What this service is for
For organisations evaluating an AI assistant, RAG system, copilot, agent, vendor platform or AI-enabled workflow before deployment, renewal or wider rollout.
ArchitectureTrace data, identity, retrieval, model context, tools and output paths.
MisuseTest realistic failure modes such as prompt injection, leakage and excessive agency.
OperationsEnsure logging, incident response, change control and fallback are defined.
Assessment areas
Typical deliverables
- Architecture and trust-boundary review.
- Threat and misuse scenario register.
- RAG and source-permission assessment where relevant.
- Agent/tool permission and approval review.
- AI vendor and model-risk findings.
- Logging, monitoring and incident-readiness gaps.
- Prioritised remediation plan with residual risk.
Security references used
The assessment can draw on OWASP GenAI guidance, the NIST AI Risk Management Framework and its Generative AI Profile, and ISO/IEC 27001 security-management principles. These references are used as practical baselines; they do not replace a system-specific threat model or testing.
When to assess
Assessment boundary: an AI security assessment reduces uncertainty; it cannot guarantee that a system is secure or eliminate all model behaviour risk. Findings should be managed through ongoing monitoring and change control.
Reference sources
Need a focused review of an AI system or vendor?
SundAI can assess the control surface and turn findings into a prioritised remediation plan.
Contact SundAI via Services →