Clause mapping (4–10)
Annex A controls where Guardway is direct evidence
What to hand your auditor
The practical artifact set Guardway can produce for an AIMS audit:- Inventory — agents, models, tools, MCP servers, gateways (discovery + fleet views).
- Control configuration — the policy set in force per application, viewable in the dashboard configuration screens.
- Operating evidence — request logs, guardrail events with redacted previews, administrative audit log, SIEM-delivered copies in your own retention system.
- Testing evidence — red-team run results with severities computed from bypass rates.
- Incident inputs — drift incidents (beta), guardrail blocks, unreachable-dependency findings.
Machine-readable mappings
Agent findings are tagged with OWASP ASI Top 10 categories (ASI01–ASI10)
in the API and dashboard; the explicit statement of which categories were
assessed, and with what limitations, is returned by the discovery summary API
(dashboard surfacing planned). ISO 42001 clause identifiers as
machine-readable tags are not shipped today; this page is the mapping.
See also the EU AI Act mapping and
Privacy and Security. For your current
attestation package, email
compliance@guardway.ai.