Download Publication

AICM Implementation & Auditing Guidelines (Frameworks)
Release Date: 10/22/2025
The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implementing and assessing the 243 controls of the AI Controls Matrix.
What’s Included in this Download:
- Implementation Guidelines: Defines practical, role-based recommendations for applying AICM controls to AI systems operating in cloud environments. Each control includes detailed implementation guidance tailored to the primary actors in the AI ecosystem: Model Providers (MPs), Application Providers (APs), Orchestrated Services Providers (OSPs), AI Customers (AICs), and Cloud Service Providers (CSPs).
- Auditing Guidelines: Complement these by providing structured auditing steps for internal or external auditors assessing organizations implementing the AI Controls Framework. It emphasizes role-specific accountability across the AI supply chain, ensuring consistent evaluation, clear expectations, and traceability across implementation and assurance activities.
These documents form a reference for practitioners, implementers, and auditors seeking to operationalize, evaluate, and strengthen governance, risk management, and compliance programs for AI systems in cloud environments.
Download the full AI Controls Matrix (AICM) here.
Download this Resource
Related Resources
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training

Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more