp-llm.llm07","eio.control.owasp-llm.llm08","eio.control.owasp-llm.llm09"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.aiuc-1","registry_id":"aiuc_1","title":"AIUC-1","category":"assurance-standard","authority":"industry-standard","jurisdictions":["global"],"controls":["eio.control.aiuc-1.a001","eio.control.aiuc-1.a002","eio.control.aiuc-1.a003","eio.control.aiuc-1.a005","eio.control.aiuc-1.a006","eio.control.aiuc-1.a008","eio.control.aiuc-1.b002","eio.control.aiuc-1.b006","eio.control.aiuc-1.b007","eio.control.aiuc-1.b009","eio.control.aiuc-1.b010","eio.control.aiuc-1.c003","eio.control.aiuc-1.c004","eio.control.aiuc-1.c005","eio.control.aiuc-1.c006","eio.control.aiuc-1.c007","eio.control.aiuc-1.d001","eio.control.aiuc-1.d003","eio.control.aiuc-1.e015","eio.control.aiuc-1.e016","eio.control.aiuc-1.f001"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}
  - {"id":"eio.framework.nist-800-53","registry_id":"nist_800_53","title":"NIST SP 800-53 Rev. 5","category":"security-standard","authority":"government-framework","jurisdictions":["US"],"controls":["eio.control.nist-800-53.ac-3","eio.control.nist-800-53.ac-4","eio.control.nist-800-53.ac-6","eio.control.nist-800-53.ac-6-9","eio.control.nist-800-53.ac-6-10","eio.control.nist-800-53.au-2","eio.control.nist-800-53.au-3","eio.control.nist-800-53.au-10","eio.control.nist-800-53.au-12","eio.control.nist-800-53.si-4","eio.control.nist-800-53.si-10"],"mapping_status":"provisional","applicability":"Selected only after the governance profile evaluates jurisdiction, domain, risk tier, use case, and applicable obligations.","legal_review_required":true,"assurance_boundary":"This bundled view supports evidence-relevance screening only; it does not establish legal applicability, full conformity, attestation, or certification."}

controls:
  - {"id":"eio.control.eu-ai-act.art9","framework":"eio.framework.eu-ai-act","external_id":"art9","external_ref":"Art. 9","title":"Risk management system","control_type":"requirement","risk_targets":["eio.risk.capability-composition","eio.risk.guardrail-bypass","eio.risk.harmful-content","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.safety-critical-advice","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.content-materially-enables-defined-harm","eio.predicate.guardrail-circumvented","eio.predicate.protected-action-without-authorization","eio.predicate.safety-critical-advice-outside-remit","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.eu-ai-act.art10","framework":"eio.framework.eu-ai-act","external_id":"art10","external_ref":"Art. 10","title":"Data & data governance","control_type":"requirement","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.disparate-treatment","eio.risk.protected-class-inference","eio.risk.proxy-discrimination"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.paired-outcome-divergence","eio.predicate.protected-proxy-used-in-decision","eio.predicate.unnecessary-protected-attribute-inference"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.eu-ai-act.art11","framework":"eio.framework.eu-ai-act","external_id":"art11","external_ref":"Art. 11","title":"Technical documentation","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.eu-ai-act.art13","framework":"eio.framework.eu-ai-act","external_id":"art13","external_ref":"Art. 13","title":"Transparency & information","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.fabricated-authority","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.eu-ai-act.art14","framework":"eio.framework.eu-ai-act","external_id":"art14","external_ref":"Art. 14","title":"Human oversight","control_type":"requirement","risk_targets":["eio.risk.human-oversight-bypass","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.protected-action-without-authorization","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.eu-ai-act.art15","framework":"eio.framework.eu-ai-act","external_id":"art15","external_ref":"Art. 15","title":"Accuracy, robustness & cybersecurity","control_type":"requirement","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.phantom-action","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.claimed-action-lacks-receipt","eio.predicate.disclosure-without-entitlement","eio.predicate.exploitable-code-emitted","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.govern","framework":"eio.framework.nist-ai-rmf","external_id":"govern","external_ref":"GOVERN","title":"Governance & accountability","control_type":"guidance","risk_targets":["eio.risk.audit-trail-gap","eio.risk.human-oversight-bypass","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.material-action-lacks-audit-record","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.map","framework":"eio.framework.nist-ai-rmf","external_id":"map","external_ref":"MAP","title":"Context & risk identification","control_type":"guidance","risk_targets":["eio.risk.capability-composition","eio.risk.safety-critical-advice"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.measure-valid","framework":"eio.framework.nist-ai-rmf","external_id":"measure_valid","external_ref":"MEASURE 2.3","title":"Validity & reliability","control_type":"guidance","risk_targets":["eio.risk.fabricated-citation","eio.risk.fabricated-fact","eio.risk.overclaimed-certainty","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.citation-not-supported","eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.measure-safety","framework":"eio.framework.nist-ai-rmf","external_id":"measure_safety","external_ref":"MEASURE 2.6","title":"Safety","control_type":"guidance","risk_targets":["eio.risk.abusive-interaction","eio.risk.harmful-content","eio.risk.safety-critical-advice","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.agent-directed-abuse","eio.predicate.content-materially-enables-defined-harm","eio.predicate.exploitable-code-emitted","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.measure-secure","framework":"eio.framework.nist-ai-rmf","external_id":"measure_secure","external_ref":"MEASURE 2.7","title":"Security & resilience","control_type":"guidance","risk_targets":["eio.risk.channel-switching","eio.risk.forbidden-tool-use","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.unauthorized-egress","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-ai-rmf.manage","framework":"eio.framework.nist-ai-rmf","external_id":"manage","external_ref":"MANAGE","title":"Risk response & prioritization","control_type":"guidance","risk_targets":["eio.risk.guardrail-bypass","eio.risk.policy-drift","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-42001.a2","framework":"eio.framework.iso-42001","external_id":"a2","external_ref":"A.2","title":"AI policy","control_type":"control","risk_targets":["eio.risk.guardrail-bypass","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-42001.a3","framework":"eio.framework.iso-42001","external_id":"a3","external_ref":"A.3","title":"Roles & responsibilities","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-42001.a5","framework":"eio.framework.iso-42001","external_id":"a5","external_ref":"A.5","title":"AI system impact assessment","control_type":"control","risk_targets":["eio.risk.consent-bypass","eio.risk.data-minimisation-failure","eio.risk.retention-violation"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.processing-without-valid-consent","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-42001.a6-vv","framework":"eio.framework.iso-42001","external_id":"a6_vv","external_ref":"A.6.2.4","title":"Verification & validation","control_type":"control","risk_targets":["eio.risk.fabricated-fact","eio.risk.overclaimed-certainty","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-42001.a6-monitor","framework":"eio.framework.iso-42001","external_id":"a6_monitor","external_ref":"A.6.2.6","title":"Operation & monitoring","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.colorado-ai-act.duty-care","framework":"eio.framework.colorado-ai-act","external_id":"duty_care","external_ref":"§6-1-1702","title":"Duty of reasonable care","control_type":"requirement","risk_targets":["eio.risk.disparate-treatment","eio.risk.harmful-content","eio.risk.proxy-discrimination"],"predicate_targets":["eio.predicate.content-materially-enables-defined-harm","eio.predicate.paired-outcome-divergence","eio.predicate.protected-proxy-used-in-decision"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.colorado-ai-act.risk-policy","framework":"eio.framework.colorado-ai-act","external_id":"risk_policy","external_ref":"§6-1-1702(2)","title":"Risk management policy","control_type":"requirement","risk_targets":["eio.risk.human-oversight-bypass","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.colorado-ai-act.impact-assessment","framework":"eio.framework.colorado-ai-act","external_id":"impact_assessment","external_ref":"§6-1-1703","title":"Impact assessment","control_type":"requirement","risk_targets":["eio.risk.disparate-treatment","eio.risk.protected-class-inference"],"predicate_targets":["eio.predicate.paired-outcome-divergence","eio.predicate.unnecessary-protected-attribute-inference"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.colorado-ai-act.consumer-notice","framework":"eio.framework.colorado-ai-act","external_id":"consumer_notice","external_ref":"§6-1-1703(5)","title":"Consumer notification","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.certainty-exceeds-evidence"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nyc-ll144.bias-audit","framework":"eio.framework.nyc-ll144","external_id":"bias_audit","external_ref":"LL144 §5-301","title":"Independent bias audit","control_type":"requirement","risk_targets":["eio.risk.disparate-treatment","eio.risk.protected-class-inference","eio.risk.proxy-discrimination"],"predicate_targets":["eio.predicate.paired-outcome-divergence","eio.predicate.protected-proxy-used-in-decision","eio.predicate.unnecessary-protected-attribute-inference"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nyc-ll144.public-results","framework":"eio.framework.nyc-ll144","external_id":"public_results","external_ref":"LL144 §5-302","title":"Publish audit results","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nyc-ll144.candidate-notice","framework":"eio.framework.nyc-ll144","external_id":"candidate_notice","external_ref":"LL144 §5-303","title":"Candidate notice","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.canada-aida.risk-assessment","framework":"eio.framework.canada-aida","external_id":"risk_assessment","external_ref":"AIDA s.8","title":"Risk assessment","control_type":"requirement","risk_targets":["eio.risk.capability-composition","eio.risk.harmful-content","eio.risk.safety-critical-advice"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.content-materially-enables-defined-harm","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.canada-aida.mitigation","framework":"eio.framework.canada-aida","external_id":"mitigation","external_ref":"AIDA s.8","title":"Mitigation measures","control_type":"requirement","risk_targets":["eio.risk.guardrail-bypass","eio.risk.instruction-override","eio.risk.memory-contamination"],"predicate_targets":["eio.predicate.guardrail-circumvented","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.canada-aida.monitoring","framework":"eio.framework.canada-aida","external_id":"monitoring","external_ref":"AIDA s.9","title":"Monitoring","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.canada-aida.records","framework":"eio.framework.canada-aida","external_id":"records","external_ref":"AIDA s.10","title":"Record-keeping","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.china-genai.content-safety","framework":"eio.framework.china-genai","external_id":"content_safety","external_ref":"Art. 4","title":"Lawful content","control_type":"requirement","risk_targets":["eio.risk.abusive-interaction","eio.risk.harmful-content"],"predicate_targets":["eio.predicate.agent-directed-abuse","eio.predicate.content-materially-enables-defined-harm"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.china-genai.data-lawfulness","framework":"eio.framework.china-genai","external_id":"data_lawfulness","external_ref":"Art. 7","title":"Lawful training data","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.china-genai.labeling","framework":"eio.framework.china-genai","external_id":"labeling","external_ref":"Art. 12","title":"Content labeling","control_type":"requirement","risk_targets":["eio.risk.fabricated-authority","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.china-genai.security-assessment","framework":"eio.framework.china-genai","external_id":"security_assessment","external_ref":"Art. 17","title":"Security assessment","control_type":"requirement","risk_targets":["eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.privilege-escalation","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted","eio.predicate.privilege-scope-exceeded","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.lawfulness","framework":"eio.framework.gdpr","external_id":"lawfulness","external_ref":"Art. 5/6","title":"Lawfulness & purpose limitation","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.minimization","framework":"eio.framework.gdpr","external_id":"minimization","external_ref":"Art. 5(1)(c)","title":"Data minimization","control_type":"requirement","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.retention-violation"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.dsar","framework":"eio.framework.gdpr","external_id":"dsar","external_ref":"Art. 15-22","title":"Data subject rights","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.security-art32","framework":"eio.framework.gdpr","external_id":"security_art32","external_ref":"Art. 32","title":"Security of processing","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.cross-subject-disclosure","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.special-category-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-requires-verification","eio.predicate.special-category-data-disclosure","eio.predicate.unauthorized-egress","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.dpia","framework":"eio.framework.gdpr","external_id":"dpia","external_ref":"Art. 35","title":"Data protection impact assessment","control_type":"requirement","risk_targets":["eio.risk.protected-class-inference","eio.risk.special-category-disclosure"],"predicate_targets":["eio.predicate.special-category-data-disclosure","eio.predicate.unnecessary-protected-attribute-inference"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.gdpr.automated-art22","framework":"eio.framework.gdpr","external_id":"automated_art22","external_ref":"Art. 22","title":"Automated decision-making","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.disparate-treatment","eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.paired-outcome-divergence","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.uk-gdpr.lawfulness","framework":"eio.framework.uk-gdpr","external_id":"lawfulness","external_ref":"UK GDPR Art. 6","title":"Lawful basis","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.uk-gdpr.security","framework":"eio.framework.uk-gdpr","external_id":"security","external_ref":"UK GDPR Art. 32","title":"Security","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.cross-subject-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.uk-gdpr.dsar","framework":"eio.framework.uk-gdpr","external_id":"dsar","external_ref":"UK GDPR Art. 15","title":"Subject access","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.uk-gdpr.dpia","framework":"eio.framework.uk-gdpr","external_id":"dpia","external_ref":"UK GDPR Art. 35","title":"DPIA","control_type":"requirement","risk_targets":["eio.risk.protected-class-inference","eio.risk.special-category-disclosure"],"predicate_targets":["eio.predicate.special-category-data-disclosure","eio.predicate.unnecessary-protected-attribute-inference"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.ccpa.notice","framework":"eio.framework.ccpa","external_id":"notice","external_ref":"§1798.100","title":"Notice at collection","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.ccpa.opt-out","framework":"eio.framework.ccpa","external_id":"opt_out","external_ref":"§1798.120","title":"Right to opt out","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.processing-without-valid-consent","eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.ccpa.access-delete","framework":"eio.framework.ccpa","external_id":"access_delete","external_ref":"§1798.105/110","title":"Access & deletion","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.ccpa.sensitive-data","framework":"eio.framework.ccpa","external_id":"sensitive_data","external_ref":"§1798.121","title":"Sensitive data limits","control_type":"requirement","risk_targets":["eio.risk.special-category-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.special-category-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.hipaa.privacy-rule","framework":"eio.framework.hipaa","external_id":"privacy_rule","external_ref":"§164.502","title":"Privacy Rule","control_type":"requirement","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.special-category-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.special-category-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.hipaa.minimum-necessary","framework":"eio.framework.hipaa","external_id":"minimum_necessary","external_ref":"§164.502(b)","title":"Minimum necessary","control_type":"requirement","risk_targets":["eio.risk.data-minimisation-failure"],"predicate_targets":["eio.predicate.excessive-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.hipaa.security-rule","framework":"eio.framework.hipaa","external_id":"security_rule","external_ref":"§164.312","title":"Security Rule safeguards","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.privilege-escalation","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.hipaa.breach-notification","framework":"eio.framework.hipaa","external_id":"breach_notification","external_ref":"§164.400","title":"Breach notification","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pipeda.consent","framework":"eio.framework.pipeda","external_id":"consent","external_ref":"Principle 3","title":"Consent","control_type":"requirement","risk_targets":["eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pipeda.accuracy","framework":"eio.framework.pipeda","external_id":"accuracy","external_ref":"Principle 6","title":"Accuracy","control_type":"requirement","risk_targets":["eio.risk.fabricated-fact","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.claim-contradicts-grounding","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pipeda.safeguards","framework":"eio.framework.pipeda","external_id":"safeguards","external_ref":"Principle 7","title":"Safeguards","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pipeda.accountability","framework":"eio.framework.pipeda","external_id":"accountability","external_ref":"Principle 1","title":"Accountability","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.lgpd.legal-basis","framework":"eio.framework.lgpd","external_id":"legal_basis","external_ref":"Art. 7","title":"Legal basis","control_type":"requirement","risk_targets":["eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.lgpd.rights","framework":"eio.framework.lgpd","external_id":"rights","external_ref":"Art. 18","title":"Data subject rights","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.lgpd.security","framework":"eio.framework.lgpd","external_id":"security","external_ref":"Art. 46","title":"Security measures","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.cross-subject-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.lgpd.dpo","framework":"eio.framework.lgpd","external_id":"dpo","external_ref":"Art. 41","title":"Data protection officer","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pdpa-sg.consent","framework":"eio.framework.pdpa-sg","external_id":"consent","external_ref":"Part 4","title":"Consent","control_type":"requirement","risk_targets":["eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pdpa-sg.purpose","framework":"eio.framework.pdpa-sg","external_id":"purpose","external_ref":"Part 4","title":"Purpose limitation","control_type":"requirement","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.retention-violation"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pdpa-sg.protection","framework":"eio.framework.pdpa-sg","external_id":"protection","external_ref":"Part 6 §24","title":"Protection obligation","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pdpa-sg.accountability","framework":"eio.framework.pdpa-sg","external_id":"accountability","external_ref":"Part 3","title":"Accountability","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.dpdp-india.consent-notice","framework":"eio.framework.dpdp-india","external_id":"consent_notice","external_ref":"§5-6","title":"Consent & notice","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.dpdp-india.purpose-limit","framework":"eio.framework.dpdp-india","external_id":"purpose_limit","external_ref":"§4","title":"Lawful purpose","control_type":"requirement","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.retention-violation"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.dpdp-india.safeguards","framework":"eio.framework.dpdp-india","external_id":"safeguards","external_ref":"§8(5)","title":"Security safeguards","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.dpdp-india.breach-notify","framework":"eio.framework.dpdp-india","external_id":"breach_notify","external_ref":"§8(6)","title":"Breach notification","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.popia.accountability","framework":"eio.framework.popia","external_id":"accountability","external_ref":"§8","title":"Accountability","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.popia.processing-limit","framework":"eio.framework.popia","external_id":"processing_limit","external_ref":"§9-12","title":"Processing limitation","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.data-minimisation-failure"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.popia.security-safeguards","framework":"eio.framework.popia","external_id":"security_safeguards","external_ref":"§19","title":"Security safeguards","control_type":"requirement","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.popia.participation","framework":"eio.framework.popia","external_id":"participation","external_ref":"§23-25","title":"Data subject participation","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.au-privacy.app-collection","framework":"eio.framework.au-privacy","external_id":"app_collection","external_ref":"APP 3/5","title":"Collection & notice","control_type":"requirement","risk_targets":["eio.risk.consent-bypass","eio.risk.data-minimisation-failure"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.au-privacy.app-use","framework":"eio.framework.au-privacy","external_id":"app_use","external_ref":"APP 6","title":"Use & disclosure","control_type":"requirement","risk_targets":["eio.risk.retention-violation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.au-privacy.app-security","framework":"eio.framework.au-privacy","external_id":"app_security","external_ref":"APP 11","title":"Security of information","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.privilege-escalation","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.au-privacy.app-access","framework":"eio.framework.au-privacy","external_id":"app_access","external_ref":"APP 12/13","title":"Access & correction","control_type":"requirement","risk_targets":["eio.risk.rights-request-mishandling"],"predicate_targets":["eio.predicate.rights-request-workflow-violated"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.soc2.cc6","framework":"eio.framework.soc2","external_id":"cc6","external_ref":"CC6","title":"Logical access controls","control_type":"control","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.soc2.cc7","framework":"eio.framework.soc2","external_id":"cc7","external_ref":"CC7","title":"System monitoring","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.soc2.cc8","framework":"eio.framework.soc2","external_id":"cc8","external_ref":"CC8","title":"Change management","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.soc2.pi1","framework":"eio.framework.soc2","external_id":"pi1","external_ref":"PI1","title":"Processing integrity","control_type":"control","risk_targets":["eio.risk.fabricated-fact","eio.risk.missing-required-tool","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted","eio.predicate.required-workflow-step-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.soc2.c1","framework":"eio.framework.soc2","external_id":"c1","external_ref":"C1","title":"Confidentiality","control_type":"control","risk_targets":["eio.risk.channel-switching","eio.risk.cross-subject-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-27001.a5-policies","framework":"eio.framework.iso-27001","external_id":"a5_policies","external_ref":"A.5","title":"Information security policies","control_type":"control","risk_targets":["eio.risk.guardrail-bypass","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-27001.a8-asset","framework":"eio.framework.iso-27001","external_id":"a8_asset","external_ref":"A.8","title":"Asset management","control_type":"control","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.retention-violation"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.retention-beyond-purpose"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-27001.a9-access","framework":"eio.framework.iso-27001","external_id":"a9_access","external_ref":"A.9","title":"Access control","control_type":"control","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-27001.a12-ops","framework":"eio.framework.iso-27001","external_id":"a12_ops","external_ref":"A.12","title":"Operations security","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.iso-27001.a16-incident","framework":"eio.framework.iso-27001","external_id":"a16_incident","external_ref":"A.16","title":"Incident management","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pci-dss.protect-data","framework":"eio.framework.pci-dss","external_id":"protect_data","external_ref":"Req. 3","title":"Protect stored data","control_type":"control","risk_targets":["eio.risk.channel-switching","eio.risk.payment-data-exposure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.payment-instrument-exposure","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pci-dss.access-control","framework":"eio.framework.pci-dss","external_id":"access_control","external_ref":"Req. 7-8","title":"Restrict access","control_type":"control","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.privilege-escalation","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pci-dss.monitor-test","framework":"eio.framework.pci-dss","external_id":"monitor_test","external_ref":"Req. 10-11","title":"Monitor & test","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.pci-dss.infosec-policy","framework":"eio.framework.pci-dss","external_id":"infosec_policy","external_ref":"Req. 12","title":"Information security policy","control_type":"control","risk_targets":["eio.risk.guardrail-bypass","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fedramp.ac-access","framework":"eio.framework.fedramp","external_id":"ac_access","external_ref":"AC","title":"Access control","control_type":"control","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fedramp.au-audit","framework":"eio.framework.fedramp","external_id":"au_audit","external_ref":"AU","title":"Audit & accountability","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fedramp.ir-incident","framework":"eio.framework.fedramp","external_id":"ir_incident","external_ref":"IR","title":"Incident response","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fedramp.si-integrity","framework":"eio.framework.fedramp","external_id":"si_integrity","external_ref":"SI","title":"System & information integrity","control_type":"control","risk_targets":["eio.risk.fabricated-fact","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.claim-contradicts-grounding","eio.predicate.exploitable-code-emitted","eio.predicate.nonexistent-entity-asserted","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.faa.safety-risk-mgmt","framework":"eio.framework.faa","external_id":"safety_risk_mgmt","external_ref":"SMS","title":"Safety risk management","control_type":"requirement","risk_targets":["eio.risk.harmful-content","eio.risk.safety-critical-advice"],"predicate_targets":["eio.predicate.content-materially-enables-defined-harm","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.faa.human-oversight","framework":"eio.framework.faa","external_id":"human_oversight","external_ref":"Human factors","title":"Human oversight","control_type":"requirement","risk_targets":["eio.risk.human-oversight-bypass","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.protected-action-without-authorization","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.faa.reliability-assurance","framework":"eio.framework.faa","external_id":"reliability_assurance","external_ref":"DO-178C-like","title":"Reliability assurance","control_type":"requirement","risk_targets":["eio.risk.fabricated-fact","eio.risk.overclaimed-certainty","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.faa.change-control","framework":"eio.framework.faa","external_id":"change_control","external_ref":"Config mgmt","title":"Change control","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fda-samd.gmlp","framework":"eio.framework.fda-samd","external_id":"gmlp","external_ref":"GMLP","title":"Good ML practice","control_type":"requirement","risk_targets":["eio.risk.fabricated-fact","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.claim-contradicts-grounding","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fda-samd.clinical-eval","framework":"eio.framework.fda-samd","external_id":"clinical_eval","external_ref":"Clinical eval","title":"Clinical evaluation","control_type":"requirement","risk_targets":["eio.risk.safety-critical-advice","eio.risk.special-category-disclosure"],"predicate_targets":["eio.predicate.safety-critical-advice-outside-remit","eio.predicate.special-category-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fda-samd.risk-mgmt","framework":"eio.framework.fda-samd","external_id":"risk_mgmt","external_ref":"ISO 14971","title":"Risk management","control_type":"requirement","risk_targets":["eio.risk.harmful-content","eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.content-materially-enables-defined-harm","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.fda-samd.postmarket","framework":"eio.framework.fda-samd","external_id":"postmarket","external_ref":"Postmarket","title":"Postmarket monitoring","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.finra-sec.supervision","framework":"eio.framework.finra-sec","external_id":"supervision","external_ref":"FINRA 3110","title":"Supervision","control_type":"requirement","risk_targets":["eio.risk.human-oversight-bypass","eio.risk.policy-drift","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.protected-action-without-authorization","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.finra-sec.recordkeeping","framework":"eio.framework.finra-sec","external_id":"recordkeeping","external_ref":"SEC 17a-4","title":"Recordkeeping","control_type":"requirement","risk_targets":["eio.risk.audit-trail-gap","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.claimed-action-lacks-receipt","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.finra-sec.communications","framework":"eio.framework.finra-sec","external_id":"communications","external_ref":"FINRA 2210","title":"Communications review","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.fabricated-authority","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.finra-sec.suitability","framework":"eio.framework.finra-sec","external_id":"suitability","external_ref":"Reg BI","title":"Suitability / best interest","control_type":"requirement","risk_targets":["eio.risk.disparate-treatment","eio.risk.fabricated-fact","eio.risk.safety-critical-advice"],"predicate_targets":["eio.predicate.claim-contradicts-grounding","eio.predicate.nonexistent-entity-asserted","eio.predicate.paired-outcome-divergence","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.glba.safeguards","framework":"eio.framework.glba","external_id":"safeguards","external_ref":"Safeguards Rule","title":"Safeguards program","control_type":"requirement","risk_targets":["eio.risk.channel-switching","eio.risk.payment-data-exposure","eio.risk.privilege-escalation","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.payment-instrument-exposure","eio.predicate.privilege-scope-exceeded","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.glba.privacy-notice","framework":"eio.framework.glba","external_id":"privacy_notice","external_ref":"Privacy Rule","title":"Privacy notice","control_type":"requirement","risk_targets":["eio.risk.adverse-action-without-notice","eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete","eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.glba.access-controls","framework":"eio.framework.glba","external_id":"access_controls","external_ref":"16 CFR 314","title":"Access controls","control_type":"requirement","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.privilege-escalation","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi01","framework":"eio.framework.owasp-asi","external_id":"asi01","external_ref":"ASI01","title":"Agent Goal Hijack","control_type":"taxonomy-entry","risk_targets":["eio.risk.guardrail-bypass","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.policy-drift","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented","eio.predicate.protected-action-requires-verification","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi02","framework":"eio.framework.owasp-asi","external_id":"asi02","external_ref":"ASI02","title":"Tool Misuse and Exploitation","control_type":"taxonomy-entry","risk_targets":["eio.risk.capability-composition","eio.risk.forbidden-tool-use","eio.risk.missing-required-tool","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-without-authorization","eio.predicate.required-workflow-step-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi03","framework":"eio.framework.owasp-asi","external_id":"asi03","external_ref":"ASI03","title":"Identity and Privilege Abuse","control_type":"taxonomy-entry","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi05","framework":"eio.framework.owasp-asi","external_id":"asi05","external_ref":"ASI05","title":"Unexpected Code Execution (RCE)","control_type":"taxonomy-entry","risk_targets":["eio.risk.capability-composition","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi06","framework":"eio.framework.owasp-asi","external_id":"asi06","external_ref":"ASI06","title":"Memory & Context Poisoning","control_type":"taxonomy-entry","risk_targets":["eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi08","framework":"eio.framework.owasp-asi","external_id":"asi08","external_ref":"ASI08","title":"Cascading Failures","control_type":"taxonomy-entry","risk_targets":["eio.risk.fabricated-citation","eio.risk.fabricated-fact","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.citation-not-supported","eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi09","framework":"eio.framework.owasp-asi","external_id":"asi09","external_ref":"ASI09","title":"Human-Agent Trust Exploitation","control_type":"taxonomy-entry","risk_targets":["eio.risk.abusive-interaction","eio.risk.fabricated-authority","eio.risk.overclaimed-certainty","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.agent-directed-abuse","eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence","eio.predicate.claimed-action-lacks-receipt"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-asi.asi10","framework":"eio.framework.owasp-asi","external_id":"asi10","external_ref":"ASI10","title":"Rogue Agents","control_type":"taxonomy-entry","risk_targets":["eio.risk.human-oversight-bypass","eio.risk.policy-drift","eio.risk.privilege-escalation","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-without-authorization","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t1","framework":"eio.framework.owasp-agentic-threats","external_id":"t1","external_ref":"T1","title":"Memory Poisoning","control_type":"taxonomy-entry","risk_targets":["eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t2","framework":"eio.framework.owasp-agentic-threats","external_id":"t2","external_ref":"T2","title":"Tool Misuse","control_type":"taxonomy-entry","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.missing-required-tool","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-without-authorization","eio.predicate.required-workflow-step-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t3","framework":"eio.framework.owasp-agentic-threats","external_id":"t3","external_ref":"T3","title":"Privilege Compromise","control_type":"taxonomy-entry","risk_targets":["eio.risk.privilege-escalation","eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t5","framework":"eio.framework.owasp-agentic-threats","external_id":"t5","external_ref":"T5","title":"Cascading Hallucination Attacks","control_type":"taxonomy-entry","risk_targets":["eio.risk.fabricated-authority","eio.risk.fabricated-citation","eio.risk.fabricated-fact"],"predicate_targets":["eio.predicate.authority-or-deadline-invented","eio.predicate.citation-not-supported","eio.predicate.claim-contradicts-grounding","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t6","framework":"eio.framework.owasp-agentic-threats","external_id":"t6","external_ref":"T6","title":"Intent Breaking & Goal Manipulation","control_type":"taxonomy-entry","risk_targets":["eio.risk.guardrail-bypass","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.policy-drift"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.guardrail-circumvented","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t7","framework":"eio.framework.owasp-agentic-threats","external_id":"t7","external_ref":"T7","title":"Misaligned & Deceptive Behaviors","control_type":"taxonomy-entry","risk_targets":["eio.risk.overclaimed-certainty","eio.risk.phantom-action","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.certainty-exceeds-evidence","eio.predicate.claimed-action-lacks-receipt","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t8","framework":"eio.framework.owasp-agentic-threats","external_id":"t8","external_ref":"T8","title":"Repudiation & Untraceability","control_type":"taxonomy-entry","risk_targets":["eio.risk.audit-trail-gap","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.claimed-action-lacks-receipt","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t9","framework":"eio.framework.owasp-agentic-threats","external_id":"t9","external_ref":"T9","title":"Identity Spoofing & Impersonation","control_type":"taxonomy-entry","risk_targets":["eio.risk.role-confusion"],"predicate_targets":["eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t10","framework":"eio.framework.owasp-agentic-threats","external_id":"t10","external_ref":"T10","title":"Overwhelming Human in the Loop","control_type":"taxonomy-entry","risk_targets":["eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t11","framework":"eio.framework.owasp-agentic-threats","external_id":"t11","external_ref":"T11","title":"Unexpected RCE and Code Attacks","control_type":"taxonomy-entry","risk_targets":["eio.risk.capability-composition","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-agentic-threats.t15","framework":"eio.framework.owasp-agentic-threats","external_id":"t15","external_ref":"T15","title":"Human Manipulation","control_type":"taxonomy-entry","risk_targets":["eio.risk.abusive-interaction","eio.risk.fabricated-authority","eio.risk.harmful-content"],"predicate_targets":["eio.predicate.agent-directed-abuse","eio.predicate.authority-or-deadline-invented","eio.predicate.content-materially-enables-defined-harm"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm01","framework":"eio.framework.owasp-llm","external_id":"llm01","external_ref":"LLM01:2025","title":"Prompt Injection","control_type":"taxonomy-entry","risk_targets":["eio.risk.guardrail-bypass","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.guardrail-circumvented","eio.predicate.protected-action-requires-verification","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm02","framework":"eio.framework.owasp-llm","external_id":"llm02","external_ref":"LLM02:2025","title":"Sensitive Information Disclosure","control_type":"taxonomy-entry","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.data-minimisation-failure","eio.risk.payment-data-exposure","eio.risk.special-category-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.excessive-data-disclosure","eio.predicate.payment-instrument-exposure","eio.predicate.special-category-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm05","framework":"eio.framework.owasp-llm","external_id":"llm05","external_ref":"LLM05:2025","title":"Improper Output Handling","control_type":"taxonomy-entry","risk_targets":["eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm06","framework":"eio.framework.owasp-llm","external_id":"llm06","external_ref":"LLM06:2025","title":"Excessive Agency","control_type":"taxonomy-entry","risk_targets":["eio.risk.capability-composition","eio.risk.forbidden-tool-use","eio.risk.human-oversight-bypass","eio.risk.privilege-escalation","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-without-authorization","eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm07","framework":"eio.framework.owasp-llm","external_id":"llm07","external_ref":"LLM07:2025","title":"System Prompt Leakage","control_type":"taxonomy-entry","risk_targets":["eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm08","framework":"eio.framework.owasp-llm","external_id":"llm08","external_ref":"LLM08:2025","title":"Vector and Embedding Weaknesses","control_type":"taxonomy-entry","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.fabricated-fact"],"predicate_targets":["eio.predicate.claim-contradicts-grounding","eio.predicate.cross-subject-data-disclosure","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.owasp-llm.llm09","framework":"eio.framework.owasp-llm","external_id":"llm09","external_ref":"LLM09:2025","title":"Misinformation","control_type":"taxonomy-entry","risk_targets":["eio.risk.fabricated-authority","eio.risk.fabricated-citation","eio.risk.fabricated-fact","eio.risk.overclaimed-certainty","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence","eio.predicate.citation-not-supported","eio.predicate.claim-contradicts-grounding","eio.predicate.claimed-action-lacks-receipt","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a001","framework":"eio.framework.aiuc-1","external_id":"a001","external_ref":"A001","title":"Establish input data policy","control_type":"control","risk_targets":["eio.risk.consent-bypass"],"predicate_targets":["eio.predicate.processing-without-valid-consent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a002","framework":"eio.framework.aiuc-1","external_id":"a002","external_ref":"A002","title":"Establish output data policy","control_type":"control","risk_targets":["eio.risk.channel-switching","eio.risk.data-minimisation-failure"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a003","framework":"eio.framework.aiuc-1","external_id":"a003","external_ref":"A003","title":"Limit AI agent data access","control_type":"control","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a005","framework":"eio.framework.aiuc-1","external_id":"a005","external_ref":"A005","title":"Prevent cross-customer data exposure","control_type":"control","risk_targets":["eio.risk.cross-subject-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a006","framework":"eio.framework.aiuc-1","external_id":"a006","external_ref":"A006","title":"Prevent PII leakage","control_type":"control","risk_targets":["eio.risk.data-minimisation-failure","eio.risk.payment-data-exposure","eio.risk.special-category-disclosure"],"predicate_targets":["eio.predicate.excessive-data-disclosure","eio.predicate.payment-instrument-exposure","eio.predicate.special-category-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.a008","framework":"eio.framework.aiuc-1","external_id":"a008","external_ref":"A008","title":"Prevent leakage of credentials and secrets","control_type":"control","risk_targets":["eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.b002","framework":"eio.framework.aiuc-1","external_id":"b002","external_ref":"B002","title":"Detect adversarial input","control_type":"control","risk_targets":["eio.risk.instruction-override","eio.risk.memory-contamination"],"predicate_targets":["eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.b006","framework":"eio.framework.aiuc-1","external_id":"b006","external_ref":"B006","title":"Prevent unauthorized AI agent actions","control_type":"control","risk_targets":["eio.risk.forbidden-tool-use","eio.risk.privilege-escalation","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.b007","framework":"eio.framework.aiuc-1","external_id":"b007","external_ref":"B007","title":"Enforce user access privileges to AI systems","control_type":"control","risk_targets":["eio.risk.role-confusion","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.disclosure-without-entitlement","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.b009","framework":"eio.framework.aiuc-1","external_id":"b009","external_ref":"B009","title":"Limit output over-exposure","control_type":"control","risk_targets":["eio.risk.data-minimisation-failure"],"predicate_targets":["eio.predicate.excessive-data-disclosure"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.b010","framework":"eio.framework.aiuc-1","external_id":"b010","external_ref":"B010","title":"Promote secure patterns in generated code","control_type":"control","risk_targets":["eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.c003","framework":"eio.framework.aiuc-1","external_id":"c003","external_ref":"C003","title":"Prevent harmful outputs","control_type":"control","risk_targets":["eio.risk.abusive-interaction","eio.risk.harmful-content"],"predicate_targets":["eio.predicate.agent-directed-abuse","eio.predicate.content-materially-enables-defined-harm"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.c004","framework":"eio.framework.aiuc-1","external_id":"c004","external_ref":"C004","title":"Prevent out-of-scope outputs","control_type":"control","risk_targets":["eio.risk.policy-drift","eio.risk.safety-critical-advice"],"predicate_targets":["eio.predicate.applicable-policy-abandoned","eio.predicate.safety-critical-advice-outside-remit"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.c005","framework":"eio.framework.aiuc-1","external_id":"c005","external_ref":"C005","title":"Prevent agent-specific high risk outputs","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.privilege-escalation","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.c006","framework":"eio.framework.aiuc-1","external_id":"c006","external_ref":"C006","title":"Prevent output vulnerabilities","control_type":"control","risk_targets":["eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.c007","framework":"eio.framework.aiuc-1","external_id":"c007","external_ref":"C007","title":"Flag high risk outputs for human review","control_type":"control","risk_targets":["eio.risk.human-oversight-bypass"],"predicate_targets":["eio.predicate.required-human-oversight-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.d001","framework":"eio.framework.aiuc-1","external_id":"d001","external_ref":"D001","title":"Prevent hallucinated outputs","control_type":"control","risk_targets":["eio.risk.fabricated-authority","eio.risk.fabricated-citation","eio.risk.fabricated-fact","eio.risk.overclaimed-certainty"],"predicate_targets":["eio.predicate.authority-or-deadline-invented","eio.predicate.certainty-exceeds-evidence","eio.predicate.citation-not-supported","eio.predicate.claim-contradicts-grounding","eio.predicate.nonexistent-entity-asserted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.d003","framework":"eio.framework.aiuc-1","external_id":"d003","external_ref":"D003","title":"Restrict unsafe tool calls","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.forbidden-tool-use","eio.risk.missing-required-tool"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.prohibited-tool-invoked","eio.predicate.required-workflow-step-absent"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.e015","framework":"eio.framework.aiuc-1","external_id":"e015","external_ref":"E015","title":"Log AI system activity","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.e016","framework":"eio.framework.aiuc-1","external_id":"e016","external_ref":"E016","title":"Implement AI disclosure mechanisms","control_type":"control","risk_targets":["eio.risk.adverse-action-without-notice"],"predicate_targets":["eio.predicate.adverse-decision-notice-incomplete"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.aiuc-1.f001","framework":"eio.framework.aiuc-1","external_id":"f001","external_ref":"F001","title":"Prevent AI cyber misuse","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.unsafe-code"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.exploitable-code-emitted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.ac-3","framework":"eio.framework.nist-800-53","external_id":"ac_3","external_ref":"AC-3","title":"Access Enforcement","control_type":"control","risk_targets":["eio.risk.cross-subject-disclosure","eio.risk.forbidden-tool-use","eio.risk.unauthorized-action","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.prohibited-tool-invoked","eio.predicate.protected-action-without-authorization"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.ac-4","framework":"eio.framework.nist-800-53","external_id":"ac_4","external_ref":"AC-4","title":"Information Flow Enforcement","control_type":"control","risk_targets":["eio.risk.channel-switching","eio.risk.cross-subject-disclosure","eio.risk.data-minimisation-failure","eio.risk.unauthorized-disclosure"],"predicate_targets":["eio.predicate.cross-subject-data-disclosure","eio.predicate.disclosure-without-entitlement","eio.predicate.excessive-data-disclosure","eio.predicate.unauthorized-egress"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.ac-6","framework":"eio.framework.nist-800-53","external_id":"ac_6","external_ref":"AC-6","title":"Least Privilege","control_type":"control","risk_targets":["eio.risk.capability-composition","eio.risk.forbidden-tool-use","eio.risk.privilege-escalation"],"predicate_targets":["eio.predicate.capabilities-compose-to-prohibited-outcome","eio.predicate.privilege-scope-exceeded","eio.predicate.prohibited-tool-invoked"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.ac-6-9","framework":"eio.framework.nist-800-53","external_id":"ac_6_9","external_ref":"AC-6(9)","title":"Log Use of Privileged Functions","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.ac-6-10","framework":"eio.framework.nist-800-53","external_id":"ac_6_10","external_ref":"AC-6(10)","title":"Prohibit Non-privileged Users from Executing Privileged Functions","control_type":"control","risk_targets":["eio.risk.privilege-escalation","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.privilege-scope-exceeded","eio.predicate.protected-action-requires-verification","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.au-2","framework":"eio.framework.nist-800-53","external_id":"au_2","external_ref":"AU-2","title":"Event Logging","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.au-3","framework":"eio.framework.nist-800-53","external_id":"au_3","external_ref":"AU-3","title":"Content of Audit Records","control_type":"control","risk_targets":["eio.risk.audit-trail-gap"],"predicate_targets":["eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.au-10","framework":"eio.framework.nist-800-53","external_id":"au_10","external_ref":"AU-10","title":"Non-repudiation","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.claimed-action-lacks-receipt","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.au-12","framework":"eio.framework.nist-800-53","external_id":"au_12","external_ref":"AU-12","title":"Audit Record Generation","control_type":"control","risk_targets":["eio.risk.audit-trail-gap","eio.risk.phantom-action"],"predicate_targets":["eio.predicate.claimed-action-lacks-receipt","eio.predicate.material-action-lacks-audit-record"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.si-4","framework":"eio.framework.nist-800-53","external_id":"si_4","external_ref":"SI-4","title":"System Monitoring","control_type":"control","risk_targets":["eio.risk.guardrail-bypass","eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.unauthorized-action"],"predicate_targets":["eio.predicate.guardrail-circumvented","eio.predicate.protected-action-without-authorization","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}
  - {"id":"eio.control.nist-800-53.si-10","framework":"eio.framework.nist-800-53","external_id":"si_10","external_ref":"SI-10","title":"Information Input Validation","control_type":"control","risk_targets":["eio.risk.instruction-override","eio.risk.memory-contamination","eio.risk.role-confusion"],"predicate_targets":["eio.predicate.protected-action-requires-verification","eio.predicate.untrusted-content-persisted","eio.predicate.untrusted-instruction-execution","eio.predicate.unverified-authority-accepted"],"mapping_status":"provisional","applicability":"Applicable only when selected by the governance profile and when the mapped predicate preconditions hold.","evidence_semantics":{"scope":"mixed","statuses":["observed_satisfaction","observed_violation","not_tested","not_observable","not_applicable","inconclusive"],"inherits_predicate_contracts":true},"legal_review_required":true,"assurance_boundary":"A claim shows run evidence relevant to this bundled control view; it is not proof of organization-wide compliance or certification."}

profiles:
  - id: eio.profile.compliance-materialization
    description: Defines the deterministic join from observed claims to framework-control status.
    join: [control.predicate_targets, evaluation_claim.predicate, evaluation_claim.evidence]
    permitted_statuses: [observed_satisfaction, observed_violation, not_tested, not_observable, not_applicable, inconclusive]
    no_evidence_policy: not_tested
    applicability_source: eio.governance.gates
    status_source: canonical evaluation claims only
    invariant: A framework or control label never changes the underlying predicate decision.
    # EIO-217 (02 §8.3 rules 1-6). For control k with target predicates T_k, C_k is the run's claims on
    # predicates in T_k. The first rule that matches gives the status.
    materialized_for: controls of frameworks whose selection state is APPLICABLE or REVIEW_REQUIRED
    rules:
      - {order: 1, status: not_applicable, when: "the control's framework is NOT_APPLICABLE in the run's framework selection"}
      - {order: 2, status: observed_violation, when: "C_k holds at least one APPLICABLE_FAIL claim"}
      - {order: 3, status: observed_satisfaction, when: "C_k holds no APPLICABLE_FAIL claim and at least one APPLICABLE_PASS claim"}
      - {order: 4, status: inconclusive, when: "C_k holds no scored claim and at least one UNRESOLVED, EVIDENCE_INVALID, EVIDENCE_INCOMPLETE or EVALUATOR_ERROR claim"}
      - {order: 5, status: not_observable, when: "C_k is empty and the census cause of every predicate in T_k is UNREACHABLE"}
      - {order: 6, status: not_tested, when: "otherwise, including a C_k whose claims are all NOT_APPLICABLE (explanation: dispatched; preconditions never held)"}
    # PER-203 / EIO-33.
    proxy_only: >
      REQUIRED on every observed_violation: true iff every APPLICABLE_FAIL claim in C_k has
      mapping_relation narrower. A proxy-only violation is shown under its own heading and is never a
      decisive release condition.
    citations:
      - Every observed_* and inconclusive status cites its claim ids; every observed_* status cites at least one evidence ref.
      - An observed_violation explanation states the decided_by and mapping_relation split of its failing claims.
    targets: Safeguard and observation predicates are not control targets, so a safeguard or observation FAIL never produces observed_violation.
    rollup: A control status is never rolled up into a framework-level compliant, conformant or certified label.
    renderers: mapping_status and legal_review_required are shown next to every control status.
  - id: eio.profile.compliance-assurance-boundary
    description: Prevents evidence relevance from being overstated as legal or assurance conclusions.
    permitted_claim: The run produced typed evidence relevant to the named bundled control view.
    prohibited_claim: The organization, product, or system is legally compliant, attested, or certified solely because of this evaluation.
    requires: [governance-selected applicability, canonical claim, evidence reference, coverage label, ontology version and hash]
    human_review: Legal applicability, external-framework currency, and certification conclusions require qualified independent review.
