35% of ASEAN Guide on AI Governance and Ethics you already have
AWS Well-Architected Security Pillar already covers about 35% of ASEAN Guide on AI Governance and Ethics, leaving
24 of 37 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 24
No control in AWS Well-Architected Security Pillar
maps directly to one in ASEAN Guide on AI Governance and Ethics. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in AWS Well-Architected Security Pillar reaches these. This is the list to scope.
AIGE-HI-1Establish AI objectives and assess against principles and risks
AIGE-HI-3Determine the level of human involvement
AIGE-HI-5Mitigate automation bias and protect affected groups
AIGE-IG-2Define roles and responsibilities for AI oversight
AIGE-IG-4Training, awareness and capability building
AIGE-IG-5Periodic review of the governance model
AIGE-IG-6Apply risk-based proportionality
AIGE-OM-1Project governance and problem statement definition
AIGE-OM-10Third-party and vendor AI governance
AIGE-OM-2Data quality and representativeness
AIGE-OM-3Bias identification and mitigation
AIGE-OM-5Model explainability
AIGE-OM-6Repeatability and reproducibility
AIGE-OM-7Robustness and security testing
AIGE-OM-8Traceability and auditability
AIGE-OM-9Deployment, monitoring and review
AIGE-P1Transparency and Explainability
AIGE-P2Fairness and Equity
AIGE-P6Accountability and Integrity
AIGE-SI-1Stakeholder communication policy and AI-use disclosure
AIGE-SI-2Feedback channels
AIGE-SI-3Decision review and recourse channels
AIGE-SI-4Acceptable use policies
Show the 13 you already have
AIGE-HI-2Assess probability and severity of harm
AIGE-HI-4Document risk impact assessments
AIGE-IG-1Establish internal AI governance structures and oversight body
AIGE-IG-3AI ethics policies, standards and code of conduct
AIGE-NR-1Nurture AI talent and upskill the workforce
AIGE-NR-2Invest in AI research and development
AIGE-NR-3Support the AI innovation ecosystem and investment
AIGE-OM-4Data provenance, minimisation and protection
AIGE-P3Security and Safety
AIGE-P5Privacy and Data Governance
AIGE-P7Robustness and Reliability
AIGE-RR-1Establish an ASEAN Working Group on AI Governance
AIGE-RR-2Foster regional alignment, cooperation and interoperability
How this is calculated
Already covered means a mapping runs from a control in AWS Well-Architected Security Pillar to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition