Audit AI
The audit-ready controls library for AI systems.
Test of Design. Test of Operating Effectiveness. Evidence requirements. Sample sizes. Framework mappings. Authored by a senior IT auditor for the auditors, AI governance leads, and supervisory authorities responsible for AI systems in regulated enterprises.
Why this exists
Audit-ready
Every control has ToD procedures, ToOE procedures with sample sizes, and evidence requirements. Drop straight into a working paper.
Multi-framework
One control, all the mappings: ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM / Agentic / DSGAI, SOC 2, MITRE ATLAS, OSFI E-21.
Practitioner-authored
Authored by a senior IT auditor who co-leads OWASP GenAI Data Security and sits on Canada's ISO/IEC JTC 1/SC 42 mirror committee.
Featured controls
View all 20 →- directive
AI-CTRL-001
AI System Inventory and Classification
Maintain a complete, current, and classified inventory of all AI systems in development, deployment, and decommissioning to enable risk-based governance.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-003
Adversarial Robustness Testing for LLM Systems
Validate that production-bound LLM and agentic AI systems have been tested against direct prompt injection, indirect prompt injection, jailbreak, refusal evasion, and (where applicable) multi-modal adversarial inputs, with documented findings, remediation, and re-test cycles.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-020
Shadow AI Detection
Detect, triage, and remediate use of unsanctioned AI services and unauthorized AI tooling by employees, contractors, and other authorized users, with documented response and metrics.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01
About the author
Emmanuel Guilherme Jr. is a Senior Global IT Auditor and AI security researcher based in Toronto, Canada. He co-leads the Data Security Initiative of the OWASP GenAI Security Project and serves as a Candidate Expert on Canada's mirror committee for ISO/IEC JTC 1/SC 42, the body that shapes ISO/IEC 42001, 23894, and 42005.
Full bio →