BAICS - Banking AI Controls Standard
OverviewHow to UseControlsCategoriesFramework Mappings

Framework Mappings

BAICS controls by the Financial Services AI Council mapped to industry standards and frameworks

ISO/IEC 42001

AI Management System Standard

20 mappings
across 65 controls
ISACA AI Audit Toolkit

AI Audit and Assurance Framework

26 mappings
across 58 controls

ISO/IEC 42001 Mappings

10.1 – Nonconformity & Corrective Action

1 related control

4.1
10.2 – Continual Improvement

1 related control

6.5
5.2 – AI Policy

3 related controls

6.9
6.1
6.13
5.3 – Roles, Responsibilities, Authorities

8 related controls

1.11
1.12
2.4
3.7
5.1
5.3
6.3
6.1
6.1 – Actions to Address AI Risk

8 related controls

1.14
1.15
1.16
1.19
2.6
6.12
6.13
6.14
6.2 – AI Objectives and Planning

2 related controls

6.4
6.1
7.2 – Competence & Training

4 related controls

2.8
3.5
3.12
6.15
7.4 – Communication / Documentation

7 related controls

1.6
1.2
1.21
4.3
4.4
4.5
6.7
8.2.1 – Data Governance & Access Control

8 related controls

1.17
2.2
2.7
2.9
2.1
2.16
3.2
3.5
8.2.2 – Data Privacy & Anonymization

9 related controls

1.17
1.18
2.1
3.3
3.7
3.8
3.1
3.11
+1 more
8.2.3 – Data Provenance & Supply Chain Integrity

2 related controls

1.5
2.12
8.3.1 – Model Development & Testing (Fairness, Safety)

9 related controls

1.3
2.4
2.15
3.4
3.5
3.11
4.4
4.8
+1 more
8.3.2 – Model Deployment & Versioning

8 related controls

1.9
2.11
2.12
2.14
4.1
5.2
5.3
6.14
8.3.3 – Human Oversight

2 related controls

4.3
6.11
8.4.1 – Security of Runtime Environments

21 related controls

1.3
1.4
1.5
1.6
1.8
1.9
1.1
1.11
+13 more
8.4.2 – Resilience & Fail-Safes

2 related controls

4.1
5.3
8.4.3 – Robustness, Red-Teaming, Stress Testing

3 related controls

1.4
2.8
2.17
9.1 – Monitoring, Measurement & Performance

4 related controls

2.4
3.4
3.9
5.1
9.2 – Internal Audit / External Certification

4 related controls

1.19
3.4
3.6
6.8
9.3 – Management Review

1 related control

6.6

ISACA AI Audit Toolkit Mappings

Data → Access Control & Tamper-Evidence

7 related controls

1.17
2.7
2.11
2.13
2.14
3.2
3.5
Data → Lineage, Provenance, Cataloging

2 related controls

2.12
3.2
Data → Retention & Deletion

7 related controls

2.1
3.3
3.7
3.8
3.1
3.11
3.12
Fairness → Bias Detection/Testing

2 related controls

2.4
6.8
Governance → AI Policy & Strategy

3 related controls

6.9
6.1
6.13
Governance → Regulatory Alignment & Reporting

7 related controls

1.19
1.22
3.4
6.4
6.5
6.8
6.13
Governance → Risk Appetite & ERM Integration

4 related controls

2.6
6.6
6.12
6.13
Governance → Roles & Responsibilities

9 related controls

1.11
1.12
2.4
3.7
5.1
5.3
6.3
6.6
+1 more
Governance → Vendor/Third-Party Risk Management

2 related controls

2.12
3.7
Impact → DPIAs & Privacy Controls

5 related controls

3.3
3.7
3.8
3.1
3.12
Impact → External Audit/Attestation

2 related controls

2.12
6.8
Impact → Societal & Ethical Impact Assessments

4 related controls

6.2
6.8
6.9
6.15
Impact → Transparency Portals

4 related controls

1.2
4.3
4.4
4.5
Performance → Benchmarking Against Standards

4 related controls

1.22
2.5
2.15
6.8
Performance → Continuous Monitoring Dashboards

2 related controls

3.4
5.2
Performance → Drift Detection & SLA Monitoring

5 related controls

2.4
3.4
3.9
5.1
6.5
Performance → Versioning & Rollback Criteria

3 related controls

2.11
2.12
2.14
Rationale → Alignment with Strategy & Objectives

2 related controls

6.4
6.13
Rationale → Purpose Clarity for Stakeholders

2 related controls

1.2
4.3
Responsibility → Accountability Structures

1 related control

6.1
Responsibility → Assigned Roles

4 related controls

2.6
5.1
6.3
6.8
Responsibility → Training & Awareness

4 related controls

2.8
3.5
3.12
6.15
Safety → Adversarial Robustness Testing

3 related controls

1.4
2.8
2.17
Safety → Fail-Safes, Kill-Switches, Rollback Plans

2 related controls

4.1
5.3
Safety → Runtime Environment Hardening

19 related controls

1.3
1.4
1.5
1.8
1.9
1.1
1.11
1.12
+11 more
Safety → Secure Coding & Patching

2 related controls

1.1
2.5
BAICS - Banking AI Controls Standard
by Financial Services AI Council

© 2026 Financial Services AI Council. All rights reserved. | Terms of Use | Privacy Policy

Information provided for reference and evaluation only. Actual use of the Banking AI Controls Standard (BAICS) is subject to licensing from FSAIC. Visit www.fsaic.org for licensing information.