The Executive Diagnostic and Governance Toolkit
Artificial Intelligence Security Toolkit
Score your own artificial Intelligence Security red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
| 1 |
You stop guessing where you stand. You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis. |
| 2 |
You can defend the decision. You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language. |
| 3 |
The work actually moves. The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total. |
| 4 |
You use it the day it lands. No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over. |
The situation this is built for
Every day, new AI systems go live without clear ownership of security outcomes. You’re expected to know where risks live, how to rank them, and justify your focus—yet there’s no standard way to assess maturity across data, models, access, and compliance. When leadership asks why you’re fixing one problem over another, you need more than intuition. You need evidence, structure, and a defensible order of operations. Without it, your function appears reactive, not strategic.
Who this is for
The leader who owns artificial intelligence security within their organization. They are responsible for risk assessment, incident planning, compliance readiness, and resource allocation across AI systems. They report to technical or risk leadership and must justify priorities in cross-functional reviews.
Who this is not for
This is not for individual contributors implementing AI models, data scientists tuning algorithms, or vendors selling security tools. It is not for general cybersecurity teams without specific AI system oversight.
What you walk away with
- Map your organization’s AI security maturity across data, models, and infrastructure
- Rank risks by impact and urgency using a repeatable framework
- Defend your priority order in budget and planning meetings
- Align AI security decisions with regulatory requirements like the right to be forgotten
- Produce an auditable record of your assessment and roadmap
How this maps to your situation
- Assessing current state
- Prioritizing next actions
- Defending decisions
- Sustaining improvements
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed for completion over 12 weeks with practical application between modules.
How this compares to the alternatives
Unlike general cybersecurity courses or vendor-specific training, this program focuses exclusively on the leadership work of AI security: assessment, prioritization, and defense of decisions. It does not teach coding, tool configuration, or product features.
Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)
Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.
- Identifying all AI systems currently in production
- Mapping data sources feeding AI models and pipelines
- Documenting ownership and operational responsibility for each system
- Assessing model versioning and update frequency
- Classifying data types processed by AI systems
- Determining where unstructured data resides and how it is accessed
- Evaluating access controls for model training environments
- Reviewing logging practices for AI inference activity
- Inventorying third-party components in AI pipelines
- Assessing dependencies on external data providers
- Documenting model input and output specifications
- Creating a living register of AI assets
- Tracing personal data through AI training pipelines
- Measuring the volume of sensitive data used in models
- Evaluating anonymization effectiveness in training sets
- Identifying data leakage points during preprocessing
- Assessing data retention policies for model inputs
- Determining if synthetic data reduces exposure risk
- Auditing data sharing agreements with partners
- Evaluating data provenance tracking mechanisms
- Measuring data drift and its security implications
- Assessing encryption status of data at rest and in transit
- Identifying shadow data sources outside governance
- Mapping data flow across geographic boundaries
- Defining normal versus anomalous model output
- Assessing model confidence thresholds and drift
- Evaluating model susceptibility to adversarial inputs
- Measuring consistency of outputs across versions
- Identifying model bias as a security concern
- Assessing model explainability for audit purposes
- Evaluating model performance under stress conditions
- Determining if model logic can be reverse-engineered
- Assessing model sensitivity to input perturbations
- Reviewing model retraining triggers and criteria
- Measuring output variance over time
- Documenting model decision boundaries for review
- Defining what constitutes an AI security incident
- Classifying severity levels for model failures
- Mapping incident detection points in AI pipelines
- Establishing escalation paths for model anomalies
- Creating playbooks for data poisoning responses
- Developing response steps for model drift detection
- Designing rollback procedures for compromised models
- Identifying forensic data required after an incident
- Assessing notification requirements for affected parties
- Integrating AI incidents into existing SOC workflows
- Testing incident response with red team exercises
- Documenting post-incident model validation steps
- Evaluating GDPR compliance for AI training data
- Assessing right to be forgotten implementation gaps
- Mapping AI systems to data subject request workflows
- Evaluating model auditability for regulatory review
- Assessing algorithmic impact on protected groups
- Documenting model decisions for explainability audits
- Reviewing data minimization in AI pipelines
- Assessing cross-border data flow compliance
- Evaluating consent mechanisms for data use
- Measuring compliance with sector-specific regulations
- Preparing for AI-specific regulatory audits
- Documenting compliance controls for external assessors
- Estimating frequency of model degradation events
- Quantifying potential damage from data leakage
- Assessing probability of adversarial attacks
- Measuring impact of model downtime on operations
- Predicting exposure from third-party model use
- Estimating retraining costs after data breaches
- Assessing reputational risk from biased outputs
- Measuring compliance penalty exposure
- Forecasting incident volume based on system count
- Ranking systems by risk surface area
- Prioritizing fixes based on business impact
- Building a weighted risk scoring model
- Mapping roles with model deployment authority
- Reviewing access logs for model training environments
- Evaluating least privilege enforcement for data access
- Assessing service account security in pipelines
- Identifying overprivileged users in AI workflows
- Reviewing model registry access controls
- Auditing API key management for inference endpoints
- Measuring frequency of privilege escalation requests
- Assessing multi-factor authentication coverage
- Evaluating break-glass access procedures
- Documenting access revocation processes
- Tracking third-party vendor access to models
- Evaluating code review practices for model training
- Assessing version control for model artifacts
- Reviewing testing coverage for model behavior
- Measuring drift detection implementation rate
- Assessing model signing and integrity checks
- Evaluating rollback capabilities for failed deployments
- Reviewing CI/CD pipeline security for AI models
- Measuring model documentation completeness
- Assessing model deprecation and retirement process
- Evaluating monitoring coverage for inference endpoints
- Reviewing backup and recovery for model weights
- Assessing audit trail coverage across lifecycle
- Inventorying third-party AI models in use
- Assessing vendor security certifications
- Reviewing third-party model audit rights
- Evaluating data licensing terms from providers
- Measuring transparency of external model behavior
- Assessing risk from pre-trained model dependencies
- Reviewing contractual liability clauses
- Evaluating patching timelines for vendor models
- Assessing supply chain provenance for model components
- Measuring frequency of third-party security updates
- Reviewing exit strategies for vendor-dependent models
- Documenting fallback options during service outages
- Defining baseline behavior for model inference
- Setting thresholds for abnormal output patterns
- Measuring coverage of logging across AI components
- Assessing real-time monitoring for model drift
- Evaluating alerting effectiveness for data shifts
- Reviewing correlation between model and data logs
- Measuring mean time to detect model anomalies
- Assessing integration with existing SIEM tools
- Evaluating false positive rates in detection rules
- Designing dashboards for AI security posture
- Reviewing retention period for security logs
- Assessing automated response capabilities
- Structuring risk presentations for executive review
- Translating technical findings into business impact
- Building comparative risk heat maps
- Documenting assumptions behind risk scores
- Creating visualizations for priority trade-offs
- Preparing responses to 'why not this?' questions
- Aligning AI security priorities with business goals
- Demonstrating risk reduction over time
- Benchmarking against industry peer expectations
- Using historical incident data to justify investment
- Linking security efforts to compliance outcomes
- Communicating resource needs with clarity
- Scheduling recurring AI security posture reviews
- Assigning ownership for risk remediation tasks
- Measuring progress on priority fixes over time
- Updating risk models with new system data
- Incorporating lessons from incident responses
- Reviewing model inventory for obsolescence
- Assessing team capability gaps annually
- Updating playbooks based on new threats
- Measuring leadership satisfaction with reporting
- Evaluating automation of assessment steps
- Tracking maturity score changes over quarters
- Publishing annual AI security transparency report
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Thousands of organisations have bought from The Art of Service since 2000.