The AI Controls Matrix: 243 Control Objectives Across 18 Domains

Most organisations building AI governance are choosing between regulatory frameworks — the AI Act, NIST’s AI RMF, ISO 42001 — without realising there’s also a genuinely comprehensive, freely available technical controls catalogue purpose-built to sit underneath all of them. The Cloud Security Alliance’s AI Controls Matrix is the specification most AI governance conversations are missing, not because it’s obscure, but because it lives in security-practitioner circles that governance and compliance conversations don’t always reach.

I’ve written about crosswalking AI RMF, ISO 42001, and CSF generally. The AICM is the artefact that makes a genuine crosswalk considerably easier to build, because it was designed from the start to map to exactly those standards, rather than requiring an organisation to construct the mapping itself from scratch.

What the AICM actually contains

Published in its first version in July 2025, the AICM sets out 243 control objectives — since lightly revised upward in a subsequent point release — organised across 18 security domains, spanning both familiar territory like identity and access management and data security, and genuinely AI-specific domains like model security and AI supply-chain governance. Each control maps explicitly to external standards including ISO 42001, ISO 27001, NIST AI RMF, and Germany’s BSI AIC4 — precisely the crosswalk work I’ve written about generally, done once, by a neutral industry body, rather than needing to be reconstructed independently by every organisation building AI governance.

Free · 4 minutes

Would you survive contact with a determined attacker — or an auditor?

Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.

The matrix is structured around a shared-responsibility model recognising that AI security in practice spans several distinct roles — cloud service providers, model providers, orchestration-service providers, and application providers — each accountable for different controls depending on where in the AI stack they actually sit, which matters because most real AI deployments span more than one of these roles simultaneously, and a governance approach that doesn’t distinguish between them tends to produce gaps at exactly the boundaries between roles.

Why this is genuinely useful even without pursuing formal certification

The Cloud Security Alliance also offers a STAR for AI certification path built on the AICM, but the matrix itself is freely available and useful independent of any certification ambition — as a genuine gap-assessment tool, mapping an organisation’s current AI controls against a comprehensive, externally validated catalogue rather than reasoning from first principles about what controls an AI deployment might need. This connects directly to the AI system inventory discipline I’ve written about generally: the AICM gives an organisation a structured way to assess each inventoried system against a genuinely comprehensive control set, rather than an ad hoc list assembled internally under time pressure.

Where it fits alongside the regulatory frameworks

The AICM is deliberately a controls catalogue, not a regulatory framework — it doesn’t carry legal force the way the AI Act does, and it doesn’t replace the risk-management process structure the NIST AI RMF provides. What it offers is the specific, granular technical detail those higher-level frameworks describe only in general terms: not “manage AI risk” but the concrete control objectives that make managing it operationally real, which is precisely the gap between framework alignment and genuine implementation I’ve written about for runtime governance generally.

What one gap assessment actually found

A firm confident in its AI governance, having recently completed an ISO 42001 alignment exercise, ran its actual technical controls against the AICM’s full 18 domains as a genuine gap check. The exercise found solid coverage in the domains ISO 42001 emphasises heavily — governance, risk management process — and genuine gaps in the more technically specific domains the AICM covers in greater depth, including model supply-chain management and several identity-and-access-management controls specific to non-human, machine identities. The ISO alignment had been real. It simply hadn’t reached the operational depth the AICM’s more granular catalogue was built to surface.

Running a specific AI deployment’s controls against the AICM’s comprehensive catalogue — surfacing genuine gaps against an externally validated standard, not an internally assembled list — is exactly the kind of technical assessment a technology control assessment is built to perform.

The matrix is freely downloadable, which makes the barrier to running this exact comparison for any organisation’s own AI deployment considerably lower than most governance teams currently assume.

Running the comparison doesn’t require replacing an existing ISO 42001 or NIST AI RMF programme — it requires layering the AICM’s operational specificity on top of the governance structure already in place.

For GPAI providers specifically, the Code of Practice is the more immediately consequential document — see the Code of Practice’s enforcement timeline.

Most governance teams already have the higher-level framework alignment in place. The AICM comparison is the missing operational layer underneath it, not a competing programme to choose between.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming