Over the past weeks I completed an AI Governance Professional course that also covered agentic AI systems, and I turned the learnings into working as a governance professional for the Swiss and EU context (revDSG, GDPR, EU AI Act). The thing that carried the pivot is an ICM workspace. The factory (Layer 3) is a corpus with two shelves. One holds the legal texts: Swiss data protection law, the EU AI Act, GDPR, regulator soft law. The other holds the Responsible AI stack: NIST AI RMF, ISO/IEC 42001, the OECD AI Principles and Due Diligence Guidance, the Council of Europe HUDERIA methodology. Every folder carries a MANIFEST declaring source, date and license. On top of the corpus sits the layer I care most about, because it moves from citation to action. Cross-walks map the frameworks against each other in delta tables, for example ISO 42001 against the AI Act, or the OECD due diligence steps against the Swiss and EU legal stack. Mitigation playbooks take recurring constellations (cloud LLM with personal data, professional secrecy plus external AI, high-risk systems needing human oversight, the first 24 hours after a suspected breach) and translate the obligation into contractual, technical and organisational measures, with anti-patterns and escalation triggers. Templates chain into a full workflow: intake, triage, a lifecycle risk register along the NIST phases with a named owner for every risk, threat model and red team plan, then DSFA and FRIA where required. Everything ships in German and English, and every measure links back to the corpus anchor it operationalises. It bends the ICM shape in two places. Router instead of pipeline. A compliance practice has no single sequential flow, so my Layer 1 is a routing table: task type, then workflow contract, then which corpus files to load. Same layered context loading, different topology. Provenance as a hard rule. Every substantive claim the agent makes must cite a stable block anchor into the corpus (#^art21-abs3 resolves to Art. 21(3) Swiss DPA). Anything outside the corpus gets flagged as a knowledge gap to check externally. A /sync drift check compares the MANIFESTs against what actually sits on disk. In a field where one hallucinated citation can end a client relationship, this rule builds more trust than any disclaimer.