Consequence Governance crosswalk

Consequence Governance does not replace management systems, risk frameworks, IAM or zero-trust controls. It adds a specific boundary question: may this exact proposed consequence become real now?

Crosswalk, not equivalence. The rows below identify complementary control concerns; they do not claim formal certification mappings.

Where the category fits

Existing control domainPrimary concernConsequence Governance adds
ISO/IEC 42001-style AI managementOrganizational AI management, policy, responsibility, risk and lifecycle controlsAn executable consequence boundary that can apply those mandates and constraints immediately before effect
NIST AI RMF-style risk managementGovern, map, measure and manage AI riskA deterministic runtime decision over the exact proposed consequential state transition
Zero TrustContinuous verification of subjects, devices, sessions and accessVerification of the consequential action itself, not only the entity or access path
IAM / RBAC / ABACIdentity, roles, attributes and resource accessFresh consequence-specific authorization using current purpose, constraints, state and evidence
Agent governanceAgent identity, tools, permissions, behavior and orchestrationA worker-independent boundary that remains valid when the agent, model or runtime changes
Observability / audit loggingRecord and inspect system behaviorPre-effect control plus a receipt binding what was evaluated, decided, executed or refused

The separation to preserve

Policy can define authority. IAM can identify subjects and rights. Risk systems can constrain operation. Agent controls can bound tools. None of those layers should be mistaken for the final authorization of the exact consequence. The Governed Effect Path composes those signals at consequence time.

Governed Effect Path · Execution Authorization Infrastructure · REHT quickstart