Guides
AI Agent Security Review Readiness Checklist
Gather scope, controls and evidence before a buyer or internal review.
System and ownership
- Identify the system version, deployment, business owner and risk owner.
- Inventory agents, tools, identities, credentials and data flows.
- Identify high-impact actions and the requirements governing them.
- Record supplier dependencies and change notification arrangements.
Controls and tests
- Define permitted actions, resource boundaries and approval conditions.
- Record where permissions and argument checks are enforced.
- Test denied and allowed actions in an authorised environment.
- Test approval expiry, altered requests, unavailable dependencies and rollback.
- State test counts, observed results and coverage exclusions.
Evidence and decisions
- Index configuration, test and approval records against requirements.
- Assign each finding a remediation owner and acceptance test.
- Separate implemented, missing, failed and untested controls.
- Record unresolved risks and who can accept them.
- Set change triggers and the next review date.
This is a preparation checklist, not a certification or risk score.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.