Glossary
Control Mapping
Control mapping is the practice of documenting which specific technical or procedural controls satisfy which requirements in a compliance framework. For AI agent governance, control mapping links capabilities — such as runtime policy enforcement, immutable audit trails, and access reviews — to the specific clauses of frameworks like SOC 2, ISO 42001, or the EU AI Act. It is the foundation of evidence packages presented to auditors.