verifiedagents.ai
All posts

6 min readAI Agents · Cybersecurity

The Five Questions Your AI Agent Auditor Will Ask

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: Five AI Agent Audit Questions

TL;DR: Your auditor's AI agent review comes down to five questions: who is it, what is it doing, what is it using, where can it go, and what happens if it goes rogue. Answer those with evidence and you have both governance and an audit response. Two moves this week get you most of the way.

Last updated October 6, 2026. I rebuilt this piece from the ground up around the five questions and the evidence each one needs.

One tech security team found 600 AI agents running in its own systems last quarter. Security had approved almost none of them. The auditor's call is coming, and most CISOs can't answer the first question yet. I had this exact conversation with a Fortune 500 CISO at the RSAC Conference in April: three of his teams were running agents, and he couldn't name who owned any of them. He wasn't worried about a breach. He was worried about the phone call, an auditor first and then the board, with nothing ready but a list of things he didn't know.

Why are auditors suddenly asking about AI agents?

Because regulators started asking first. NIST's Center for AI Standards and Innovation launched the AI Agent Standards Initiative in February 2026, built around agent identity and authorization, and the public comment window closed April 2. That's a federal regulator drawing a line on the floor. Boards read those signals and route them to the audit committee, which routes them to you.

At the same time, real production proof arrived. Broadridge Financial took its AI agents live across trading and wealth management: 40 client rollouts, millions of transactions a month, agents that find problems and fix them on their own. The part under the headline counts more than the headline. Broadridge built a system that keeps each agent boxed into its job, with a full record of every action wired in from day one. Tight scope, clean data, complete trail. Autonomy is acceptable only when it's traceable. That's the new bar, and it's the bar your auditor will use.

What are the five questions your auditor will ask?

The Agentic Trust Framework, published by the Cloud Security Alliance in February 2026, reduces the audit to five questions. If you can't map your AI program to these five, you don't have an audit answer yet.

Question

Framework element

The evidence that passes

Who is it?

Identity Management

Each agent has its own identity tied to a named owner, a person, not a service account

What is it doing?

Behavioral Monitoring

A baseline of normal, and an alert when behavior shifts

What is it using?

Data Governance

Inputs and outputs checked every time, not one or the other

Where can it go?

Segmentation

A blast radius that stays small when one agent breaks

What if it goes rogue?

Incident Response

A kill switch that's been tested, with a path back to a clean state

Two quick self-tests. For behavior: pull the last 30 days of API calls for one agent, and if you can't draw a flat baseline, you don't know what normal is yet. For the kill switch: most don't work, because most teams have never run theirs. The build and the test are in how to build an AI agent kill switch, and the containment math is in AI agent blast radius.

How does Zero Trust fit the audit?

Zero Trust continuously verifies the connection: identity, device, posture, behavior. That's the right foundation, and your auditor will expect it. What it was never built to inspect is the meaning of what moves through a verified channel, so a prompt injection rides inside a fully trusted session. Agents also don't need to move laterally the way an attacker does, because the privileges were granted at provisioning. The lateral movement problem gets replaced by an over-privileged-at-rest problem.

So Zero Trust is necessary and not sufficient on its own. The Agentic Trust Framework extends it to what agents actually do: act on semantic intent, carry persistent memory, chain tools together. Verification has to happen at the action level, not just the connection level, and that's exactly where the five questions point.

What can you do before Friday?

  1. Pull the list.

    Name every AI agent running in your business right now. Not the approved list. The actual list. Ask IT and your business teams separately, and the difference between their answers tells you how big your shadow AI problem is.

  2. Assign owners.

    One accountable person per agent. Not the vendor, not the platform team. Someone on your team whose name you can say out loud.

A CISO at a regulated bank put the stakes plainly last month: most teams don't fear the agents doing nothing. They fear not being able to prove what the agents did. By Friday you can have a one-page list of every agent and the human accountable for each. That's the first thing an auditor asks for, and it's the answer most CISOs can't give yet.

Frequently asked questions

Who actually audits AI agents in 2026?

Internal audit, SOC 2 auditors, financial regulators, and sector-specific bodies in some industries. NIST's AI Agent Standards Initiative gives federal auditors a reference point. Most 2026 audits still ride on existing IT and access control audits, but the questions are now AI-specific.

Is shadow AI the same as shadow IT?

Same pattern, faster. Shadow IT took years to spread. Shadow AI moves in weeks, because anyone with a credit card can spin up an agent. The 600-agent discovery is the new baseline, not the outlier.

What's the difference between AI governance and AI compliance?

Governance is the system you run on yourself. What you prove to someone else is conformance, and the framework is built so the same five answers cover both. Answer the five questions with evidence and you have governance and an audit response at once.

How does the Agentic Trust Framework relate to NIST's initiative?

The framework is a CSA-published industry standard focused on agent-specific controls across its five elements. NIST's initiative is a federal effort that overlaps on identity and authorization. They work together: the framework is more operational, NIST is more foundational.

Key takeaways

  • The audit window opened between February and May 2026, when NIST's initiative and Broadridge's production proof arrived alongside the CSA framework.

  • The five audit questions map to the framework's five elements, from Identity Management through Incident Response.

  • Autonomy is acceptable only when it's traceable. Tight scope, clean data, complete trail.

  • Zero Trust verifies the connection. Agents need verification at the action level on top of it.

  • Two moves before Friday: pull the actual agent list, and put one human name on every agent.

Want to know how you'd score on all five questions before an auditor asks them? The free self assessment takes about ten minutes and shows you exactly where you'd stall.

Security teams have a playbook for a breach. Nobody handed them one for this, so the teams that write their own five answers this quarter will be the ones that take the auditor's call without flinching.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.