150 controls. 8 frameworks.
One AI risk environment.
Building an AI risk and control framework from scratch is slow, inconsistent, and difficult to defend. Most organisations do not know which controls apply to which AI systems, how those controls map to regulatory requirements, or what evidence an auditor would expect to see.
The AIVARA AI Control Library gives you a starting point that is already mapped. 150 controls across 13 domains, aligned to the EU AI Act, ISO 42001, NIST AI RMF, MAS FEAT, PDPA, IEEE, OECD, and the UK AI Code of Practice. CorpStage assigns those controls to your specific AI assets, structures the risk assessment, and builds treatment plans for every gap.
150 controls. 13 domains. 8 frameworks.
Every control is mapped across eight frameworks simultaneously so you can see regulatory coverage at a glance and identify gaps by framework or domain.
The 13 Control Domains
- 01. AI Governance and Accountability
- 02. Risk Management
- 03. Data Governance and Quality
- 04. Model Development and Validation
- 05. Transparency and Explainability
- 06. Human Oversight and Intervention
- 07. Security and Adversarial Robustness
- 08. Privacy and Data Protection
- 09. Fairness and Non-Discrimination
- 10. Environmental and Social Impact
- 11. Third-Party and Supply Chain AI
- 12. Incident Response and Monitoring
- 13. Audit, Assurance, and Compliance
The 8 Framework Mappings
- EU AI Act — Risk classification, conformity, documentation, and oversight obligations
- ISO 42001 — AI management system standard, Annex A controls
- NIST AI RMF — Govern, Map, Measure, Manage functions
- MAS FEAT — Fairness, Ethics, Accountability, and Transparency principles
- PDPA — Personal data protection obligations in AI contexts
- IEEE Ethically Aligned Design — Ethics by design principles
- OECD AI Principles — Responsible stewardship principles for trustworthy AI
- UK AI Code of Practice — Voluntary framework for responsible AI deployment
From AI asset inventory to tested control environment
AI Asset Inventory
Identify all AI systems. Classify each by risk tier, deployment context, data inputs, affected populations, and framework obligations. The foundation from which control assignment flows.
Control Assignment
Assign relevant controls from the 150-control library to each AI asset based on risk tier, domain relevance, and regulatory obligation. Not every control applies to every system.
Risk Assessment
Assess inherent risk for each AI asset across impact and likelihood. Score across the 13 control domains. Identify where inherent risk is highest before considering controls.
Control Gap Analysis
Assess current control implementation against assigned controls. Identify controls that are absent, partially implemented, or implemented but not evidenced. Score residual risk.
Treatment Planning
For each gap, define a treatment: implement, accept with rationale, transfer, or avoid by modifying the AI system or use case. Assign ownership and target dates.
Evidence and Testing Structure
Define what evidence each control requires, how it is collected, who maintains it, and how it will be tested in the assurance cycle. Without this, controls exist on paper but not in practice.
What the framework looks like in practice
AI Governance and Accountability
Defined AI governance policy. Board-approved AI risk appetite. Named AI system owners. Regular AI governance reporting to board or risk committee.
Data Governance and Quality
Data lineage documentation for training data. Data quality standards for AI inputs. Bias testing on training datasets. Data retention and deletion policies for AI-specific data.
Human Oversight and Intervention
Human review checkpoints defined for each high-risk AI system. Override mechanisms tested and documented. Escalation paths for AI output anomalies known to operators.
Transparency and Explainability
Disclosure to users when interacting with AI. Model cards or system cards for high-risk systems. Explainability requirements defined by use case and audience.
Security and Adversarial Robustness
Adversarial testing performed on deployed models. Input validation controls. Model access controls. Monitoring for unexpected model behaviour or output drift.
Third-Party and Supply Chain AI
AI vendor due diligence process. Contractual obligations for third-party AI providers on transparency, performance, and incident notification. Third-party systems in the asset register.
AIVARA Core 360 hosts, tracks, and evidences every control
Every control is assigned to an asset. Implementation status is tracked. Evidence is stored and linked. When a regulator, auditor, or board member asks whether a specific AI system has adequate controls, the answer is a system view showing the control, the evidence, the test result, and the owner.
Questions before you start
Why 150 controls? Is that too many for a mid-market organisation?
Not all 150 controls apply to every organisation or every AI system. Controls are assigned based on AI asset risk classification, regulatory obligations, and context. A mid-market company with limited AI deployment may implement 40 to 60 controls initially. The library gives you the complete set to draw from.
How does this map to ISO 42001?
ISO 42001 is an AI management system standard. The AIVARA control library maps to ISO 42001 Annex A controls so organisations can work toward ISO 42001 certification or alignment simultaneously with meeting regulatory requirements.
What is MAS FEAT and does it apply outside Singapore?
MAS FEAT stands for Fairness, Ethics, Accountability, and Transparency. It is issued by the Monetary Authority of Singapore as guidance for financial institutions using AI in Singapore. It applies directly to MAS-regulated institutions and is referenced by other APAC regulators as a relevant benchmark.
How often do controls need to be reviewed?
Control relevance should be reviewed when new AI systems are deployed, when existing systems are significantly modified, when regulatory requirements change, and as part of the annual AI governance review cycle.
Can this support ISO 42001 certification?
Yes. The control framework is designed with ISO 42001 alignment in mind. AIVARA Core 360 provides the documentation, evidence, and management system infrastructure that ISO 42001 certification requires.