AICMv1.0.3 Auditing Guidelines for Application Providers (AP)
Released: 02/23/2026
Application Provider (AP):
Builds end-user AI applications that leverage models to deliver domain-specific functionality and user experiences, and is responsible and accountable for implementing controls within its own infrastructure and the services or products it develops and offers.
About the Resource:
This resource contains assessment guidelines tailored to AICM control specifications. It provides auditors with procedures and considerations for evaluating control implementation across GenAI service delivery layers, GenAI/LLM lifecycle phases, and AI-specific threat mitigation measures.
Builds end-user AI applications that leverage models to deliver domain-specific functionality and user experiences, and is responsible and accountable for implementing controls within its own infrastructure and the services or products it develops and offers.
About the Resource:
This resource contains assessment guidelines tailored to AICM control specifications. It provides auditors with procedures and considerations for evaluating control implementation across GenAI service delivery layers, GenAI/LLM lifecycle phases, and AI-specific threat mitigation measures.
Designed to support audits of AI-enabled applications, it helps determine whether AICM controls are effectively implemented at the application layer. The AP Auditing Guidelines align with the AI security domains of the AI Controls Matrix and are intended to support effective audit and assurance activities for GenAI/LLM systems and services. Given the rapidly evolving nature of GenAI technology and regulatory requirements, auditors should apply professional judgment and adapt assessment procedures to reflect current best practices and interpretations at the time of the audit.
Topics:
Download this Resource



