AICSArtificial Intelligence Control Standard
AICS Trust Center

How AICS protects your evidence and reviews assessments.

Plain answers for buyers and security reviewers about evidence handling and independent assessments.

Independent review · Private evidence workflow · Human assessment
What AICS is and isn't

Independent assessment, not certification.

Artificial Intelligence Control Standard (AICS) is an independent assessment system. An assessment evaluates evidence and delivers findings and recommendations for the agreed scope. It is not ISO/IEC certification or regulatory approval.

What AICS does

  • Reviews evidence against an agreed Governance or FinOps assessment scope.
  • Produces findings and a client-facing report when the review is complete.

What AICS does not claim

  • An AICS result is not ISO/IEC 42001 certification.
  • An assessment is not a guarantee of compliance, security, or future performance.
  • Assessment findings are not legal advice.
Security and evidence protection

Your evidence stays private.

AICS keeps uploaded evidence in client and assessor workflows. Client sign-in, scoped evidence access, and protected server actions keep private evidence separate from the public website. Client records and uploaded evidence stored in Supabase are encrypted at rest. AICS website traffic and Supabase API connections use HTTPS in transit.

Private evidence workflows

Evidence uploads use authenticated client sessions. Approved downloads use links that expire after a short period.

Authenticated access

Client sign-in creates a session. Protected server actions verify the session and check the user’s access before continuing.

Server-side actions

Sensitive operations run on the server; privileged credentials are kept in server settings, away from client pages.

Private client reports

Approved reports are delivered through client workflows. Uploaded evidence and assessor notes are not public website content.

Are uploaded evidence files shared with AI models?

Uploaded assessment documents stay in the AICS evidence workflow and are not sent to public generative AI services. The assessment analyzer uses rule-based checks to support human review; an AICS reviewer approves results before publication. The assessment workflow does not train an AI model on uploaded documents. Ask AICS chat is separate: questions typed into chat may be sent to an external AI provider when enabled. Do not put confidential evidence in chat.

These statements describe the current AICS assessment workflow. For engagement-specific evidence handling, ask AICS.
How an assessment works

AI governance and FinOps assessment methodology.

A request alone does not start an assessment. AICS confirms scope and terms first; Governance and FinOps remain separate.

1

Confirm scope

AICS agrees to the assessment scope, applicable evidence, and engagement terms before work starts.

2

Submit evidence

Clients submit documentary evidence through the private portal. Defined assessment criteria guide the review of that evidence.

3

Analyze and evaluate

Analysis supports control evaluation by relating the submitted evidence to assessment criteria and identifying findings and gaps.

4

Human review

A reviewer evaluates supporting evidence, accepts, edits, or rejects findings, and records recommendations. Eligible results require approval before client reporting.

5

Deliver outcome

AICS delivers the approved client report with findings, priorities, and recommended actions for the agreed scope.

Automated checks support, rather than replace, reviewer judgment. Findings reflect the evidence reviewed within the agreed scope, not a guarantee of future performance. Follow-up evidence and reassessment are handled within the agreed engagement; a report does not imply continuous observation of your systems. See a sample AI governance assessment report.

Standards alignment

How the review relates to recognized guidance.

This is an illustrative topic map for discussion, not a conformity statement or an ISO certification.

ISO/IEC 42001 and an AIMS

ISO/IEC 42001 addresses an AI Management System (AIMS). In plain language, an AIMS connects an organization's AI policies, responsibilities, objectives, and operating processes so it can manage and improve how it develops or uses AI. See the ISO/IEC 42001 overview.

Readiness work helps identify evidence and gaps before an external certification process. An AICS assessment is not ISO/IEC 42001 certification, and readiness does not guarantee certification. AICS does not claim ISO accreditation; references do not imply ISO endorsement.

AI risk management with NIST

The voluntary NIST AI Risk Management Framework offers a way to organize AI risk management through Govern, Map, Measure, and Manage. It helps teams consider context, assess risk, and plan responses. The NIST AI Resource Center provides supporting resources.

These references provide context, not NIST certification or endorsement of AICS. An AICS score is not a measure of NIST conformity.

Practical readiness questions for your team
  • Who is accountable for AI governance, and which AI systems are in scope?
  • How are AI risks and impacts evaluated, and how is evidence retained?
  • How are third parties governed and incidents handled?
  • How are performance, management reviews, and corrective actions tracked?

Use these questions to organize a discussion and supporting records. Answering them does not establish conformity with a standard.

Illustrative topic connections

AICS evidence areaISO/IEC 42001 topicNIST AI RMF function
AI inventory and ownershipContext and AI system lifecycleMap · Govern
Executive oversight and policyLeadership, planning, supportGovern
Risk register and vendor reviewPlanning and operational controlsMap · Manage
Monitoring and review logsPerformance evaluation and improvementMeasure · Manage

How to use this table: These are broad connections between AICS evidence areas and recognized guidance. The table is not a clause-by-clause assessment or a statement of conformity. Your AICS Governance Report identifies the evidence reviewed and findings for your agreed scope. For the underlying guidance, see the ISO/IEC 42001 overview and NIST AI RMF Core.

FinOps for AI is a separate evidence review

AICS examines the six financial-governance areas described on the FinOps assessment overview. The FinOps Framework provides shared concepts for technology financial management. For example, Allocation relates costs to usage or services, while Unit Economics connects cost to units of business activity.

FinOps has its own evidence package and agreed reporting period. Follow-up reviews are optional and separately scoped. The six evidence areas are:

  • Cost ownership: who is accountable for AI spending and cost centers.
  • Budgeting and forecasting: planned spending, forecasts, and variance context.
  • Usage metering and allocation: connecting usage and costs to services for spending visibility.
  • Spending guardrails: thresholds, alerts, response ownership, and anomaly management.
  • Value and unit economics: cost per unit of activity, outcomes, and KPIs.
  • Vendors, licensing, and commitments: utilization and review informing rate optimization and SaaS decisions.
Framework Alignment is reference information only. AICS results do not establish FinOps Foundation certification or endorsement, Framework compliance, capability completion, or a Framework compliance percentage. AICS does not promise cost savings.
Prepare for your assessment

AI governance evidence checklist

Prepare for your AI governance readiness assessment with records that show who owns AI decisions, what was reviewed, and what action followed. Examples depend on the agreed assessment scope:

  • Ownership and policy: AI policies, governance charters, and assigned responsibilities.
  • AI inventory: systems and tools in use, their purposes, and accountable owners.
  • Risk and impact: assessments, documented decisions, and follow-up actions.
  • Data and vendors: data-handling documentation and third-party review records.
  • Operational oversight: output checks, monitoring, incident processes, and training records.
  • Review and improvement: management reviews and corrective-action records.

These are examples, not a universal list of mandatory documents. AICS confirms the evidence required for your agreed scope.

Readiness and ISO/IEC 42001 certification

An AICS readiness assessment reviews submitted evidence and identifies supported practices and gaps within the agreed scope. It does not award ISO/IEC 42001 certification. AICS provides an independent assessment, not an accredited standards certification.

Read the assessment methodology and limitations →

Documents and contacts

Review the evidence behind the trust story.

Access public documents here. Request engagement-specific security details directly from AICS.

Sample engagement terms

Scope and terms are confirmed for each engagement. A public sample agreement is not currently available.

Request sample terms →

Service providers involved in the platform

ProviderRole in AICS workflowsData category
NetlifyWebsite hosting and server-side functionsSite and function request data
SupabaseClient records and evidence storageClient account and evidence data
ResendTransactional email when configuredDelivery and request details
OpenAI APIOptional Ask AICS chat responsesQuestions typed into chat, not portal evidence files

Report a vulnerability to support@aicontrolstandard.org. Please do not attach confidential evidence to your first message.

Quick answers

Common questions.

Is my uploaded evidence public?

No. Uploaded evidence and assessor notes remain in authorized client and assessor workflows.

Does an AICS assessment provide ISO/IEC 42001 certification?

No. AICS delivers assessment findings and recommendations for an agreed scope. The report is not ISO/IEC 42001 certification.

Is FinOps included in a Governance assessment?

FinOps for AI is separately scoped, with its own evidence, review, and client report. You can request Governance, FinOps, or both.

How do I request deletion or retention details?

Contact AICS support with your client and request ID. Applicable terms and current retention practices should be confirmed for your engagement.

Need more detail?

Request a security conversation.

Tell us which controls or documents your team needs to review.

Trust Center page updated October 8, 2026.