An AI security assessment is a structured review of everything that surrounds your models: data pipelines, training and fine-tuning workflows, vector stores, inference endpoints, prompt and tool architecture, third-party model providers, and the human processes that approve what goes live.
I evaluate model supply-chain risk (untrusted weights, unsafe serialisation formats, poisoned or unlicensed training data), data governance and PII flow into prompts and embeddings, tenant isolation inside RAG and vector databases, secrets and key handling for provider APIs, rate limiting and cost controls, logging and monitoring of model interactions, and the guardrail stack protecting inputs and outputs.
The output is a clear risk register mapped to NIST AI RMF, ISO/IEC 42001 and OWASP LLM guidance, a target-state architecture for your AI platform, and a prioritised roadmap that distinguishes what must be fixed before launch from what can be improved iteratively — so AI adoption moves forward with known, accepted risk instead of unknown exposure.
Why it matters
- Shows leadership exactly where AI risk sits before scaling adoption
- Prevents sensitive data leaking into prompts, embeddings and provider logs
- Catches multi-tenant isolation gaps in RAG and vector stores early
- Produces the risk evidence enterprise buyers and auditors request
My approach
How the engagement runs
Typical engagement: inventory of AI use cases and data flows, architecture and configuration review, control-gap analysis against NIST AI RMF and OWASP LLM Top 10, risk register with ratings, and a phased remediation roadmap.

