ChaptersEventsBlog
Card testing is hitting revenue, not just fraud. What should payment companies do now? Register for this March 10 webinar →

AICM v1.0 Implementation Guidelines

Updated: 11/12/2025

Open Until: 08/06/2025

AICM v1.0 Implementation Guidelines
The Cloud Security Alliance (CSA) invites public peer review of its draft Implementation Guidelines of the AI Controls Matrix (AICM).

This initiative supports our ongoing commitment to harmonize AI security and governance frameworks, enabling organizations to better manage AI-specific risks across regulatory and industry-aligned standards.

The purpose of this document is to define a set of practical, role-based implementation guidelines for a core set of security, governance, and assurance controls applicable to AI systems operating in cloud environments. Each control includes detailed implementation guidance tailored to the AI systems' roles: Model Providers (MPs), Application Providers (APs), Orchestrated Services Providers (OSPs), and AI Customers (AICs), including the Cloud Service Providers (CSPs).

The purpose of this review is to validate the practicality and Real-World Relevance: To ensure the implementation guidelines are realistic, actionable, and reflect the operational realities faced by different actors (CSPs, MPs, APs, OSPs, AICs).

Contributors can:
  • Identify areas where the guidance is too generic or lacks role-specific clarity
  • Suggest refinements that reflect how responsibilities shift between providers and customers

About the Working Group

The AI Controls Framework Working Group at CSA has developed the AI Controls Matrix (AICM) to extend the widely adopted Cloud Controls Matrix (CCM) into the domain of AI. These implementation guidelines are recommendations suggested (not exhaustive) for the implementation of each of the 243 controls of the new AI Controls Matrix.

Download this Resource

Resource unavailable

Featured by CSA

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.