
François B. Arthanas
Founder of CyberProsAI | Agentic AI Governance Advisor | CISSP, CISA, AAIA
Somewhere in your company, an AI agent is about to go live. It reads emails. It calls APIs. Maybe it can move money. And someone probably you is expected to say it's safe.
Most teams answer with assurances. "The vendor handles security." "We'll add the guardrails after launch." Assurances don't survive an incident, an audit, or a regulator.
This kit replaces assurances with evidence. One rule runs through it: tick a box only when you've seen proof a log, a config screen, a test result. Every unticked box becomes a finding with a named owner and a due date.
No tooling. No vendor. No 40-page framework to read first. Run your first review this week.
A 3-tier risk classification: A read-only summarizer and an agent that moves money don't deserve the same review. Tier first; the tier sets the depth.
The 36-check review across 9 domains: Identity and access, tools and actions, data protection, prompt injection, human oversight, observability, vendor risk, testing, incident readiness. Every check is a yes/no question a non-engineer can ask an engineer.
One framework anchor per check: NIST AI RMF, ISO/IEC 42001, EU AI Act, AIUC-1, OWASP, MITRE ATLAS so your review maps to standards your auditors recognize.
A go/no-go sign-off record: The one page a CISO or auditor actually wants to see: findings, decision, residual risk, signatures.
A fully worked example: A refund agent failing its review, including the crafted "customer" email that tricked it into paying out, and the no-go record that turned a near-headline into a three-week fix list.
Security, GRC, risk, and compliance professionals who just inherited "the AI thing"
AI governance leads who need a repeatable review stakeholders will actually complete
Practitioners building an AI governance portfolio run the worked example and you have a work sample
Anyone interested in AI and Agenting AI Governance
Free
Prove an AI agent is safe to ship. A tier-based 36-check review, a go/no-go sign-off record, and a fully worked example.