Skip to main content
AI Controls Catalog

Audit AI

The audit-ready controls library for AI systems.

Test of Design. Test of Operating Effectiveness. Evidence requirements. Sample sizes. Framework mappings. Authored by a senior IT auditor for the auditors, AI governance leads, and supervisory authorities responsible for AI systems in regulated enterprises.

ISO/IEC 42001 NIST AI RMF EU AI Act OWASP LLM / Agentic / DSGAI MITRE ATLAS

Why this exists

Audit-ready

Every control has ToD procedures, ToOE procedures with sample sizes, and evidence requirements. Drop straight into a working paper.

Multi-framework

One control, all the mappings: ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM / Agentic / DSGAI, SOC 2, MITRE ATLAS, OSFI E-21.

Practitioner-authored

Authored by a senior IT auditor who co-leads OWASP GenAI Data Security and sits on Canada's ISO/IEC JTC 1/SC 42 mirror committee.

Featured controls

View all 20 →

About the author

Emmanuel Guilherme Jr. is a Senior Global IT Auditor and AI security researcher based in Toronto, Canada. He co-leads the Data Security Initiative of the OWASP GenAI Security Project and serves as a Candidate Expert on Canada's mirror committee for ISO/IEC JTC 1/SC 42, the body that shapes ISO/IEC 42001, 23894, and 42005.

Full bio →