This page explains how the AI Control Standard works, how assessment determinations are made, how organizations maintain status, and how third parties verify credentials.
A structured explanation of the assessment and registration workflow, public status verification, lifecycle monitoring, standards alignment, and the request path for new assessments.
AICS presents trust information in layers: a concise overview for business stakeholders, expandable technical details for IT/security reviewers, and curated assistant responses for common procurement questions.
Uploaded governance artifacts are handled through authenticated client portal workflows and are separated from public registry verification.
Client portal access, administrative operations, and public verification are intentionally separated by workflow and system purpose.
Privileged workflows are intended to execute through protected backend functions rather than browser-exposed logic.
The public registry validates recognition status without exposing uploaded evidence, policies, procedures, or internal governance files.
The AICS workflow is designed to keep client evidence private while supporting controlled review, recognition publication, and public status verification.
Client access is provisioned so evidence can be submitted through a controlled portal workflow.
Governance artifacts are uploaded into the client workspace for assessment support.
AICS reviews evidence against governance domains and operational readiness expectations.
Approval and issuance workflows are handled through administrative pathways, separated from public pages.
Public verification metadata is made available for registry lookup and third-party verification.
These sections provide depth without overwhelming the page. Reviewers can expand the topics most relevant to their security or governance questions.
Access is limited to the minimum level required for the relevant client or administrative workflow.
Controls are layered across frontend delivery, backend execution, database policies, storage access, and workflow separation.
Administrative workflows are separated from client-facing evidence submission and public verification experiences.
Public registry and verification pages are isolated from private client evidence and internal governance artifacts.
Governance workflows are designed to support traceability across request, review, approval, and issuance stages.
Sensitive operations use protected backend pathways instead of exposing privileged actions directly in browser code.
Browser-facing code may use public Supabase access configuration combined with Row-Level Security policies. This is different from exposing privileged service-role credentials.
Privileged service-role keys are intended only for protected server-side functions and should not appear in HTML, client JavaScript, screenshots, or public repositories.
Operations such as assessment request creation, portal access delivery, and recognition publication can run through protected Netlify Functions.
AICS does not claim to eliminate all cybersecurity risk. The platform uses layered controls, controlled workflows, and shared responsibility practices to reduce risk.
Client workspaces require authenticated portal access for evidence upload, assessment status visibility, and recognition document access.
Supabase Row-Level Security supports database-level restrictions so records can be segmented by client identity, workflow role, and authorized access path.
Evidence storage and registry verification are separated so public pages do not function as evidence repositories.
Administrative workflows are separated from public verification pages and client-facing evidence submission experiences.
Select a common IT/security question below. Responses are curated to keep trust, security, and governance statements consistent.
This assistant provides controlled, pre-approved explanations for common IT, procurement, and governance review questions.
No. AICS public verification systems are designed to expose public verification metadata only. Uploaded evidence and internal governance documents remain within authenticated client evidence workflows.
The AICS Governance Assessment follows a structured, evidence-based process designed for executive visibility, control maturity assessment, and public trust.
Organizations with an AICS registration receive a public status record that third parties can independently verify.
The public status service presents the organization’s registration identifier, current governance status, scope, and applicable dates without issuing a customer display mark.
The AICS public registry allows third parties to confirm whether an organization’s registration status is active, expired, or otherwise not currently valid.
Organizations listed in the AICS Public Registry are assigned a registration status reflecting the current standing of their governance assessment.
The organization has completed an AICS Governance Assessment and currently maintains an active registration status. Registration status remains subject to continued alignment and periodic review.
Registration status has lapsed due to the end of the assessment cycle without follow-up review. The organization may pursue re-assessment to restore status.
Registration status has been withdrawn due to material governance deficiencies, misrepresentation, or failure to maintain required controls.
AICS registration status reflects a lifecycle designed to support ongoing governance maturity.
Assessment of governance controls, structured scoring, and governance status determination.
Light-touch annual review to confirm controls remain active and governance expectations continue to be met.
Periodic reassessment with updated evidence and a renewed recognition cycle.
AICS governance is informed by recognized governance, risk, and control frameworks relevant to responsible AI adoption.
NIST and ISO are referenced for informational alignment only. AICS is an independent assessment and readiness framework and is not affiliated with or endorsed by these organizations.
Governance & Accountability • Data Governance & Input Controls • Output Validation & Decision Controls • Vendor & Model Risk Oversight • Monitoring & Executive Attestation
These answers are designed for buyers, IT reviewers, procurement teams, and organizations evaluating whether AICS is appropriate for their governance needs.
No. Public registry and verification pages expose only public verification metadata such as recognition status, recognition date, validity information, and verification details. Uploaded evidence, internal policies, procedures, and governance artifacts remain part of the protected client evidence workflow.
The public registry is designed to verify recognition status. It may display organization name, recognition identifier, status, validity period, and related verification information. It is not designed to publish private evidence files or internal governance documents.
Evidence is handled through authenticated client portal workflows and separated from public-facing verification pages. Access controls, protected storage patterns, and Row-Level Security concepts support separation between client evidence, administrative workflows, and public registry records.
AICS is designed to support controlled governance review workflows. The client-facing evidence workflow should not be positioned as a public AI training pipeline. If automated analysis capabilities are used in the future, AICS should clearly define the review process, data handling boundaries, and client-facing disclosures.
Row-Level Security, often called RLS, is a database access control approach that restricts which records a user can read or modify. In an AICS context, this supports the principle that clients should only access records tied to their authorized account and workflow.
A Statement of Applicability-style view helps clarify which governance controls are applicable, not applicable, implemented, partially implemented, or pending evidence. This gives leadership, IT, and compliance reviewers a clearer view of scope, rationale, and evidence linkage.
No. AICS is an independent AI governance assessment and readiness framework. AICS may be informed by recognized governance concepts and AI management system principles, but it should not be represented as ISO/IEC 42001 certification or official ISO accreditation unless a separate formal accreditation path is completed.
Clients receive governance readiness observations, evidence review results, maturity scoring, executive impact analysis, remediation priorities, an assessment determination, and public verification assets when recognition is published.
Organizations interested in recognized AICS status may request an AICS Governance Assessment.