Consequence Governance does not replace management systems, risk frameworks, IAM or zero-trust controls. It adds a specific boundary question: may this exact proposed consequence become real now?
Crosswalk, not equivalence. The rows below identify complementary control concerns; they do not claim formal certification mappings.
| Existing control domain | Primary concern | Consequence Governance adds |
|---|---|---|
| ISO/IEC 42001-style AI management | Organizational AI management, policy, responsibility, risk and lifecycle controls | An executable consequence boundary that can apply those mandates and constraints immediately before effect |
| NIST AI RMF-style risk management | Govern, map, measure and manage AI risk | A deterministic runtime decision over the exact proposed consequential state transition |
| Zero Trust | Continuous verification of subjects, devices, sessions and access | Verification of the consequential action itself, not only the entity or access path |
| IAM / RBAC / ABAC | Identity, roles, attributes and resource access | Fresh consequence-specific authorization using current purpose, constraints, state and evidence |
| Agent governance | Agent identity, tools, permissions, behavior and orchestration | A worker-independent boundary that remains valid when the agent, model or runtime changes |
| Observability / audit logging | Record and inspect system behavior | Pre-effect control plus a receipt binding what was evaluated, decided, executed or refused |
Policy can define authority. IAM can identify subjects and rights. Risk systems can constrain operation. Agent controls can bound tools. None of those layers should be mistaken for the final authorization of the exact consequence. The Governed Effect Path composes those signals at consequence time.
Governed Effect Path · Execution Authorization Infrastructure · REHT quickstart