Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Security assurance
  3. AI security and governance assessment

Security assurance

AI security and governance assessment

We assess how your organisation adopts, governs and secures AI, from staff copilots to the systems you build, with evidence rather than a questionnaire.

Scope a test Call 1300 AURIAN

Who this is for

  • You are in government, or supply it, and AI use must be accounted for

    Commonwealth agencies answer to the policy for the responsible use of AI in government, NSW agencies to the AI Assessment Framework, and their suppliers are being asked the same questions.

  • You are rolling out Copilot, or staff already use AI tools of their own

    An assistant over the Microsoft 365 tenancy reads everything a user can reach, including the files nobody meant to share, and consumer tools keep whatever is pasted into them.

  • A board, customer or insurer has asked how AI is governed

    Board papers, due-diligence questionnaires and renewal forms now ask what AI is in use, who owns it and what controls sit around it, and the answer needs evidence behind it.

What our AI security assessment covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers Artificial intelligence INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE Microsoft 365 Copilot and tenancy configuration What each vendor retains and trains on Audit logging of prompts and tool calls EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: CHECKS INCLUDE Consumer AI tools and browser extensions in use Data loss prevention on what staff paste and upload IDENTITY: CHECKS INCLUDE Who can reach which AI services Permissions held by agents and integrations Conditional access for AI tools WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: CHECKS INCLUDE Oversharing reachable through an assistant Sensitivity labels on the data that matters Client and personal data sent to vendors SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. ARTIFICIAL INTELLIGENCE: CHECKS INCLUDE Inventory of AI in use, sanctioned and otherwise Ownership, policy and vendor terms Human oversight and transparency Permissions held by copilots and agents Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers Artificial intelligence INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE Microsoft 365 Copilot and tenancy configuration What each vendor retains and trains on Audit logging of prompts and tool calls OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: CHECKS INCLUDE Consumer AI tools and browser extensions in use Data loss prevention on what staff paste and upload WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: CHECKS INCLUDE Who can reach which AI services Permissions held by agents and integrations Conditional access for AI tools CROWN JEWELS: CHECKS INCLUDE Oversharing reachable through an assistant Sensitivity labels on the data that matters Client and personal data sent to vendors SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. ARTIFICIAL INTELLIGENCE: CHECKS INCLUDE Inventory of AI in use, sanctioned and otherwise Ownership, policy and vendor terms Human oversight and transparency Permissions held by copilots and agents

We assess the organisation's AI use as a whole, sanctioned and otherwise, against ISO/IEC 42001, the NIST AI Risk Management Framework and the Voluntary AI Safety Standard, testing the controls that matter rather than reading the policy.

  • An inventory of AI in use, covering assistants, copilots, AI features in vendor products, systems you build and the tools staff have adopted on their own
  • Governance, including an accountable owner, an acceptable-use policy, risk assessment before adoption and a register of AI systems
  • Data governance, covering what each model can retrieve, what is sent to vendors, and what they retain and train on
  • Microsoft 365 Copilot and tenancy configuration, including oversharing, sensitivity labels, data loss prevention and audit logging
  • Identity and access to AI services, from who can use which model to what agents and integrations can do with their permissions
  • Human oversight and transparency where AI output reaches decisions, customers or the public
  • Logging, monitoring and incident response for AI systems, including records of prompts and tool calls

How we test it

AI arrives in an organisation three ways at once: switched on inside products it already pays for, rolled out as a copilot over the tenancy, and adopted by staff who found a free tool that does part of their job. Each route brings data to a model and a model to a decision, and few organisations can list all three, let alone say who owns each one. An Aurian AI security and governance assessment starts with that list, then measures what surrounds every entry on it against the standards boards, regulators and customers now ask about: ISO/IEC 42001, the NIST AI Risk Management Framework and the ten guardrails of Australia’s Voluntary AI Safety Standard.

The method is the one we apply to the Essential Eight: test the control rather than read the policy. A policy that forbids pasting client data into consumer chatbots is tested by trying it through the proxy from a standard account. A Copilot deployment described as respecting permissions is tested by asking it, as an ordinary user, for payroll, board papers and the personnel file, because it will find whatever the permissions already allowed. Vendor terms are read against what the tenancy actually sends and what the privacy policy promised. Each control area is rated with the evidence behind it, so the rating holds up in front of an auditor, a regulator or a customer’s security team.

The report leads with the gaps that carry the most risk, usually the sharing nobody knew about and the tools nobody had approved, and gives a roadmap ordered by risk reduction and effort. Where one assistant or agent faces customers or acts on their behalf, our AI penetration test takes it apart in depth, and the assessment tells you which ones deserve that.

Standards ISO/IEC 42001, NIST AI Risk Management Framework, Voluntary AI Safety Standard, ASD guidance on engaging with and deploying AI

  1. 01 Inventory

    We build the real list of AI in use from the tenancy, the network and the people, because the tools an organisation does not know about are the ones nobody has governed.

  2. 02 Governance review

    A consultant reviews ownership, policy, risk assessment, vendor terms and records against ISO/IEC 42001, the NIST framework and the ten guardrails of the Voluntary AI Safety Standard.

  3. 03 Testing the controls

    We test what the controls actually do. We ask a standard user's Copilot for payroll files, paste a client record into a consumer chatbot through the proxy, and check what each vendor retains against what the contract says.

  4. 04 Rating and roadmap

    You receive a rating for each control area with the evidence behind it, a gap analysis against the standard you nominate and a prioritised roadmap ordered by risk reduction and effort.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

High AUR-2026-014 Sample finding, fictional environment

Copilot surfaces payroll files through tenancy-wide sharing

Affected asset
Microsoft 365 Copilot, a standard staff account
Rating
High Likely 4 × High 4 = 16

Description

A standard user asked Copilot for the current salary review and received a summary of a payroll spreadsheet, with a citation to the file. The file sits in a human resources SharePoint site shared with everyone except external users, a setting applied years ago to make a single policy document easy to find. Copilot honours permissions exactly; the permissions were already wrong, and Copilot made them searchable in plain English.

Evidence

prompt   > Summarise the FY26 salary review and list the biggest increases.
Copilot  > Based on "Payroll review FY26.xlsx" (HR Team site, modified
           12 August 2026): 214 staff were reviewed. The largest increases
           were [names and salaries follow] ...
# account: a.nguyen, standard user, not a member of HR
# site sharing: "Everyone except external users", set 14 March 2021

A standard user's Copilot summarised the payroll spreadsheet, named the file and the site, and listed salaries by name.

Impact

Every staff member can read every salary, and the same sharing exposes whatever else the site holds. Before Copilot the files were reachable but unfound; now a question in plain English finds them, and the first person to ask is unlikely to report it. Payroll data is personal information under the Privacy Act 1988, and an organisation that cannot say who has read it cannot answer the questions the Notifiable Data Breaches scheme asks.

Remediation

Treat it as a sharing problem first: use the sharing reports in SharePoint's data access governance to find every site shared with everyone or with large groups, restore least privilege, and restrict content discovery for the sites that cannot be fixed at once. Apply sensitivity labels to the payroll library with a data loss prevention policy that keeps labelled content out of Copilot responses, and review Copilot activity in the audit log for who has already asked.

References

  • ASD, Engaging with Artificial Intelligence
  • Microsoft Learn, oversharing and Microsoft 365 Copilot
  • Executive summary with the overall position and the headline gaps, written for the board
  • A register of the AI systems and tools in use, sanctioned and otherwise, with an owner recorded for each
  • A rating for each control area against the standard you nominate, with the evidence behind it
  • A prioritised uplift roadmap, ordered by risk reduction and effort
  • A debrief call to walk your team through the ratings and the roadmap

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Nobody owns the AI

    Tools adopted team by team with no accountable owner, no register and no risk assessment before adoption, so nobody can say what is in use or on what terms.

  • Copilot reaches files nobody meant to share

    Sites shared with everyone and libraries without sensitivity labels, reachable for years but unfound until an assistant answered a question in plain English.

  • Client data in consumer tools

    Staff pasting documents, records and code into free chatbots whose terms permit training on the input, past a data loss prevention policy that never named them.

  • Vendor terms unread

    AI features switched on inside existing products, with retention, training and sub-processor terms that nobody has compared against the privacy policy or client contracts.

  • Agents with standing permissions

    Integrations and agents holding broad, permanent access to mail, files and systems where the user they serve has far less, and no log of what they did with it.

  • Output trusted without oversight

    AI output reaching customers, decisions or published material with no review step, no disclosure, and no way for the people affected to challenge it.

Frequently asked questions

Is this an audit or a certification?

Neither. It is an independent assessment against the standard you nominate, with evidence gathered by testing controls rather than reading policy. It is not an ISO/IEC 42001 certification audit, and Aurian is not a certification body; organisations preparing for certification use it to find the gaps first.

Which standard should we assess against?

Most organisations start with the ten guardrails of the Voluntary AI Safety Standard, which the Australian Government published for this purpose, and map the result to ISO/IEC 42001 or the NIST AI Risk Management Framework where a customer, regulator or parent company asks for one. Government agencies add their own policy, such as the Commonwealth policy for the responsible use of AI in government or the NSW AI Assessment Framework. We agree the standard at scoping and name it in the report.

How is this different from AI penetration testing?

A penetration test attacks one assistant or agent to show what an attacker can reach through it. This assessment looks at the organisation: every AI system and tool in use, who owns each, what data they reach and what governs them. Organisations that have built something customer-facing usually need both.

Does it cover Microsoft 365 Copilot?

Yes, and for most organisations that is where the findings are. We review the tenancy's sharing, sensitivity labels, data loss prevention and audit settings, then test them from a standard user's account by asking Copilot for what that user should not be able to find.

What do you need from us?

A technical contact, read access to the Microsoft 365 or Google Workspace tenancy and the identity platform, the AI policy and vendor agreements you hold, a standard user account for testing, and a few hours of your team's time across the engagement. We send the list at scoping so nothing is a surprise.

How long does it take?

It depends on the size of the tenancy and the number of AI systems and vendors in scope: typically three to ten days, with the report following. We confirm the timeframe after scoping.

Related services

AI penetration testing

AI penetration testing of chatbots, copilots, agents and LLM features: prompt injection, retrieval authorisation, tool abuse and the application around them.

Essential Eight assessment

Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

Configuration review and benchmarking

Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Security assurance and compliance services

Scope an assessment with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.