Skip to content
Framework · Cloud Security Alliance 1.0

CSA AI CM

The Cloud Security Alliance's structured controls catalog for AI systems — covering data, model, governance, and deployment dimensions. The most prescriptive AI controls framework available.

243 Talarity controls mapped
Who it's for: Cloud-native AI providers and AI-using SaaS vendors selling to enterprise customers that include AI in their procurement security questionnaires.
Talarity coverage

Mapped, monitored, and audit-ready.

Every CSA AI CM control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

243
Talarity controls mapped

Talarity's pre-built control library covering CSA AI CM, with linked evidence, owners, and testing schedules.

Cross-maps to
NIST AI RMFISO 42001SOC 2ISO 27001

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • Training data classification and provenance
  • Model evaluation and red-team results
  • Prompt-injection and jailbreak testing logs
  • Fine-tuning and customer-data isolation records
  • AI vendor due-diligence questionnaires

Your CSA AI CM dashboard

Every completed CSA AI CM assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed CSA AI Controls Matrix assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

Customers send you the CAIQ-AI questionnaire and you're answering 200+ questions from scratch every time.

Talarity

CAIQ-AI ships as a Talarity assessment template. Answer once, reuse the responses across customer requests with framework-specific tweaks.

Pain

AI control evidence is a moving target — model updates change the controls in scope.

Talarity

Model lifecycle workflows trigger control reassessment on every significant update. Stale evidence is flagged before customers ever see it.

Pain

Mapping CSA AI CM to NIST AI RMF and ISO 42001 manually is a quarter-long project.

Talarity

Built-in cross-mappings between the major AI frameworks. Run CSA AI CM, satisfy NIST AI RMF and ISO 42001 controls automatically.

Pain

Red-team evaluations live in PDFs that age out the moment they're filed.

Talarity

Evaluation runs are first-class artifacts with metadata (model version, evaluator, test categories). Linked directly to controls; freshness tracked.

CSA AI CM — common questions

What is the CSA AI Controls Matrix?
It is a Cloud Security Alliance control framework for securing and governing artificial intelligence systems, published in the same tradition as the Cloud Controls Matrix. It sets out control objectives spanning the AI lifecycle — data, model development, deployment, monitoring and governance — so that AI-specific risks can be assessed with the same rigour as cloud infrastructure.
How does it relate to the Cloud Controls Matrix?
The CCM addresses cloud infrastructure and service controls; the AI Controls Matrix addresses risks specific to AI systems such as training data governance, model behaviour and misuse. Most organisations running AI on cloud infrastructure need both, and because they share CSA's structural conventions the two map together rather than competing.
Can it be used to assess AI vendors?
Yes, and that is one of its more immediate uses. The control objectives give a structured basis for asking AI suppliers concrete questions about data handling, model provenance, evaluation and monitoring, in place of unstructured questionnaires. It works alongside the AI-related questions increasingly appearing in general third-party assessments.
How does it fit with the EU AI Act and NIST AI RMF?
The AI Controls Matrix is control-level, the NIST AI RMF is a risk methodology, and the EU AI Act is binding law with risk-tiered obligations. They operate at different altitudes and are complementary: the RMF shapes how you reason about risk, the Act determines what you must do for a given system, and the matrix supplies concrete controls to implement and evidence.

Working with CSA AI CM

Step-by-step walkthroughs from the Talarity library.

Ready to ship CSA AI CM?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.