Contribute
Contribute a control or improvement
Contributions are welcome — especially from auditors, AI governance leads, CISOs, and regulators with field experience. The contribution model favors quality over quantity: a single control authored to the catalog's quality bar beats ten thin entries.
Ways to contribute
- Propose a new control — open an issue with the proposed scope, then submit a PR with a JSON file matching the schema.
- Improve an existing control — open a PR editing the relevant JSON. Edits trigger a version bump and changelog entry.
- Add framework mappings — particularly for SOC 2, MITRE ATLAS, OSFI E-21, and NYDFS 500, which are growing through community contribution.
- Report a mapping issue — open an issue with the source citation. Framework references evolve; corrections are valued.
Quality bar
A control is ready when:
- All schema fields are populated — no nulls or TODOs.
- Test of Design has ≥ 3 procedures, inquiries, and inspections.
- Test of Operating Effectiveness has ≥ 3 procedures and explicit sample-size guidance.
- ≥ 3 framework mappings with valid references.
- Evidence requirements include format and retention.
- ≥ 2 authoritative references.
- Changelog has an initial entry dated today.
Attribution
Contributors are added to CONTRIBUTORS.md. For substantive
content contributions, the contributor's name appears alongside
Emmanuel's in the author or reviewed_by
field on the affected control(s). Substantive contributors (≥ 3
merged content PRs) are listed on the About page.
Submitting
Open a PR at github.com/emmanuelgjr/AI-Controls-Catalog. For substantive proposals, please open an issue first so the scope and approach can be discussed before you invest time.