OECD AI Principles
Robustness, Security, Safety

OECD AI Principles OECDAI-3: Robustness, Security, Safety, and Adversarial Attack Protection

Adhere to OECD AI Principles Section 1.4 (Robustness + security + safety). AI systems should be robust + secure + and safe throughout their entire lifecycle so that in conditions of normal use + foreseeable use or misuse + or other adverse conditions they function appropriately and do not pose unreasonable safety risk. To this end AI actors should ensure traceability + auditability + ability to log + and apply a systematic risk management approach to each phase of the AI system lifecycle on a continuous basis to address risks related to AI systems + including privacy + digital security + safety + and bias. Implement (a) AI risk identification and assessment aligned with NIST AI RMF + ISO/IEC 23894 + ISO/IEC 42001, (b) AI system categorisation by risk level + (c) AI model validation and testing covering performance + robustness + fairness + safety + security + (d) ongoing AI risk monitoring including drift + adversarial attack + emergent capability + (e) AI model security and integrity including model signing + provenance + access control + (f) adversarial attack protection (evasion + poisoning + extraction + inference + prompt injection + jailbreak + agentic misuse + similar) + (g) safe AI deployment procedures + (h) AI system lifecycle management + (i) AI system robustness and resilience.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 228 controls across 91 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

ISO/IEC 23894:2023 · 6 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation

NIST SP 800-53 Rev 5 · 6 controls

  • IM8-DAT.1 Data Classification
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.205 Information Security Risk Assessment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management

API 1164 · 4 controls

  • API1164-02 Risk Management Framework
  • API1164-07 Remote Access
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-24 Vulnerability assessment for critical systems
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

APRA CPS 234 · 4 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 4 controls

  • IEC62443-02 System security categorization
  • IEC62443-07 Personnel risk assessment
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-02 System security categorization
  • ISO27019-07 Personnel risk assessment
  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-24 Vulnerability assessment for critical systems

NIST SP 1800-32 · 4 controls

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • BS65000-RM-03 Leadership and Culture

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • CAT-D1-2 Risk management
  • CAT-D5-4 Resilience planning and testing
  • CAT-ML-2 Evolving
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 27003:2017 · 3 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27031:2011 · 3 controls

  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • AIGF-1.1 Risk Management and Internal Controls
  • AIGF-1.2 AI Ethics Governance Body
  • AIGF-3.2 Explainability
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment
  • AMLCTF-82 Part A Compliance
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.2 Machine Learning Architecture
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

NIST SP 800-190 · 2 controls

  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • AS9100D-8.1 Operational Planning and Control
  • ASD37-20 Multi-factor authentication (Essential)
  • ACQS-8-4 Risk Management

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

GDPR · 1 control

  • ISO-14064-1-5.4 Categorization of indirect GHG emissions
  • ISO-20400-4.5 Key considerations for sustainable procurement
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO 27799:2025 · 1 control

  • ISO27799-06 Security management process and risk analysis
  • ISO28001-SA-04 Security Risk Treatment Planning
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

  • 27010-8.2 Membership Termination

ISO/IEC 27043:2015 · 1 control

  • ISO27043-08 Information classification and labeling

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ISO/SAE 21434 · 1 control

  • ISO21434-08 Information classification and labeling

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CPSC-RA.3 Lifecycle Risk Assessment
  • CERT-1 RRA Certification to EPA
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 228 it maps to, and the evidence behind each claim, over MCP and REST.