All 20 Controls
Browse every control across all six lifecycle domains, with audit checklists and framework mappings.
DATA AI Data Controls
3 controls — Address the unique risks of data input, retention, and generation in AI systems, which often differ from standard data protection needs.
MODEL AI Model Controls
5 controls — Focus on securing the AI models themselves against adversarial attacks and ensuring output quality.
Adversarial Input Defense
Model Output Sanitization
Adversarial Query Restriction and Cost Governance
System Prompt Protection
AI Output Reliability and Hallucination Mitigation
APPLICATION AI Application Controls
4 controls — Govern the behavior of AI agents, user interfaces, and integrations.
AI Transparency and User Disclosure
Agent and Plugin Permission Governance
Agent Observability and Auditability
AI Supply Chain and Third-Party Component Security
ASSURANCE AI Assurance Controls
3 controls — Focus on testing and monitoring AI systems for vulnerabilities, anomalous behavior, and incident readiness.
GOVERNANCE AI Governance Controls
3 controls — Establish the policies and human oversight required for safe AI adoption across the organization.
INFRASTRUCTURE AI Infrastructure Controls
2 controls — Ensure the underlying AI assets and vendors are inventoried and managed securely.