AICMv1.0.3 Auditing Guidelines for Orchestrated Service Providers (OSP)
Released: 02/23/2026
Orchestrated Service Provider (OSP): Provides AI platforms and orchestration layers that integrate and govern models in enterprise environments, and is responsible for implementing controls to mitigate security, privacy, and compliance risks associated with LLM/genAI technologies.
About the Resource:
This resource contains assessment guidelines tailored to AICM control specifications. It provides auditors with procedures and considerations for evaluating control implementation across GenAI service delivery layers, GenAI/LLM lifecycle phases, and AI-specific threat mitigation measures.
It outlines how to assess AICM control implementation within AI orchestration platforms and management layers, supporting audits of monitoring practices, access management, workflow automation, model integration, and governance enforcement mechanisms. Given the rapidly evolving nature of GenAI technology and regulatory requirements, auditors should apply professional judgment and adapt assessment procedures to reflect current best practices and interpretations at the time of the audit.
Topics:
Download this Resource



