Digital security · audit · $1,500–$3,000, once
AI Security & Risk Audit
You already run AI — an agent, a chatbot, three automations, a vendor model behind a form. This audit tells you, in one scorecard, who it answers to, what it can touch, how it fails, and what to fix first.
The scorecard we sell is the scorecard we run on ourselves
Our own fleet, measured 2026-09-11
50.2%Developing — 25 controls, 19 open findings, 3 controls with no evidence yet (G6, M4, E2), scored 0 and said so.
Rebuilt from data/security/ai-rmf-scorecard.json by the same script that audits a client. A control nobody measures scores zero; we do not estimate.
Why publish a number that low
Because an auditor who will not print their own score has not run the method. Every week eight security agents re-measure this fleet — identity, prompt injection, secrets, supply chain, data boundaries, actions, incident response — and the lead assembles the card. The number moves when a measurer lands, never when a sentence is rewritten.
What the audit covers
| Function | Weight | Our score | Controls |
|---|---|---|---|
| Govern | 20% | 40% | G1, G2, G3, G4, G5, G6 |
| Map | 20% | 37% | M1, M2, M3, M4, M5, M6 |
| Measure | 35% | 54% | E1, E2, E3, E4, E5, E6, E7 |
| Manage | 25% | 63% | A1, A2, A3, A4, A5, A6 |
Govern
Who is accountable, which policies exist and are enforced, how humans stay in the loop, how third-party AI is procured, what regulation applies.
Map
Every AI system inventoried with owner and purpose, the data each one touches, its dependencies, its impact if it is wrong, and what a bad day looks like.
Measure
Access and identity for non-human actors, prompt-injection screening with an adversarial test set, secrets handling, monitoring and drift, bias and quality checks, output validation.
Manage
Guardrails on consequential actions, an incident runbook that has been drilled, patching and dependency hygiene, change control, decommissioning, continuous improvement.
What you receive
- The scorecard. 25 controls, each scored 0–5 with the evidence string that produced the score and the file it came from. Function scores weighted 20 / 20 / 35 / 25; an overall maturity band from Absent to Optimized.
- The findings register. Every control at 3 or below becomes a finding with an owner and a target date — Critical inside 7 days, High 30, Medium 90, Low by the next cycle.
- The honest gaps. Controls we could not evidence are listed as such, not guessed. That list is usually the first sprint.
- A 30-day re-measure. We run the same method again and show the delta, so the report is a baseline rather than a document.
Fixes the audit surfaces — a deny list for an agent, a screen in front of an inbox, a runbook, a rotation — are quoted separately as a build. The audit stands on its own.
Who this is for
A business that adopted AI faster than it governed it
A support bot on the site, an agent that reads the inbox, automations that move money or data. Nobody has written down what each one may do.
A firm that has to answer a customer or regulator
A vendor questionnaire, a cyber-insurance renewal, a due-diligence request. You need a framework-mapped answer with evidence, not a policy PDF.
Method and receipts: how we measure the rest of our work, the console we hold our own pages to, and who runs this.
Questions people ask before booking
What do I get?
A 25-control maturity scorecard across the four NIST AI RMF functions, a findings register where every gap has an owner and a target date (Critical 7 days, High 30, Medium 90), the controls we could not evidence named as such, and a re-measure 30 days later.
What do you need from me?
An inventory conversation (what AI runs, who owns it, what it can touch), read access to configuration and logs for the systems in scope, and one person who can answer policy questions. Most audits complete inside two weeks.
Is the scorecard yours or a standard?
The framework is NIST AI RMF 1.0. The 25 controls and weights are the practitioner scorecard we run on our own fleet every week — our current number is printed on this page, not a testimonial.
What does it cost?
$1,500–$3,000, once. If the review shows fixes we can build, those are quoted separately and never bundled into the audit.
Book the discovery call
Thirty minutes. Tell us what AI runs in the business and who owns it; we tell you whether the audit is the right first step and what it would cover. No slides.
Last measured 2026-09-11.