Methodology
How this catalog is built
Control authorship
Every control is hand-authored by an IT auditor with field experience. No control is AI-generated. The author is named on each control and on the changelog. Where contributors propose controls, they are attributed and the merging maintainer is named as reviewer.
Quality bar
A control is not shipped until it meets all of the following:
- All schema fields are populated — no nulls, no TODOs.
- Test of Design has at least three procedures, inquiries, and inspections.
- Test of Operating Effectiveness has at least three procedures and explicit sample-size guidance.
- At least three framework mappings with valid clause/section references.
- Evidence requirements include format and retention.
- Changelog has at least an initial entry.
- References include at least two authoritative sources.
Framework mappings
Mappings reflect the author's reading of the cited standard, supported where applicable by the OWASP GenAI Security crosswalk and primary source review. Mappings are reviewed quarterly because frameworks evolve (the EU AI Act is being implemented in stages; OWASP lists are revised annually).
Versioning
Controls use semantic versioning. Every substantive change increments
the minor or patch version with a dated changelog entry. The
last_reviewed field is updated on every review even
without content change, so consumers can see which controls have been
affirmed recently.
Review cadence
- Framework mappings: quarterly.
- Long-form sections (objective, narrative): annually.
- Sample sizes and evidence requirements: annually or upon material regulatory development.
Limits and disclaimers
This catalog is a reference, not regulatory advice. Specific engagements should validate framework references against the current published version. Where the catalog and a regulator disagree, the regulator wins — please open an issue with the citation so the catalog can be corrected.