What AICS does
- Reviews evidence against an agreed Governance or FinOps assessment scope.
- Produces findings and a client-facing report when the review is complete.
Plain answers for buyers and security reviewers about evidence handling and independent assessments.
Artificial Intelligence Control Standard (AICS) is an independent assessment system. An assessment evaluates evidence and delivers findings and recommendations for the agreed scope. It is not ISO/IEC certification or regulatory approval.
AICS keeps uploaded evidence in client and assessor workflows. Client sign-in, scoped evidence access, and protected server actions keep private evidence separate from the public website. Client records and uploaded evidence stored in Supabase are encrypted at rest. AICS website traffic and Supabase API connections use HTTPS in transit.
Evidence uploads use authenticated client sessions. Approved downloads use links that expire after a short period.
Client sign-in creates a session. Protected server actions verify the session and check the user’s access before continuing.
Sensitive operations run on the server; privileged credentials are kept in server settings, away from client pages.
Approved reports are delivered through client workflows. Uploaded evidence and assessor notes are not public website content.
Uploaded assessment documents stay in the AICS evidence workflow and are not sent to public generative AI services. The assessment analyzer uses rule-based checks to support human review; an AICS reviewer approves results before publication. The assessment workflow does not train an AI model on uploaded documents. Ask AICS chat is separate: questions typed into chat may be sent to an external AI provider when enabled. Do not put confidential evidence in chat.
These statements describe the current AICS assessment workflow. For engagement-specific evidence handling, ask AICS.A request alone does not start an assessment. AICS confirms scope and terms first; Governance and FinOps remain separate.
AICS agrees to the assessment scope, applicable evidence, and engagement terms before work starts.
Clients submit documentary evidence through the private portal. Defined assessment criteria guide the review of that evidence.
Analysis supports control evaluation by relating the submitted evidence to assessment criteria and identifying findings and gaps.
A reviewer evaluates supporting evidence, accepts, edits, or rejects findings, and records recommendations. Eligible results require approval before client reporting.
AICS delivers the approved client report with findings, priorities, and recommended actions for the agreed scope.
Automated checks support, rather than replace, reviewer judgment. Findings reflect the evidence reviewed within the agreed scope, not a guarantee of future performance. Follow-up evidence and reassessment are handled within the agreed engagement; a report does not imply continuous observation of your systems. See a sample AI governance assessment report.
This is an illustrative topic map for discussion, not a conformity statement or an ISO certification.
ISO/IEC 42001 addresses an AI Management System (AIMS). In plain language, an AIMS connects an organization's AI policies, responsibilities, objectives, and operating processes so it can manage and improve how it develops or uses AI. See the ISO/IEC 42001 overview.
Readiness work helps identify evidence and gaps before an external certification process. An AICS assessment is not ISO/IEC 42001 certification, and readiness does not guarantee certification. AICS does not claim ISO accreditation; references do not imply ISO endorsement.
The voluntary NIST AI Risk Management Framework offers a way to organize AI risk management through Govern, Map, Measure, and Manage. It helps teams consider context, assess risk, and plan responses. The NIST AI Resource Center provides supporting resources.
These references provide context, not NIST certification or endorsement of AICS. An AICS score is not a measure of NIST conformity.
Use these questions to organize a discussion and supporting records. Answering them does not establish conformity with a standard.
| AICS evidence area | ISO/IEC 42001 topic | NIST AI RMF function |
|---|---|---|
| AI inventory and ownership | Context and AI system lifecycle | Map · Govern |
| Executive oversight and policy | Leadership, planning, support | Govern |
| Risk register and vendor review | Planning and operational controls | Map · Manage |
| Monitoring and review logs | Performance evaluation and improvement | Measure · Manage |
How to use this table: These are broad connections between AICS evidence areas and recognized guidance. The table is not a clause-by-clause assessment or a statement of conformity. Your AICS Governance Report identifies the evidence reviewed and findings for your agreed scope. For the underlying guidance, see the ISO/IEC 42001 overview and NIST AI RMF Core.
AICS examines the six financial-governance areas described on the FinOps assessment overview. The FinOps Framework provides shared concepts for technology financial management. For example, Allocation relates costs to usage or services, while Unit Economics connects cost to units of business activity.
FinOps has its own evidence package and agreed reporting period. Follow-up reviews are optional and separately scoped. The six evidence areas are:
Prepare for your AI governance readiness assessment with records that show who owns AI decisions, what was reviewed, and what action followed. Examples depend on the agreed assessment scope:
These are examples, not a universal list of mandatory documents. AICS confirms the evidence required for your agreed scope.
An AICS readiness assessment reviews submitted evidence and identifies supported practices and gaps within the agreed scope. It does not award ISO/IEC 42001 certification. AICS provides an independent assessment, not an accredited standards certification.
Access public documents here. Request engagement-specific security details directly from AICS.
Evidence boundaries, access paths, and client reporting are summarized on this page.
Review security topics →See the format of a sample client-facing report. Sample content is illustrative.
View the sample AI governance assessment report →Scope and terms are confirmed for each engagement. A public sample agreement is not currently available.
Request sample terms →| Provider | Role in AICS workflows | Data category |
|---|---|---|
| Netlify | Website hosting and server-side functions | Site and function request data |
| Supabase | Client records and evidence storage | Client account and evidence data |
| Resend | Transactional email when configured | Delivery and request details |
| OpenAI API | Optional Ask AICS chat responses | Questions typed into chat, not portal evidence files |
Report a vulnerability to support@aicontrolstandard.org. Please do not attach confidential evidence to your first message.
No. Uploaded evidence and assessor notes remain in authorized client and assessor workflows.
No. AICS delivers assessment findings and recommendations for an agreed scope. The report is not ISO/IEC 42001 certification.
FinOps for AI is separately scoped, with its own evidence, review, and client report. You can request Governance, FinOps, or both.
Contact AICS support with your client and request ID. Applicable terms and current retention practices should be confirmed for your engagement.
Tell us which controls or documents your team needs to review.
Trust Center page updated October 8, 2026.