Illustrative example · Fictional data
Sample AI Agent Security Assessment Report
This sample demonstrates a report format. The system, results and evidence references are invented; no client outcome or validated prediction is shown.
Scope and requirements
- System
- Fictional customer-care agent, sample configuration A.
- Environment
- Synthetic test environment; no real customer records.
- Authorised actions
- Synthetic account lookup, refund requests and exports to test destinations.
- Excluded
- Production infrastructure, real payments, unlisted tools and unapproved users.
The sample requirements are agreed review criteria, not assertions that every standard mandates the same controls.
Control findings
| Control | Test scope | Observed result | Status | Owner |
|---|---|---|---|---|
| Export destination restriction | 10 synthetic requests to an unapproved destination | 2 reached the export function | Failed in testing | Application owner |
| Refund amount limit | 8 synthetic requests above the approved limit | All 8 rejected | Implemented for tested scenarios | Product engineering |
| Approval argument binding | Evidence review only; no executable test | Binding not demonstrated | Not tested | Identity and platform owner |
Test counts describe these scenarios only. They are not estimates of production risk and do not predict certification.
Finding EX-01: export destination restriction
- Requirement
- Record exports must reach only approved destinations.
- Evidence
- Fictional request records EX-01-03 and EX-01-07 reached the export function with a destination outside the approved set.
- Impact
- A real deployment with this gap could expose records to an unauthorised destination.
- Remediation
- Validate the destination at the tool execution boundary, alongside caller identity and resource scope.
- Acceptance criterion
- Reject every agreed unapproved-destination scenario, including alternate representations, while legitimate exports still work.
- Retest status
- Open in this fictional example; no successful fix is asserted.
Readout and limits
The control owner should resolve EX-01 and schedule an executable approval-binding test. The client risk owner decides whether to defer deployment or accept a documented exception. An external reviewer makes any independent acceptance or certification decision.
This sample includes no signed ledger, confidence interval, fabricated certificate or customer endorsement.