Download Publication

Who it's for:
- AI model providers
- Orchestrated service providers
- Infrastructure operators
- Application developers
- AI customers
AI Controls Matrix
Release Date: 07/09/2025
Updated On: 07/16/2025
- AI Controls Matrix: A spreadsheet of 243 control objectives analyzed by five critical pillars, including Control Type, Control Applicability and Ownership, Architectural Relevance, LLM Lifecycle Relevance, and Threat Category.
- Consensus Assessment Initiative Questionnaire for AI (AI-CAIQ): A set of questions that map to the AICM. These questions can guide organizations in performing a self-assessment or an evaluation of third-party vendors.
- Mapping to the BSI AIC4 Catalog
- Mapping to NIST AI 600-1 (2024)
- Cloud Controls Matrix (CCM): A cybersecurity control framework for cloud computing. Both providers and customers can use the CCM as a tool for the systematic assessment of a cloud implementation.
- AI Trustworthy Pledge: A pledge that organizations can sign to signal commitment to developing and supporting trustworthy AI.
- STAR for AI Program: A CSA initiative to deliver an upcoming certification for organizations to demonstrate AI trustworthiness.
- Trusted AI Safety Knowledge Certification Program: An upcoming training and certificate program by CSA and Northeastern University. It aims to help professionals manage AI risks, apply safety controls, and lead responsible AI adoption.
Download this Resource
Acknowledgements

Ankit Sharma
Security Officer, Compute BU at Cisco Systems
Marina Bregkou
Principal Research Analyst, Associate VP

Ken Huang
CEO & Chief AI Officer, DistributedApps.ai
Ken Huang is an acclaimed author of 8 books on AI and Web3. He is the Co-Chair of the AI Organizational Responsibility Working Group and AI Control Framework at the Cloud Security Alliance. Additionally, Huang serves as Chief AI Officer of DistributedApps.ai, which provides training and consulting services for Generative AI Security.
In addition, Huang contributed extensively to key initiatives in the space. He is a core contribut...

Jan Gerst
Cybersecurity Subject Matter Expert, Charter Communications

Asif Jamal
Cloud Security Consultant, Jcloudit Service & Training Inc.
Interested in helping develop research with CSA?
Related Certificates & Training

Learn more