Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

CSA Official Press Release

Published 11/14/2024

Cloud Security Alliance Issues Comprehensive Guidelines for Auditing Artificial Intelligence (AI) Systems, Beyond Compliance

Cloud Security Alliance Issues Comprehensive Guidelines for Auditing Artificial Intelligence (AI) Systems, Beyond Compliance

Paper presents a holistic overview and applicable methodology for impartially assessing intelligent systems

SEATTLE Nov. 14, 2024 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released Artificial Intelligence (AI) Risk Management: Thinking Beyond Regulatory Boundaries. Drafted by CSA’s AI Governance & Compliance Working Group, the document offers a comprehensive framework for auditing AI systems, addressing the critical aspects of AI technology and providing auditors with much-needed insights and tools to ensure the reliability and responsible innovation of intelligent systems.

“The ubiquitousness of intelligent systems in today’s world requires that auditors are not only willing but able to assess these systems beyond simply ticking checkboxes,” said Ryan Gifford, Research Analyst, Cloud Security Alliance, and part of the AI Governance & Compliance Working Group leadership team. “While the need for accurate, purposeful, and results-based AI auditing is mission-critical, trust in AI can only be achieved through a far-reaching approach to auditing that goes beyond what’s required. It’s our hope that auditors can begin to address compliance proactively and thoroughly, utilizing the framework outlined in this document.”

Written as a follow up to AI Resilience: A Revolutionary Benchmarking Model for AI Safety, the guidelines are designed to be universally applicable across various industries, emphasizing privacy, security, and trustworthiness through a risk-based approach that focuses on critical and investigative thinking, curiosity, and the auditor’s ability to assess systems for unintended behavior.

Building upon existing AI audit best practices, the document takes an innovative approach as it spans the entire AI lifecycle — from development and deployment to monitoring and decommissioning — and includes sample questions to be covered during an audit or assessment. The document is structured to provide foundational knowledge on AI resilience, types of AI systems, and key concepts such as responsibility, accountability, and liability, with detailed sections on AI governance, applicable laws and standards, third-party supplier management, and infrastructure. By incorporating a holistic approach to AI auditing, the guidelines aim to mitigate risks, enhance transparency, and ensure that AI systems are not only compliant but truly trustworthy.

Download AI Risk Management: Thinking Beyond Regulatory Boundaries.

The AI Governance & Compliance Working Group aspires to be the industry’s cornerstone for establishing, advocating, and disseminating governance and compliance standards for artificial intelligence. The committee aims to shape policy, influence legislation, and create benchmarks that set the gold standard.Individuals interested in becoming involved in future research and initiatives are invited to join the working group.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Media Contacts
Kristina Rundquist
ZAG Communications for the CSA
[email protected]

Share this content on your favorite social network today!

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.

For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.