AI Security Due Diligence

A buyer-focused security due-diligence guide for AI-enabled services.

AI security due diligence should combine conventional SaaS security with AI-specific risks. The goal is not to collect badges; it is to establish whether the proposed service is securely designed, deployed and operated for the buyer's intended use.

Architecture and trust boundaries

Request a current view of hosting, model providers, retrieval systems, data stores, APIs, tools, agents and privileged integrations. Identify which components sit outside the supplier's direct control.

Identity and access

Check authentication, privileged access, tenant isolation, service accounts, secrets, administrative controls and least-privilege design. Agentic services need explicit limits on tool permissions and actions.

Secure development and supply chain

Review secure-development practice, dependency management, vulnerability handling, software/model supply chain, change control and relevant testing.

AI-specific threats

Depending on architecture, assess prompt injection, retrieval manipulation, unsafe tool execution, data leakage, poisoned content, insecure output handling, excessive agency and model/provider compromise.

Logging and investigation

Determine whether material user actions, administrative changes, tool calls, security events and model/version information can be investigated without creating disproportionate privacy risk.

Testing evidence

Relevant evidence can include penetration-test summaries, threat models, secure-development attestations, vulnerability records, red-team results and remediation evidence. Ensure tests match the actual production architecture.

Incidents and maintenance

Check notification, escalation, evidence preservation, patching, lessons learned and how material model/provider changes are handled after award.

The NCSC Guidelines for secure AI system development provide a useful lifecycle reference for secure design, development, deployment and operation.

How AI TrustMark fits

AI TrustMark can independently verify supplier security evidence within a defined product scope. It does not create NCSC accreditation or guarantee that a service is vulnerability-free.

Organisation-specific security questionnaires, technical evidence reviews, testing scopes, procurement matrices and remediation plans remain professional services.

Return to the AI Procurement Knowledge Base or read the NCSC Secure AI procurement guide.