Enterprise AI Security Assessment (EAISA) Methodology
A practical, evidence-driven methodology for assessing enterprise AI systems across identity, data, retrieval, applications, agents, tools, integrations and operational controls.
The security boundary is wider than the model
Testing the model alone does not provide sufficient assurance for an enterprise AI system.
Jailbreaks and prompt manipulation remain relevant, but significant weaknesses can exist in the surrounding services. Retrieval may fail to enforce source-system permissions, an agent may operate with excessive privileges, a connected tool may accept unsafe parameters or instructions, or the audit and telemetry records needed to investigate an incident may be incomplete.
An enterprise assessment therefore needs to examine the model together with the identities, data sources, applications, APIs, tools, cloud services, and operational controls on which it depends.
What the methodology examines
EAISA follows data, identity, instructions and delegated authority across the complete enterprise AI attack surface.
Identity and permission boundaries
Whether users, groups, roles, tenants, and workload identities remain within their authorised access and execution boundaries.
Data and retrieval security
How sensitive information is processed, stored, indexed, retrieved, combined, cited, and deleted across source and derived systems.
Prompts and orchestration
How trusted instructions, user input, retrieved content, guardrails, routing, and context construction influence system behaviour.
Agents, tools and MCP
Whether delegated identity, capability scope, arguments, approvals, and downstream authorisation constrain what the system can do.
Applications, APIs and cloud
How application logic, sessions, integrations, storage, network paths, credentials, and provider controls protect the AI capability.
Monitoring and operational readiness
Whether use, retrieval and actions are attributable, detectable, and support effective containment, investigation, and recovery.
Designed for real assessment work
The methodology provides a consistent structure for deciding what to assess, how far testing may go and what evidence supports the result.
Assurance levels
Scale assessment depth from readiness review through technical validation, adversarial testing, and continuous assurance.
Testing safety classes
Define permitted interaction, operational safeguards, stop conditions, and activities that require separate authorisation.
Evidence and risk
Separate confidence in the evidence from severity, then assess likelihood, and impact in the deployed business context.
Production readiness
Support an accountable go-live decision based on validated controls, accepted residual risk, and conditions for reassessment.
Choose the format that works for you
Use the navigable HTML version for online reference or download the PDF for review, circulation and offline use.