Governance. Risk. Compliance. Cybersecurity.
checklist

AI Platform VAPT Checklist

A 12-section, practitioner-grade checklist for scoping and executing penetration tests on LLM apps, RAG pipelines, agents and MLOps — mapped to OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF and ISO/IEC 42001.

23 June 2026AI SecurityVAPTLLMOWASP LLM Top 10MITRE ATLASNIST AI RMFISO 42001

What's inside

A downloadable PDF checklist used by our AI red team on real engagements. Twelve sections covering scoping, prompt injection, RAG and vector stores, agents and tool calling, sensitive-information disclosure, model DoS and cost, supply chain, MLOps, identity and tenant isolation, monitoring and IR, governance mapping (ISO 42001, NIST AI RMF, EU AI Act, CBUAE AI, SDAIA AI) and reporting.

Who it's for

  • Product and platform security leaders shipping LLM, RAG or agentic features
  • AI/ML platform teams building MLOps and inference infrastructure
  • GRC and assurance teams evidencing ISO 42001, NIST AI RMF or EU AI Act readiness

How to use it

Use it to brief your internal red team, score a third-party pentest proposal, or as the test-design backbone for an AI Platform VAPT engagement with MAST.

Related resources