ChaptersEventsBlog
Join global cybersecurity leaders shaping the future of AI security! Share your insights on AI Safety in this Deloitte executive survey

AICM Auditing Guidelines

Updated: 08/04/2025

Open Until: 09/03/2025

AICM Auditing Guidelines
Auditing steps for each of the 243 controls of the AI Controls Matrix for internal or external auditors that are going to examine organizations implementing the AI Controls Framework. These auditing steps are not exhaustive or prescriptive by nature, rather than a generic guide through recommendations for assessment. The auditing guidelines will address the 5 actors of an AI system: Application Provider (AP) Model Provider (MP) Orchestrated Service Provider (OSP) AI Customer (AIC) Cloud Service Provider (CSP).
The AICM auditing guidelines emphasize role-specific accountability across the AI supply chain, requiring tailored evaluation for model providers, application developers, orchestrators, platforms, and customers. Key focus areas include AI-aware change management, structured exception handling, rollback readiness, and rigorous quality testing. 

The intent of this public peer review is to ensure the auditing gudelines are clear, scoped appropriately, and aligned with the control’s requirement to "include programs for all the relevant domains of the AICM", while avoiding overemphasis on AI specifics where they may not apply.
Please review the guidelines for:

  • Accuracy and completeness of control coverage

  • Appropriateness of AICM domain inclusion per actor

  • Clarity of expectations and implementation logic

  • Consistency in structure and tone across roles




Resource unavailable

Partner Event Spotlight

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.