ChaptersEventsBlog
Register for the Visibility is Velocity webinar on Oct 28 to learn how leading IT teams turn insights into real-time action.

Download Publication

AI Controls Matrix
AI Controls Matrix
Who it's for:
  • AI model providers
  • Orchestrated service providers
  • Infrastructure operators
  • Application developers
  • AI customers

AI Controls Matrix

Release Date: 07/09/2025

The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic framework for cloud-based AI systems. Organizations can use the AICM to develop, implement, and operate AI technologies in a secure and responsible manner. Developed by industry experts, the AICM builds on CSA’s Cloud Controls Matrix (CCM) and incorporates the latest AI security best practices.

The AICM contains 243 control objectives distributed across 18 security domains. It maps to leading standards, including ISO 42001, ISO 27001, NIST AI RMF 1.0, and BSI AIC4. The AICM is freely available to download (see 'Download the Resource' below).

What’s Included in this Download:
  • AI Controls Matrix: A spreadsheet of 243 control objectives analyzed by five critical pillars, including Control Type, Control Applicability and Ownership, Architectural Relevance, LLM Lifecycle Relevance, and Threat Category.
    • Mapping to the BSI AIC4 Catalog
    • Mapping to NIST AI 600-1 (2024)
    • Mapping to ISO 42001:2023
    • Implementation Guidelines
    • Auditing Guidelines
  • Consensus Assessment Initiative Questionnaire for AI (AI-CAIQ): A set of questions that map to the AICM. These questions can guide organizations in performing a self-assessment or an evaluation of third-party vendors.
  • Filling in the AI-CAIQ: Guidance on accurately completing the AI-CAIQ self-assessment, including ownership, evidence, and documentation rules.
  • STAR for AI Level 1 Submission Guide: Step-by-step instructions for submitting an AI-CAIQ self-assessment to the STAR Registry.
Related Resources:
  • Cloud Controls Matrix (CCM): A cybersecurity control framework for cloud computing. Both providers and customers can use the CCM as a tool for the systematic assessment of a cloud implementation.
  • AI Trustworthy Pledge: A pledge that organizations can sign to signal commitment to developing and supporting trustworthy AI.
  • STAR for AI Program: A CSA initiative to deliver an upcoming certification for organizations to demonstrate AI trustworthiness.
  • Trusted AI Safety Knowledge Certification Program: An upcoming training and certificate program by CSA and Northeastern University. It aims to help professionals manage AI risks, apply safety controls, and lead responsible AI adoption.
Download this Resource

Bookmark
Share
Related resources
AICM Implementation & Auditing Guidelines (Frameworks)
AICM Implementation & Auditing Guidelines (Fram...
Beyond the Hype: A Benchmark Study of AI Agents in the SOC
Beyond the Hype: A Benchmark Study of AI Agents...
Analyzing Log Data with AI Models to Meet Zero Trust Principles
Analyzing Log Data with AI Models to Meet Zero ...
The Reasoning Revolution: When Logs Finally Explain "Why"
The Reasoning Revolution: When Logs Finally Explain "Why"
Published: 10/22/2025
Introducing TAISE: The Trusted AI Safety Expert Certificate
Introducing TAISE: The Trusted AI Safety Expert Certificate
Published: 10/22/2025
How to Improve Risk Management with an Application Fabric
How to Improve Risk Management with an Application Fabric
Published: 10/21/2025
What to Know About the EU AI Code of Practice
What to Know About the EU AI Code of Practice
Published: 10/20/2025
Cloudbytes Webinar Series
Cloudbytes Webinar Series
January 1 | Virtual

Acknowledgements

Deepak Antiya
Deepak Antiya
Principal, Oracle

Deepak Antiya

Principal, Oracle

Anirudh Murali
Anirudh Murali
Principal Engineer

Anirudh Murali

Principal Engineer

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.

He has co-chaired...

Read more

Jan Gerst
Jan Gerst
Lead Cybersecurity Engineer SME, Charter

Jan Gerst

Lead Cybersecurity Engineer SME, Charter

MSMIT Cloud, MBA, MSMIT Cybersecurity
 
CSA CSP CCSK 
 
Cornell University - Technology Leadership | Business Management 
 
https://www.linkedin.com/in/jan-gerst-cybersecurity-professional

Read more

Alvin Chang
Alvin Chang
Founder & CEO, Good CISO

Alvin Chang

Founder & CEO, Good CISO

Visionary C-suite technology leader specializing in digital risk transformation for global organizations. Key highlights: • Secured 50+ regulated startups, FTSE100, and unicorns as vCISO and CTO. • Delivered talks at Cyber Security Symposium Africa; co-authored AI Control Matrix, shaping security standards. • Founder & CEO, Good CISO; vCISO at Lessonspace, driving robust, innovative frameworks. • Expert in C-suite co...

Read more

Ankit Sharma
Ankit Sharma
Security Officer, Compute BU, Cisco Systems India Pvt Ltd

Ankit Sharma

Security Officer, Compute BU, Cisco Systems India Pvt Ltd

Marina Bregkou
Marina Bregkou
Principal Research Analyst, Associate VP, CSA

Marina Bregkou

Principal Research Analyst, Associate VP, CSA

Ken Huang
Ken Huang
CEO & Chief AI Officer, DistributedApps.ai

Ken Huang

CEO & Chief AI Officer, DistributedApps.ai

Ken Huang is an acclaimed author of 8 books on AI and Web3. He is the Co-Chair of the AI Organizational Responsibility Working Group and AI Control Framework at the Cloud Security Alliance. Additionally, Huang serves as Chief AI Officer of DistributedApps.ai, which provides training and consulting services for Generative AI Security.

In addition, Huang contributed extensively to key initiatives in the space. He is a core contribut...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training