AI Governance Solutions / AI Risk and Control Framework

150 controls. 8 frameworks.
One AI risk environment.

Building an AI risk and control framework from scratch is slow, inconsistent, and difficult to defend. Most organisations do not know which controls apply to which AI systems, how those controls map to regulatory requirements, or what evidence an auditor would expect to see.

The AIVARA AI Control Library gives you a starting point that is already mapped. 150 controls across 13 domains, aligned to the EU AI Act, ISO 42001, NIST AI RMF, MAS FEAT, PDPA, IEEE, OECD, and the UK AI Code of Practice. CorpStage assigns those controls to your specific AI assets, structures the risk assessment, and builds treatment plans for every gap.

Book AI Risk Framework SessionTry AIVARA Core 360 Free →
AI Control Library v1

150 controls. 13 domains. 8 frameworks.

Every control is mapped across eight frameworks simultaneously so you can see regulatory coverage at a glance and identify gaps by framework or domain.

The 13 Control Domains

  • 01. AI Governance and Accountability
  • 02. Risk Management
  • 03. Data Governance and Quality
  • 04. Model Development and Validation
  • 05. Transparency and Explainability
  • 06. Human Oversight and Intervention
  • 07. Security and Adversarial Robustness
  • 08. Privacy and Data Protection
  • 09. Fairness and Non-Discrimination
  • 10. Environmental and Social Impact
  • 11. Third-Party and Supply Chain AI
  • 12. Incident Response and Monitoring
  • 13. Audit, Assurance, and Compliance

The 8 Framework Mappings

  • EU AI Act — Risk classification, conformity, documentation, and oversight obligations
  • ISO 42001 — AI management system standard, Annex A controls
  • NIST AI RMF — Govern, Map, Measure, Manage functions
  • MAS FEAT — Fairness, Ethics, Accountability, and Transparency principles
  • PDPA — Personal data protection obligations in AI contexts
  • IEEE Ethically Aligned Design — Ethics by design principles
  • OECD AI Principles — Responsible stewardship principles for trustworthy AI
  • UK AI Code of Practice — Voluntary framework for responsible AI deployment
Our Process

From AI asset inventory to tested control environment

Step 01

AI Asset Inventory

Identify all AI systems. Classify each by risk tier, deployment context, data inputs, affected populations, and framework obligations. The foundation from which control assignment flows.

Step 02

Control Assignment

Assign relevant controls from the 150-control library to each AI asset based on risk tier, domain relevance, and regulatory obligation. Not every control applies to every system.

Step 03

Risk Assessment

Assess inherent risk for each AI asset across impact and likelihood. Score across the 13 control domains. Identify where inherent risk is highest before considering controls.

Step 04

Control Gap Analysis

Assess current control implementation against assigned controls. Identify controls that are absent, partially implemented, or implemented but not evidenced. Score residual risk.

Step 05

Treatment Planning

For each gap, define a treatment: implement, accept with rationale, transfer, or avoid by modifying the AI system or use case. Assign ownership and target dates.

Step 06

Evidence and Testing Structure

Define what evidence each control requires, how it is collected, who maintains it, and how it will be tested in the assurance cycle. Without this, controls exist on paper but not in practice.

Control Examples by Domain

What the framework looks like in practice

AI Governance and Accountability

Defined AI governance policy. Board-approved AI risk appetite. Named AI system owners. Regular AI governance reporting to board or risk committee.

Data Governance and Quality

Data lineage documentation for training data. Data quality standards for AI inputs. Bias testing on training datasets. Data retention and deletion policies for AI-specific data.

Human Oversight and Intervention

Human review checkpoints defined for each high-risk AI system. Override mechanisms tested and documented. Escalation paths for AI output anomalies known to operators.

Transparency and Explainability

Disclosure to users when interacting with AI. Model cards or system cards for high-risk systems. Explainability requirements defined by use case and audience.

Security and Adversarial Robustness

Adversarial testing performed on deployed models. Input validation controls. Model access controls. Monitoring for unexpected model behaviour or output drift.

Third-Party and Supply Chain AI

AI vendor due diligence process. Contractual obligations for third-party AI providers on transparency, performance, and incident notification. Third-party systems in the asset register.

The Platform Layer

AIVARA Core 360 hosts, tracks, and evidences every control

Every control is assigned to an asset. Implementation status is tracked. Evidence is stored and linked. When a regulator, auditor, or board member asks whether a specific AI system has adequate controls, the answer is a system view showing the control, the evidence, the test result, and the owner.

Try AIVARA Core 360 Free →

Questions before you start

Why 150 controls? Is that too many for a mid-market organisation?

Not all 150 controls apply to every organisation or every AI system. Controls are assigned based on AI asset risk classification, regulatory obligations, and context. A mid-market company with limited AI deployment may implement 40 to 60 controls initially. The library gives you the complete set to draw from.

How does this map to ISO 42001?

ISO 42001 is an AI management system standard. The AIVARA control library maps to ISO 42001 Annex A controls so organisations can work toward ISO 42001 certification or alignment simultaneously with meeting regulatory requirements.

What is MAS FEAT and does it apply outside Singapore?

MAS FEAT stands for Fairness, Ethics, Accountability, and Transparency. It is issued by the Monetary Authority of Singapore as guidance for financial institutions using AI in Singapore. It applies directly to MAS-regulated institutions and is referenced by other APAC regulators as a relevant benchmark.

How often do controls need to be reviewed?

Control relevance should be reviewed when new AI systems are deployed, when existing systems are significantly modified, when regulatory requirements change, and as part of the annual AI governance review cycle.

Can this support ISO 42001 certification?

Yes. The control framework is designed with ISO 42001 alignment in mind. AIVARA Core 360 provides the documentation, evidence, and management system infrastructure that ISO 42001 certification requires.

CorpStage uses cookies to understand how visitors use the site and to improve your experience. Analytics cookies are only set if you accept. Privacy Policy