One Set of Properties Answers Every Framework Buyers Ask About

One set of evidence satisfies SOC 2, HIPAA, ISO 27001, ISO 42001, and AIUC-1 at once. Intercom proved it by putting AI-approved pull requests in front of one auditor, Schellman (Intercom). Their design constraint from day one was that every AI-approved PR be "labelled, logged, and queryable." The seven properties cover the technical controls of every framework buyers ask about, and none of the organizational ones. The frameworks differ in vocabulary, not in what they demand of an autonomous committer.

Buyers rarely ask "is it compliant?"; they name a framework, and the question is which property answers it. Each framework gets a deep dive of its own.

FrameworkWhat it cares aboutProperties that answer itDeep dive
SOC 2Change management (CC8.1), logical access (CC6.x), audit logging, segregation of dutiesAttribution (1), Audit trail (2), Least privilege (3), Segregation of duties (5), Reproducibility (6), Dependency provenance (7)SOC 2 & ISO 27001
ISO 27001The ISMS plus Annex A: access control, privileged access, logging, environment separation, configuration, supply chainAudit trail (2), Least privilege (3), Isolation (4), Reproducibility (6), Dependency provenance (7)SOC 2 & ISO 27001
ISO 42001AI management systems: defined roles, recorded decisions, a managed AI life cycle, human oversightAttribution (1), Audit trail (2), Segregation of duties (5), Reproducibility (6)ISO 42001
AIUC-1AI-agent-specific assurance: log activity, assign accountability, limit data access, prevent cross-customer exposureAttribution (1), Audit trail (2), Least privilege (3), Isolation (4), Segregation of duties (5)AIUC-1
HIPAAPHI access control, unique user identification, audit controls, minimum necessaryAttribution (1), Audit trail (2), Least privilege (3), Isolation & residency (4)GDPR, HIPAA, EU AI Act
GDPRData minimization, accountability, security of processing, cross-border transfersAttribution (1), Audit trail (2), Least privilege (3), Isolation & residency (4), Reproducibility (6)GDPR, HIPAA, EU AI Act
NIST AI RMFVoluntary, but the questionnaire behind most US enterprise security reviews: govern, map, measure, manageAttribution (1), Audit trail (2), Segregation of duties (5)Standards in motion

Every framework is converging on the same fix: agents as identities

The pattern across every row is one fix in six vocabularies: treat agents as identities with defined permissions, logged activity, and named owners. The IBM Cost of a Data Breach Report 2025 found that 97% of organizations reporting an AI-related security incident lacked proper AI access controls, and Vanta reports 70% of companies have AI tools accessing their environment outside procurement (Vanta). The frameworks are responding to that gap, and the market is too: Microsoft now ships agent identities as first-class directory objects with sign-in logs, audit logs, and lifecycle governance (Entra Agent ID). A system already built on the seven properties is what that convergence is converging toward, because attribution and the audit trail are exactly the agent-as-identity and logged-activity demands stated as architecture.

NIST's AI RMF is the soft version of the same demand. Nobody certifies against it, but its four functions (govern, map, measure, manage) shape US security questionnaires, and AIUC-1 publishes a crosswalk to it (AIUC, NIST), so teams pursuing AIUC-1 can answer RMF-shaped questionnaires through one mapping instead of two.

Property 7 maps to controls we expect, not ones that exist

Dependency provenance is this handbook's prescription, not observed practice, and no audited framework names this exact install-time package gate yet. It maps to SOC 2's change-management criteria and ISO 27001's supply-chain controls by intent rather than by citation. The likeliest place it lands first is AIUC-1, which refreshes quarterly; the Q2-2026 update (released April 15, 2026) added controls for MCP security, third-party risk, and agent identity and permissions (AIUC). That quarterly cadence also means this table has a shelf life: recheck the AIUC-1 row against the current control set before any audit cycle.

No architecture writes your policies

The properties cover the technical half of every framework and none of the organizational half. Risk and impact assessments, the AI policy, training records, vendor due diligence (including BAAs under HIPAA and DPAs under GDPR for the model provider and the platform vendor), and incident response plans are documents, meetings, and contracts. The architecture feeds them facts; it does not replace them. The full per-framework gap lists live on the linked pages, and the consolidated version is the same list whether you build, assemble, or buy.

Stage 2 is where the architecture pays

Stage 2 tests whether the design actually ran, and that is where the seven properties earn their keep. Schellman's published process generalizes across the frameworks it audits under one roof (Schellman): Stage 1 (1–2 days) reviews documents, almost none of which the architecture produces; Stage 2 (3–9+ days) tests the design. Stage 2 questions take the form "show me everything that touched X between these dates," and a system built on the seven properties answers them by query rather than by reconstruction. Certification then runs on a three-year cycle with annual surveillance audits, which Schellman scopes at 2–5+ days against Stage 2's 3–9+. Multiplied across five frameworks and three years, evidence-as-a-byproduct versus evidence-assembled-by-hand is most of the economic argument for getting the architecture right before the first Stage 1, which is the case Evidence as a byproduct makes in full.