How to derive and manage AI controls from frameworks and assessments
A practical guide to what an AI governance control is, where controls come from and how to get them in place and keep them current by deriving them from enabled frameworks and the assessments you run.
How do you derive and manage AI controls from frameworks and assessments?
AI controls are the specific measures you put in place to keep the risks a framework names at an acceptable level. You do not have to assemble them by hand. You enable the frameworks that apply to your organisation, register your AI systems and run the assessments, and the control set falls out of what those frameworks require and what the assessments find. From there you assign owners and track what is actually in place.
This guide explains what a control is in an AI governance program, where controls come from and how you get them in place and keep them current. It is written for the person standing up the program, not chasing a date.
What a control is here
A control is a measure you put in place to manage a risk. In an AI governance program, controls are the doing layer. Above them sit the frameworks you have adopted, which describe what good governance looks like. Below them sits the evidence that a control is working. On their own, a framework tells you what to aim for and an assessment tells you where you stand. A control is the thing you actually do about it.
An adopted framework is a statement of intent and a register of your AI systems is a catalogue, and neither of those on its own manages a risk. Having a framework and a catalogue is not the same as governing what they describe. The controls are where the program stops describing and starts working, so getting them in place is the step that turns “we have adopted a framework” into “we have governance running”.
Where controls come from
Controls are derived, not drawn up from a blank page. Two inputs generate them.
The first is the frameworks you enable. Each framework sets out what it expects of an organisation running AI. ISO/IEC 42001, the AI management system standard, sets out a set of reference controls in Annex A, grouped by control objective, covering areas such as AI policies, roles and responsibilities, the AI system life cycle and data for AI systems. The NIST AI Risk Management Framework is organised around four functions, Govern, Map, Measure and Manage, each broken into categories and subcategories that describe outcomes to work towards. AI6 and NSW AIAF set their own expectations for Australian organisations. Enable a framework and its expectations become part of the picture Aicura works from.
The second is the assessments you run. An org-wide assessment looks at how your organisation governs AI as a whole. A per-system assessment looks at a single AI system, its purpose, its data, the decisions it affects and the risk it carries. The findings tell you which of a framework’s expectations actually apply to you and how far they reach.
Put together, the enabled frameworks say what is expected and the assessments say what is relevant. The controls are what you get when you hold those two against each other. Register a system and assess it, and the controls that system needs are generated for you.
Building controls by hand versus having them derived
Built by hand, this is slow and expensive work. An analyst reads through Annex A of ISO 42001, the NIST subcategories and each framework you have adopted, works out which expectations apply to each of your systems, writes a control for each one and tracks the lot in a spreadsheet. A consultant does the same on a day rate. Either way you are paying for someone to translate frameworks and assessment findings into a control set, one line at a time, and to redo the translation every time a system or a framework changes.
Aicura collapses that translation. The frameworks and the assessments are the input, and the controls are generated from them. The expertise that an analyst would apply by hand is already internalised in how the controls are derived, so you review a control set that is already drafted against your systems rather than building one from nothing. That is the difference between assembling controls and having them derived, and it is the reason the program comes together in a working week rather than a consulting engagement.
The controls are generated for review, not imposed. You read what has been derived, you decide what fits and you own the result. Aicura surfaces the picture so that the call remains with you.
How to get controls in place
-
Enable the frameworks that apply to you. Choose the frameworks your organisation governs against, such as AI6 and NSW AIAF for an Australian organisation, alongside ISO/IEC 42001 or the NIST AI RMF where they apply. The frameworks you enable set the expectations the controls are derived from.
-
Register your AI systems. Aicura is your AI Register. It holds the AI systems in use as the record, versioned as systems change, so the register reflects what you actually run. A control set is only as complete as the register it is drawn against, so this is the foundation.
-
Run the assessments. Run the org-wide assessment to establish how your organisation governs AI as a whole, then run a per-system assessment for each registered system. The assessments establish what each system is, what it affects and the risk it carries.
-
Review the derived controls. With the frameworks enabled and the assessments run, Aicura derives the control set from both and presents it for review. Read what has been generated against each system, keep what fits and set aside what does not apply.
-
Assign an owner to each control. A control without an owner does not get done. Assign each control to the person or team accountable for it, so the program has names against measures rather than a list on a page.
-
Track what is in place and keep it current. Track the status of each control so you can see, at any point, what is in place and what is outstanding. As you register new systems, run new assessments or enable new frameworks, Aicura prompts and versions the picture so the controls move with your real usage rather than drifting out of date.
Tracking what is in place
A control set is not a one-off deliverable. Systems change, new AI comes into use, assessments are re-run and frameworks are updated. The value of tracking controls in one place is that the state of the program is legible at a glance. You can see which controls are in place, which are outstanding and who owns each one, without reconstructing it from a spreadsheet each quarter.
This is where an AI governance program earns the word “program” rather than “project”. The controls are not set once and filed. They are the standing picture of how your AI footprint is governed, kept current as that footprint grows. Aicura versions that picture so you can see how it has changed over time and what prompted each change.
The boundary
Aicura supports the work. It does not do the deciding, and it does not certify. It derives the controls and surfaces the picture for you, and where something needs attention it prompts you to look. Whether a control is adequate, whether a system’s risk is acceptable and whether the program is where it needs to be are calls for you and the accountable business owner to make. Aicura does not issue a compliance verdict, produce a score or stand in for professional advice. It gives you a clear, current view so the people accountable can decide well.
Where the frameworks say it
This guide is downstream of the frameworks themselves. For the source expectations, go to the primary documents.
- ISO/IEC 42001:2023 (Information technology, Artificial intelligence, Management system) and its Annex A reference controls, published by the International Organization for Standardization.
- The NIST AI Risk Management Framework (AI RMF 1.0), published by the US National Institute of Standards and Technology.
- The AI6 and NSW AIAF framework pages on aicura.com.au, for the frameworks Aicura supports for Australian organisations.
A note on this page. This is general guidance on how to derive and manage AI controls, not legal, audit or certification advice. It does not tell you whether your organisation meets any framework or obligation. The frameworks are the authority on what they require, and the decision on whether your program is adequate rests with your organisation and its advisers.
Related guides
Do this work in Aicura
Aicura is your AI Register, and Essentials runs the risk assessments, the risk register, the derived controls and the governance policies on top of it, with the privacy disclosure work included. It is guidance to help you do the work, not certification or legal advice.