Tier 3: Safety and resilience controls
AI-related security and model abuse risk
Security threats unique to AI systems, including prompt injection, data leakage, model theft, training data poisoning, and abusive use of model outputs.
Board-defensible evidence
- Threat model documenting AI-specific risks, attack surfaces, and controls, including who approved the threat model and how often it is updated.
- Security control evidence showing access controls, secrets management, environment isolation, and model endpoint protections, with configuration baselines and review logs.
- Testing evidence showing prompt-injection and data-exfiltration testing, abuse case testing, and documented mitigations validated through retesting.
- Monitoring and alerting evidence showing detection of anomalous usage patterns, abuse signals, and data leakage indicators, with incident tickets and response timelines.
- Vendor security due diligence records showing how third-party models or platforms were assessed, what security assurances were obtained, and what contractual safeguards are in place.
Why this matters
AI security incidents often trigger both cyber response and governance questions about why foreseeable abuse paths were not controlled.
How ready is your board on safety and resilience controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.