Framework · Open specification
AI Control Architecture
A ten-pillar framework for provable AI governance.
The AI Control Architecture (ACA) is a framework for governing artificial-intelligence systems by proving that controls are in place rather than asserting that they should be. It organises the full surface of AI risk into ten control pillars, each crosswalked to the prevailing governance standards, and pairs them with a structured assessment methodology that takes an AI use case from a plain-language description to a defensible, evidence-backed governance decision. Its organising principle is a single sentence: we do not ask whether a control is in place — we prove it.
The six questions it answers
For any AI use case — a copilot, an agent, embedded vendor AI, a RAG system, an internal LLM application, or a customer-facing model — the architecture answers six practical questions:
- What AI exists?
- What can the AI see?
- What can the AI decide?
- What can the AI do?
- Who is accountable?
- How is failure evidenced and contained?
The ten control pillars
The framework organises all AI controls into ten pillars. Each is a coherent domain of risk with its own objectives, controls, and evidence. Together they span the lifecycle from knowing what AI exists to recovering when an AI system fails.
Crosswalked to the standards you already answer to
Each pillar and its controls are crosswalked to the principal AI-governance standards, so work performed once satisfies several frameworks simultaneously. A control is never expressed in isolation — always with its mapping — so evidence is portable across regulatory and audit contexts.
| Standard | Role in the crosswalk |
|---|---|
| NIST AI Risk Management Framework | Govern / Map / Measure / Manage functions mapped per pillar. |
| ISO/IEC 42001 | AI management-system clauses and Annex A controls. |
| EU AI Act | Risk-tier obligations for high-risk and GPAI systems. |
| OWASP (LLM & Agentic) | Technical failure modes — injection, excessive agency, data exposure. |
Sector crosswalks extend the same evidence to SR 11-7 (model risk), NYDFS Part 500, and emerging US state AI laws.
From plain language to a decision on the record
The architecture pairs the pillars with a structured assessment methodology. A use case starts as a plain-language description; it is assigned a risk tier; a proportionate and complete set of controls is selected across the ten pillars by tier and behavioural pattern; each control is expressed with its standards crosswalk; evidence shows the control exists and assurance (a test plan with explicit pass criteria) shows it works. The output is a defensible, evidence-backed governance decision — with scope-lock so risk cannot drift silently, re-assessment when the system or its dependencies change, and portfolio governance that rolls posture up across the whole AI estate.
How it relates to control planes and control matrices
An AI control plane enforces policy at runtime; an AI controls matrix (such as the CSA AICM) catalogs control objectives. The AI Control Architecture is the connective methodology between them: it decides which controls a specific use case actually needs, proves they work, and produces a decision on the record. Its enforcement counterpart — the Recursive Cyber Defense Framework (RCDF) — governs how those controls are observed and, where warranted, enforced in the path of an AI's actions at machine speed, under human authority.
Run it on the Neo platform Read RCDF →