Security
AI threat modeling, adversarial robustness, PII handling, incident response, and regulatory compliance.
Is AI model security (adversarial robustness, prompt injection protection) addressed?
Are AI systems included in your threat modeling and security review processes?
Is there a policy for handling PII and sensitive data in AI model training and inference?
Are AI models and data pipelines subject to penetration testing?
Is model explainability required for high-risk AI decisions?
Are access controls and least-privilege enforced for AI training environments?
Do you have an AI incident response plan?
Is there supply chain security assessment for third-party ML models or datasets?
Are AI systems audited for bias, fairness, and discriminatory outcomes?
Is there encryption at rest and in transit for all AI training data?
Is there a process for responsible disclosure of AI model failures?
Are AI-related regulatory compliance requirements (GDPR, AI Act, etc.) tracked?