Skip to main content

    AI Security, Governance & Agentic AI Assurance

    Understand how AI is authorized, built, deployed and used in your organization. AuditPartners reviews the governance decisions and technical controls behind AI-enabled workflows, from work tickets and code review to permissions, connectors, testing and deployment evidence.

    AI General Controls

    Three ways to scope it

    AuditPartners delivers the professional engagement. AI General Controls (AIGC™) is the assessment approach for AI-enabled workflows, and RiskAssist™ is supporting technology. Human professionals own judgment, exception review and final conclusions.

    AIGC Technical

    For whom
    Engineering, platform and security teams shipping AI-generated code or agents.
    Questions answered
    Can an authorized task be traced through the exact change, review, testing and release? Are agent capabilities bounded and observable?
    Scope
    Selected repositories, delivery pipelines, agent runtimes, identities and connected tools for an agreed workflow and period.
    Evidence
    Work tickets, commit histories, reviews, test runs, release records, permissions and runtime traces.
    Deliverable
    A technical controls report with documented procedures, tested exceptions and prioritized recommendations.

    AIGC Governance

    For whom
    AI owners, risk leaders, internal audit and boards seeking a view of AI oversight.
    Questions answered
    Is AI use known, owned and risk-assessed? Do approval, oversight and incident arrangements match actual use?
    Scope
    Selected AI use cases, inventory, policies, risk decisions, third parties and oversight processes.
    Evidence
    Inventory records, risk assessments, approval decisions, vendor reviews, oversight records and incident exercises.
    Deliverable
    A governance assessment with coverage gaps, evidence limitations, ownership observations and an action plan.

    AIGC Integrated

    For whom
    Teams that need to connect management expectations with engineering practice.
    Questions answered
    Do governance decisions translate into the permissions, review gates and recovery arrangements used in production?
    Scope
    An agreed set of AI workflows reviewed across both governance and technical controls.
    Evidence
    Linked policy and risk decisions, system configurations, change records and samples of control operation.
    Deliverable
    A combined report showing where governance and implementation align, where exceptions exist and what remains unknown.

    The AIGC technical scope

    We follow the selected workflow from authorization to operation and recovery. These areas guide scoping; the procedures, samples and level of testing are agreed for the engagement. Evidence examples are requests, not claims that a customer's controls have been tested.

    1. 1. Authorized work ticket & agent authorization

      What we test: Trace selected tasks to an approved purpose, accountable owner and the agent actions permitted for that task. Review how changes in task scope are authorized.

      Example evidence: Approved work tickets, acceptance criteria, agent execution policies and task authorization records.

    2. 2. The exact change & review

      What we test: Trace the commit or revision to the task and the artifact released. Inspect the review decision and whether reviewers could see the actual change before approving it.

      Example evidence: Commit identifiers, pull requests, revision history, reviewer records and artifact references.

    3. 3. Test integrity

      What we test: Inspect whether the tests relate to the reviewed change, whether results can be bypassed or altered, and how failed tests are handled. Reperform selected checks where agreed.

      Example evidence: Pipeline definitions, protected test settings, test outputs, failure records and exception approvals.

    4. 4. Release approval

      What we test: Trace sampled releases to the tested artifact and approval. Review who can deploy, override a gate or authorize an emergency change.

      Example evidence: Release approvals, deployment records, artifact digests, pipeline access and emergency-change records.

    5. 5. Human and agent permissions

      What we test: Compare human and service identities with their intended roles. Inspect privilege boundaries, delegation, access reviews and removal of access; test selected boundaries where authorized.

      Example evidence: Role definitions, identity configuration, service-account grants, access reviews and joiner/mover/leaver records.

    6. 6. Skills, plugins, connectors & MCP servers

      What we test: Review which capabilities an agent can invoke, who approves them and how their versions and permissions are controlled. Inspect the boundary between a requested action and an allowed tool call.

      Example evidence: Capability inventories, connector configuration, Model Context Protocol (MCP) server settings, approval records and tool-call traces.

    7. 7. Secrets and data

      What we test: Review credential handling and the data available to the workflow. Inspect classification, retrieval boundaries and external transfers; use authorized non-sensitive test cases for selected access checks.

      Example evidence: Secret-store configuration, redacted access records, data-flow diagrams, retention settings and retrieval access rules.

    8. 8. Runtime evidence

      What we test: Trace selected actions through logs, traces and monitoring. Review whether records identify the acting identity, tool, outcome and relevant revision, and whether alerts reach an accountable person.

      Example evidence: Redacted execution logs, correlated traces, monitoring configuration, alert records and retention settings.

    9. 9. Intervention and recovery

      What we test: Review how a person can stop an agent, revoke its access, roll back a change and handle an incident. Inspect exercises or agreed tests rather than assuming a written plan works.

      Example evidence: Stop and rollback procedures, revocation records, recovery exercises, incident tickets and follow-up actions.

    Governance scope

    We connect governance documentation to decisions and observed practice. The assessment maps to the NIST AI RMF 1.0 functions Govern, Map, Measure and Manage, and to relevant ISO/IEC 42001:2023 themes such as leadership, planning, operation, performance evaluation and improvement. For generative AI, the Generative AI Profile (NIST AI 600-1) can inform agreed risk criteria. These are reference mappings, not framework equivalence or certification.

    • AI inventory

      Identify the selected use cases, owners, purpose, data, models and dependencies; reconcile records with observed use.

    • Ownership

      Review decision rights, risk acceptance, reporting and responsibility across business and technical teams.

    • Acceptable use

      Check whether permitted and prohibited uses, approval paths and exceptions are understood and reflected in practice.

    • Risk assessment

      Inspect risk assessments, affected stakeholders, evaluation criteria and decisions about treatment or acceptance.

    • Third parties

      Review vendor responsibilities, data use, access, change notifications and dependency risks.

    • Human oversight

      Review who intervenes, what they can observe, when they must act and whether intervention is recorded.

    • Incident handling

      Inspect reporting, escalation, containment, recovery and lessons learned for AI-related incidents.

    How findings are classified

    A completed checklist or methodology workbook is not proof of tested customer controls. We state what each piece of evidence supports and avoid extending a design observation into a conclusion about control operation.

    • Design

      Does the documented control address the agreed risk, with an owner, trigger and expected evidence?

    • Implementation

      Is the control configured or put in place in the selected system or workflow?

    • Operating effectiveness

      Does evidence from the agreed period and samples show that the control operated as intended?

    • Evidence not available

      Is evidence missing, inaccessible or insufficient to reach a conclusion? We identify the unknown rather than treat it as a pass.

    Deliverables

    • Scope memo describing systems, criteria, period, exclusions and agreed testing.
    • Evidence request list and a record of evidence reviewed and unavailable.
    • Documented procedures and sample coverage, with traceability from findings to evidence.
    • Findings classified by design, implementation, operating effectiveness or unavailable evidence.
    • Prioritized recommendations and a readout for technical and management stakeholders.

    Limitations

    Conclusions are limited to the workflows, period, criteria and samples reviewed and tested. Changes to models, prompts, code, data or connected tools can change the risk after the review.

    A controls assessment does not establish the safety, fairness or reliability of every model output, certify compliance or replace legal advice. Specialized model evaluation or adversarial security testing requires separately agreed scope and authorization.

    A QuickScan or checklist is preparation, not a professional assessment. Management retains responsibility for risk decisions and operating controls.

    Who it is for

    Teams shipping AI-generated code or agents; platform and security leads reviewing permissions and delivery controls; internal audit evaluating AI-related risks; and boards wanting an independent view of a defined AI workflow or governance question.

    Small teams are welcome. Scope follows the risk and the decision you need to make, not an employee-count minimum.

    Related resources

    Related reading

    Educational guides written by AuditPartners; not advice for a specific organisation.

    Use the checklists to organize questions and evidence. Their completion does not demonstrate operating effectiveness.

    Understand the controls behind your AI workflow

    Discuss the systems, agents and decisions you want reviewed, then agree the evidence and testing scope.