ai · security · skills

Library / GRC

GRC

Governance, Risk and Compliance

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

15

Control objectives

97

Skills

12

Cross-cutting

Objectives fitted

AISMM maturity context

Governance · Foundational domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 8 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Governance Program Policy and ProceduresGRC-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider2 steps
Model Provider2 steps
Orchestrated Services Provider2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Risk Management ProgramGRC-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider8 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Organizational Policy ReviewsGRC-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation6 steps
Cloud Service Provider6 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Policy Exception ProcessGRC-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation6 steps
Cloud Service Provider7 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Information Security ProgramGRC-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider7 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Governance Responsibility ModelGRC-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider7 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Information System Regulatory MappingGRC-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider7 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Special Interest GroupsGRC-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider6 steps
Application Provider4 steps
Model Provider4 steps
Orchestrated Services Provider4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Acceptable Use of the AI ServiceGRC-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider5 steps
Model Provider4 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI Impact AssessmentGRC-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider5 steps
Model Provider5 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Bias and Fairness AssessmentGRC-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider5 steps
Model Provider5 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Ethics CommitteeGRC-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider4 steps
Application Provider4 steps
Model Provider5 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Explainability RequirementGRC-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider5 steps
Model Provider5 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Explainability EvaluationGRC-14

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation5 steps
Cloud Service Provider5 steps
Application Provider5 steps
Model Provider5 steps
Orchestrated Services Provider5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Human supervisionGRC-15

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation6 steps
Cloud Service Provider6 steps
Application Provider6 steps
Model Provider6 steps
Orchestrated Services Provider6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — GRC

Implementing GDPR Data Protection ControlsConducting A GDPR Data Protection Impact AssessmentBuilding An Executive Dashboard From ROPA DataIndia DPDP Act 2023 ObligationsSouth Africa POPIA ComplianceCPRA Sensitive Pi Limit Right ComplianceUS State Privacy Law Applicability TestAI Bias Special Category Data MitigationAI Inference Derived Data GDPR GovernancePia Methodology Selection Cross JurisdictionHealth Data DPIA Art9 Clinical ResearchPia Vendor Processor Art28 Due Diligence

Sample view. 12 of 97 skill names shown; the full list is available to the owner.