Cloud and AI control,
in one matrix.
Answer AI security questionnaires with a control set your cloud reviewers already know.
MDS · model development security — the domain AICM adds that ordinary cloud control has no equivalent for.
What the matrix asks you to control.
AICM extends the Cloud Controls Matrix to AI — 247 control objectives across 18 domains. These are the ones where AI needs controls cloud security alone doesn’t cover.
Model development security
The model itself as an asset — where it came from, who can touch it, what attacks it.
Data security and privacy
Training, tuning and inference data — tracked, retained on purpose, and not leaking.
Identity and access
Who and what can reach a model, its tools and the data behind it.
Logging and monitoring
Prompts, tool calls and responses recorded well enough to investigate an incident.
Supply chain
The models, datasets and services you didn’t build — assessed and tracked.
Governance and compliance
Ownership, policy and proof that each control is actually running.
How a control is qualified
Five pillars carried on every control objective.
Each objective is tagged along five axes — which is how one matrix can serve a cloud provider, a model provider and an app team at once.
Domains and pillars as published in AICM v1.1.
The matrix ships with mappings to ISO/IEC 42001, ISO/IEC 27001 and BSI AIC4, so one answer can serve several reviewers.
From matrix to practice.
AICM gives AI security a shared vocabulary. Using it means connecting those control objectives to the systems, owners and evidence behind each answer.
An answer is credible when it reflects a control that’s actually running.
A control domain is useful when you know which systems it reaches.
A claimed control becomes assurance when the evidence sits behind it.
Assurance stays true as models, data and services change.
From control objectives to live AI governance.
Strai8 connects AICM control objectives to the systems, owners, controls and evidence across your AI environment.
Discovery
Find the AI already in use.
Find every AI system before assurance begins — endpoints, apps, models, third-party services.
Control mapping
Connect domains to systems.
Map each control objective to the systems, owners and services it applies to.
Model security
Treat the model as an asset.
Track provenance, access and integrity for the models your systems actually run.
Evidence
Attach proof to the objective.
Store each proof against the control it answers, not inside a questionnaire response.
Monitoring
Keep answers current.
Get told when a change to a model or service makes an earlier answer stale.
Cross-mapping
Answer several reviewers at once.
Reuse the same evidence where AICM maps to ISO/IEC 42001, ISO/IEC 27001 and BSI AIC4.
Questions teams ask about the CSA AI Controls Matrix.
Answer AI security questions from the record.
Thirty minutes on your own estate: which control objectives carry evidence, and which do not.