One Set of Properties Answers Every Framework Buyers Ask About
One set of evidence satisfies SOC 2, HIPAA, ISO 27001, ISO 42001, and AIUC-1 at once. Intercom proved it by putting AI-approved pull requests in front of one auditor, Schellman (Intercom). Their design constraint from day one was that every AI-approved PR be "labelled, logged, and queryable." The seven properties cover the technical controls of every framework buyers ask about, and none of the organizational ones. The frameworks differ in vocabulary, not in what they demand of an autonomous committer.
Buyers rarely ask "is it compliant?"; they name a framework, and the question is which property answers it. Each framework gets a deep dive of its own.
| Framework | What it cares about | Properties that answer it | Deep dive |
|---|---|---|---|
| SOC 2 | Change management (CC8.1), logical access (CC6.x), audit logging, segregation of duties | Attribution (1), Audit trail (2), Least privilege (3), Segregation of duties (5), Reproducibility (6), Dependency provenance (7) | SOC 2 & ISO 27001 |
| ISO 27001 | The ISMS plus Annex A: access control, privileged access, logging, environment separation, configuration, supply chain | Audit trail (2), Least privilege (3), Isolation (4), Reproducibility (6), Dependency provenance (7) | SOC 2 & ISO 27001 |
| ISO 42001 | AI management systems: defined roles, recorded decisions, a managed AI life cycle, human oversight | Attribution (1), Audit trail (2), Segregation of duties (5), Reproducibility (6) | ISO 42001 |
| AIUC-1 | AI-agent-specific assurance: log activity, assign accountability, limit data access, prevent cross-customer exposure | Attribution (1), Audit trail (2), Least privilege (3), Isolation (4), Segregation of duties (5) | AIUC-1 |
| HIPAA | PHI access control, unique user identification, audit controls, minimum necessary | Attribution (1), Audit trail (2), Least privilege (3), Isolation & residency (4) | GDPR, HIPAA, EU AI Act |
| GDPR | Data minimization, accountability, security of processing, cross-border transfers | Attribution (1), Audit trail (2), Least privilege (3), Isolation & residency (4), Reproducibility (6) | GDPR, HIPAA, EU AI Act |
| NIST AI RMF | Voluntary, but the questionnaire behind most US enterprise security reviews: govern, map, measure, manage | Attribution (1), Audit trail (2), Segregation of duties (5) | Standards in motion |
Every framework is converging on the same fix: agents as identities
The pattern across every row is one fix in six vocabularies: treat agents as identities with defined permissions, logged activity, and named owners. The IBM Cost of a Data Breach Report 2025 found that 97% of organizations reporting an AI-related security incident lacked proper AI access controls, and Vanta reports 70% of companies have AI tools accessing their environment outside procurement (Vanta). The frameworks are responding to that gap, and the market is too: Microsoft now ships agent identities as first-class directory objects with sign-in logs, audit logs, and lifecycle governance (Entra Agent ID). A system already built on the seven properties is what that convergence is converging toward, because attribution and the audit trail are exactly the agent-as-identity and logged-activity demands stated as architecture.
NIST's AI RMF is the soft version of the same demand. Nobody certifies against it, but its four functions (govern, map, measure, manage) shape US security questionnaires, and AIUC-1 publishes a crosswalk to it (AIUC, NIST), so teams pursuing AIUC-1 can answer RMF-shaped questionnaires through one mapping instead of two.
Property 7 maps to controls we expect, not ones that exist
Dependency provenance is this handbook's prescription, not observed practice, and no audited framework names this exact install-time package gate yet. It maps to SOC 2's change-management criteria and ISO 27001's supply-chain controls by intent rather than by citation. The likeliest place it lands first is AIUC-1, which refreshes quarterly; the Q2-2026 update (released April 15, 2026) added controls for MCP security, third-party risk, and agent identity and permissions (AIUC). That quarterly cadence also means this table has a shelf life: recheck the AIUC-1 row against the current control set before any audit cycle.
No architecture writes your policies
The properties cover the technical half of every framework and none of the organizational half. Risk and impact assessments, the AI policy, training records, vendor due diligence (including BAAs under HIPAA and DPAs under GDPR for the model provider and the platform vendor), and incident response plans are documents, meetings, and contracts. The architecture feeds them facts; it does not replace them. The full per-framework gap lists live on the linked pages, and the consolidated version is the same list whether you build, assemble, or buy.
Stage 2 is where the architecture pays
Stage 2 tests whether the design actually ran, and that is where the seven properties earn their keep. Schellman's published process generalizes across the frameworks it audits under one roof (Schellman): Stage 1 (1–2 days) reviews documents, almost none of which the architecture produces; Stage 2 (3–9+ days) tests the design. Stage 2 questions take the form "show me everything that touched X between these dates," and a system built on the seven properties answers them by query rather than by reconstruction. Certification then runs on a three-year cycle with annual surveillance audits, which Schellman scopes at 2–5+ days against Stage 2's 3–9+. Multiplied across five frameworks and three years, evidence-as-a-byproduct versus evidence-assembled-by-hand is most of the economic argument for getting the architecture right before the first Stage 1, which is the case Evidence as a byproduct makes in full.