GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

SaaS AI Provider

stable saas-ai-provider · v1.0

A vendor that builds a cloud product with AI in it, runs it for many customers and places it on the market under its own name. This is the AICF library as written: every control, evidence record and question was drafted from this seat, so the profile marks every control as required apart from the four conformity and market-obligation controls that bind only a provider whose system falls in a high-risk or general-purpose class. It covers the security programme a SaaS company runs, the privacy duties it owes as a processor and as a controller, the AI governance of the systems it builds and the transparency duties that attach to generative features. The duties of the customer that deploys the product belong to enterprise-ai-deployer; the Chapter V duties of a general-purpose model provider belong to gpai-model-provider.

Roles
Provider
Deployment models
Cloud, multi-tenant SaaSCloud, single tenant
Risk classes
noneminimaltransparencyhigh-risk-annex-iiigpai
Jurisdictions
EUUS-federalINT
Frameworks
SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGDPR

Applicability statement

201 controls Download CSV
required 186 controls In scope for this profile. The control has to be in place and evidenced.

GOV · Governance & Risk

The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.

DAT · Data Protection

Customer-held keys are a commitment of a hosted service.

Location transparency is a commitment of a hosted service to its tenants.

Export and portability are commitments of a hosted service to its tenants.

Exit is executed by the provider on the customer's behalf, because the customer cannot run the transition on infrastructure it does not control.

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

VND · Vendor & Third-Party Risk

The shared responsibility matrix exists because the customer's workload runs on the provider's service.

Requests for customer data reach the provider because it hosts the tenant's data.

A hosted service has customers whose data it holds, so the terms on which a customer leaves and the terms a regulation makes compulsory for that data are commitments of the service rather than internal practice.

A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.

AIG · AI Governance

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Art.5 binds every provider, whatever the risk class of its other systems.

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

The statement on customer data in training and the opt-out are the provider's to give.

Any organisation that trains, fine-tunes or evaluates a production model runs the pipeline this control secures. A provider that only calls a third-party model records that no pipeline exists against the inventory entry.

Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).

conditional 4 controls In scope when the stated condition holds. Read the condition before deciding.

AIG · AI Governance

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii

Conformity assessment, the declaration and the CE marking (Art.43, 47, 48) bind providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii and the organisation is established outside the Union

Art.22 binds providers of high-risk systems established outside the Union. The Art.54 arm for general-purpose model providers belongs to the gpai-model-provider profile.

Condition: ai_risk_class in high-risk-annex-iii

Art.20 and Art.21 bind providers of high-risk systems. The Art.53.5 cooperation duty on general-purpose model providers belongs to the gpai-model-provider profile.

not-applicable 11 controls Out of scope for this profile. It is stated rather than omitted so the exclusion is auditable.

AIG · AI Governance

Worker notification before a system is put into use at a workplace is an employer's duty under Art.26(7). A provider placing the system on the market owes it for its own workforce only where it is also the deployer, which is the enterprise-ai-deployer seat.

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

The public training content summary is the gpai-provider seat (ADR-046). A provider that fine-tunes a third-party model for its product records provenance under AIG-013 and is not the models provider.

The copyright policy and crawler conduct of a general-purpose model provider are the gpai-provider seat (ADR-046). A SaaS providers own licensed assets and training data licences are GOV-015 and AIG-013.

Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.

Evaluation under standardised protocols attaches to a designated general-purpose model (ADR-046). A SaaS provider evaluates the systems it operates under AIG-026 and AIG-008.

Protection of a designated models weights to a stated security goal is the gpai-provider seat (ADR-046). A SaaS providers development assets and training pipeline are IAM-014 and AIG-055.

Reporting to the AI Office about a designated model is the gpai-provider seat (ADR-046). A SaaS provider reports a systems serious incident to the competent authority under AIG-021.

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Published 2026-09-14