Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 10/10 to answer.
Re-assessing Hooli. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.
Data Security
DSP-01Is there a written rule for how data used by AI is protected and kept private?
verify · Ask for the data security & privacy policy and check it addresses AI training and inference data.
DSP-04Is the data flowing into and out of your AI classified by how sensitive it is?
verify · Sample the data feeding a model and check whether each source carries a sensitivity label.
CEK-03Is sensitive AI data encrypted, both stored and in transit?
verify · Confirm encryption on the AI data stores and the channels carrying training/inference data.
DSP-07Is data protection built into how AI data pipelines are designed, not bolted on after?
verify · Review a recent pipeline design doc for protection controls decided up front.
DSP-08Are privacy protections (minimisation, purpose limits) applied by default to personal data the AI touches?
verify · Check whether personal data is minimised and purpose-limited before it reaches a model.
CEK-12Are the encryption keys protecting AI data rotated and managed on a defined schedule?
verify · Pull the key-management records: rotation dates and ownership for the AI data keys.
DSP-09Do you run a data protection impact assessment when AI processing could affect people’s privacy?
verify · Ask for the most recent impact assessment tied to an AI use case and its refresh date.
DSP-17Does the most sensitive data the AI handles get the strongest protection, verified by evidence?
verify · Take the highest-sensitivity data class and trace its controls end to end with evidence.
Governance
HRS-15Are the data security and privacy team trained on using AI safely and verifying its output?
verify · Ask for this team’s training record and whether it covers verifying AI output.
GRC-15Is there a named person accountable for reviewing how AI uses sensitive data?
verify · Get the name and the review cadence; confirm it is a real responsibility.