Compliance Controls
The controls assessed by AIControls span the following AI RMF categories.
Control categories
| Category | Examples of what AIControls assesses |
|---|---|
| Govern | Policy documentation, approval workflows, exception tracking, audit log retention |
| Map — Risk Identification | Identity attribution, tool classification, blast-radius tracking, anomaly detection coverage |
| Measure — Monitoring | Continuous audit logging, behavioral baselines, token spike detection, violation rate tracking |
| Measure — Content Safety | PII detection, prompt injection scanning, output filtering policies |
| Manage — Human Oversight | HITL approval rules for high-risk operations, auto-pause configuration, session review |
| Manage — Access Control | Identity-scoped budget rules, tool-level allow/deny policies, PAT scope restrictions |
| Manage — Incident Response | Alert routing, anomaly escalation, session pause capability, audit export for investigation |