CISO ACCOUNTABILITY
Where the line fallsbetween you and the provider.
The core AI security controls, read from the AI Customer's chair. Given how your organisation consumes AI — building and running it, or procuring a third-party — which controls sit on your side of the Shared Security Responsibility Model (SSRM)?
Our authored read of the SSRM, scoped to the core set — a navigation affordance, not a measured claim.
Our authored read of the SSRM, scoped to the core set — a navigation affordance, not a measured claim. Ownership and posture tags reflect our judgment of the AI-Customer obligation under the Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0 Shared Security Responsibility Model. Self-assessed, never certified.
Board view · two parties
Your side. Their side.
Two-party rollup for the board: every AI Controls Matrix (AICM) domain sits on your (Deployer) side or your provider's. The four-role view above (Cloud Service Provider (CSP) / Application Provider (AP) / Model Provider (MP) / Orchestrated Services Provider (OSP)) stays canonical for the practitioner judgment; same data, different altitude.
Typical case · 10 domains on the deployer side · 8 domains on the provider side · specific control objectives can sit on either side per their facts.
| Domain | Typical owner | Why |
|---|---|---|
| IAM · Identity & Access Management | Deployer (you, the AI Customer) | Deployer owns its own identity directory + access decisions. Provider supplies IAM hooks; deployer wires them. |
| AIS · AI System Security | Deployer (you, the AI Customer) | Deployer owns secure-SDLC for AI apps it builds. Flips to Provider if the deployer only consumes the AI as a service. |
| MDS · Model Security | Provider (CSP / AP / MP / OSP) | Provider trains + serves the model. Deployer owns model-fitting + guardrails on its own data. |
| DSP · Data Security & Privacy | Deployer (you, the AI Customer) | Deployer owns the data classification + lawful basis. Provider provides encryption + isolation. |
| CEK · Cryptography, Encryption & Key Mgmt | Provider (CSP / AP / MP / OSP) | Provider operates the key-management substrate. Deployer owns key policy + BYOK decisions. |
| I&S · Infrastructure Security | Provider (CSP / AP / MP / OSP) | Provider operates the network + host substrate. Deployer owns east-west policy at its edge. |
| DCS · Datacenter Security | Provider (CSP / AP / MP / OSP) | Provider operates the physical datacenters. Deployer never sees this control surface. |
| UEM · Endpoint & Workload Security | Deployer (you, the AI Customer) | Deployer owns its endpoints + the workloads it places on the provider. Provider supplies the substrate. |
| CCC · Change & Config (cloud) | Provider (CSP / AP / MP / OSP) | Provider owns the cloud-platform change cadence. Deployer owns its own deploy-time change controls. |
| LOG · Logging & Monitoring | Deployer (you, the AI Customer) | Deployer owns its SIEM + the SOC. Provider supplies log feeds; deployer integrates them. |
| SEF · Security Incident Mgmt | Deployer (you, the AI Customer) | Deployer owns its own incident response. Provider escalates platform-side incidents. |
| TVM · Threat & Vuln Mgmt | Deployer (you, the AI Customer) | Deployer prioritises + remediates its own backlog. Provider patches its own substrate. |
| GRC · Governance, Risk & Compliance | Deployer (you, the AI Customer) | Deployer always owns its policy + risk-management program. Provider offers attestations. |
| A&A · Audit & Assurance | Deployer (you, the AI Customer) | Deployer is the audited party. Provider responds to questionnaires + supplies SOC reports. |
| STA · Supply Chain Transparency | Provider (CSP / AP / MP / OSP) | Provider documents its own sub-processors + supply chain. Deployer owns its vendor-risk program. |
| BCR · Business Continuity & Resilience | Provider (CSP / AP / MP / OSP) | Provider operates the resilient substrate. Deployer owns business-continuity at the application altitude. |
| IPY · Interoperability & Portability | Provider (CSP / AP / MP / OSP) | Provider supplies export + migration interfaces. Deployer owns its own exit strategy. |
| HRS · Human Resources Security | Deployer (you, the AI Customer) | Deployer owns its own staff training + EU AI Act Article 4 literacy duty. Provider trains its own staff. |
Owned, shared, inherited — then who reskills
Build what you own, coordinate what is shared, verify what the provider inherits. The assessment result page joins the same gaps to persona skill deltas with this split attached.