Compliance Assessment for Agentic Processes:
Evidence-Governed Promotion, Control Mapping, and Bounded Compliance Claims

Arslan Brömme

Abstract

Agentic processes increasingly combine AI agents, tools, persistent state, delegated authority, external systems, and human oversight. Their operation can generate large volumes of heterogeneous telemetry, security findings, audit records, testing results, and incident evidence, but neither volume nor technical success alone establishes compliance beyond the specific policy, control, and assessment scope actually evaluated.

This paper develops and specifies an evidence-governed assessment model for agentic processes. It addresses three research questions concerning claim-preserving control mapping, bounded compliance assessment, and selective promotion of high-volume observations into active governance workflows.

First, the model defines a claim-preserving specialization of established evidence-to-assessment practice for heterogeneous agentic evidence. Second, it defines an evidence-governed promotion chain that separates evidence preservation from workflow activation so that retained telemetry does not automatically become an active GRC object. Third, it places these semantics in an interoperable plan-do-check-act lifecycle that connects controlled testing, runtime monitoring, intrusion response, investigation-derived evidence, remediation, retesting, reassessment, and existing enterprise GRC platforms through a platform-neutral semantic interface.

The model uses five typed control-assessment states: Supported, Contradicted, Insufficient evidence, Unresolved, and Not applicable. It also specifies bounded exchange records and a worked approval-before-payment example.

The central claim boundary is that security and assurance evidence may support and, where an authorized assessment method defines a closed technical control objective and the required observation conditions are satisfied, may justify a bounded Supported or Contradicted control assessment. Such a result does not by itself establish broader legal, regulatory, or organizational compliance or non-compliance beyond the assessed scope.

The model is presented as a research design for subsequent controlled proof of concept evaluation. It does not provide legal advice, prescribe a proprietary GRC implementation, replace mandatory logging or retention obligations, or claim that technical conformance to selected controls establishes legal compliance.

Key concepts

  • Applicability context before evidence assessment
  • Requirement and control mapping
  • Explicit evidence requirements
  • Evidence producers and evidence qualification
  • Control assessment with bounded claims
  • Raw telemetry separated from qualified evidence
  • Insufficient evidence separated from non-compliance
  • Control satisfaction separated from legal compliance

Keywords

Agentic AI · AI Agents · Agentic Processes · Compliance Assessment · AI Governance · Cybersecurity · Control Mapping · Evidence Qualification · GRC · Multi-Agent Systems · Bounded Compliance Claims

Citation

Brömme, Arslan (2026). Compliance Assessment for Agentic Processes: Evidence-Governed Promotion, Control Mapping, and Bounded Compliance Claims. Version v0.9.0.14. Zenodo. DOI: 10.5281/zenodo.22858862.

BibTeX

@misc{broemme2026complianceassessment,
  author       = {Arslan Brömme},
  title        = {Compliance Assessment for Agentic Processes:
                  Evidence-Governed Promotion, Control Mapping, and Bounded Compliance Claims},
  year         = {2026},
  month        = sep,
  version      = {v0.9.0.14},
  publisher    = {Zenodo},
  doi          = {10.5281/zenodo.22858862},
  url          = {https://doi.org/10.5281/zenodo.22858862}
}