Publication Peer Review

AICM Implementation Guidelines
Open Until: 08/06/2025
The Cloud Security Alliance (CSA) invites public peer review of its draft Implementation Guidelines of the AI Controls Matrix (AICM).
This initiative supports our ongoing commitment to harmonize AI security and governance frameworks, enabling organizations to better manage AI-specific risks across regulatory and industry-aligned standards.
The purpose of this document is to define a set of practical, role-based implementation guidelines for a core set of security, governance, and assurance controls applicable to AI systems operating in cloud environments. Each control includes detailed implementation guidance tailored to the AI systems' roles: Model Providers (MPs), Application Providers (APs), Orchestrated Services Providers (OSPs), and AI Customers (AICs), including the Cloud Service Providers (CSPs).
The purpose of this review is to validate the practicality and Real-World Relevance: To ensure the implementation guidelines are realistic, actionable, and reflect the operational realities faced by different actors (CSPs, MPs, APs, OSPs, AICs).
Contributors can:
- Identify areas where the guidance is too generic or lacks role-specific clarity
- Suggest refinements that reflect how responsibilities shift between providers and customers
About the Working Group
The AI Controls Framework Working Group at CSA has developed the AI Controls Matrix (AICM) to extend the widely adopted Cloud Controls Matrix (CCM) into the domain of AI. These implementation guidelines are recommendations suggested (not exhaustive) for the implementation of each of the 243 controls of the new AI Controls Matrix.
Contribute to Peer Review
Peer Review AgreementBy participating in this peer review, you acknowledge and agree to the following:
- Your name will be included as a reviewer only if you provide substantive feedback (e.g., content, clarity, accuracy). Feedback limited to grammar, syntax, or formatting will not qualify for acknowledgement.
- CSA's authors will have final descretion over which suggestions are incorporated into the document. Not all feedback will be implemented.
- You will not plagiarize or submit unmodified AI-generated text. If using AI-generated content, you must apply your expertise to refine, reformat, or integrate it meaningfully into the document.
Open Until: 08/06/2025