The AI control catalog
The 66 controls in four blocks, the standards anchoring them, and what was left out on purpose.
From 22 to 66
The block started with 22 controls derived from NIST AI RMF 1.0, all of them governance: policy, roles, inventory, compliance. Audited against the CSA AICM and ISO/IEC 42001, two gaps of different natures appeared.
Technical surface was missing. There was no control on separating instruction from data, guardrails, tool execution isolation, agent boundaries, model artifact integrity, or data poisoning — which is where the exploitable risk lives when assessing an AI supplier.
And the management system was missing. Clauses 4 to 10 of ISO 42001 require an AI management system — context, leadership, objectives, internal audit, management review. The catalog had the risk controls and not the system that holds them up.
Block | Controls | Anchor |
|---|---|---|
ARC01–22 | 22 | NIST AI RMF 1.0 |
ARC23–38 | 16 | CSA AICM — technical surface |
ARC39–47 | 9 | ISO/IEC 42001 Annex A |
ARC48–66 | 19 | ISO/IEC 42001 clauses 4–10 |
Final ISO 42001 coverage is 23 of 23 clauses and 36 of the 38 Annex A controls.
Two deliberate exclusions
Two Annex A controls are left out when the direction is assessing a supplier: AI system requirements specification and data preparation. They are internal to the supplier and produce weak evidence when requested from outside.
They are recorded as a gap with an explicit justification, not as a silent hole. And they return when the direction is self-assessment — a Statement of Applicability has to address all 38.
Why no single standard would do
Four controls anchor to the AI RMF and to nothing in ISO 42001: AI regulatory compliance, adversarial scenario, explainability, and rapid model deactivation. In the other direction, AI RMF 1.0 has no subcategory for adversarial threat — the AICM is what filled that gap.
It is the concrete argument against adopting a single framework: choosing one framework is choosing which part of the risk not to see.
A known limitation
At 66 controls the block stopped being homogeneous: 19 are management system, 16 are technical surface, and the rest split across transparency, training data, and supply chain. Asking all 66 of any supplier is not viable, and the 19 management-system ones only make sense for an organization that intends to run a formal AI program — not for a SaaS consuming a third-party API.
What is missing is a scope axis by role in the AI chain — API consumer, model operator, model provider — orthogonal to the criticality profile. It is recorded as an open methodology item.