AI systems introduce a fundamentally new attack surface that traditional security frameworks do not address. Models can be manipulated through carefully crafted inputs. Training data can be poisoned. Inference pipelines can leak sensitive information through model outputs. And the supply chain for open-weight models introduces risks that most procurement teams are not equipped to evaluate.

We developed this 25-point checklist based on security audits we have performed for enterprises across healthcare, finance, legal, and defense. Each control is mapped to an OWASP Top 10 for LLM Applications category where applicable.

Category 1: Model Access Control (Controls 1-5)