Skip to main content

Compliance Controls

Reference

The controls assessed by AIControls span the following AI RMF categories.

Control categories

CategoryExamples of what AIControls assesses
GovernPolicy documentation, approval workflows, exception tracking, audit log retention
Map — Risk IdentificationIdentity attribution, tool classification, blast-radius tracking, anomaly detection coverage
Measure — MonitoringContinuous audit logging, behavioral baselines, token spike detection, violation rate tracking
Measure — Content SafetyPII detection, prompt injection scanning, output filtering policies
Manage — Human OversightHITL approval rules for high-risk operations, auto-pause configuration, session review
Manage — Access ControlIdentity-scoped budget rules, tool-level allow/deny policies, PAT scope restrictions
Manage — Incident ResponseAlert routing, anomaly escalation, session pause capability, audit export for investigation

See also