AI Control Objectives

Control Implementation and Assurance

aiaudit.services is the public face of the AI Control Objectives workbench: put the control set into operation for DORA, NIS2, CRA, NIST, and national cyber catalogues, then evaluate, evidence, and sign that those controls work.

7
regulatory themes
Implement | Assure
controls and evidence
30-day
trial, then annual licence
How it works
  1. 1
    Select a theme
    DORA, NIS2, CRA, NIST CSF, NIST AI RMF, NCD, NCDN, or AI Control Objectives
  2. 2
    Implement controls
    Put AI Control Objectives into operation for that regulation or framework
  3. 3
    Assure and sign
    Evaluate effectiveness, attach evidence, and lock a signed report
  4. 4
    Download, trial, or procure
    Workbench installer, 30-day trial, or 365-day annual subscription
Lead product: AI Control Objectives
Themes

Regulatory and framework workbenches

Each theme applies AI Control Objectives in two modes: implementation (putting the controls into operation) and assurance (evaluating, evidencing, and signing that those controls work).

Lead product

AI Control Objectives

AIIA Software

Control implementation and assurance across legitimacy, accountability, auditability, security, transparency, fairness, and the related control set. This is the lead product for aiaudit.services.

Implementation

Decision rights, residual-risk appetite, human oversight, vendor and data controls, build guardrails, runbooks, and metrics.

Assurance

Independent review, test evidence, incident and continuity records, internal audit, and signed evidence packs.

DORA

Digital Operational Resilience Act: ICT risk, incidents, testing, third-party ICT, information sharing; AI Control Objectives applied to ICT/AI operations.

Implementation

Map AI Control Objectives onto DORA ICT risk, incident handling, resilience testing, and third-party ICT arrangements.

Assurance

Evaluate and evidence operational effectiveness; sign residual-risk and control conclusions for ICT/AI operations.

NIS2

Directive (EU) 2022/2555: governance, risk management, incident reporting, certification, information sharing.

Implementation

Operationalise AI Control Objectives for NIS2 governance, risk management, incident reporting, and certification duties.

Assurance

Independent review, incident evidence, and signed conformance records against the NIS2 control set.

CRA

Cyber Resilience Act (EU) 2024/2847: product classification, essential requirements, SBOM/vuln handling, conformity, reporting.

Implementation

Apply AI Control Objectives to product security, SBOM and vulnerability handling, and conformity tasks for AI-enabled products.

Assurance

Test evidence, conformity records, and signed reports for essential requirements.

NIST CSF

NIST Cybersecurity Framework 2.0.

Implementation

Embed AI Control Objectives in CSF 2.0 Govern, Identify, Protect, Detect, Respond, and Recover functions for AI systems.

Assurance

Control testing, evidence packs, and signed assessments against the CSF profile.

NIST AI RMF

NIST AI Risk Management Framework 1.0 (Govern, Map, Measure, Manage).

Implementation

Put AI Control Objectives into the Govern-Map-Measure-Manage cycle for each AI system.

Assurance

Design reviews, measurement evidence, and signed risk-management conclusions.

NCD

National cyber catalogue as delivered on the NCD workbench.

Implementation

Implement AI Control Objectives against the national cyber control catalogue.

Assurance

Evidence and sign national-catalogue conformance for in-scope AI systems.

NCDN

Combined national cyber and NIST AI catalogue as delivered on the NCDN workbench.

Implementation

Implement AI Control Objectives across the combined national and NIST AI catalogue.

Assurance

Cross-catalogue evidence packs and signed assurance reports.

Named AI Control Objectives

Compact view of the control set used for implementation and assurance. The full catalogue is on the catalogue page.

Legitimacy
Accountability
Auditability
Model output accuracy
Personal data protection
Security
Availability
Robustness
Transparency
Explainability
Fairness
Intervenability
Safety
Human rights
Risk management
Downloads

Workbench installers

Per-theme Setup executables. If an installer is not yet published at this path, request a trial and we will issue the current build.

Trial

30-day trial

Request a 30-day evaluation of a workbench. We will confirm access by email to the address you provide.

Request a trial

Delivered to info@aiaudit.services with subject Trial request.

Procurement

Annual subscription

365-day annual licence. Pricing is by quotation. Tell us the organisation, product, and seats; we will respond from info@aiaudit.services.

Request procurement

No online checkout on this host. We issue a quotation for a 365-day term.

Platform

One workbench for implementation and assurance

The AI Control Objectives workbench is the operating model: implement the control set for a chosen theme, then run assurance to evaluate, evidence, and sign the result. Related programmes (ISO, NIST, EU AI Act) sit on the same backbone.

Control implementation

Put AI Control Objectives into operation for the selected regulation or framework: decision rights, design, build guardrails, and runbooks.

Assurance executions

Snapshot the published control set against an AI system; capture scores, conclusions, and progress in one place.

Findings and recommendations

Structured findings linked to evidence, with recommendations that feed management response and follow-up.

Review, approve, and sign

Submit, review, approve or reject, then sign and lock, with independence guards and a post-sign freeze.

Reports and evidence packs

Export reports and JSON evidence packages for audit committees, regulators, and third-party review.

Plans and engagements

Assurance plans, scheduled engagements, multi-system assignment, and open execution from the engagement record.

Workflow

From control design to locked evidence

Designed for risk, compliance, and AI governance teams that need repeatable, defensible implementation and assurance.

Implement
Operate the controls

Apply AI Control Objectives to the chosen theme and AI systems.

Activate
Assurance snapshot

Freeze the published control set against the target AI system.

Fieldwork
Assess and document

Scores, findings, evidence links, and a progress meter.

Close
Sign and respond

Approve, sign, export packs; capture management responses.

Related programmes

ISO, NIST, and EU AI Act on the same backbone

AI Control Objectives remain the lead catalogue. ISO, NIST, and the EU AI Act are related assurance programmes you can run alongside the theme workbenches.

Full catalogue
Standards
  • ISO/IEC 5259 data quality | 25059 software quality
  • ISO/IEC 5339 applications | TS 8200 controllability
  • TR 24027 bias | TR 24028 trustworthiness | TR 5469 safety
  • TS 6254 explainability | 42105 human oversight
Regulation and risk
  • EU AI Act general assurance and GPAI governance
  • GDPR | DPIA | FRIA | breach notification
  • DORA | NIS2 | CRA and CRA maturity
  • NIST AI RMF | GenAI profile | CSF 2.0
AI practice
  • Agentic AI lifecycle and acquisition
  • Application controls | COSO GenAI controls
  • Computer vision evaluation (prEN 18281)
  • Deployer audit of provider | CSA AI controls
Evidence integrity

Defensible records for boards and auditors

Executions freeze the control set at activation. Workflow and signing protect the fieldwork record. Evidence attachments and exports support working-paper discipline.

  • AI system identity and traceability
  • Progress calculation and independence guards
  • Management response board for findings follow-up
  • Signed reports and JSON evidence packs
Typical deliverables
Implemented control set for the chosen theme
Completed assurance with scores and findings
Signed report + JSON evidence pack
Management responses and remediation trail

Ready to implement and assure AI Control Objectives?

Start with a 30-day trial of AI-IA software or a theme workbench, or request a 365-day quotation.

Start 30-day trial Request procurement
Contact

Contact us

Ask about demos, deployment, or how AI Control Objectives map to your audit plan.

Send a message

Form submissions are delivered to info@aiaudit.services.