AgentProof Learn - compliance-readiness methodology
AI Agent Compliance Readiness Library
The methodology behind the AgentProof Compliance Readiness Pilot: classify the agent, check the right controls, and build a versioned, in-workspace compliance-readiness record showing what is ready, what needs review, and what to fix.
Six topics, one compliance-readiness record
Every topic is a short, plain-English guide. Connectors such as Microsoft Power Platform are one example inside the AI estate topic, not the product. Open any topic to go deeper.
AI estate
See every AI agent across manual, discovered, connected, and hybrid environments before any one of them gets a record.
The AI estate inventory
One view of every AI agent your organisation is building, running, or considering — so nothing gets trusted off the radar.
Read this topic →Manual and discovered agents
Agents you connect and agents you add by hand sit side by side — with the source of every one visible.
Read this topic →Capability Zones
Place your agent so you can document the right controls.
Read this topic →Evidence
Back every claim with real evidence, where received is never quietly counted as accepted.
The evidence register
One evidence store per agent, where received is never quietly counted as accepted.
Read this topic →The agent test pack
The seven checks that turn 'we tested it' into a documented record — where a test never run is a gap, not a pass.
Read this topic →The vendor and model review
Document the model, provider, and terms behind the agent — because a brand name is never a substitute for evidence.
Read this topic →Controls
Map the guardrails an agent should have to the evidence that proves them, and keep the record alive after go-live.
The control checklist
Map the guardrails an agent should have to the evidence that proves them — so no control passes on assertion alone.
Read this topic →Controls & Oversight
Six control families with maturity ladders from Basic to Evidence-ready.
Read this topic →Good Agent Design
10 design principles that separate a credible, documented agent from one that only works in an illustrative setting.
Read this topic →Monitoring, incidents, and reassessment
Keep the record alive after go-live — and reassess before it silently goes stale.
Read this topic →The approval and decision record
Turn 'we agreed in a meeting' into a traceable decision with a named owner and explicit limits.
Read this topic →Documentation coverage
View the same record through jurisdiction-aware lenses as documentation and evidence coverage, never a graded verdict.
What is AI agent governance documentation?
The record you build before your compliance review — what it is, and what it is not.
Read this topic →EU AI Act — documentation support
A documentation and evidence coverage lens for the EU AI Act — coverage of expectations, never a legal verdict.
Read this topic →UK AI principles — documentation support
A documentation and evidence coverage lens for the UK's five cross-sector AI principles, with context on the sector regulators that apply them — coverage of expectations, never a legal verdict.
Read this topic →US AI governance — documentation support
A documentation and evidence coverage lens for the layered US model — NIST RMF, FTC practice, sectoral rules, federal direction, and a state-law watch; never one US AI law.
Read this topic →NIST AI RMF — documentation support
Organise your agent evidence by the four NIST AI RMF functions — Govern, Map, Measure, and Manage.
Read this topic →ISO/IEC 42001 — documentation support
See your agent record through the ISO/IEC 42001 AI management-system structure.
Read this topic →OWASP GenAI / LLM security — documentation support
Line up your agent test pack and controls against OWASP GenAI / LLM and agent-security expectations.
Read this topic →Radar
Keep records current as the AI landscape moves. Nothing applies automatically; Radar recommends reassessment for the specific affected agents.
Trust boundaries
Why AI compliance needs evidence, and where compliance-readiness documentation support ends and your own review begins.
How a review works, end to end
AgentProof runs one workflow in five beats: see the whole estate, know the agent, evidence the record, decide, and keep it current. It is the same workflow across the whole site, with the eleven practitioner steps grouped beneath each beat.
See the full workflow →Public preview vs full workspace
Public preview
Useful knowledge before you sign in
- Capability zones with examples and risk profile
- Good agent design with failure patterns
- Control families with a maturity ladder
- The AI landscape radar
- Reference library index with last-reviewed dates
Inside the workspace
Deeper, record-linked guidance
- Full per-zone control checklists
- Record-linked deep dives on each finding
- Improvement-cycle suggestions wired in
- Reassessment recommended when a pack version changes
Access is arranged through a Compliance Readiness Pilot. AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.