Jump to Content

Risk Self Assessment

Every organization and AI implementation is unique. We developed this self-assessment for security practitioners, to help identify which AI risks may be most relevant to you.

Use this assessment to start conversations and guide further research.

Risk Self Assessment

This is a resource to help you understand which SAIF risks may be relevant to your organization.

It is for informational purposes only and does not constitute or replace professional advice. Your answers are not collected or shared. By continuing, you agree with the terms.

Learn more.

Risk Self Assessment

Risk Assessment Questions

Which of the following best describes your organization’s use of Generative AI models? You may select more than one option.

Risk Self Assessment

Risk Assessment Questions

Do you have robust management of all training, tuning, or evaluation data used with your models to ensure that sensitive, unauthorized, or malicious data does not enter your models?

Risk Assessment Questions

Are you able to detect, remove, and remediate malicious or accidental changes in your training, tuning, or evaluation data?

Risk Assessment Questions

Is any sensitive user data used in training, tuning, or evaluating your AI models?

Risk Assessment Questions

Do you have robust management of all user data that results from your Generative AI applications to ensure that user data is stored, processed, and used in accordance with user consents and user policies?

Risk Assessment Questions

Do you have a complete inventory of all models, datasets (for training, tuning, or evaluation), and related ML artifacts (such as code)?

Risk Assessment Questions

Do you have robust access controls on all models, datasets, and related ML artifacts to minimize, detect, and prevent unauthorized reading or copying?

Risk Assessment Questions

Are you able to ensure that all data, models, and code used to train, tune, or evaluate models cannot be tampered without detection during model development and during deployment?

Risk Assessment Questions

Are the frameworks, libraries, software systems, and hardware components used in the development and deployment of your models analyzed for and protected against security vulnerabilities?

Risk Assessment Questions

Do you protect your Generative AI applications and models against large-scale malicious queries from user accounts, devices, or via APIs?

Risk Assessment Questions

Are you using secure-by-default designs and coding frameworks in applications integrated with Generative AI applications?

Risk Assessment Questions

Do you perform adversarial testing and training on models and Generative AI applications to improve resistance to adversarial inputs?

Risk Assessment Questions

Do you build or deploy Generative AI powered agents or tools that can take actions on behalf of internal or external users?

SAIF Risk Report

Based on your self assessment answers, the following risks may be relevant to your organization.

This report has been shared with you. Start over to create your own report.

Assessment & risks

Risks which are relevant to your organisation

Risks which you have mitigated