Resources

Security & trust

This pillar translates the CSA AI Controls Matrix for an organisation that uses AI services without building them. It separates what you must do yourself (policy, inventory, oversight, training) from what you must require and check with your providers.

General recommendations: the assessment selects those that match your situation and ranks them by priority.

AI acceptable use

The first risk is not technical: it is employees pasting a contract, a customer file or source code into a public assistant. A short policy, known to everyone, that says which tools are authorised, with which data, and what is done with the results, covers the essentials.

What we recommend

AI inventory

You cannot govern what you cannot see. A register of AI systems and uses — tool, provider, purpose, data processed, internal owner — is the foundation for everything else: AI Act compliance, cost control, incident response.

What we recommend

Data protection in AI use

What you send to an AI service may be stored, used to train the model, read by a subcontractor or hosted outside Europe. The issue is handled at three levels: what users are allowed to send, what you negotiate with the provider, and what you do with production data in projects.

What we recommend

Pre-deployment impact assessment

Before enabling an AI feature in business software or launching a project, a proportionate assessment (who it is for, what data, what risks of error, what obligations) avoids unpleasant surprises. The AI Act makes it mandatory for high-risk uses; the AICM recommends it for all.

What we recommend

Human oversight

When AI influences a decision about a person (candidate, customer, patient, student), someone must be able to understand, challenge and correct it. This is not only a requirement of the AI Act and the GDPR: it is what protects the organisation when the model gets it wrong.

What we recommend

Bias and fairness

A model that sorts CVs or scores customers can reproduce past discrimination without anyone intending it. The customer of the service bears the legal responsibility. So you need to ask the provider what it has tested, and check for yourself on your own cases.

What we recommend

Explainability and transparency

Being able to explain why the tool produced a given result is necessary to answer a customer, an employee, an auditor or a judge. The expected level of explanation must be defined in advance and required from the provider.

What we recommend

Governance and accountability

Someone must be accountable for AI in the organisation: deciding on requests, tracking risks, reporting to management. In an SME it is a designated lead; in a mid-sized company, a committee bringing together business units, IT, legal and HR.

What we recommend

AI literacy and training

Since February 2025, the AI Act has required staff who use AI systems to have a sufficient level of AI literacy. Beyond the obligation, it is the most cost-effective measure: a trained employee does not paste confidential data into a public tool and can spot a wrong answer.

What we recommend

AI supplier requirements

Most of the AICM's 247 controls are carried by your providers. Your role is to ask them the right questions before buying, obtain written commitments and check periodically. The CSA's STAR for AI registry publishes some providers' self-assessments (AI-CAIQ): it is a free and valuable source.

What we recommend

Identity, access and endpoints

AI services are applications like any other: named accounts, strong authentication, access removed when people leave, no uncontrolled browser extensions. These rules probably already exist in your organisation; the point is to apply them to AI tools too.

What we recommend

Logging and monitoring of AI use

For your own applications that integrate a model, you must be able to answer after the fact “who asked what, and what did the system reply”. This is the basis for investigating an incident, detecting misuse and proving human oversight.

What we recommend

Guardrails and AI application security

An application that connects a model to your data and your users is exposed to AI-specific attacks: prompt injection, data extraction through the model, bypassing of instructions. Technical guardrails and regular testing are needed.

What we recommend

Autonomous AI agents

An agent that sends emails, changes data or triggers payments needs explicit boundaries: what it is allowed to do, with which accounts, up to what amount, and what requires a human.

What we recommend

AI incidents and resilience

A data leak through an assistant, a wrong answer sent to a customer, a tool that changes behaviour overnight: these are incidents. They must be reported, handled and, for some uses, notified to the authorities.

What we recommend

Open models and in-house development

Hosting an open-source model or training one yourself shifts to you responsibilities normally carried by the provider: model provenance and licence, file integrity, data quality and relevance, version management.

What we recommend

Frameworks

Where does your organisation stand?

The assessment evaluates these points for your organisation and ranks the actions by priority. Free, about 15 minutes, no account needed.

The other pillars