The Cloud Security Alliance's AI Controls Matrix (AICM) is a vendor-agnostic set of control objectives for AI systems, built as an extension of CSA's existing Cloud Controls Matrix. As of the version CSA has published in 2026, it organizes 247 control objectives across 18 security domains, and it maps directly to ISO/IEC 42001, NIST AI 600-1, and Germany's BSI AIC4 catalogue. This post covers what the matrix contains, how it relates to those other frameworks, and where it is actually useful — mainly as a shared reference for vendor due diligence and internal control mapping, not as a replacement for a management-system standard or a legal compliance obligation.
What the AICM is, and where it came from
The AICM did not start from a blank page. CSA built it as an extension of the Cloud Controls Matrix (CCM), the cloud-security controls framework CSA has maintained for years and that many organizations already use for cloud vendor assessments. Extending the CCM into AI meant CSA could reuse a control-mapping structure security teams were already familiar with, rather than introducing an entirely new taxonomy.
The AICM's scope covers the AI lifecycle broadly: development (how systems are built and trained), implementation (how they are deployed and integrated), and operation (how they are run and monitored). This breadth is what distinguishes it from narrower frameworks focused on a single phase — a model-security checklist, for instance, or a data-governance policy alone.
How the matrix is structured
The version of the AICM published in 2026 groups its control objectives into 18 security domains, covering areas such as governance, risk management, data governance, model lifecycle, third-party and supply-chain risk, and incident response, extended with AI-specific additions across those domains. The total control count has grown as the framework has matured — an earlier version listed 243 controls, and the count referenced above reflects the later, expanded version. If you are building a compliance program against the AICM, confirm the exact control count and domain list against CSA's own published matrix directly, since these frameworks version frequently and secondary summaries can lag the current release.
The practical unit you work with is the individual control objective — a specific, checkable statement (for example, whether training-data provenance is documented, or whether model outputs are monitored for drift) rather than a broad principle. That granularity is what makes the AICM usable as a direct input to a vendor questionnaire or an internal audit checklist, in a way that a higher-level framework is not.
How it maps to ISO 42001, NIST AI 600-1, and BSI AIC4
The AICM is explicitly built to cross-reference other AI governance frameworks rather than compete with them:
- ISO/IEC 42001 — the international AI management system standard. See ISO/IEC 42001 for AI management systems for what that standard requires directly; the AICM gives you control-level detail that can serve as evidence toward ISO 42001's Annex A controls.
- NIST AI 600-1 — the Generative AI Profile that extends the NIST AI Risk Management Framework. See NIST AI RMF for agents for the risk-management-process view; the AICM's controls give that process concrete, checkable implementation detail.
- BSI AIC4 — the German Federal Office for Information Security's AI cloud-service criteria catalogue, a regional counterpart with its own certification relevance for organizations operating in or selling into Germany.
This cross-mapping is the AICM's main practical value: it lets a compliance or security team maintain one detailed control set and produce evidence that satisfies multiple frameworks' higher-level requirements, instead of running separate control-implementation projects for each standard independently.
STAR for AI and the AI-CAIQ questionnaire
The AICM is the foundation for two things CSA runs on top of it. STAR for AI is CSA's registry and certification programme for AI systems, extending the existing CSA STAR programme that many cloud vendors already participate in for cloud-security assurance. AI-CAIQ (the AI Consensus Assessment Initiative Questionnaire) is the vendor-facing due-diligence questionnaire built from the AICM's control objectives — a standardized set of questions a buyer can send an AI vendor instead of writing a bespoke security questionnaire from scratch.
For a buyer evaluating AI vendors, this is the most immediately actionable piece: rather than building a custom AI vendor security questionnaire internally, or comparing an AI vendor's ad-hoc self-attestation against no common reference point, AI-CAIQ gives both sides a shared, control-mapped starting point. The AICM was named a 2026 CSO Awards winner on 10 March 2026, which is a reasonable signal that buyer-side adoption of this shared reference is growing rather than staying niche.
When the AICM is the right tool, versus ISO 42001 or NIST AI RMF
| Question you're asking | Best-fit framework |
|---|---|
| "What must our AI management system achieve to be certifiable?" | ISO/IEC 42001 |
| "How do we structure an ongoing AI risk-management process?" | NIST AI RMF / AI 600-1 |
| "What specific controls should we check for, or ask a vendor to attest to?" | CSA AI Controls Matrix (AICM) |
| "Which threats and adversary techniques should our red team model against?" | See MITRE ATLAS vs the OWASP Agentic AI Top 10 for that separate comparison |
These are not competing choices — a mature AI governance program typically uses ISO 42001 or NIST AI RMF as the structural backbone and the AICM as the detailed control checklist that produces evidence for that backbone, particularly during vendor assessment where a granular, checkable list is more useful than a high-level process description.
Using the AICM in a vendor evaluation
A practical way to use the AICM without adopting the full framework wholesale:
- Start from AI-CAIQ rather than the full 247-control matrix when evaluating a vendor — it is the vendor-facing subset designed for exactly this purpose.
- Cross-reference vendor answers against your own ISO 42001 or NIST AI RMF program, using the AICM's mapping to avoid asking the same question twice in different frameworks' language.
- Weight domains by relevance to what the vendor actually does — a model-hosting provider and an agent orchestration platform will surface different domains as material; not all 18 domains carry equal weight for every vendor type.
- Treat a completed AI-CAIQ as a starting point for verification, not a substitute for it — a self-attested questionnaire response is evidence to be checked, not proof on its own, the same discipline that applies to any vendor security questionnaire.
Our own AI governance platform RFP checklist covers the broader set of questions to ask when evaluating an AI governance vendor, and the AICM's control domains are a useful cross-reference when building that checklist out for AI-specific vendors specifically. For the AI-specific impact-assessment layer that sits alongside vendor control evaluation, see ISO/IEC 42005 explained and the broader AI governance pillar guide.
Praesidia is an AI agent security and governance control plane — agent identity and access, guardrails, audit evidence, and cost controls in one place — and the kind of evidence a control-mapped framework like the AICM asks for (access controls, audit logs, vendor and connection registries) is the category of output an agent governance platform is built to produce continuously rather than as a point-in-time attestation.
Common questions
Is the AICM a certification, like ISO 42001? Not on its own. The AICM is a controls framework and questionnaire foundation; STAR for AI is CSA's registry and certification programme built on top of it. ISO 42001 remains the internationally recognized management-system certification; the AICM is better understood as detailed evidence and a due-diligence tool that can support, rather than replace, that kind of certification.
Do we need to implement all 247 controls? No framework of this size expects universal, uniform implementation. Like ISO 42001's Annex A, the AICM is meant to be scoped to what is relevant to your organization's specific AI systems and risk profile, with exclusions justified rather than every control applied blindly.
How is the AICM different from NIST AI 600-1? NIST AI 600-1 describes risk categories and a risk-management process organized around governance, content provenance, testing, and incident disclosure. The AICM gives you specific, checkable control objectives you can map to that process or to a vendor questionnaire. They are complementary — many organizations use NIST's framework for structure and the AICM for control-level detail.
Who is AI-CAIQ actually for? Primarily buyers evaluating AI vendors and vendors responding to that due diligence. It standardizes the questions so a vendor is not answering a differently-worded bespoke questionnaire from every prospective customer, and so a buyer gets comparable answers across vendors being evaluated side by side.
Does the AICM cover AI agents specifically, or just AI systems generally? The AICM's control domains — third-party and supply-chain risk, model lifecycle, incident response, data governance, and others — apply to AI systems broadly, which includes agents. It does not currently offer an agent-specific control subset the way a framework like the OWASP Agentic AI Top 10 addresses agent-specific risk categories directly; for that framing, see the OWASP Agentic AI Top 10 guide.