All controls
20 controls across five categories.
Govern
Policy, roles, training and the risk management process. Ensures AI use in an organization has an owner and that a shared understanding of what is and isn't allowed exists and is understood within the organization.
Comply
The legal and regulatory obligations that follow directly from using AI: knowing which laws apply, marking AI-generated content, and the extra steps required around higher-risk uses.
Register
What AI is deployed, for what purpose, and how proportionate it is to the task. The register is what makes the rest of the framework possible to check in the first place.
Access
Access rights for AI systems themselves, not only for the people who use them. AI that acts with its own credentials or autonomously needs the same access discipline as any other account.
Track
How deployed AI actually performs once it's in use: effectiveness, internal feedback and errors, collected so the organization's understanding of AI risk and effectiveness is based on proven metrics.