AI Control Requirements Mapping Template
This template is used to map an AI use case to the applicable AI Control Architecture requirements.
The purpose is to create traceability between:
- AI risk tier
- AI control pillars
- control objectives
- functional requirements
- non-functional requirements
- implementation controls
- evidence
- assurance testing
- exceptions
- ownership
This template helps ensure that AI controls are not applied informally or inconsistently.
1. Mapping Information
AI Use Case Name
[Enter AI use case name]
Mapping ID
[Enter mapping ID]
Date
[Enter date]
Prepared By
Name:
Function:
Email:
Business Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Related Documents
2. AI Use Case Summary
Short Description
[Describe the AI use case]
AI Pattern
Select all that apply:
[ ] Copilot
[ ] Internal LLM application
[ ] RAG system
[ ] AI-enabled SaaS
[ ] Embedded vendor AI
[ ] Agent
[ ] AI-enabled workflow automation
[ ] Customer-facing AI
[ ] Employee-facing AI
[ ] Developer AI tool
[ ] Security operations AI
[ ] Decision-supporting AI
[ ] Action-capable AI
[ ] Other
Assigned Risk Tier
Select one:
[ ] Tier 1: Low-risk productivity or public-data use
[ ] Tier 2: Internal productivity with enterprise data
[ ] Tier 3: Decision-supporting AI
[ ] Tier 4: Action-capable AI
[ ] Tier 5: High-impact autonomous or regulated AI
Highest Risk Drivers
Select all that apply:
[ ] Sensitive data
[ ] Regulated data
[ ] Personal data
[ ] Customer impact
[ ] Employee impact
[ ] Financial impact
[ ] Legal or compliance impact
[ ] Security impact
[ ] Production impact
[ ] Decision influence
[ ] Tool/action capability
[ ] Agentic autonomy
[ ] External exposure
[ ] Vendor dependency
[ ] Low recoverability
[ ] Weak evidence
[ ] Unknown risk
3. Requirement Applicability Summary
4. Pillar 1: AI Inventory and Classification Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document inventory and classification notes, gaps, assumptions, or exceptions]
5. Pillar 2: AI Identity and Access Control Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document identity and access notes, gaps, assumptions, or exceptions]
6. Pillar 3: Data Boundary Control Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document data boundary notes, gaps, assumptions, or exceptions]
7. Pillar 4: Prompt and Input Control Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document prompt and input notes, gaps, assumptions, or exceptions]
8. Pillar 5: Output and Decision Control Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document output and decision notes, gaps, assumptions, or exceptions]
9. Pillar 6: Tool and Action Control Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document tool and action notes, gaps, assumptions, or exceptions]
10. Pillar 7: Human Accountability Model Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document human accountability notes, gaps, assumptions, or exceptions]
11. Pillar 8: AI Assurance and Testing Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document assurance and testing notes, gaps, assumptions, or exceptions]
12. Pillar 9: Monitoring, Logging, and Evidence Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document monitoring, logging, and evidence notes, gaps, assumptions, or exceptions]
13. Pillar 10: Incident Containment and Recovery Requirements
Applicability
[Applicable / Not applicable / Partially applicable]
Requirement Mapping
Notes
[Document incident containment and recovery notes, gaps, assumptions, or exceptions]
14. Non-Functional Requirement Mapping
Use this section to map non-functional requirements that apply across the AI control design.
15. Evidence Mapping
Required Evidence Summary
16. Assurance Mapping
Required Assurance Activities
17. Gap Summary
Requirement Gaps
Exception Required?
[ ] No
[ ] Yes
[ ] Unknown
Exception Summary
18. Approval
Mapping Completed By
Name:
Function:
Date:
Business Owner Review
Name:
Decision:
Date:
Notes:
Architecture / Security Review
Name or forum:
Decision:
Date:
Notes:
Risk / Governance Review
Name or forum:
Decision:
Date:
Notes:
19. Summary
Use case:
Risk tier:
Applicable pillars:
Highest priority requirements:
Required evidence:
Required assurance:
Open gaps:
Exceptions required:
Approval status:
Next review date: