Governance & Compliance · Data artifact

AI Control Catalog

Data artifactGovernance & ComplianceSafety, Security & Governancearc:AIControlCatalog

A catalog of technical and organizational AI controls grouped by category (governance, data, bias and fairness, transparency, risk management, monitoring, incident management, human oversight) with applicability by risk tier.

Responsibility. Lists the controls the organization can select to treat AI risks.

Also known as: Annex A controls, Control library

is read bysends data tois audited byControl Effectiveness Evaluator: is read byControl Effectiveness Ev…Risk Treatment Plan: sends data toRisk Treatment PlanInternal Auditor: is audited byInternal Auditor
Direct neighbourhood (hover for relationship types)

Relationships

is read by dependency

sends data to dynamic

is audited by assurance

Design guidance

Classification

Patterns
Select stage of staged NIST AI RMF implementation
Quality attributes
Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)Transparency and accountability (NIST AI RMF: accountable and transparent)
Risks mitigated
Ad-hoc, inconsistent controls across systems
Frameworks & regulations
ISO/IEC 42001 Annex ANIST AI RMF: MANAGEISO 27001ISO 27701

Sources

  1. Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.