Comply · Global standards & industry frameworks
CSA AI Controls Matrix
The Cloud Security Alliance AI Controls Matrix.
The CSA AI Controls Matrix (AICM) is a control framework from the Cloud Security Alliance for securing and governing AI systems. It provides a structured set of controls across domains — spanning governance, risk, security, data, and model management — to assess and strengthen AI assurance.
Who it applies to
Organizations that want a detailed, security-oriented control set for AI assurance.
Key obligations
- Implement AI security and governance controls by domain
- Assess AI systems against the control matrix
- Manage model and data risks with defined controls
- Evidence control effectiveness
How Maetra maps agents to CSA AICM
Maetra's control catalog maps agents to AICM-style controls, tracks evidence and gaps in Comply, and reinforces security controls at runtime through Secure.
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether CSA AICM is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove CSA AICM compliance with Maetra
Classify your AI agents once and Maetra maps them to CSA AICM and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.