Skip to content

Standards Compliance

Version: 1.0
Status: Release Candidate
Date: 2026-01-16
Purpose: Map ARAL conformance to major AI/security/privacy standards


ARAL (Agent Runtime Abstraction Layer) is designed to comply with and support implementation of major international standards for AI systems, security, privacy, and ethics. This document provides a comprehensive mapping between ARAL specifications and industry standards.


1.1 ISO/IEC 42001:2023 - AI Management System

Section titled “1.1 ISO/IEC 42001:2023 - AI Management System”

Status: ✅ Fully Compliant

ISO 42001 RequirementARAL ImplementationReference
AI policy frameworkPolicy schema with enforcementARAL-SECURITY-1.0 L3-P
Risk managementMulti-layer risk controlsARAL-SECURITY-1.0 §3
Lifecycle managementRuntime lifecycle controlsARAL-CORE-1.0 L1
Data governanceMemory layer with auditARAL-CORE-1.0 L2
TransparencyTrace schema with lineageARAL-PROTOCOL-1.0 L7
Human oversightRequire confirmation flagsARAL-SECURITY-1.0 §2.3
Continuous monitoringMetrics and health checksARAL-CORE-1.0 L1-009
DocumentationManifest and audit trailschemas/manifest.schema.json

Evidence:

  • ARAL-L1-009: Runtime MUST provide metrics endpoint (Prometheus format)
  • ARAL-L2-007: Memory MUST log all write operations for audit
  • ARAL-L5-006: Persona MUST validate against security policy before activation
  • ARAL-L7-001 to L7-010: Complete observability and tracing requirements

1.2 ISO/IEC 23894:2023 - AI Risk Management

Section titled “1.2 ISO/IEC 23894:2023 - AI Risk Management”

Status: ✅ Fully Compliant

ISO 23894 CategoryARAL ImplementationReference
Risk identificationCapability risk levelsARAL-CORE-1.0 L3
Risk analysisSecurity zones and policiesARAL-SECURITY-1.0
Risk evaluationPolicy-based constraintspersona.schema.json constraints
Risk treatmentDeny, require confirmation, auditARAL-SECURITY-1.0 §2
Risk monitoringContinuous audit loggingARAL-CORE-1.0 L2-007
Risk communicationTrace messages with risk contextARAL-PROTOCOL-1.0 L7

Evidence:

  • Capability permissions model with risk-based access control
  • Persona constraints with behavioral boundaries
  • Audit trail for all sensitive operations
  • Circuit breaker patterns for failure containment

1.3 ISO/IEC 27001:2022 - Information Security

Section titled “1.3 ISO/IEC 27001:2022 - Information Security”

Status: ✅ Fully Compliant

ARAL implements ISO 27001 controls through:

  • Access Control (A.9): Capability-based authorization, persona constraints
  • Cryptography (A.10): Signature verification, encrypted memory
  • Operations Security (A.12): Logging, monitoring, backup requirements
  • Communications Security (A.13): Secure envelope protocol
  • System Development (A.14): Security-by-design architecture
  • Supplier Relationships (A.15): LLM provider abstraction with security policies
  • Incident Management (A.16): Error handling and audit trails
  • Business Continuity (A.17): Fallback chains, circuit breakers
  • Compliance (A.18): This compliance mapping document

Reference: ARAL-SECURITY-1.0.md

1.4 ISO/IEC 27701:2019 - Privacy Management

Section titled “1.4 ISO/IEC 27701:2019 - Privacy Management”

Status: ✅ Fully Compliant

Reference: ARAL-PRIVACY-1.0.md (35 requirements covering all ISO 27701 privacy controls)


2. NIST AI Risk Management Framework (AI RMF 1.0)

Section titled “2. NIST AI Risk Management Framework (AI RMF 1.0)”

Status: ✅ Fully Aligned

NIST AI RMF FunctionARAL ImplementationEvidence
GOVERNPolicy schema, governance docsgovernance/, policy.schema.json
MAPCapability mapping, persona rolesARAL-CORE-1.0 L3, L5
MEASUREMetrics, monitoring, tracingARAL-CORE-1.0 L1-009, trace.schema.json
MANAGERisk-based constraints, circuit breakersARAL-SECURITY-1.0
CharacteristicARAL SupportImplementation
Valid & Reliable✅ YesSchema validation, conformance tests
Safe✅ YesSandboxing, capability restrictions, human oversight
Secure & Resilient✅ YesSecurity layer, fallback chains, circuit breakers
Accountable & Transparent✅ YesAudit trails, trace lineage, explainable decisions
Explainable & Interpretable✅ YesTrace reasoning, action justifications
Privacy-Enhanced✅ YesGDPR compliance, data minimization, consent management
Fair with Harmful Bias Managed✅ YesPersona audit criteria for bias detection

Reference: ARAL-SECURITY-1.0.md, ARAL-PRIVACY-1.0.md


Status: ✅ Ready for High-Risk AI Systems

ARAL enables EU AI Act compliance for High-Risk AI Systems (Annex III):

EU AI Act RequirementARAL ImplementationReference
Risk management systemPolicy-based constraints, auditARAL-SECURITY-1.0
Data governanceMemory layer with audit, GDPR complianceARAL-PRIVACY-1.0
Technical documentationManifest, persona docs, trace lineageAll schemas
Record-keepingTrace schema with immutable logstrace.schema.json
TransparencyUser-facing explanations in tracesARAL-PROTOCOL-1.0 L7
Human oversightRequire confirmation flagspersona.schema.json constraints
Accuracy, robustness, cybersecuritySecurity layer, fallback chainsARAL-SECURITY-1.0

3.2 Transparency Obligations (Articles 13, 52)

Section titled “3.2 Transparency Obligations (Articles 13, 52)”
  • L7-004: Trace MUST include human-readable explanation field
  • L7-005: Trace MUST record all LLM provider invocations
  • Persona metadata includes clear descriptions of capabilities and limitations

ARAL provides mechanisms to prevent:

  • Subliminal manipulation (via persona behavioral constraints)
  • Social scoring (via policy enforcement)
  • Real-time biometric identification (via capability permissions)
  • Exploitation of vulnerabilities (via audit criteria for bias detection)

Reference: ARAL-PRIVACY-1.0.md, ARAL-SECURITY-1.0.md


Status: ✅ Compliant Architecture

  • Privacy Rule: ARAL-PRIVACY-1.0 enforces data subject rights
  • Security Rule: ARAL-SECURITY-1.0 implements administrative, physical, technical safeguards
  • Breach Notification: ARAL-P-007 requires 72-hour notification
  • Minimum Necessary: Memory layer supports data minimization
  • Audit Controls: L2-007 logs all memory write operations
  • Integrity Controls: L2-004 atomic read-modify-write operations
  • Access Controls: Capability-based authorization

Reference: ARAL-INTEGRATION-SCENARIOS.md (Healthcare scenario)

Status: ✅ Compliant

  • Parental Consent: ARAL-P-004 consent management for minors
  • Data Minimization: Memory layer with TTL-based expiration
  • Transparency: Clear privacy policies in persona metadata
  • Security: Encryption and secure storage requirements

Reference: ARAL-PRIVACY-1.0.md §4.6

Status: ✅ Compliant

All GDPR-equivalent rights implemented in ARAL-PRIVACY-1.0.md:

  • Right to know (access)
  • Right to delete (erasure)
  • Right to opt-out (consent withdrawal)
  • Right to correct (rectification)
  • Right to limit use (processing restriction)

5.1 OWASP Top 10 for LLM Applications (2023)

Section titled “5.1 OWASP Top 10 for LLM Applications (2023)”

Status: ✅ All Mitigated

OWASP LLM RiskARAL MitigationReference
LLM01: Prompt InjectionInput validation, persona constraintsARAL-SECURITY-1.0 §2.1
LLM02: Insecure Output HandlingOutput validation, schema enforcementARAL-CORE-1.0 L3
LLM03: Training Data PoisoningProvider abstraction, multi-model validationARAL-CORE-1.0 L4
LLM04: Model Denial of ServiceRate limiting, circuit breakersARAL-CORE-1.0 L1-008
LLM05: Supply Chain VulnerabilitiesSignature verification, trusted sourcespersona.schema.json signature
LLM06: Sensitive Information DisclosureMemory security, PII redactionARAL-PRIVACY-1.0
LLM07: Insecure Plugin DesignCapability permissions modelARAL-CORE-1.0 L3
LLM08: Excessive AgencyPersona constraints, human oversightpersona.schema.json constraints
LLM09: OverrelianceConfidence scores, uncertainty indicationARAL-PROTOCOL-1.0 L7
LLM10: Model TheftProvider abstraction, no direct model accessARAL-CORE-1.0 L4

Status: ✅ Aligned

ARAL personas can implement Model Spec principles:

  • Follow the chain of command: Persona priority and defer_to configuration
  • Comply with applicable laws: Policy enforcement layer
  • Don’t provide information hazards: Capability restrictions
  • Respect creators and their rights: License metadata in persona
  • Protect people’s privacy: GDPR-compliant privacy layer
  • Don’t respond with NSFW content: Content moderation in orchestration

Reference: docs/guides/multi-llm-orchestration.md §8

Status: ✅ Compatible

Persona audit criteria can encode constitutional principles:

"audit": {
"enabled": true,
"criteria": [
"harmlessness",
"helpfulness",
"honesty",
"bias-check"
]
}

Reference: persona.schema.json audit section

Status: ✅ Aligned

  • IEEE 7000: Values-based engineering → Persona metadata includes values/skills
  • IEEE 7001: Transparency → Trace schema with lineage
  • IEEE 7002: Data privacy → ARAL-PRIVACY-1.0
  • IEEE 7003: Algorithmic bias → Audit criteria for bias detection
  • IEEE 7010: Well-being metrics → Extensible trace metrics

6. Semantic Web & Interoperability Standards

Section titled “6. Semantic Web & Interoperability Standards”

Status: ✅ Compatible

Persona signatures support verifiable credential patterns:

{
"id": "persona-uuid",
"signature": "base64-encoded-signature",
"signature_algorithm": "Ed25519",
"public_key": "-----BEGIN PUBLIC KEY-----"
}

Can be extended to full VC format with proof chains.

Reference: persona.schema.json signature fields

Status: ✅ Integration Ready

  • Agent identity can be bound to OAuth2 tokens
  • Persona can include OIDC subject claims
  • Capability permissions map to OAuth2 scopes

Reference: ARAL-SECURITY-1.0.md (authentication section)

Status: ✅ Compatible

  • Trace schema compatible with OTel span format
  • L1-009: Prometheus metrics endpoint
  • Distributed tracing support via trace IDs

Reference: trace.schema.json, ARAL-PROTOCOL-1.0.md L7


  • PCI-DSS: Secure memory, audit logging
  • MiFID II: Transaction recording (trace schema)
  • SOX: Audit trail, access controls
  • GLBA: Privacy protections

Reference: ARAL-INTEGRATION-SCENARIOS.md (Financial scenario)

  • NIST 800-53: Security controls mapping
  • FedRAMP: Cloud security baseline support
  • ITAR/EAR: Export control via capability restrictions
  • Institutional Review Board (IRB): Consent management
  • Research Ethics: Audit criteria for ethical AI research
  • Open Science: MIT/Apache license support

When implementing ARAL-compliant systems:

  • Deploy with ARAL-PRIVACY-1.0 for GDPR/CCPA compliance
  • Enable audit logging (L2-007, L7 tracing)
  • Configure capability permissions based on risk assessment
  • Implement human oversight for high-risk operations
  • Use persona signatures for verifiable provenance
  • Enable content moderation for public-facing agents
  • Configure circuit breakers and fallback chains
  • Document AI system in manifest.schema.json
  • Conduct DPIA for high-risk AI systems
  • Implement OWASP LLM mitigations
StandardARAL Support LevelCertification Path
ISO 42001Full supportAudit ARAL implementation
ISO 27001Full supportInclude ARAL in ISMS
GDPRFull complianceDeploy ARAL-PRIVACY-1.0
EU AI ActHigh-risk readyFollow Article 16-51
NIST AI RMFFully alignedUse ARAL as framework
SOC 2 Type IISupports controlsAudit ARAL runtime

ARAL provides conformance tests for standard compliance:

Terminal window
# Run ISO 42001 compliance tests
npm run test:iso42001
# Run GDPR compliance tests
npm run test:gdpr
# Run OWASP LLM security tests
npm run test:owasp-llm
# Full compliance test suite
npm run test:compliance

Reference: tests/HARNESS.md


VersionDateStandards Added
1.02026-01-16Initial: ISO 42001, 23894, 27001, 27701, NIST AI RMF, EU AI Act, HIPAA, COPPA, CCPA, OWASP LLM Top 10, OpenAI Model Spec, IEEE 7000, W3C VC, OAuth2, OpenTelemetry

ARAL Standards Compliance will be updated as new standards emerge:

  • Quarterly review of new AI regulations
  • Annual audit against updated ISO standards
  • Continuous monitoring of OWASP LLM risks
  • Integration of emerging best practices

  1. ISO/IEC 42001:2023 - Artificial intelligence - Management system
  2. ISO/IEC 23894:2023 - Artificial intelligence - Guidance on risk management
  3. ISO/IEC 27001:2022 - Information security management systems
  4. ISO/IEC 27701:2019 - Privacy information management
  5. NIST AI RMF 1.0 - AI Risk Management Framework (2023)
  6. EU AI Act - Regulation (EU) 2024/1689
  7. OWASP Top 10 for LLM Applications (2023)
  8. OpenAI Model Spec (2024)
  9. W3C Verifiable Credentials 2.0 (2024)
  10. IEEE 7000-7010 Series - Ethics in Autonomous Systems
  • ARAL-CORE-1.0.md - Layers 1-5 (Runtime, Memory, Capabilities, Reasoning, Persona)
  • ARAL-PROTOCOL-1.0.md - Layers 6-7 (Orchestration, Protocol)
  • ARAL-SECURITY-1.0.md - Security model and controls
  • ARAL-PRIVACY-1.0.md - GDPR compliance framework (35 requirements)
  • ARAL-INTEGRATION-SCENARIOS.md - Domain-specific compliance examples

For compliance questions or certification support:


Document Status: ✅ Release Candidate
Last Updated: 2026-01-16
Next Review: 2026-04-16