Governance & Compliance · Data artifact
AI Control Catalog
Data artifactGovernance & ComplianceSafety, Security & Governancearc:AIControlCatalog
A catalog of technical and organizational AI controls grouped by category (governance, data, bias and fairness, transparency, risk management, monitoring, incident management, human oversight) with applicability by risk tier.
Responsibility. Lists the controls the organization can select to treat AI risks.
Also known as: Annex A controls, Control library
Relationships
is read by dependency
sends data to dynamic
is audited by assurance
Design guidance
- SHOULD select controls per system based on risk category, feasibility, effectiveness and cost.
- SHOULD define success metrics for each selected control.
Classification
- Patterns
- Select stage of staged NIST AI RMF implementation
- Quality attributes
- Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Ad-hoc, inconsistent controls across systems
- Frameworks & regulations
- ISO/IEC 42001 Annex ANIST AI RMF: MANAGEISO 27001ISO 27701
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.