sipi.bot · compliance
ISO 27001 compliance for AI agent spend
ISO 27001 Annex A.12 (Operations Security) and A.14 (System Acquisition) apply to autonomous agent spend. Every transaction must be governed by documented procedure and auditable.
What ISO 27001 requires for agent spend
ISO 27001:2022 A.12.1 requires documented procedures for operations. A.12.4 requires event logging. A.14.2 requires controls in automated processes. A spend firewall with documented per-transaction rules, tamper-evident audit log, and policy-version tracking satisfies these for the spend-control surface.
How sipi.bot maps to ISO 27001 controls
| Requirement | sipi.bot capability | Evidence |
|---|---|---|
| Documented policy gate | evaluate_spend in <5ms against rules | Policy version per decision |
| Immutable audit log | Tamper-evident decision log | Full JSON audit trail |
| Human escalation | FLAGGED → approval queue | Queue history with reviewer ID |
| Access control | Agent-key-scoped policies | Auth + authorization log |
Frequently asked questions
What does ISO 27001 require for agent spend?
A documented, enforced policy gate on every autonomous transaction, with an immutable audit trail and human escalation. sipi.bot evaluates every transaction against your rules in <5ms, logs the decision with policy version, and queues flagged transactions for human review.
Is sipi.bot certified for this?
sipi.bot is not a certifying body. It provides the technical controls — deterministic evaluation, audit logging, human escalation — that satisfy these governance requirements. Your auditor maps these to the framework criteria.
How do I produce audit evidence?
The sipi.bot audit log exports every decision (transaction, amount, merchant, rule triggers, verdict, policy version, timestamp) as structured JSON. This log is tamper-evident and can be fed into SOC 2, ISO 27001, or GDPR audit trails.