Threat model walkthrough: prompt injection, exfiltration, poisoning
A field-tested checklist distilled from 40+ AI audit cycles across SOC 2, HIPAA, and GDPR. Covers threat model, data governance, prompt-injection defense, audit trail, vendor review, and incident response with acceptance criteria and evidence templates.
What's inside
Sections included in this template
Data governance controls: retention, redaction, purpose limitation
Authentication, authorization, and per-inference logging
Guardrails and output validation requirements
Model card and evaluation documentation requirements
Vendor risk review: OpenAI, Anthropic, Bedrock, Azure OpenAI
SOC 2, HIPAA, and GDPR cross-reference matrix
Incident response playbook with disclosure timelines
Evidence artifact templates for each control
Download
Get the full editable template
Edit freely. No login, no drip sequence, no retargeting pixel circus.
