CSA STAR for AI & ISO/IEC 42001: Which Should You Choose?

By Lois Colby Published on August 12, 2026
In this Article
CSA AICM Guidance from an Auditor

In this continuously evolving field of Artificial Intelligence (AI), companies that use AI as part of their daily practices and customers who subscribe to services offered by providers that use AI as part of their business model are voicing concerns about this use of AI.

Questions are asked. What data is being used to train a model? Is my data secure if it is used as part of an AI process? Are the AI processes run authorized by an individual? Can the AI query go rogue and branch off into unauthorized activity or activity outside of the defined query? How easy is it for a data breach to occur? What controls exist to manage the usage? The questions go on and on. The news highlights AI activity gone wrong:

The average reader cannot overlook these types of articles.  This begs the question of how the usage of AI can be controlled, monitored, and audited to gain a level of comfort and confidence that addresses these concerns.

What AI Frameworks Are Out There?

Enter into the picture ISO/IEC 42001:2023 (ISO 42001), Information Technology – Artificial Intelligence – Management System, and Cloud Security Alliance (CSA) STAR for AI. You can review CSA’s official STAR for AI page for the full program details. ISO 42001 is a standard crafted to aid organizations in handling AI-related risks and addressing the security, ethics, and reliability of organizations’ AI systems. See our blog for an understanding of ISO 42001.

CSA STAR for AI provides a program to establish a standard process to build, assess, and prove trust in AI systems with a focus on cloud-native and Generative AI. CSA STAR for AI builds off of the controls matrix created for its other offerings, resulting in what CSA calls the AI Controls Matrix (AICM).

 

Comparing AI Frameworks

ISO 42001 & CSA AICM: A Side-by-Side Comparison

In order to choose which framework is the best option, a company using AI as part of its business practices must understand the basic differences and similarities between ISO 42001 and CSA STAR for AI. Here’s a quick breakdown:

Component Breakdown ISO 42001 CSA AICM
Framework Type A certifiable AI management system standard A controls and assessment framework for AI security
Issuing Organization International Organization for Standardization (ISO)/ International Electrotechnical Commission (IEC) Cloud Security Alliance (CSA)
Current Version ISO/IEC 42001:2023 V1.1 issued in July 2026
Objective Provides requirements for establishing, implementing, maintaining, and continually improving an AI management system. Such efforts are beyond the management of classical IT systems. Provides a “transparent, expert-driven, and consensus-based mechanism for organizations to assess, demonstrate, and ensure AI trustworthiness.”
Structure Consists of the standard management system structure found in the other ISOs (such as ISO/IEC 27001): Clauses 4-10; Annex A, 38 controls across 9 themes; Annex B, implementation guidance; and Annexes C/D, objectives and use cases. Consists of 18 security domains containing 247 individual control objectives and, within that, 320 questions (v1.1).
Certification Certification provided by accredited certification bodies, similar to ISO/IEC 27001. Performed through CSA’s STAR for AI certification/registry program by an authorized assessor organization of CSA.
Components A single certificate for the assessment against the components defined above in the Structure section Includes:

  1. The Consensus Assessment Initiative Questionnaire for AI (AI-CAIQ), which is a self-assessment performed by the company (Level 1).
  2. The second component, after completing the self-assessment, is an enhanced version of STAR for AI Level 1 where the organization’s AI-CAIQ passes the Valid-AI-ted automated system assessment (Valid-AI-ted).
  3. The third component requires both an ISO 42001 certification and a Valid-AI-ted AI-CAIQ (STAR for AI Level 2). It is a third-party assessment performed by an authorized assessor organization of CSA.
Shared Responsibility Applies to any organization that develops, provides, or uses AI. Not role-based. Provides for a Shared Security Responsibility Model (SSRM) for control ownership into the following categories:

  1. Owned by the Cloud Service Provider (CSP)
  2. Owned by the Model Provider (MP)
  3. Owned by the Orchestrated Service Provider (OSP)
  4. Owned by the Application Provider (AP)
  5. Owned by the Customer (AIC)

Also included are categories of shared responsibilities across the defined providers and customer.

Intended User Any organization that develops, provides, or uses AI-based products or services. Organizations focusing on cloud or SaaS offerings, Generative AI application builders, AI model developers.

Key Differences Between the Frameworks

Note that there are several key differences between the frameworks:

  1. ISO 42001 is a full management system standard with a path to certification. CSA STAR for AI is a security controls matrix and assessment tool.
  2. ISO 42001 is relatively high-level and organization-centric rather than supply-chain-centric. CSA STAR’s AICM is more granular and divides responsibility across the five defined AI ownership roles.
  3. ISO 42001, in alignment with the historical direction of ISO management systems, places more weight on organizational governance, leadership, and lifecycle risk management.  CSA STAR’s AICM is focused more toward technical and cloud-security controls specific to AI systems.

 

ISO 42001: Required or optional?

Can You Get CSA STAR for AI Without ISO 42001 Certification?

What must be noted is that the CSA STAR for AI Level 2 can only be obtained if the ISO 42001 certification has already been obtained. The CSA STAR for AI Level 1 can be obtained without an ISO 42001 certification.

Charting Your AI Governance Path Forward

Which framework is best for your company? That’s for your management team to decide based on the needs of the organization and requests, inquiries, and/or requirements from your customers. An assessor firm that can perform the audits for these frameworks should hold an open discussion with your team and you to help provide guidance on the path to take.

Linford & Co is here to support you in making an informed choice. We provide expert and honest advice when considering the different frameworks and can create a path forward for achieving the desired certification. Reach out to Linford & Co today to discuss these AI options and how they can address concerns of your internal and external stakeholders and current and future customers.

For more on CSA’s frameworks and certifications, check out these related articles:

About The Author

Lois Colby
Lois Colby

Lois started with Linford & Co., LLP in 2020. She began her career in 1990 and has spent her career working in public accounting at Ernst & Young and in the industry focusing on SOC 1 and SOC 2 and other audit activities, ethics & compliance, governance, and privacy. At Linford, Lois specializes in SOC 1, SOC 2, HIPAA, ISO, and CMMC audits. Lois’ goal is to collaboratively serve her clients to provide a valuable and accurate product that meets the needs of her clients and their customers all while adhering to professional standards.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**