AICMv1.0.3 Auditing Guidelines for Cloud Service Providers (CSP)
Released: 02/23/2026
Cloud Service Provider (CSP): Delivers the underlying cloud infrastructure that hosts and supports AI systems and workloads, and is responsible for designing, developing, implementing, and enforcing controls to mitigate security, privacy, and compliance risks in the cloud services they provide.
About the Resource:
This resource contains assessment guidelines tailored to AICM control specifications. It provides auditors with procedures and considerations for evaluating control implementation across GenAI service delivery layers, GenAI/LLM lifecycle phases, and AI-specific threat mitigation measures.
It outlines how to evaluate AICM control implementation within cloud environments hosting AI systems, supporting audits of infrastructure security, tenant isolation, logging, identity controls, and supply chain assurance mechanisms. Given the rapidly evolving nature of GenAI technology and regulatory requirements, auditors should apply professional judgment and adapt assessment procedures to reflect current best practices and interpretations at the time of the audit.
Topics:
Download this Resource



