ACF
acfstandard.io
Developer docs
FR
Mapping

ACF® × COBIT 2019

Mapping of the 17 ACF® cards to the COBIT 2019 governance and management objectives. This is the bridge between agentic governance and your organisation’s classical IT audit.

iNote
If your internal audit function runs on COBIT, ACF® plugs into it naturally: EDM-01 for the agentic charter, MEA-01 for the signed register, BAI-09 for the agent card, DSS-02 for the kill switch. No rewrite of the audit framework is needed — ACF® documents its artifacts in the vocabulary your auditors already use.

ISACA COBIT 2019 framework

COBIT 2019 — ISACA framework for the governance and management of enterprise IT. The reference for IT audit shops and internal audit functions. Articulates around domains: Evaluate-Direct-Monitor (EDM), Align-Plan-Organise (APO), Build-Acquire-Implement (BAI), Deliver-Service-Support (DSS), Monitor-Evaluate-Assess (MEA).

ACF® mapping → COBIT 2019

Each row below is an ACF® methodological card and the principal article of the standard it maps to. The mapping is deliberately conservative — when a card covers several articles, only the principal article is cited here. The full multi-standard view is on the matrix.

CardTitleCOBIT 2019
ACF-00Sovereignty ScoreEDM-01
ACF-01Decision MapEDM-03
ACF-02Criticality MatrixAPO-12
ACF-03Agentic ConstitutionEDM-01
ACF-04Agent CardBAI-09
ACF-05Supervision & GovernanceMEA-02
ACF-06Kill SwitchDSS-02
ACF-07First Agent DossierBAI-01
ACF-08Agentic Decision RegisterMEA-01
ACF-09Action & Improvement PlanBAI-08
ACF-1030-Day Governance AuditMEA-02 + MEA-03
ACF-11Agentic Risk AssessmentAPO-12
ACF-12Agent MandateAPO-05
ACF-13Guided Practical CaseBAI-05
ACF-14Teacher GuideAPO-07
ACF-15Governance SimulationBAI-06
ACF-16Accountability by DesignEDM-01