ai · security · skills
← Assessments

What a finished pack can look like

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Govern · maturity coverage · 2 of 4

Your team adopted AI before you decided anything.

Security Governance, Risk & Assurance. Answer for Initech.

Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 26/26 to answer.

Re-assessing Initech. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.

Governance
GRC-01Is there an AI governance program with documented policies and procedures?
GRC-02Is there an AI risk management program feeding decisions, with named ownership?
GRC-03Are AI policies reviewed on a tracked cadence with metrics and exceptions managed?
HRS-15Are the analysts using AI in this function trained on acceptable use and on verifying AI output before acting on it?
GRC-15Is there named human supervision for AI-assisted assurance work — someone accountable for what the AI drafts?
App Security
AIS-01Is there an application security policy covering the AI-enabled apps your teams assure?
AIS-04Is there a secure development lifecycle (SDLC) for AI-enabled applications?
AIS-07Is application vulnerability remediation tracked to closure with metrics?
AI Supported Development and Supply Chain Security
TVM-01Is there a threat & vulnerability management policy covering AI components and their dependencies?
TVM-03Are vulnerabilities in AI components and their supply chain identified?
TVM-08Is remediation for AI-component vulnerabilities scheduled and tracked?
Privacy and Compliance
A&A-01Is there a written audit and assurance approach for your AI systems?

verify · Ask for the audit & assurance policy and whether AI is named in scope.

A&A-02Does someone independent of the AI work check that its controls actually hold?

verify · Ask who performed the last independent review and which AI areas it covered.

A&A-05Is there a managed process for planning AI audits and tracking findings to closure?

verify · Ask for the audit plan and the findings register with owners and due dates.

A&A-06When an AI audit finds a gap, is the fix owned and chased to done with status reported?

verify · Pull the corrective-action log from the last AI audit and check the close-out rate.

Risk & Provider Assessment & Management
STA-01Is there a written approach to the risk your AI suppliers and model providers bring?

verify · Ask for the supply-chain risk policy and whether AI/model providers are in scope.

STA-08Do you know every external AI service, model, and data source your systems depend on?

verify · Ask for the AI supply-chain inventory and when it was last reconciled.

STA-10Are the risks from your AI providers assessed and managed on an ongoing basis?

verify · Ask for the last provider risk assessment and its refresh trigger.

STA-13Do you verify your AI providers actually meet the security commitments they made?

verify · Ask for the provider attestations or audit reports you hold and their dates.

IPY-01Is there a written approach to avoiding lock-in to a single AI provider?

verify · Ask for the portability policy and whether AI/model providers are addressed.

IPY-03Could you move to a different AI model or provider without a rebuild?

verify · Ask how the app calls the model and what a provider swap would take.

IPY-04Can you get your data and prompts back out of an AI provider if you leave?

verify · Check the provider contract for data-return/portability terms and test an export.

Infrastructure Security and Resilience
BCR-01Is there a written plan for keeping AI services running through disruption?

verify · Ask for the business-continuity policy and whether AI services are in scope.

BCR-02Have you worked out what an AI outage or failure would actually cost the business?

verify · Ask for the impact analysis and the recovery targets for the AI services.

BCR-08Can you restore the data and configuration your AI depends on if it is lost?

verify · Ask for the last successful restore test of the AI data and configuration.

BCR-06Do you rehearse recovering an AI service before a real outage happens?

verify · Ask for the last continuity exercise and its findings.