Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI Controls Matrix explained

AI Controls Matrix: 247 Essential CSA Controls and STAR for AI

The AI Controls Matrix — the AICM — is the Cloud Security Alliance’s control framework for cloud-based AI systems, and version 1.1, released on 22 June 2026, is the reference behind STAR for AI: 247 control objectives across 18 security domains, built on the Cloud Controls Matrix and mapped to ISO/IEC 42001:2023, ISO 27001, BSI’s AIC4 catalogue, the EU AI Act, NIST’s AI RMF and AI 600-1, and AIUC-1. It ships with an AI-CAIQ questionnaire, implementation and auditing guidelines split by role — model provider, orchestrated service provider, application provider, AI customer and cloud service provider — and a STAR for AI Level 1 submission guide.

Submit an AI-CAIQ and you hold STAR for AI Level 1; run it through Valid-AI-ted and pair it with an ISO/IEC 42001 certificate and, since 20 November 2025, you hold Level 2. This guide sets out what the AICM contains and how it is structured, the five pillars each control is analysed by, the role model that decides which controls are yours, the mappings and what they save, the STAR for AI levels, and how to use the matrix without treating it as a checklist.

AI Controls Matrix v1.1: structure, roles and the STAR for AI ladder
247 control objectives · 18 domains · 5 analysis pillars · roles: model provider, orchestrated service provider, application provider, AI customer, cloud service provider · mappings to ISO 42001, ISO 27001, AIC4, EU AI Act, NIST AI RMF/600-1, AIUC-1 · AI-CAIQ → STAR for AI Level 1; Valid-AI-ted + ISO 42001 → Level 2.

What the AI Controls Matrix is

CSA describes the AICM as “a first-of-its-kind vendor-agnostic framework for cloud-based AI systems” that organisations can use “to develop, implement, and operate AI technologies in a secure and responsible manner”. It builds on the CCM — the 17-domain cloud framework behind STAR — and adds the domain and controls AI needs. Version 1.1 contains 247 control objectives across 18 domains and is free to download.

Where the CCM asks which of two actors implements a control, the AICM asks which of five, because the AI supply chain is longer: the organisation that trains the model, the platform that orchestrates it, the application built on it, the customer using it, and the cloud that hosts it. Our guide to CSA STAR covers the programme the AICM feeds.

The five pillars of the AI Controls Matrix

CSA’s spreadsheet analyses each of the 247 objectives along five pillars, which it names as control type, control applicability and ownership, architectural relevance, LLM lifecycle relevance and threat category:

Pillar What it records (per CSA’s description of the spreadsheet) How to use it
Control type The type of each control objective, as classified in the matrix Check the balance of a domain’s control set
Control applicability and ownership Which of the five roles the control applies to and who owns its implementation The shared-responsibility engine — decides which controls are yours
Architectural relevance The parts of the AI system architecture the control is relevant to Scope by what you actually build and operate
LLM lifecycle relevance The stages of the large-language-model lifecycle the control touches Puts controls on a timeline rather than a list
Threat category The category of AI threat the control addresses Lets an AI risk assessment drive selection

The five roles

Role CSA’s description Typical organisation
Model provider (MP) Develops, trains and distributes foundational or fine-tuned models — the foundation layer of the AI stack Foundation-model labs; companies fine-tuning and distributing models
Orchestrated service provider (OSP) Provides AI platforms and orchestration layers that integrate and govern models in enterprise environments, responsible for controls mitigating LLM and generative-AI risks AI platform and agent-orchestration vendors
Application provider (AP) Builds end-user AI applications on models, accountable for controls within its own infrastructure and the products it offers SaaS products with AI features
AI customer (AIC) Consumes AI services, platforms or applications and is responsible for controls within its own organisation Every enterprise deploying AI
Cloud service provider (CSP) Delivers the cloud infrastructure that hosts AI systems and workloads Hyperscalers and hosting providers

CSA publishes separate implementation and auditing guidelines for each role, which is the practical way in: a SaaS company with an AI feature is an application provider and probably an AI customer of a model provider, and its control set is the union of those two roles’ applicable objectives, not all 247.

The mappings, and what they save

The AI Controls Matrix ships with mappings: version 1.1 includes crosswalks to ISO/IEC 42001:2023, BSI’s AIC4 catalogue, the EU AI Act, the AIUC-1 standard, and NIST’s AI RMF and AI 600-1 profile, alongside the CCM lineage to ISO 27001. For an organisation already running ISO 42001 the mapping is the reuse route — most AICM objectives are evidenced by the AI management system’s documented information — and for one facing the EU AI Act’s high-risk obligations, the mapping shows which controls serve which article. The mappings are CSA’s reading; treat them as a starting crosswalk to verify, as with any published mapping. Our guide to ISO 42001 certification covers the management-system side.

STAR for AI: the two levels the AI Controls Matrix supports

Level What it takes Registry listing
STAR for AI Level 1 Submit an AI-CAIQ self-assessment against the AICM AI CAIQ; or ValidAIted AI CAIQ where CSA’s AI tool scored it
STAR for AI Level 2 Since 20 November 2025: a Valid-AI-ted AI-CAIQ combined with an ISO/IEC 42001 certification; AI Attestation and AI Certification listings also exist ValidAIted + 42001; AI Certification; AI Attestation

On 19 September 2026 the STAR Registry showed around 60 AI-CAIQ listings and a handful of ISO/IEC 42001-based entries — early, but the filter exists and buyers are starting to use it. Our guide to Valid-AI-ted covers the scoring that turns a Level 1 AI-CAIQ into a Level 2 component.

Using the AI Controls Matrix without turning it into a checklist

  1. Decide your roles first. Most organisations hold two; the guidelines are written per role and the applicable set follows.
  2. Scope by architecture and lifecycle. Use the pillars to exclude controls for layers and stages you do not operate, and record why.
  3. Drive selection from threats. The threat-category pillar lets an AI risk assessment pick controls rather than the reverse.
  4. Reuse the management system. If ISO 42001 exists, map its documented information to the objectives before writing anything new.
  5. Answer the AI-CAIQ as evidence pointers, submit for Level 1, score it with Valid-AI-ted, and pair with ISO 42001 for Level 2.

Frequently asked questions

What is the AI Controls Matrix?
The Cloud Security Alliance’s vendor-agnostic control framework for cloud-based AI systems: 247 control objectives across 18 domains in version 1.1 (22 June 2026), built on the Cloud Controls Matrix, analysed by five pillars, allocated across five roles, and mapped to ISO/IEC 42001, ISO 27001, BSI AIC4, the EU AI Act, NIST AI RMF and AI 600-1, and AIUC-1. It is free to download.

What is the AI-CAIQ?
The questionnaire derived from the AICM, used for self-assessment or vendor evaluation and submitted to the STAR Registry for STAR for AI Level 1.

How do I get STAR for AI Level 2?
Since 20 November 2025, by combining a Valid-AI-ted AI-CAIQ with an ISO/IEC 42001 certification; AI Certification and AI Attestation listings also exist.

Do I need all 247 controls?
No. Applicability follows your roles — model provider, orchestrated service provider, application provider, AI customer, cloud service provider — and the architectural and lifecycle scope you operate.

How does it relate to ISO 42001?
ISO 42001 is the certifiable AI management system; the AICM is the control catalogue with a published mapping to it, and the pairing is what earns STAR for AI Level 2.

Where this leaves you

Treat the AI Controls Matrix as a scoped catalogue: pick your roles, cut the 247 objectives by architecture, lifecycle and threat, reuse the ISO 42001 management system for evidence, and answer the AI-CAIQ honestly. Level 1 is a submission; Level 2 is the AI-CAIQ scored plus the certificate — and the registry filter buyers will use is already there.

References

More on CSA STAR

The Program Charter and Roadmap, the Level Selection Decision, the SSRM Documentation and Matrix Workbook, the CCM crosswalks and the seventeen CCM domain documents the AICM builds on are in the CSA STAR Cloud Security Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.