Controls Mapping

AI Risk to Control Framework Mapping

This maps AI-specific risks to controls across common frameworks.

AI RiskNIST AI RMFNIST CSF 2.0ISO 27001CIS Controls
Prompt InjectionMAP 1.5, MEASURE 2.6PR.DS, DE.CMA.8.25, A.8.26CIS 16 (App Security)
Data PoisoningMAP 3.4, GOVERN 1.4PR.DS, PR.IPA.5.21, A.8.9CIS 2 (Software Assets)
Model ExtractionMAP 1.1, MANAGE 2.3PR.AC, PR.DSA.8.11, A.5.33CIS 3 (Data Protection)
Training Data LeakageGOVERN 6.1, MAP 5.1PR.DS, PR.IPA.5.34, A.8.11CIS 3 (Data Protection)
Shadow AIGOVERN 1.1, GOVERN 6.2ID.AM, PR.ACA.5.9, A.5.10CIS 1 (Inventory)
HallucinationMEASURE 2.5, MANAGE 3.1DE.CMA.8.25CIS 16 (App Security)
Third-Party Model RiskMAP 3.4, GOVERN 6.1ID.SCA.5.19-A.5.22CIS 15 (Service Provider)
Bias/DiscriminationMAP 2.3, MEASURE 2.11
Model DriftMEASURE 1.1, MANAGE 1.3DE.CMA.8.16CIS 8 (Audit Log)

Control Categories for AI

CategoryControls
PreventiveInput filtering, access control, data validation, supply chain verification
DetectiveOutput monitoring, anomaly detection, drift detection, audit logging
CorrectiveModel rollback, circuit breakers, human-in-the-loop override, incident response
CompensatingFallback models, disclaimer systems, rate limiting, multi-model consensus