The short answer
An AI governance assessment examines policy, accountability, inventory, approvals, risk process, oversight, third parties, monitoring, and improvement. An AI security assessment examines how a system can fail, be manipulated, disclose information, enable misuse, or create operational harm—and whether the controls meant to reduce those risks work in context.
They overlap, but neither substitutes for the other. Strong policy cannot compensate for an application that lets untrusted content invoke a privileged tool. A well-defended application cannot compensate for unclear ownership or uncontrolled procurement.
What governance should establish
The best governance work is operational: named decisions, evidence expectations, escalation paths, and repeatable practices. A policy that cannot be traced to an operating system, responsible owner, and actual record is not yet an effective control.
- Which AI systems and uses are in scope, and who owns them
- How approvals, exceptions, escalation, and risk acceptance work
- Which evidence is required before deployment and after material change
- How incidents, performance drift, and decommissioning are handled
What security assessment should establish
Testing should be proportionate to the decision and environment. The objective is not a theatrical red-team exercise; it is defensible evidence about the risks that matter.
- Architecture, data flows, trust boundaries, models, suppliers, and tools
- Credible manipulation, disclosure, misuse, availability, and resilience scenarios
- Whether access, isolation, validation, monitoring, and human oversight are effective
- The consequence, priority, owner, and residual risk for material findings
The leadership test
Ask whether the work lets an accountable executive answer: What can go materially wrong? What evidence supports that view? Which controls are effective? What must change before the next decision? Who owns the residual risk? If the work cannot support those answers, its label matters less than its design.
Primary reference
Guidance should be checked for the version applicable to the decision date.
NIST AI Risk Management Framework