Compliance/AI Maturity Assessment
AI
Testing expected by auditors

AI Maturity Assessment penetration testing

AI Maturity Assessment (security-led AI readiness review)

A scored review of your AI readiness where the security domain is measured by live adversarial testing, not a questionnaire.

Sample report

Engagement at a glance

Drives testing

No external mandate: A voluntary baseline before you commit to a standard

Cadence

Every 6 to 12 months, or before a major AI launch

Typical duration

2 to 4 weeks end to end

Region

Global

Issued by

Advisory output from XHack. Not a certification. Mapped to ISO 42001 and the NIST AI Risk Management Framework

6

Domains assessed

5

Maturity levels

2 to 4 wk

Typical duration

3

Frameworks mapped

The requirement

What AI Maturity Assessment asks for

No external mandate · A voluntary baseline before you commit to a standard

This is not a regulatory requirement. It is the assessment organisations run before committing to ISO 42001 or preparing for AI Act obligations, to find out where they actually stand and what the gap costs to close.

Most organisations are shipping AI faster than they are governing it. The AI Maturity Assessment gives you an honest, scored picture of where you stand across six domains, and a roadmap that says what to do first.

What makes it different from a governance questionnaire is the security domain. Rather than asking whether you have guardrails, we attack your live AI systems with AI Probe and score what actually happens. A team that believes its chatbot is safe and a team that has watched it leak its system prompt have very different roadmaps.

The output is built for two audiences at once: a maturity scorecard and risk heat map for leadership, and a technical findings report for the engineers. Every recommendation maps to ISO 42001 and the NIST AI Risk Management Framework, so the work carries over if you certify later.

What your auditor checks

The report has to clear every one of these

These are the questions a AI Maturity Assessment auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.

Every domain scored against a defined five level scale

Each score supported by documented evidence, not opinion

Security domain measured by live adversarial testing

Full inventory of AI systems, models and vendors

Findings tied to concrete business and individual impact

Recommendations prioritised by effort and impact

Mapping to ISO 42001 and the NIST AI RMF

A readout that works for both board and engineering

A defined re-assessment cadence to show progress

Signed report from the testing firm, clearly marked as not a certification

What we test

Where the testing effort concentrates

The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.

Security and privacy of AI systems

Measured by live AI Probe testing

100%

Risk and regulatory alignment

ISO 42001, NIST AI RMF, EU AI Act

85%

Strategy and governance

Ownership, policy, accountability

80%

Data readiness

Quality, provenance, access, privacy

75%

Operations and evaluation

Monitoring, evals, change control

70%

People and skills

Awareness, roles, training

55%

Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.

How the engagement runs

Scope, test, close, attest

Typically 2 to 4 weeks end to end. The retest is included, because a report full of open findings is not evidence of anything.

01

Inventory and discovery

Week 1

Every AI system, model, vendor and integration in use, plus stakeholder interviews and document review across the six domains.

02

Live adversarial testing

Weeks 1 to 2

AI Probe runs against your real AI systems under agreed rules of engagement, so the security score reflects behaviour rather than intent.

03

Scoring with evidence

Weeks 2 to 3

Each domain scored from level 1 Initial to level 5 Optimised, with the evidence behind every score recorded so it can be challenged and re-tested later.

04

Roadmap and readout

Weeks 3 to 4

Quick wins for the next quarter, strategic moves for the year, each mapped to ISO 42001 and the NIST AI RMF, presented to leadership and engineering separately.

Where the effort goes

Share of a typical engagement, by phase

100%EFFORT

Discovery & interviews

25%

Live AI security testing

35%

Scoring & analysis

25%

Roadmap & readout

15%

What we bring

Built for the AI Maturity Assessment auditor specifically

The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.

Security measured, not claimed

The security domain is scored from real attack results against your live systems, which is what separates this from a maturity questionnaire.

Evidence behind every score

Five levels per domain, each justified by documented evidence you can put in front of a board or challenge internally.

A roadmap you can execute

Prioritised by effort and impact, with quick wins separated from the multi-quarter work.

Reusable when you certify

Every recommendation maps to ISO 42001 and the NIST AI RMF, so the work carries over if you certify later.

The deliverable

What lands on your auditor's desk

A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.

In the report

  • AI system, model and vendor inventory

  • Maturity scorecard across six domains on a five level scale

  • Risk heat map with the evidence behind each rating

  • AI Probe findings from your live systems, with transcripts

  • Prioritised roadmap separating quick wins from strategic work

  • Mapping to ISO 42001 and the NIST AI Risk Management Framework

  • Executive readout and a separate engineering briefing

Control mapping

How the report evidences each control

ISO 42001 impact assessment

Demonstrated AI risks feeding a real impact assessment.

NIST AI RMF Govern

Governance and accountability maturity scored with evidence.

NIST AI RMF Map and Measure

AI systems inventoried and their risks actually measured by testing.

NIST AI RMF Manage

A prioritised roadmap for treating the risks found.

EU AI Act readiness

Obligations mapped so you know what applies before it bites.

Where our work stops, and who takes it from there

XHack provides the penetration testing evidence for No external mandate. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For AI Maturity Assessment, that sits with: Advisory output from XHack. Not a certification. Mapped to ISO 42001 and the NIST AI Risk Management Framework. Staying independent of them is exactly what makes our evidence worth something when they review it.

Questions

AI Maturity Assessment testing, answered

No. It is an assessment that tells you where you stand and what to do next. Most clients run it before committing to ISO 42001 or preparing for AI Act obligations, because it turns a vague sense of risk into a costed plan.

By testing. AI Probe runs adversarial payloads against your live AI systems under agreed rules of engagement, and the score reflects what actually happened. A domain scored on evidence tends to land differently from one scored on a self-assessment.

Level 1 Initial is ad hoc with no defined practice. Level 5 Optimised is measured and continuously improved. The value is the delta between assessments, which is why we record the evidence behind every score.

Both audiences, deliberately separated. Leadership gets a scorecard, heat map and roadmap. Engineering gets the technical findings with transcripts and reproduction detail. One document, two entry points.

Get the AI Maturity Assessment evidence sorted

Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.

All frameworks