Templates & Checklists
Checklist
AI Security Assessment

In 2024, a deepfake attacker joined a video call using the fabricated voice and likeness of a financial executive and talked a company's finance team into wiring $25 million. AI adoption inside most organizations has outpaced security review, and most security teams don't yet have a clear picture of where AI lives inside their environment. This assessment gives CISOs and security leaders a structured, five-phase framework for evaluating AI exposure across sanctioned tools, shadow AI, embedded SaaS features, and autonomous agents, producing a prioritized, board-ready roadmap your team can act on immediately.
What’s inside:
- 1A five-phase evaluation framework: discovery and inventory, configuration and access review, governance and policy assessment, agentic and LLM security review, and strategic guidance and reporting
- 2Sample AI asset inventory and configuration review tables showing exactly what a completed assessment surfaces, from unsanctioned ChatGPT use to autonomous procurement agents
- 3A governance gap analysis mapped to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and MITRE ATLAS
- 4Agentic and LLM-specific risk findings covering prompt injection, data leakage, overly permissive scope, and human oversight gaps
- 5A prioritized 30/60/90-day roadmap of quick wins, architectural changes, and governance updates, each mapped to a specific finding and owner


