| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | ||||||||||||||||||||||||||
2 | GuideNet AI Control Framework | |||||||||||||||||||||||||
3 | ||||||||||||||||||||||||||
4 | Overview and Usage Guide | |||||||||||||||||||||||||
5 | ||||||||||||||||||||||||||
6 | ||||||||||||||||||||||||||
7 | ||||||||||||||||||||||||||
8 | Purpose | |||||||||||||||||||||||||
9 | ||||||||||||||||||||||||||
10 | The GuideNet AI Control Framework provides a structured and implementable control architecture to govern Artificial Intelligence across its lifecycle. | |||||||||||||||||||||||||
11 | It is designed to enable organisations to manage AI risk, demonstrate regulatory compliance, and support independent assurance. | |||||||||||||||||||||||||
12 | ||||||||||||||||||||||||||
13 | ||||||||||||||||||||||||||
14 | Scope | |||||||||||||||||||||||||
15 | ||||||||||||||||||||||||||
16 | The framework covers the end to end AI lifecycle including: | |||||||||||||||||||||||||
17 | ||||||||||||||||||||||||||
18 | • Governance and oversight | |||||||||||||||||||||||||
19 | • Data sourcing and management | |||||||||||||||||||||||||
20 | • Model development and transparency | |||||||||||||||||||||||||
21 | • Deployment, monitoring, and resilience | |||||||||||||||||||||||||
22 | • Legal and regulatory compliance | |||||||||||||||||||||||||
23 | • Third party and supply chain risk | |||||||||||||||||||||||||
24 | • Evidence, auditability, and assurance | |||||||||||||||||||||||||
25 | • Ethical and sustainability considerations | |||||||||||||||||||||||||
26 | ||||||||||||||||||||||||||
27 | It applies to all AI systems, including predictive models, machine learning solutions, and generative AI. | |||||||||||||||||||||||||
28 | ||||||||||||||||||||||||||
29 | ||||||||||||||||||||||||||
30 | ||||||||||||||||||||||||||
31 | Structure of the Framework | |||||||||||||||||||||||||
32 | ||||||||||||||||||||||||||
33 | The framework is organised into: | |||||||||||||||||||||||||
34 | ||||||||||||||||||||||||||
35 | • 12 control domains | |||||||||||||||||||||||||
36 | • 88 defined control objectives | |||||||||||||||||||||||||
37 | • Detailed operationalised controls | |||||||||||||||||||||||||
38 | • Cross framework mappings | |||||||||||||||||||||||||
39 | • Adoption stage applicability | |||||||||||||||||||||||||
40 | ||||||||||||||||||||||||||
41 | Each control is uniquely identified and aligned to enterprise control expectations. | |||||||||||||||||||||||||
42 | ||||||||||||||||||||||||||
43 | ||||||||||||||||||||||||||
44 | ||||||||||||||||||||||||||
45 | Framework Alignment | |||||||||||||||||||||||||
46 | ||||||||||||||||||||||||||
47 | The framework is structurally aligned to leading standards and regulatory expectations including: | |||||||||||||||||||||||||
48 | ||||||||||||||||||||||||||
49 | • NIST AI Risk Management Framework | |||||||||||||||||||||||||
50 | • ISO 42001 | |||||||||||||||||||||||||
51 | • EU AI Act | |||||||||||||||||||||||||
52 | • GDPR | |||||||||||||||||||||||||
53 | • OECD AI Principles | |||||||||||||||||||||||||
54 | ||||||||||||||||||||||||||
55 | Forward and reverse mapping enables traceability between regulatory obligations and control implementation. | |||||||||||||||||||||||||
56 | ||||||||||||||||||||||||||
57 | ||||||||||||||||||||||||||
58 | ||||||||||||||||||||||||||
59 | Assurance and Audit Relevance | |||||||||||||||||||||||||
60 | ||||||||||||||||||||||||||
61 | The framework is designed to support: | |||||||||||||||||||||||||
62 | ||||||||||||||||||||||||||
63 | • Internal audit and independent assurance | |||||||||||||||||||||||||
64 | • External audit and ICFR considerations | |||||||||||||||||||||||||
65 | • Regulatory inspections and compliance reviews | |||||||||||||||||||||||||
66 | • Risk management and governance oversight | |||||||||||||||||||||||||
67 | ||||||||||||||||||||||||||
68 | Controls that impact financial reporting or audit reliance are identified through assurance flags. | |||||||||||||||||||||||||
69 | ||||||||||||||||||||||||||
70 | ||||||||||||||||||||||||||
71 | ||||||||||||||||||||||||||
72 | Adoption Model | |||||||||||||||||||||||||
73 | ||||||||||||||||||||||||||
74 | The framework is aligned to a four stage AI adoption model: | |||||||||||||||||||||||||
75 | ||||||||||||||||||||||||||
76 | • Foundation | |||||||||||||||||||||||||
77 | • Experimentation | |||||||||||||||||||||||||
78 | • Operational | |||||||||||||||||||||||||
79 | • Scaled | |||||||||||||||||||||||||
80 | ||||||||||||||||||||||||||
81 | This enables organisations to implement controls progressively based on maturity, risk exposure, and reliance. | |||||||||||||||||||||||||
82 | ||||||||||||||||||||||||||
83 | Refer to the “AI Adoption Model” tab for detailed definitions. | |||||||||||||||||||||||||
84 | ||||||||||||||||||||||||||
85 | ||||||||||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | How to Use the RACM | |||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | The RACM tab provides the detailed control matrix and should be used to: | |||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | • Identify applicable controls based on AI use cases | |||||||||||||||||||||||||
92 | • Map controls to regulatory and framework requirements | |||||||||||||||||||||||||
93 | • Assess control design and implementation | |||||||||||||||||||||||||
94 | • Support audit and assurance activities | |||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | Each row includes: | |||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | • Control ID and objective | |||||||||||||||||||||||||
99 | • Risk addressed | |||||||||||||||||||||||||
100 | • Operationalised controls |