Public Release · Version 1.0 – Jul 26

Enterprise AI Security Assessment (EAISA) Methodology

A practical, evidence-driven methodology for assessing enterprise AI systems across identity, data, retrieval, applications, agents, tools, integrations and operational controls.

Why EAISA

The security boundary is wider than the model

Testing the model alone does not provide sufficient assurance for an enterprise AI system.

Jailbreaks and prompt manipulation remain relevant, but significant weaknesses can exist in the surrounding services. Retrieval may fail to enforce source-system permissions, an agent may operate with excessive privileges, a connected tool may accept unsafe parameters or instructions, or the audit and telemetry records needed to investigate an incident may be incomplete.

An enterprise assessment therefore needs to examine the model together with the identities, data sources, applications, APIs, tools, cloud services, and operational controls on which it depends.

The central question is not simply whether the model can be manipulated. It is whether the complete system continues to enforce the organisation’s security boundaries when AI is used to retrieve information or perform an action.
Assessment scope

What the methodology examines

EAISA follows data, identity, instructions and delegated authority across the complete enterprise AI attack surface.

Identity and permission boundaries

Whether users, groups, roles, tenants, and workload identities remain within their authorised access and execution boundaries.

Data and retrieval security

How sensitive information is processed, stored, indexed, retrieved, combined, cited, and deleted across source and derived systems.

Prompts and orchestration

How trusted instructions, user input, retrieved content, guardrails, routing, and context construction influence system behaviour.

Agents, tools and MCP

Whether delegated identity, capability scope, arguments, approvals, and downstream authorisation constrain what the system can do.

Applications, APIs and cloud

How application logic, sessions, integrations, storage, network paths, credentials, and provider controls protect the AI capability.

Monitoring and operational readiness

Whether use, retrieval and actions are attributable, detectable, and support effective containment, investigation, and recovery.

Practical assurance

Designed for real assessment work

The methodology provides a consistent structure for deciding what to assess, how far testing may go and what evidence supports the result.

Assurance levels

Scale assessment depth from readiness review through technical validation, adversarial testing, and continuous assurance.

Testing safety classes

Define permitted interaction, operational safeguards, stop conditions, and activities that require separate authorisation.

Evidence and risk

Separate confidence in the evidence from severity, then assess likelihood, and impact in the deployed business context.

Production readiness

Support an accountable go-live decision based on validated controls, accepted residual risk, and conditions for reassessment.

Read EAISA

Choose the format that works for you

Use the navigable HTML version for online reference or download the PDF for review, circulation and offline use.