All 25 terms

Tier 3: Safety and resilience controls

AI-related security and model abuse risk

Security threats unique to AI systems, including prompt injection, data leakage, model theft, training data poisoning, and abusive use of model outputs.

Board-defensible evidence

Why this matters

AI security incidents often trigger both cyber response and governance questions about why foreseeable abuse paths were not controlled.

How ready is your board on safety and resilience controls?

Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.

Take the readiness check