ISACA AAISM: Controls for Enterprise AI Systems
Controls for enterprise AI systems should protect the entire application path, not only the model endpoint. A production AI service combines identity, data, prompts, retrieval, model providers, tools, memory, APIs, deployment pipelines, monitoring, and human decisions. Each layer can introduce risk, and a safeguard in one layer cannot compensate for every weakness in another.
The control model belongs inside Enterprise AI Governance and maps directly to the current AAISM exam emphasis on AI security architecture, lifecycle controls, data management, privacy, trust and safety, monitoring, and risk-based human oversight. The practical goal is to map controls to failure scenarios and verify that they operate under realistic conditions.
Put identity before model intelligence
The model should never become a shortcut around authorization. Users, workloads, agents, connectors, and tools need distinct identities with least-privilege access. If an AI system can call a database, ticketing platform, cloud API, or payment service, the authorization boundary should be enforced by that service and identity layer rather than trusted to a prompt instruction.
Create hard data boundaries
Prompts and policies cannot safely replace data access control. Retrieval systems should enforce user or workload authorization when selecting documents, and sensitive datasets should have explicit rules for which models, regions, and providers may process them. Output should not contain data the caller could not access directly.
Threat-model the AI workflow
Enterprise AI introduces attack paths that traditional application reviews may miss: prompt injection, indirect injection through retrieved documents, malicious tool arguments, model extraction, data poisoning, unsafe deserialization, dependency compromise, and abuse of autonomous actions. Threat modeling should follow data and authority across the whole workflow.
Treat guardrails as layered controls
Content filters, model policies, system prompts, and classifiers are useful, but they are probabilistic and may be bypassed. High-impact systems need deterministic controls around them: schema validation, allowlisted actions, transaction limits, approval gates, network boundaries, data-loss prevention, and separate enforcement of authorization.