Fieldwork from NexNith
Agents pathway

Assurance for AI agents

Nine modules for the governance, risk, audit, and security professionals who have been made responsible for AI agents. No certification is attached to this pathway, and none of it will appear on an exam.

The four advanced credentials in this field were developed against 2024 practice. Their published outlines address AI as models and systems, and none of them contains the word agent. The material below covers the work as it is carried out now. Where a topic is adjacent to a published subtopic, the mapping is stated on the page.

Beyond the published outlines

Every module in this pathway is marked as sitting outside the published exam content. Three of its topics have no equivalent in any of the four outlines, five are adjacent to subtopics that name the topic but not the current practice, and one is broadly covered.

A candidate preparing for an examination should not study this pathway expecting it to be tested.

Available now
Module 0

AI agents: how they are built, and where the controls sitGuided

The definition and the autonomy and reach grid, the four components, the loop traced through one request, the harness, the six points at which a control can sit, and five risk categories with the business impact of each. No code, and no term used before it has been defined.
50 minutes
Foundations
Module 1

Assessing an AI agent: a guided engagementTwo renderings

A risk assessment of one AI agent at an imaginary credit union, from the first request to the register handed to a committee. The guided rendering takes one route through it, asking what you would request at each point before showing what the evidence returns, and covering reach, where each stated limit is enforced, agent-to-agent routes, identity binding, retrieval, and escalation. The unassisted rendering gives the same mandate with no guidance, and reports coverage, evidence quality, prioritization, and judgment.
25 min guided
30 to 45 unassisted
Briefs

Ten briefs behind Module 1Read

Each brief sets out one idea in full and stands on its own: the tool surface as the control boundary, what an agent can actually do, where a stated limit is enforced, identity binding on the tool call, retrieval as an authority surface, agent-to-agent handoffs, scoping, evidence, escalation, and configuration change. Each ends with check questions put against a real artifact.
5 to 8 minutes each
Standalone
In preparation
Module 2

Excessive agency and permission scoping

The committee holds the register and has asked what should be removed. Every restriction carries an operational cost, and the costs are specified.
Module 3

Untrusted input paths

Two hundred and six member summaries left the organization over nine days. Four entry points are plausible and one of them is real.
Module 4

Autonomy boundaries and human oversight

Handling time has risen and servicing wants the thresholds loosened. You set the numbers, and the numbers are played forward twelve months.
Module 5

Memory, state, and goal drift

Three complaints in a week, all from long conversations, and engineering cannot reproduce any of them.
Module 6

Multi-agent trust and the tool supply chain

The collections agent is calling a tool server that is not the organization’s, and nobody can say who operates it.
Module 7

Runtime governance and attributable evidence

The regulator has asked which members were affected. The logs are complete, well retained, and cannot answer the question.
Module 8

Continuous assurance as agents change

Nine configuration changes since the report, none of which reached the committee. Internal audit asks how often the work needs repeating.
Standing references
Reference

The AI agent risk landscapeFree

Every published AI agent risk taxonomy, from OWASP, NIST, MITRE, the Cloud Security Alliance, ISO, the Institute of Internal Auditors, and the EU AI Act, crosswalked into five categories with the business impact and the controls for each. Maintained and updated as these publications change.
Reference
Cite freely
Fieldwork is independent educational material produced by NexNith. It is not affiliated with, endorsed by, or connected to ISACA or the International Association of Privacy Professionals (IAPP). AAIA, AAISM, AAIR, CISA, CISM, and CRISC are trademarks of ISACA. AIGP and CIPT are trademarks of the IAPP. No examination content is reproduced. All material is original and aligned only to publicly published exam content outlines and bodies of knowledge. The material is free to use and will remain so.

© 2026 NexNith. Questions to support@nexnith.com.