GOVERNANCE SPECIFICATION

The CG-AG AI Governance Framework

An open, operational framework defining 12 discrete controls for governing AI systems and autonomous agents from source code to production.

Architectural Overview of CG-AG

The CodeGuard AI Governance (CG-AG) framework was engineered to provide security and compliance teams with a rigorous, operational model tailored specifically to generative models, autonomous agents, and multi-agent systems.

CG-AG organizes governance across four lifecycle pillars (Discover, Govern, Operate, Assure), encompassing 12 discrete, auditable controls:

  • CG-AG-01 (Identity & Boundary): Verification of agent identity, role scopes, and separation of duties.
  • CG-AG-02 (Tool & Capability Scope): Explicit whitelisting of tool functions, schemas, and parameters.
  • CG-AG-03 (Model & Provider Transparency): Documentation of model versions, temperatures, and provider boundaries.
  • CG-AG-04 (Memory & Context Isolation): Separation of vector embeddings and conversation state across tenants.
  • CG-AG-05 (Human-in-the-Loop Gates): Mandatory human sign-off on destructive, financial, or privileged actions.
  • CG-AG-06 (Data Egress & Lineage): Tracking sensitive data flow and outbound API connections.
  • CG-AG-07 (Prompt & Instruction Integrity): Safeguards against instruction override and prompt drift.
  • CG-AG-08 (Exception & Failsafe Protocols): Deterministic, fail-closed handling of agent loop errors.
  • CG-AG-09 (Decision Record Persistence): Unambiguous capture of rationale and inputs for automated decisions.
  • CG-AG-10 (Cryptographic Asset Passports): Versioned, tamper-evident asset passports for every agent.
  • CG-AG-11 (Hash-Chained Audit Ledger): Immutable SHA-256 event chaining for complete audit defense.
  • CG-AG-12 (Regulatory Crosswalk): Direct bidirectional mapping to EU AI Act, ISO 42001, and LGPD/GDPR.
Regulatory Crosswalk Principle CG-AG maps technical code discoveries to regulatory obligations without claiming legal certification, providing compliance teams with empirical evidence packages.

Mapping CG-AG to Global AI Standards

The framework maps cleanly to major international standards:

• ISO/IEC 42001 (AI Management System): Aligns with Clause 6 (Planning & Risk Assessment) and Clause 8 (Operation of AI Systems).

• EU AI Act: Aligns with Article 9 (Risk Management System), Article 12 (Record-Keeping & Logging), and Article 14 (Human Oversight).

• Brazil LGPD / GDPR: Maps directly to Article 38 (Relatório de Impacto à Proteção de Dados - RIPD) and DPIA automated processing requirements.

Frequently Asked Questions

Is CG-AG proprietary to ComplyPRO?

The CG-AG control definitions and framework architecture are published as an open reference standard (see docs/CG_AG_FRAMEWORK_SPECIFICATION.md). ComplyPRO serves as the commercial Governance OS implementing the framework.

Can an organization adopt CG-AG alongside NIST AI RMF?

Yes. CG-AG operationalizes the high-level recommendations of NIST AI RMF (Govern, Map, Measure, Manage) into concrete code-level controls and verifiable evidence records.

Discover What Your AI Can Do

Run the Free AI Governance Scan in your browser. Zero code upload.

Launch Free Scan