Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
Application & DevSecAIOps Security. Answer for Globex.
Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 14/14 to answer.
Re-assessing Globex. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.
IAM
IAM-01Is there a documented identity & access policy covering the AI systems and the people and services that touch them?
IAM-05Is least privilege enforced for access to models, training data, and AI pipelines?
IAM-08Are access rights to AI systems reviewed on a tracked cadence, with exceptions managed?
Infrastructure Security and Resilience
I&S-03Is the network around your AI infrastructure segmented and secured?
I&S-04Are the hosts and OS running AI workloads hardened to a defined baseline?
I&S-06Are production and non-production AI environments segregated?
Data Security
DSP-04Is data flowing into and out of AI systems classified by sensitivity?
DSP-07Is data protection by design applied to AI data pipelines?
App Security
AIS-01Is there an application security policy covering AI-enabled apps and their interfaces?
AIS-05Is application security testing run against AI-enabled applications?
AIS-11Are security boundaries defined for AI agents: which tools they may call, what data they may reach, and where they may act?
AIS-03Are application security metrics tracked for AI-enabled applications in operation?
Governance
HRS-15Are the engineers using AI in this function trained on acceptable use and on verifying AI output before acting on it?
GRC-15Is there named human supervision for AI-assisted engineering work — someone accountable for reviewing what the AI changes?