/blog · the soft-law tier · OECD · ISO 24028 · AIGP

ENTRY № 15 · SYNTHESIS · OECD · ISO 24028 · AIGP
PUBLISHED 2026-05-09 · ~10-MIN READ · WARRANT COMPLIANCE

OECD principles, ISO/IEC 24028, and the AIGP body of knowledge.

three references that compliance officers reach for before opening any binding regulator. the OECD AI Principles are the soft-law floor most regulators cite. ISO/IEC 24028 is the trustworthiness vocabulary AI engineering teams converge on. the IAPP AIGP body of knowledge is what an AI Governance Professional must evidence to certify. read together, they form the methodological connective tissue between binding regulators (EU AI Act, NYDFS Part 500, FCA Consumer Duty) and operational practice.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.

OECD PRINCIPLES
5 principles· 5 recommendations
51 adherents as of 2026-08-06 · 2019 / 2024. Adopted 22 May 2019, revised 3 May 2024. Definition tracked by EU AI Act Art 3(1); AI RMF 1.0 adapts the 2019 OECD definition.
ISO/IEC 24028:2020
trustworthiness· vocabulary
Published 2020-05. Overview of trustworthiness in AI. Vocabulary feeds into ISO 42001 and ISO 23894. Sets the conceptual baseline for accuracy, robustness, transparency, controllability.
IAPP AIGP
certification· BoK 4 domains
Exam launched March 2024. First professional certification for AI governance. Body of knowledge v2.0.1, effective 3 February 2025: foundations, laws and standards, governing development, governing deployment and use.
W
SOFT-LAW TIER · OECD · ISO 24028 · AIGP
Three non-binding references the binding regulators cite. Read together, they are the methodology stack a Chief AI Officer reaches for when the regulator shows up.
01 · THREE REFERENCES FOR ONE JOB

Three references for one job.

OECD AI Principles · ISO/IEC 24028:2020 · IAPP AIGP body of knowledge

Every AI compliance team has these three references on the bookshelf. None of them is binding by itself. The OECD AI Principles are a Council recommendation, OECD/LEGAL/0449. ISO/IEC 24028 is a Technical Report, an informative deliverable that carries no normative requirements. The IAPP AIGP is a professional credential, awarded to individuals, not organisations. A defence counsel reading any one of them in isolation reads a non-binding text.

Read together, they are the methodology stack a Chief AI Officer reaches for when the regulator shows up. The OECD principles supply the values. ISO/IEC 24028 supplies the vocabulary that operationalises the values. The AIGP body of knowledge supplies the curriculum the human governing the system has internalised. The three references cover the same ground at three altitudes: principle, terminology, practice.

Coverage matters because the binding texts converge on the same concepts, though not by citation. As of the enacted text of Regulation (EU) 2024/1689, the OECD is not named in the Regulation: Recital 12 says the notion of an AI system "should be closely aligned with the work of international organisations working on AI", and Article 3(1) tracks the OECD definition closely without attributing it. NIST AI RMF 1.0 does not cite the OECD AI Principles either; it adapts the 2019 OECD definition of an AI system and credits the OECD's 2022 classification framework for its life-cycle figure. The US federal claim that used to sit here has been removed: OMB M-24-10 was rescinded and replaced by M-25-21 on 3 April 2025, and M-25-21 contains no reference to the OECD principles or to the NIST AI RMF, so there is no current OMB instrument naming either as a vendor-evaluation benchmark. ISO/IEC 24028's vocabulary is what the certifiable management system standard, ISO/IEC 42001:2023, reuses in its Annex A controls. The AIGP curriculum is the only mainstream credential aligned to the cross-jurisdiction body of work spanning all of the above.

This entry reads each reference at the level of detail a compliance officer needs to map evidence to artefact. OECD principles supply the values. ISO 24028 supplies the threat taxonomy. AIGP supplies the practitioner.

02 · OECD AI PRINCIPLES · 5 PRINCIPLES

OECD AI Principles · the 5 principles.

OECD/LEGAL/0449 · adopted 22 May 2019 · revised 3 May 2024 · 51 adherents as of 2026-08-06

The OECD AI Principles, at the values layer, are five headings. The five headings of §§ 1.1 to 1.5, as revised 3 May 2024 — the revision expanded some of them, so the 2019 wording is not the current wording:

"1.1 Inclusive growth, sustainable development and well-being. 1.2 Respect for the rule of law, human rights and democratic values, including fairness and privacy. 1.3 Transparency and explainability. 1.4 Robustness, security and safety. 1.5 Accountability." OECD AI Principles · OECD/LEGAL/0449 · §§ 1.1–1.5 · as revised 3 May 2024

The five values were adopted by the OECD Council on 22 May 2019, the first intergovernmental standard for trustworthy AI. As of 6 August 2026 the OECD's adherence record for OECD/LEGAL/0449 lists 51 adherents, and adherence has continued after the May 2024 revision — four of the entries post-date it. The record publishes country references rather than a name list, so this entry names none and quotes no total of its own.

Regulation (EU) 2024/1689 does not name the OECD. Recital 12 requires the notion of an AI system to be "closely aligned with the work of international organisations working on AI", and Article 3(1) is where that alignment shows. Nothing in NIST AI RMF 1.0 grounds its Govern, Map, Measure and Manage functions in the OECD principles either; those four functions are NIST's own. A regulator that opens with "your system shall be transparent and accountable" without further citation is reaching for the vocabulary OECD principles 1.3 and 1.5 set, but the citation has to be shown in the instrument before it is asserted.

P1
Inclusive growth, sustainable development and well-beingVALUES LAYER · BENEFICIAL OUTCOMES
P2
Respect for the rule of law, human rights and democratic values, including fairness and privacyVALUES LAYER · RIGHTS-BASED CONSTRAINT
P3
Transparency and explainabilityVALUES LAYER · DISCLOSURE OBLIGATION
P4
Robustness, security and safetyVALUES LAYER · TECHNICAL ASSURANCE
P5
AccountabilityVALUES LAYER · NAMED-OWNER REQUIREMENT

The values layer maps to a record. Principle 1.3 maps to a per-decision rationale. Principle 1.4 maps to an adversarial robustness eval per release. Principle 1.5 maps to a named-owner record per decision. Compliance is a question about the records that exist under each value, not about the values themselves.

03 · OECD AI PRINCIPLES · 5 RECOMMENDATIONS TO GOVERNMENTS

OECD recommendations · the 5 to governments.

OECD/LEGAL/0449 · § 2.1 to § 2.5 · applied recommendations

The principles bind values; the recommendations bind state action. The operative wrapper and the five headings of §§ 2.1 to 2.5, as the instrument sets them out — the lead-in "Governments should consider", which this entry used to print as the frame, belongs to § 2.1(a) alone and not to the five:

"RECOMMENDS that Adherents implement the following recommendations […]: 2.1 Investing in AI research and development; 2.2 Fostering an inclusive AI-enabling ecosystem; 2.3 Shaping an enabling interoperable governance and policy environment for AI; 2.4 Building human capacity and preparing for labour market transformation; 2.5 International co-operation for trustworthy AI." OECD AI Principles · OECD/LEGAL/0449 · § 2.1 to § 2.5

These recommendations are the soft-law signposts domestic AI regulators reach for when justifying rules. This entry attributes no numbered OECD recommendation to any domestic instrument: the enacted EU AI Act does not name the OECD, and for the UK, Indian and Singaporean programmes the referencing claim could not be confirmed against a primary text, so it is not made here. Two precisions on the bodies usually named in this context. The UK AI Safety Institute was renamed the UK AI Security Institute on 14 February 2025. Singapore's Model AI Governance Framework, second edition (2020), and its Model AI Governance Framework for Generative AI (2024) are two different documents, and this entry does not treat them as one.

Recommendation 2.4, "Building human capacity and preparing for labour market transformation", is the recommendation that closes the loop with the AIGP credential. The AIGP curriculum is one literal answer to the recommendation: a human-capacity programme certifying individuals on the body of knowledge governments have endorsed. The recommendation does not name AIGP, but the credential is the most direct route to evidencing the recommendation in a covered organisation's training register.

04 · THE MAY 2024 REVISION · WHAT CHANGED

The May 2024 revision · what changed.

OECD/LEGAL/0449 revision · adopted 3 May 2024 · expanded headings · information integrity

The OECD Council revised the 2019 text on 3 May 2024. The five principles and five recommendations were retained in number, but not untouched: the instrument records that "some of the headings of the principles and recommendations were expanded for clarity, and the text on traceability and risk management was further elaborated and moved to the 'Accountability' principle". Any page that reproduces a 2019 heading as the current one is quoting a superseded string — which is exactly the defect this entry carried until 6 August 2026.

The first change is information integrity. The revision adds attention to misinformation and disinformation, and to safeguarding information integrity, in the supporting text. It names no provenance technology: "content authenticity", "watermark", "synthetic content" and "provenance" each occur zero times in the instrument, and this entry previously asserted all four. The binding counterpart is not an operationalisation of an OECD provenance clause that does not exist — EU AI Act Article 50, transparency obligations for providers and deployers of certain AI systems, is the Union's own transparency regime, and it applies from 2 August 2026.

The second change concerns co-operation on advanced AI. The instrument does not use the vocabulary of systemic risk or foundation models — "systemic risk" and "foundation model" occur zero times, and the single hit for "general-purpose" is the background sentence describing AI as a general-purpose technology. What does exist is recommendation 2.5, international co-operation for trustworthy AI, and the EU has built its own general-purpose regime on top: EU AI Act Articles 51 to 56 on general-purpose AI models, and the General-Purpose AI Code of Practice, are the binding and quasi-binding instruments that operationalise this 2024 OECD addition. Cite the Code in its final form: the Commission received the final version on 10 July 2025, superseding the drafts, and it runs to three chapters — Transparency and Copyright for all general-purpose model providers, and Safety and Security for providers of the most advanced models. The Commission describes it as a voluntary tool developed by 13 independent experts, aimed at the general-purpose AI rules that entered into application on 2 August 2025. The third draft of March 2025 is superseded and is not the citable text.

The third is the OECD definition of an AI system. The Council adopted the revised definition on 8 November 2023 and the 2024 revision retains it: a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. EU AI Act Article 3(1) tracks it closely, adding that the system "is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment", and attributes it to nobody. NIST AI RMF 1.0, published in January 2023, predates the revision and carries the 2019 form, adapted — so a team aligning its inventory to the OECD definition should say which OECD definition, because the EU and US texts are not quoting the same one.

The fourth set of changes is broader than provenance: the revision adds addressing uses outside intended purpose and misuse, overridability and safe decommissioning, responsible business conduct across the life cycle, interoperable governance, and an explicit reference to environmental sustainability. "OECD-aligned" now means "post-2024 OECD-aligned". A team that drafted its AI policy against the 2019 text has a refresh task on its register.

05 · ISO/IEC 24028:2020 · THE TRUSTWORTHINESS VOCABULARY

ISO/IEC 24028:2020 · the trustworthiness vocabulary.

ISO/IEC TR 24028:2020 · published 2020-05-28 · Technical Report

ISO/IEC TR 24028:2020 was prepared by ISO/IEC JTC 1, Subcommittee SC 42, Artificial Intelligence, published in May 2020, and remains the conceptual baseline most other ISO/IEC AI standards build on. The "TR" prefix is meaningful: a Technical Report is an informative deliverable that carries no normative requirements. The trade-off is that 24028 is not certifiable. The advantage is that 24028 can describe the field without prescribing a single methodology, which is what made it the working dictionary downstream standards reuse.

The document delivers three artefacts a Chief AI Officer needs. Its clause structure is worth stating, because this entry misnumbered it until 6 August 2026: 1 Scope · 2 Normative references · 3 Terms and definitions · 4 Overview · 5 Existing frameworks applicable to trustworthiness · 6 Stakeholders · 7 Recognition of high-level concerns · 8 Vulnerabilities, threats and challenges · 9 Mitigation measures · 10 Conclusions · Annex A · Bibliography.

  • Trustworthiness characteristics. Accuracy, availability, controllability, reliability, resilience, robustness, safety, security, transparency, privacy. The terms are defined in clause 3; clause 5 is a survey of existing frameworks applicable to trustworthiness, at 5.1 to 5.5. These are the words ISO/IEC 42001's Annex A controls and ISO/IEC 23894's risk catalogue point at when they say "transparency" or "robustness".
  • Threats to trustworthiness. Data poisoning, model evasion, adversarial inputs, distribution shift, oracle attacks, model extraction, model inversion, membership inference, transfer attacks, backdoor attacks, availability attacks. The threats list is 24028 § 8, "Vulnerabilities, threats and challenges"; the AI-specific security threats sit at § 8.2.
  • Stakeholder roles. Clause 6 covers stakeholders — general concepts (6.1), types (6.2), assets (6.3) and values (6.4). This entry previously printed a five-role list and an alignment to EU AI Act Articles 25 to 27; neither could be confirmed against the standard, so both are withdrawn.

24028 is the vocabulary 42001's Annex A controls operationalise. ISO/IEC 23894:2023, the AI risk management guidance, and ISO/IEC 5338:2023, the AI system life cycle process standard, both build on the SC 42 vocabulary 24028 established. Neither reuse is described here as verbatim: both standards are paywalled and the claim could not be quoted. Life-cycle phases in particular are not 24028's to reuse — 24028 has no life-cycle clause, and the AI system life-cycle stages are defined in ISO/IEC 22989:2022. Reading 42001 without 24028 is reading a checklist without the dictionary.

"The goal of this document is to analyse the factors that can impact the trustworthiness of systems providing or using AI, called hereafter artificial intelligence (AI) systems." ISO/IEC TR 24028:2020 · Introduction

The standard's defined term for trustworthiness, in clause 3, turns on meeting stakeholders' expectations in a verifiable way. That phrase carries the load, and it belongs to the definition rather than to the Introduction — this entry previously quoted it as Introduction text at a pinpoint, "§ 0.2", that does not exist, because the Introduction is unnumbered. Verifiability is the bridge from soft-law value to hard-law evidence. A regulator does not grade your trustworthiness; the regulator grades the records you produce that show, in the standard's terms, that the trustworthiness characteristics were tested, the threats were enumerated, and the lifecycle phases were tagged.

06 · THE THREATS LIST · WHAT A CHIEF AI OFFICER MUST ENUMERATE

The threats list · what a Chief AI Officer must enumerate.

ISO/IEC TR 24028:2020 · § 8 · vulnerabilities, threats and challenges · evidence-of-mitigation

Clause 8 of ISO/IEC 24028, "Vulnerabilities, threats and challenges", is where the threat material sits — clause 6 is Stakeholders, and this entry cited clause 6 until 6 August 2026. Clause 8.2 covers AI-specific security threats, naming data poisoning (8.2.2), adversarial attacks (8.2.3), model stealing (8.2.4) and hardware-focused threats to confidentiality and integrity (8.2.5); unpredictability sits at 8.5 and system hardware faults at 8.10, and mitigation measures are clause 9. The clause is not normative, and it is not a flat ten-item list. The ten categories below are this entry's consolidation for evidence purposes, not the standard's own enumeration:

T1 · DATA POISONING
Adversarial training data
Manipulation of the training set such that the model learns the wrong distribution. Mitigation: provenance of training data, supply-chain controls, anomaly detection at training time.
T2 · ADVERSARIAL INPUT · EVASION
Inference-time perturbation
Crafted inputs that cross a decision boundary. Mitigation: adversarial training, input pre-processing, ensemble defence.
T3 · MODEL EXTRACTION
Stealing the model
Querying the deployed model to reconstruct an approximate copy. Mitigation: query-rate limits, output watermarking, differential privacy on outputs.
T4 · MODEL INVERSION
Reconstructing training inputs
Querying the model to reconstruct training-set members. Mitigation: differential-privacy training, output suppression on low-confidence regions.
T5 · MEMBERSHIP INFERENCE
Was X in the training set?
Inferring training-set membership from model output statistics. Mitigation: differential privacy, output regularisation.
T6 · TRANSFER ATTACKS
Cross-model adversarial transfer
An adversarial input crafted against model A that succeeds against model B. Mitigation: ensemble defence, defensive distillation.
T7 · BACKDOOR ATTACKS
Trojan triggers
Hidden trigger patterns inserted at training time that cause specified outputs at inference. Mitigation: training-data sanitisation, neural-network inspection.
T8 · ORACLE ATTACKS
Confidence-score leakage
Use of model confidence outputs to extract proprietary information. Mitigation: output rounding, confidence-score suppression.
T9 · DISTRIBUTION SHIFT
Operational drift
Production distribution diverges from the training distribution. Mitigation: drift monitoring, periodic re-evaluation, canary deployment.
T10 · AVAILABILITY ATTACKS
Denial of inference
Inputs crafted to consume disproportionate compute or memory. Mitigation: input length limits, rate limits, bounded-time inference.

For each of the ten categories, an organisation needs an evidence-of-mitigation record per AI system. The record can be short. A two-line entry stating the category, the mitigation, the test that produced the evidence, and the date of the test is sufficient for a baseline submission. The Warrant adversarial-robustness eval at /blog/regulator-grade-evals is where that record would sit per decision: a per-action threat-mitigation check pointing at the adversarial-evaluation suite that ran for the release the decision was served on. That is the target evidence shape, not the current one — the warrant-v1 evidence schema carries no such field today.

PER-RELEASE EVIDENCE

"Was the adversarial robustness eval run for this release?"

Yes or no, with eval-suite reference, eval-suite version, eval-suite output. This is the release-gate question.

PER-DECISION EVIDENCE

"Did the threat-mitigation check fire on this specific action?"

The target shape carries a per-action threat-mitigation check pointing at the eval-suite reference live at the time of the action, so an auditor can re-run the suite against the historical artefact and reproduce the result. Not yet emitted: the current package records per-action authorization and obligation rows, and no threat-mitigation field.

07 · IAPP AIGP · BODY OF KNOWLEDGE · 4 DOMAINS

The IAPP AIGP body of knowledge · 4 domains.

IAPP · AIGP credential · exam launched March 2024 · BoK v2.0.1 effective 2025-02-03

The International Association of Privacy Professionals announced the Artificial Intelligence Governance Professional exam on 5 March 2024, with the first in-person sitting at its Global Privacy Summit on 4 April 2024. The AIGP is the first professional certification for AI governance and is positioned as the AI-governance counterpart to the IAPP's CIPP for privacy. The credential examines a candidate against the AIGP body of knowledge, and the current body of knowledge is v2.0.1 — approved by the AIGP Exam Development Board on 21 January 2025, effective 3 February 2025, superseding v2.0.0 — organised in four domains. The seven-domain structure belongs to the superseded v1.0.0 and is not the current outline. Domain titles:

"I. Understanding the foundations of AI governance. II. Understanding how laws, standards and frameworks apply to AI. III. Understanding how to govern AI development. IV. Understanding how to govern AI deployment and use." IAPP AIGP body of knowledge v2.0.1 · 4 domains · effective 3 February 2025
I
Understanding the foundations of AI governanceBoK v2.0.1 · DOMAIN I
II
Understanding how laws, standards and frameworks apply to AIBoK v2.0.1 · DOMAIN II
III
Understanding how to govern AI developmentBoK v2.0.1 · DOMAIN III
IV
Understanding how to govern AI deployment and useBoK v2.0.1 · DOMAIN IV

The four domains are what an AIGP holder must defend, in practice, on a real AI system. This entry does not map named OECD principles, ISO clauses or NIST functions onto individual domains: the body of knowledge is a paywalled exam outline and the cross-references cannot be quoted from it, so any such mapping would be unverifiable. Domain II is the domain a compliance officer will recognise, since laws, standards and frameworks is where the EU AI Act, NIST AI RMF and the ISO/IEC AI series enter the syllabus.

The credential is necessary, not sufficient. An audit reads evidence, not credentials. The AIGP holder is the person who assembles and defends the evidence: the system inventory and governance foundations under Domain I, the regulatory mapping under Domain II, the development-stage records under Domain III, and the deployment and ongoing-use records under Domain IV. A team with AIGP holders and no underlying evidence pipeline fails an audit no faster than a team with evidence and no credentials.

08 · THE SYNTHESIS · THREE REFERENCES, ONE EVIDENCE SHAPE

Three references, one evidence shape.

OECD principle · ISO 24028 clause · AIGP domain · Warrant evidence field

The three references resolve, at the artefact layer, to a small set of evidence fields. The mapping table makes the resolution explicit:

Reference What to evidence What a package would have to carry · and what warrant-v1 carries today
OECD principle 1.3 · transparency per-decision rationale + source attribution a per-action rationale with source attribution — carried at authorizations[].justification and obligations.<action_id>[].evidence
OECD principle 1.4 · "Robustness, security and safety" adversarial robustness eval per release a reference to the adversarial-robustness suite for the release — no such field
OECD principle 1.5 · accountability named-owner record per decision the identity of a named accountable owner — no such field
ISO 24028 § 8 threats per-decision threat-mitigation check a per-action threat-mitigation determination — no such field
ISO/IEC 22989:2022 life-cycle stage phase tag per decision (operation vs. development) a life-cycle phase tag distinguishing operation from development — no such field
AIGP Domain III · governing AI development full evidence-replay surface a pointer to a record a third party can retrieve and check — carried at trace_metadata.package_id, with the corpus digest beside it. No development-stage history is carried
AIGP Domain II · laws, standards and frameworks regulator-mapping per decision the regimes engaged, per action and per package — carried at obligations.<action_id>[].id, a sub-clause id resolvable in the corpus, and at coverage_by_regime

The mapping shows that three references, each with hundreds of pages of supporting commentary, resolve at the bottom of the stack to seven things a record would have to carry per attestable action. A package carrying all seven would satisfy the soft-law tier in one document. Three of the seven exist in warrant-v1 today and are named by their field path in the table. Four do not, and warrant-v1 is closed to added properties, so those four are described in words: naming a path for them would read as a commitment the schema does not make. What the current package does carry is set out below.

The binding instruments the corpus carries at digest 6871ee8b are EU AI Act Articles 12 and 13 and Annex IV, NYDFS Part 500, FCA Consumer Duty Principle 12 (PRIN 2.1.1R), the SEBI Retail Algorithmic Trading Framework, and India's Digital Personal Data Protection Act 2023, whose substantive obligations commence 14 May 2027 and are therefore not presently binding. The corpus also carries the RBI FREE-AI Committee Report, released 13 August 2025. That is a committee report, not a binding instrument: a mapping against its recommendations is voluntary governance design and never a duty the report creates. Which of those entries a given package cites depends on the trace it was built from. The specimen at 7de85ceaeac42a47 is an EU lending trace from a Frankfurt bank; it maps EU AI Act Article 12 and Article 13 and FCA Consumer Duty Principle 12, and no other regime. It is shown throughout this entry because the shape of the package is the point, not the regime it happens to cover — the soft-law tier read here is a different domain from the one that specimen evidences. No NYDFS section number is claimed: § 500.6 is real in the enacted Second Amendment, but the corpus carries no § 500.6 sub-clause, so a package reports Part 500 as classified and not evaluated rather than citing that clause. SR 26-2 is not among the regimes an agent-evidence package satisfies: its § II footnote 3 places generative and agentic AI outside the guidance, so for an autonomous agent the evidence is framed as general risk management and governance, never as a model-risk-management claim.

json · the shape that exists · api/spec/warrant-v1-evidence.schema.json
{
  "classification": {                                    // stage 1
    "domain": "consumer lending",
    "jurisdictions": ["EU"],
    "regimes": [],                                     // in the schema; production emits it empty
    "risk_tier": "high-risk",
    "confidence": 0.91
  },
  "actions": [                                           // stage 2
    { "action_id": "a1", "actor": "underwriter-agent-v3.2.1",
      "action": "issued credit decision", "subject": "applicant file" }
  ],
  "authorizations": [                                    // stage 3
    { "action_id": "a1", "within_purpose": "yes",
      "human_oversight_appropriate": "no", "reversible": "yes",
      "justification": "...", "confidence": 0.88, "refusal": false }
  ],
  "obligations": {                                       // stage 4, keyed by action_id
    "a1": [ { "id": "eu_ai_act_art_12.1", "compliance": "satisfied",
             "confidence": 0.9, "evidence": "..." } ]
  },
  "coverage_by_regime": { "eu_ai_act_art_12": "evaluated" },
  "risk_tier": "high-risk",
  "trace_metadata": {
    "package_id": "7de85ceaeac42a47",
    "timestamp": "2026-06-12T14:23:11.482Z",
    "regulations_corpus_sha256": "6871ee8b923f5b52..."
  }
}

Read against the mapping table, that shape covers part of the soft-law tier and not all of it. The per-decision rationale the OECD transparency principle wants is authorizations[].justification and obligations.<action_id>[].evidence. The regulator mapping the AIGP laws-and-standards domain wants is coverage_by_regime and obligations.<action_id>[].id, where the id is a corpus sub-clause id such as eu_ai_act_art_12.1, resolved against the corpus digest recorded in trace_metadata. The schema also declares classification.regimes; production leaves that array empty, so the regime set a package covers is read from the obligation rows and the coverage map, not from that field. There is no field for a named accountable owner, no life-cycle-phase tag and no eval-suite reference, so the OECD accountability record and the ISO 24028 § 8 threat-mitigation record have no home in warrant-v1 today. The record is independently verifiable without contacting Warrant. The architectural detail of the four layers, and how each one verifies, lives at /blog/four-layer-evidence-stack.

09 · WHERE THE SOFT-LAW TIER SITS

Where the soft-law tier sits in the wider stack.

soft law · standards · binding regulation · the three tiers

The three references read in this entry are the soft-law tier of a three-tier stack. The other two tiers sit above and below.

                     ┌──────────────────────────────────┐
                     │  Tier 3 · Binding regulation      │  EU AI Act · NYDFS Part 500
                     │                                  │  FCA Consumer Duty · SEBI Retail Algo
                     │                                  │  India DPDP
                     │                                  │  (DPDP substantive obligations
                     │                                  │   commence 14 May 2027)
                     ├──────────────────────────────────┤
                     │  Tier 2 · Standards               │  ISO/IEC 42001:2023 · 23894:2023
                     │                                  │  ISO/IEC 5338 · 38507
                     │                                  │  CEN-CENELEC hENs
                     │                                  │  (in development as of Aug 2026)
                     ├──────────────────────────────────┤
                     │  Tier 1 · Soft law (this entry)   │  OECD AI Principles
                     │                                  │  ISO/IEC 24028 (TR · vocabulary)
                     │                                  │  ISO/IEC TR 5469:2024 (TR)
                     │                                  │  NIST AI RMF (voluntary)
                     │                                  │  IAPP AIGP (credential)
                     └──────────────────────────────────┘

                     SR 26-2 sits in none of the three tiers. It is Fed / OCC / FDIC
                     supervisory guidance: non-compliance with it is not independently
                     enforceable, and its § II footnote 3 places generative and agentic
                     AI outside its scope.

                     RBI FREE-AI sits in none of the three tiers either. It is the
                     report of an RBI-constituted committee, released 13 August 2025:
                     seven sutras and twenty-six recommendations, which are not
                     directions binding on a regulated entity.

Tier 1 is non-binding by design. The OECD recommendation is a Council instrument with no treaty force. ISO/IEC 24028 is a Technical Report, not a certifiable standard, and so is ISO/IEC TR 5469:2024 on functional safety in AI — by the Tier 1 / Tier 2 test used here a Technical Report belongs in Tier 1, which is where this entry now places it. NIST AI RMF is a voluntary text. The AIGP is a professional credential. None of them binds an organisation by force of law on its own.

Tier 2 is voluntary but certifiable. ISO/IEC 42001:2023 is the certifiable AI Management System standard. ISO/IEC 23894:2023 is the AI risk-management guidance, intended as a sector overlay on ISO 31000. ISO/IEC 5338:2023 is the AI system life cycle process standard. ISO/IEC 38507 (AI governance for boards) and the CEN-CENELEC harmonised European standards (hENs), in development as of August 2026, sit in this tier. Tier 2 standards reuse Tier 1 vocabulary.

Tier 3 is binding. EU AI Act, NYDFS Part 500, FCA Consumer Duty, SEBI Retail Algo Framework, and India's DPDP Act 2023 — the last of which is enacted but whose substantive obligations commence 14 May 2027, so it does not presently bind. The RBI FREE-AI Committee Report is not in this tier: released 13 August 2025, it is the report of a committee constituted by the Reserve Bank, carrying seven sutras and twenty-six recommendations. Recommendations in a committee report are not directions binding on a regulated entity. Mapping a record against FREE-AI is voluntary governance design, never a duty the report creates. Federal Reserve SR 26-2 (issued 17 April 2026; supersedes and replaces SR 11-7 of 4 April 2011 and SR 21-8 of 9 April 2021) is not in this tier: it is supervisory guidance, non-compliance with it is not independently enforceable, and its § II footnote 3 places generative and agentic AI outside its scope. SR 26-2 is a different, revised interagency guidance, not a re-issue of one continuous instrument, and SR 11-7 is not current guidance either. Mapping an autonomous agent's record against SR 26-2 is voluntary governance design — general risk management and governance — never a model-risk-management claim, and never a duty the guidance itself creates. Tier 3 reuses Tier 2 vocabulary in operative clauses, and cites Tier 1 concepts more often than it cites Tier 1 documents.

The target is one document a regulator at any tier opens: the OECD transparency and accountability records, the ISO 24028 § 8 threat-mitigation record, the AIGP Domain III development record, and the EU AI Act Article 12 record-keeping fields, independently verifiable without contacting Warrant. Today the package delivers the Article 12 and Article 13 obligation rows and the per-regime coverage map; the soft-law fields listed in the synthesis table are the gap, and this entry states them as a target rather than as shipped behaviour.

10 · FOR THE AIGP CANDIDATE · THE PRACTICAL BOOKSHELF

For the AIGP candidate · the practical bookshelf.

the references an AIGP must engage with in practice · cross-jurisdictional

The AIGP exam outline lists primary references at a high level; in practice, the body of work an AIGP must engage with is bigger than the exam outline and varies by the candidate's regulatory exposure. The bookshelf, with the Warrant deep-dive entry where one exists:

  • OECD AI Principles · 2019 / 2024. The five principles, the five recommendations, the 2024 update on generative AI. This entry.
  • ISO/IEC 42001:2023 · AIMS. The certifiable AI Management System standard. Annex A controls. Sister entry at /blog/iso-iec-42001-ai-management-system.
  • ISO/IEC 23894:2023 · risk guidance. The AI risk-management guidance, sector overlay on ISO 31000. Reuses ISO 24028 threat taxonomy.
  • ISO/IEC 24028:2020 · trustworthiness vocabulary. The dictionary the other ISO AI standards reuse. This entry.
  • NIST AI RMF 1.0 · January 2023. The Govern / Map / Measure / Manage functions. Sister entry at /blog/nist-ai-rmf.
  • NIST AI RMF Generative AI Profile · July 2024. The generative-AI overlay on the 2023 voluntary text.
  • EU AI Act · Regulation (EU) 2024/1689 + Annex IV. Recital 12 requires the AI-system definition to align with international work; Annex IV is the technical-documentation list. Per-article entries at /blog/eu-ai-act-article-12 and /blog/eu-ai-act-article-13.
  • GDPR · Regulation (EU) 2016/679. The data-protection foundation any AI-governance person reasons against. Article 22 on automated decision-making is the AI-relevant clause.
  • Sector-specific. NYDFS Part 500 (cyber and audit-trail · entry at /blog/nydfs-standard-logs), Federal Reserve SR 26-2 (model-risk supervisory guidance, not binding regulation; supersedes SR 11-7 · entry at /blog/sr-11-7-model-risk), FCA Consumer Duty Principle 12 (UK retail conduct · entry at /blog/fca-consumer-duty-principle-12), the RBI FREE-AI Committee Report of 13 August 2025 (a committee report, not binding regulation), SEBI Retail Algo, and India DPDP (substantive obligations commence 14 May 2027).

The bookshelf is what an AIGP holder reads against in practice. Of the fourteen instruments on the list, six are the binding-regulation tier across jurisdictions: EU AI Act, GDPR, NYDFS Part 500, FCA Consumer Duty Principle 12, SEBI Retail Algo and India DPDP, the last of these enacted but not commencing its substantive obligations until 14 May 2027. Two are neither binding regulation nor a Tier 1 or Tier 2 text — SR 26-2, which is supervisory guidance, and the RBI FREE-AI Committee Report, which is a committee report. The remaining six are the soft-law and standards tiers read above. The Warrant blog index at /blog carries a per-item entry for each of the binding instruments where one exists. The OECD definition of an AI system is the connective tissue that lets a system inventory be read against any of the tiers.

"the OECD principles supply the values, ISO 24028 supplies the vocabulary, AIGP supplies the practitioner. the binding regulator reads the records the practitioner produces, in the vocabulary the standards mandate, in service of the values the principles set." Synthesis · Warrant Compliance · 2026-05-09
11 · CLOSING · WHAT WARRANT EVIDENCES

Closing · what Warrant evidences.

soft-law tier coverage · per attestable action · in one document

What a Warrant evidence package carries today, on every attestable action, is a stage-3 authorization row and a stage-4 obligation row: authorizations[].justification holds the per-action rationale the OECD transparency principle asks for, obligations.<action_id>[].id and coverage_by_regime hold the regulator mapping the AIGP laws-and-standards domain asks for, and trace_metadata binds the whole verdict to the corpus digest it was judged against. The remaining four fields in the synthesis table — the named accountable owner, the eval-suite reference, the ISO 24028 § 8 threat-mitigation record and the life-cycle-phase tag — do not exist in the warrant-v1 schema. They are the target shape, and this entry does not claim them in the present tense.

A compliance officer presenting the package in a regulator meeting can speak to each field by reference to its source instrument. The same officer at an internal AI ethics review can point at the same fields and read the OECD principles into the record. The same officer preparing for AIGP renewal can point at the same fields and read the body-of-knowledge domains into the record. One artefact, three readings.

The synthesis is not novel. Every mature AI compliance practice converges on a small set of evidence fields covering values, vocabulary, and curriculum. The novelty in the Warrant package is that each field becomes independently verifiable without contacting Warrant, so that, when the audit lands two years after the action, the evidence reads as it read on the day. The full attestation rationale and four-layer architecture are at /blog/four-layer-evidence-stack.

The soft-law tier does not bind. The records the soft-law tier prescribes do bind, the moment a binding regulator opens an inquiry. Read the three references on the bookshelf, at the version that is current: OECD/LEGAL/0449 as revised 3 May 2024, ISO/IEC TR 24028:2020 read by its own clause numbers, and the AIGP body of knowledge v2.0.1 effective 3 February 2025. Build the seven fields into the trace. Make the result independently verifiable without contacting Warrant. The audit, when it comes, reads the document and closes the file.

12 · FAQ

Questions a compliance officer asks first.

FAQ · questions this entry answers on the record
Are the OECD AI Principles binding?

No. The OECD AI Principles are a non-binding recommendation, OECD/LEGAL/0449, adopted by the OECD Council in May 2019 and revised in May 2024. The OECD's own note on its legal instruments states that Recommendations "are not legally binding" and "represent a political commitment to the principles they contain". As of 6 August 2026 the adherence record for OECD/LEGAL/0449 lists 51 adherents, politically committed to implementing it but under no treaty obligation. They bind indirectly rather than by citation: the enacted text of Regulation (EU) 2024/1689 does not name the OECD anywhere, and NIST AI RMF 1.0 adapts the 2019 OECD definition of an AI system without adopting the principles. A regulator citing the principles in support of a domestic rule turns the soft-law text into the justification for hard-law enforcement.

What is the difference between ISO/IEC 24028 and ISO/IEC 42001?

ISO/IEC 24028:2020 is a Technical Report. It defines the trustworthiness vocabulary and, in clause 8, the vulnerabilities, threats and challenges taxonomy that downstream standards reuse; AI system life-cycle stages are not in 24028 at all, they are defined in ISO/IEC 22989:2022. It is not certifiable. ISO/IEC 42001:2023 is a management system standard. It defines the requirements an organisation must meet to operate an AI Management System and is certifiable by accredited bodies. 24028 supplies the words; 42001 sets the requirements an organisation evidences against those words. An auditor reading a 42001 conformance file will reach for 24028 to interpret what an Annex A control on transparency or robustness actually means.

Does the AIGP credential satisfy any specific regulator?

No regulator requires AIGP. The AIGP is a professional certification, awarded to individuals, signalling fluency across the AI governance body of knowledge. It is the AI-governance counterpart to CIPP for privacy. A regulator examining a covered entity will not ask for AIGP holders by name, but the certified individual is the person most likely to assemble the documentation, threat enumeration, and lifecycle evidence the regulator does ask for. AIGP is a proxy for governance maturity, not a compliance shield.

How are the OECD AI Principles cited in the EU AI Act?

It does not. As of the enacted text of Regulation (EU) 2024/1689, the OECD is not named anywhere in the Regulation. Recital 12 states only that the notion of an AI system "should be closely aligned with the work of international organisations working on AI". Article 3(1) tracks the OECD definition closely, adding that the system "is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment", and attributes it to nobody. NIST AI RMF 1.0, published January 2023, carries the pre-revision 2019 definition rather than the November 2023 one. The alignment is real at the level of the definition; the citation is not.

Why does ISO/IEC 24028 exist if 42001 is the certifiable standard?

Vocabulary precedes requirements. 24028 was published in May 2020, three and a half years before 42001 was published in December 2023. The standards committee chose to land the trustworthiness terminology first so the management system standard could reuse it without redefinition. 24028 enumerates the threat categories, the trustworthiness characteristics, and the stakeholder roles that 42001's Annex A controls reference. Reading 42001 without 24028 is reading a checklist without the dictionary.

Will an AIGP-certified team be enough for a real audit?

AIGP-certified individuals are necessary, not sufficient. The audit reads evidence, not credentials. The credential signals that the team can produce the evidence the audit asks for: the system inventory, the impact assessment, the threat-mitigation record per system, the lifecycle phase tagging per release, the regulator-mapping per decision. A team with AIGP holders and no underlying evidence pipeline will fail an audit no faster than a team with evidence and no credentials. The credential is the prerequisite; the evidence is the artefact.

13 · READ THE SOURCE

Read the source directly.