Assessment methodology

Evidence-led review. Established frameworks. Explained judgment.

Ayliea runs an independent, evidence-led AI security assessment and maps relevant findings to recognized frameworks—not to a proprietary standard, and not as a substitute for professional judgment.

Independent assessmentFramework-mappedEvidence → Findings → Signed conclusion

THE ASSESSMENT

Methodology is supporting proof. The human-led assessment is the product.

The assessment evaluates the AI environment, sensitive-data flows, safeguards, and evidence, then maps relevant findings to established AI security frameworks. Ayliea is not a certification body; mapping and alignment describe how findings relate to those frameworks, not a certification against them.

Framework references support consistency and comparison. A methodology cannot decide whether supplied evidence is sufficient or interpret business context on its own; those judgments are explained in the report and attributable to the named assessor.

01Control domain
02Evidence
03Finding
04Severity
05Framework mapping
06Signed conclusion

STRUCTUREDefined control domains, sub-controls, and a documented scoring approach

TRACEABILITYEvidence references connected to findings

CONTEXTProfessional interpretation of impact and limitations

ACCOUNTABILITYNamed-assessor conclusion and sign-off

Evidence quality

A conclusion is only as clear as its evidence state.

Completed reports identify how each material statement was established and qualify conclusions when evidence is incomplete, stale, conflicting, or unavailable.

OBSERVED

Observed

The assessor directly inspected an in-scope artifact, setting, workflow, or demonstration.

SUPPLIED

Supplied

The client or a provider supplied documentation that the assessor reviewed within the agreed scope.

REPRESENTED

Represented

A stakeholder described a practice or condition that was not independently established by other evidence.

NOT-TESTED

Not tested

The item was in scope for discussion, but technical validation or another procedure was not performed.

NOT-ASSESSED

Not assessed

The item was outside the agreed scope, unavailable, or intentionally excluded from the conclusion.

Judgment and limitations

Reproducible does not mean judgment-free.

Severity

The report explains impact, likelihood, evidence confidence, and contextual factors rather than presenting an unexplained label.

Missing evidence

Unavailable or conflicting evidence is recorded and can limit confidence, alter severity, or leave an item not assessed.

Point in time

Every completed report identifies its assessment period or date, evidence cutoff, and change-after-assessment boundary.

Assessor override

Any departure from a mechanical result should be explained with evidence, context, and a named professional judgment.

Framework positioning

Relevant references, used carefully.

NIST AI RMF 1.0

NIST

AI risk management across Govern, Map, Measure, and Manage functions. Findings are mapped to AI RMF functions. NIST does not endorse Ayliea or any assessor.

ISO/IEC 42001:2023

ISO/IEC

AI management system (AIMS) requirements. Controls and evidence are assessed against ISO/IEC 42001 concepts. Mapping is not certification; Ayliea is not a certification body.

HIPAA Security Rule

HHS

Safeguards for electronic protected health information. Relevant findings are mapped to applicable safeguards. Not a HIPAA certification or legal opinion.

OWASP LLM Top 10

OWASP

Top security risks for LLM applications. Used to frame AI-specific application security findings. OWASP does not endorse Ayliea.

MITRE ATLAS

MITRE

Adversarial threat landscape for AI systems. Used to describe AI-specific adversarial threats where relevant. MITRE does not endorse Ayliea.

Frameworks we map to

Established standards, not a proprietary one.

Relevant findings are mapped or aligned to recognized AI security frameworks so a receiving reviewer can place them in a familiar context. Mapping and alignment are not certification, endorsement, or a legal opinion, and Ayliea is not a certification body.

Next step

Have a healthcare security review coming up?

Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.

  • Clarify the review request
  • Identify systems and evidence
  • Define a defensible scope