GRC

Governance, Risk and Compliance

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

15

Control objectives

97

Skills

12

Cross-cutting

—

Objectives fitted

AISMM maturity context

Governance · Foundational domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 8 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Governance Program Policy and ProceduresGRC-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Risk Management ProgramGRC-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 8 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Organizational Policy ReviewsGRC-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 6 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Policy Exception ProcessGRC-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 7 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Information Security ProgramGRC-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 7 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Governance Responsibility ModelGRC-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 7 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Information System Regulatory MappingGRC-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 7 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Special Interest GroupsGRC-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 6 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Acceptable Use of the AI ServiceGRC-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 4 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI Impact AssessmentGRC-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Bias and Fairness AssessmentGRC-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Ethics CommitteeGRC-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 4 steps
Application Provider — 4 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Explainability RequirementGRC-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Explainability EvaluationGRC-14

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Human supervisionGRC-15

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 6 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — GRC

Implementing GDPR Data Protection ControlsConducting A GDPR Data Protection Impact AssessmentBuilding An Executive Dashboard From ROPA DataIndia DPDP Act 2023 ObligationsSouth Africa POPIA ComplianceCPRA Sensitive Pi Limit Right ComplianceUS State Privacy Law Applicability TestAI Bias Special Category Data MitigationAI Inference Derived Data GDPR GovernancePia Methodology Selection Cross JurisdictionHealth Data DPIA Art9 Clinical ResearchPia Vendor Processor Art28 Due Diligence

Sample view. 12 of 97 skill names shown; the full list is available to the owner.