Moveworks
An employee-facing agent that resets passwords, files tickets and updates records through integrations.
What that means for the register
This week
Review the actions enabled and the identity they run under.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Agent Register.
Agents that execute without approval ISO 42001 A.6.2.6 · ISO 42001 A.9.4 · ISO 42001 A.6.2.8 · EU AI Act Art.14 · EU AI Act Art.26 · EU AI Act Art.12
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
ISO 42001 A.6.2.8 AI system event loggingEvent logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.
EU AI Act Art.14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
EU AI Act Art.12 Record-keeping (logs)High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...
Broad system reach or write access to a system of record ISO 42001 A.4.4 · ISO 42001 A.4.5 · ISO 42001 A.6.2.5 · ISO 42001 A.5.2 · EU AI Act Art.15 · EU AI Act Art.9
ISO 42001 A.4.4 Tooling resourcesThe organization shall document information about the tooling resources utilized for the AI system.
ISO 42001 A.4.5 System and computing resourcesThe organization shall document information about the system and computing resources utilized.
ISO 42001 A.6.2.5 AI system deploymentThe organization shall document a deployment plan and ensure requirements are met before deployment.
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
EU AI Act Art.15 Accuracy, robustness and cybersecurityHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against atte...
EU AI Act Art.9 Risk management systemProviders shall establish, implement, document and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and reasonably foreseeable risks, estimation/evaluation of r...
Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
ISO 42001 A.4.3 Data resourcesAs part of identifying resources, the organization shall document information about the data resources utilized for the AI system.
ISO 42001 A.7.3 Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO 42001 A.10.2 Allocating responsibilitiesEnsure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.
EU AI Act Art.10 Data and data governanceHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...
EU AI Act Art.25 Responsibilities along the AI value chainDistributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...
Do this for every tool your teams use
Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.
Build my agent register