An AI audit involves mapping an organization’s AI attack surface. It is conducted exclusively through interviews and a review of documentation, without any technical actions on the systems. The functional audit answers a specific question before even considering a penetration test: Does the organization know what it has actually deployed, does it govern these deployments, and is it capable of responding in the event of an incident? This service, typically conducted over three to four days, is structured around seven areas that, when taken together, provide a comprehensive map of an organization’s AI exposure—going far beyond the mere technical inventory to which it is all too often reduced.
1. Mapping the AI Footprint and Shadow AI
This first area establishesa comprehensive inventory of the AI systems deployed within the company by cross-referencing four groups (infrastructure, developers, executives, and employees), while incorporating a detailed analysis of sensitive technical components such as vector databases, persistent memory, and MCP servers. It systematically compares the Shadow AI against the IT department’s declarations by analyzing DNS and proxy logs, and accurately documents outbound data flows (nature, destination, region) to lay the essential groundwork for any GDPR compliance initiative.
2. Governance and AI Policy
This area assessesthe existence of a structured governance framework and a designated person in charge by verifying the presence of a usage policy, DLP coverage, and a list of actions prohibited for autonomous agents, in accordance with ANSSI recommendations. It also verifies the traceability and observability of decisions (log retention, anomaly alerts, granularity of preprocessing at the plugin level) while auditing emerging risks, such as the leakage of strategic information via shared prompt libraries or indirect exposure related to queries submitted to models.
3. Regulatory and Contractual Compliance
This area intersects with four frameworks: the classification of systems under the European AI Act, the legal basis for the processing of personal data under the GDPR, the physical location of data processing for data submitted to model providers; and, for French organizations deploying sensitive systems in the public cloud, the advisability of using SecNumCloud-certified hosting provided by ANSSI. The contractual review of providers constitutes the second, and often most revealing, aspect: do the terms of service explicitly permit the use of submitted data for model training? What are the retention periods for prompts? Has an audit rights clause been negotiated with the provider?
4. AI Risk Management and API Key Security
This area verifies thatAI is explicitly integrated into the organization’scross-functional risk analysis, with a dedicated roadmap and metrics tracked by the security steering committee. The second focus area concerns the rigor of AI identity lifecycle management: Are API keys stored in a vault or in a plaintext configuration file? Is there a rotation policy in place? Are AI platform accounts included in the employee exit process? Finally, this area covers keeping the AI tools themselves up to date (extensions, libraries, self-hosted servers), following the same patch management process as the rest of the information system.
5. AI-connected business systems (ERP, CRM) and prompt injection
This division audits AI integrations in the organization’s financial, HR, and CRM software, with one common question for each: Does the AI have read-only access, or can it create and modify records? Is there human validation for actions with significant impact? Particular attention is paid to AI assistants connected toexecutive communications (emails, calendars, board meeting documents), where the risk of indirect prompt injection via an incoming message warrants explicit documentation in the risk analysis. Finally, this area covers the technical integration layer itself: encryption of data flows between AI and business applications, mutual authentication, and the use of scoped token protocols rather than broad credentials.
6. Protection Against AI Fraud: Deepfakes and Phishing
This area assesses—through OSINT analysis and a review of procedures rather than active simulation— the organization’s exposure to AI-assisted fraud: compromise of corporate email accounts enhanced by publicly available data on executives; voice or video deepfakes exploiting publicly available recordings; brand impersonation through content generation; and social engineering specifically targeting HR processes. For each scenario, the audit verifies the existence of an out-of-band verification procedure. A systematic reminder via a trusted channel before any transfer or sensitive action is approved remains the most robust protection against these scenarios. An active simulation of these techniques is possible but requires explicit inclusion in the engagement letter, separate from the standard functional audit.
7. AI Incident Response Plan and Operational Resilience
As the final area of the functional audit, it verifiesthe existence of playbooks specific to AI incidents (detected prompt injection, compromised agent, data leaks via an LLM, deepfakes currently in use) and their integration into the general incident management process with a defined escalation path. The ability to perform an emergency shutdown of AI agents is tested on a specific point: who has the authority and technical means to revoke, in a single centralized action, all of the organization’s API keys and agent tokens. Finally, this area covers the integration of AI scenarios into the crisis management plan and a question rarely asked elsewhere: Can the organization function without its AI systems, using documented and tested human fallback procedures?
AI Audit: Defining the Scope to Optimize the Penetration Test
These seven areas provide an overview that serves as the factual basis for the next technical phase: the AI penetration test, which actively tests the resilience of systems identified as priorities based on a real adversary’s attack chain. An audit conducted without this scoping phase risks spreading testing efforts across a poorly prioritized scope—a pitfall that the seven-domain structure is specifically designed to avoid.
→ See our guide to AI security services for a comprehensive overview of our penetration testing offerings.
Frequently Asked Questions
Does an AI audit require technical access to the systems?
How long does a comprehensive functional audit take?
Is MLOps included in the standard functional audit?
Conduct a functional audit of your AI systems
Our experts cover all seven of these areas to provide a comprehensive assessment of your AI exposure. Would you like to discuss your project or evaluate your needs? Contact our experts.

