CSA AICM v1.1: 247 control objectives across 18 domains

247 control objectives across 18 domains, spanning governance, data, model and runtime

From clause to evidenceThe chain from CSA AICM v1.1 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCSA AICMAICM v1.1Duty holderNot statedApplies fromNo dateVoluntaryArtefactControlcatalogue…LayersLayer 01Layer 03Layer 05Evidence recordEvidence recordv1Same topic in 28 frameworks (360 clauses): EU AI Act, ISO 42001, NIST AI RMF, TC260 Framework 3.0, ISO 23894, Korea AIAct, UK ATRS and 21 moreAs of 2026-09-19 · illustrative, not a claim of conformity From clause to evidenceThe chain from CSA AICM v1.1 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCSA AICM · AICM v1.1Duty holderNot statedApplies fromNo date · VoluntaryArtefactControl catalogue mapped…LayersLayer 01Layer 03Layer 05Evidence recordEvidence record v1Same topic in 28 frameworks (360 clauses):EU AI Act, ISO 42001, NIST AI RMF, TC260Framework 3.0, ISO 23894 and 23 moreAs of 2026-09-19illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-CSA-AICM. Drawn from chapter 08.
Text alternative
  • Clause: CSA AICM, AICM v1.1.
  • Duty holder: Not stated.
  • Applies from: No date, Voluntary.
  • Artefact: Control catalogue mapped….
  • Layers: Layer 01, Layer 03, Layer 05.
  • Evidence record: Evidence record v1.
  • Record schema: Evidence record.
  • The same topic in 28 other frameworks; the crosswalk section below links each clause.
Id
AIGE-OBL-CSA-AICM
Instrument
CSA AI Controls Matrix (AICM) v1.1 controls
Clause
AICM v1.1
Applies from
No date Voluntary · v1.1 published 2026-06-22

The artefact that evidences it

Control catalogue mapped to policy-as-code and evals; crosswalk to ISO 42001 / NIST AI RMF.

Patterns that build it

The same topic in other frameworks

From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.

Risk management

Governance and accountability

Data governance

Documentation and transparency

Human oversight

Runtime guardrails

Robustness, security and evaluations

Incident response and monitoring

Supply chain and third parties

Content provenance and deepfakes

Deployment, change and decommissioning

Open controls that evidence it

Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.

Source

Chapter 08, section CSA AICM and STAR for AI, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). CSA AICM v1.1: 247 control objectives across 18 domains (AIGE-OBL-CSA-AICM). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{CSA AICM v1.1: 247 control objectives across 18 domains (AIGE-OBL-CSA-AICM)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm},
  note         = {Version 0.5.0}
}