Home · Practices · AI Security Health Check

Where does your AI risk
actually sit?

A 4-week diagnostic across 14 dimensions and 4 pillars. RAG-scored, evidence-graded, designed for board, audit and regulator conversations.

01 · Deliverables

Two outputs. One clear picture.

Designed to sit on a board table without further translation.

DELIVERABLE · 01

Executive Scorecard

One page. RAG-scored across 14 dimensions and 4 pillars. The artefact your Chair can read in three minutes and your risk committee can table the same day.

1 PAGE · A3 OR A4 · PDF · BOARD-READY
DELIVERABLE · 02

Detailed Findings Report

10–15 pages. Evidence, findings, prioritised remediation roadmap, control owners, standards mapping. The artefact your auditor and CISO will work from.

10–15 PAGES · PDF + DOCX · AUDITOR-DEFENSIBLE
02 · Sample scorecard

What the Executive Scorecard looks like.

AI Security Posture Scorecard
14 DIMENSIONS · 4 PILLARS · RAG SCORED
DimensionGovernProtectOperateEnable
D01 Strategy & alignmentA
D02 Accountability & ownershipR
D03 Risk appetite & toleranceG
D04 Model governanceA
D05 Vendor & third-party governanceR
D06 Data governance & protectionG
D07 Model security & integrityA
D08 Identity & access managementG
D09 Supply chain & tooling securityA
D10 Monitoring & observabilityA
D11 Incident response & recoveryR
D12 Change & release managementA
D13 Capability & skillsG
D14 Culture & awarenessA
Priority items
RD02 · Establish named board-level AI accountability
RD05 · Issue vendor AI assurance attestation
RD11 · Document kill-switch authority and test rollback
SAMPLE PREVIEW · ANONYMISED · v1.2
03 · What we score

14 dimensions. 4 pillars.

Each dimension is scored RAG against the Mycelium AI Security Framework, mapped explicitly to APRA CPS 230, CPS 234 and AS ISO/IEC 42001.

Pillar I · Govern   DIM 01–05

D01
Strategy & alignment

AI strategy aligned to business strategy, with board-endorsed objectives, scope and explicit risk appetite.

D02
Accountability & ownership

Named board-level accountability for AI risk, with formal charter, RACI and reporting cadence.

D03
Risk appetite & tolerance

Explicit AI risk appetite, tolerance thresholds and escalation triggers, integrated with enterprise risk.

D04
Model governance

Lifecycle governance for AI models — approval gates, change control, performance review and decommissioning.

D05
Vendor & third-party governance

AI risk assessed at vendor onboarding and on annual re-certification cycle. Embedded AI explicitly covered.

Pillar II · Protect   DIM 06–09

D06
Data governance & protection

Data lineage, classification, retention and protection for AI training and inference data.

D07
Model security & integrity

Protection against model tampering, data poisoning, model extraction and prompt injection.

D08
Identity & access management

Role-based access, least-privilege defaults, secrets management and segmentation for AI systems.

D09
Supply chain & tooling security

Provenance and integrity of models, libraries, datasets and tooling across the AI supply chain.

Pillar III · Operate   DIM 10–12

D10
Monitoring & observability

Drift detection, performance baselines, anomaly alerting and audit logging on production AI systems.

D11
Incident response & recovery

AI-specific incident playbooks, kill-switch authority and tested rollback procedures.

D12
Change & release management

Controlled release process for AI model updates — documented testing, approval gates and rollback paths.

Pillar IV · Enable   DIM 13–14

D13
Capability & skills

Role-specific AI literacy, including board-level training refreshed on regulatory change.

D14
Culture & awareness

Organisation-wide AI awareness, responsible use protocols and a healthy reporting culture.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
04 · Methodology

Four weeks. Four phases.

A diagnostic, not a consulting engagement. Fixed scope. Fixed timeline. Fixed deliverables.

Week 1

Scope

Executive interviews, scope confirmation, evidence-request schedule. Stakeholder map agreed.

PHASE-01 · SCOPE
Week 2

Evidence

Document review, control walkthroughs, system inventory, frontline input. Artefacts collected.

PHASE-02 · EVIDENCE
Week 3

Score

RAG scoring across 14 dimensions. Findings drafted. Priority items identified.

PHASE-03 · SCORE
Week 4

Report

Executive Scorecard finalised. Detailed Findings Report delivered. Board read-out optional.

PHASE-04 · REPORT
05 · Editions

Sector-tuned where it matters.

Core 14 dimensions are constant. Evidence requirements and standards mapping are tuned to your sector.

06 · What you end with

Board-ready. Auditor-defensible. Regulator-ready.

01

An Executive Scorecard your Chair can table at the next risk committee.

02

A Detailed Findings Report your CISO and internal audit can work from immediately.

03

A defensible position before the auditor walks in or the regulator asks.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
07 · Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.

Book a diagnostic
30-MINUTE DIAGNOSTIC CALL · VIDEO OR MELBOURNE · BOOK DIRECTLY
Or download the Boardroom Diagnostic (PDF, 2 pages) ↗