Skip to main content

Your AI gets tested before your customer tests it.

ISO 42001 expects your AI systems to be verified and validated, and your customers' security teams are starting to ask the same question. Goldline tests your AI features the way an attacker would, and the findings land in your ISO 42001 evidence, mapped to the controls, with a retest to close them.

  • A free 45 minute diagnostic, not a sales call
  • A fixed price, agreed at scoping
  • Findings mapped to ISO 42001 and ISO 27001 controls
  • A retest within 30 days to close them
Book the free 45 minute diagnosticPick a time that suits you. Bring the AI feature, the questionnaire or the customer email.Same-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

CISSP, ISO/IEC 27001 Senior Lead Implementer and Lead Auditor, ISO/IEC 42001 Lead Implementer and Lead Auditor, PMP.

What a policy can't prove

ISO 42001's Annex A includes a control on the verification and validation of AI systems. A certification audit is evidence-based: it asks for the records that show the testing happened, not a policy saying it will.

When a customer's security questionnaire asks how the AI in your product has been tested for prompt injection and data leakage, this report is the answer.

Penetration testing covers the application, the APIs and the infrastructure. It doesn't test how the model behaves in use, and that's where these findings come from.

WHAT GETS TESTED

What gets tested

Prompt injection

Direct and indirect, including instructions hidden in documents and web content the model reads.

Data leakage

System prompts, other customers' data and personal data appearing in outputs.

Excessive agency

What an agent can do with its tools, and whether it can be steered into doing it.

Guardrail bypass

Whether the limits you've set on the model hold when someone works to get round them.

Insecure output handling

Model output passed into code, queries and downstream systems without being checked.

Access control

Who and what can reach the retrieval sources and integrations behind the model.

Detection

Whether an attack would be logged and noticed.

Testing follows the recognised attack classes for AI applications, including the OWASP Top 10 for LLM Applications, and is delivered by a specialist tester under written rules of engagement.

How it runs

01

Scoping call

The scope agreed and a fixed price set.

02

Rules of engagement

Signed before testing starts. Testing runs against staging by default.

03

Threat model

Built with your team, so the testing goes where the risk is.

04

Testing

Three to five days.

05

One report

Findings with reproduction steps and fixes, mapped to ISO 42001 and ISO 27001 controls.

06

Retest

Within 30 days, to confirm the fixes hold.

THE FEE

Three ways to buy

Single AI feature

£4,500 fixed

A chatbot, copilot or assistant over defined data.

Agentic system

£8,500 fixed

Agents with tools, actions and multiple data sources.

Continuous evaluation

From £9,500 to build, then £1,500 a quarter

An automated test suite built around your product that runs on every release, with a quarterly review.

Prices exclude VAT. The fee is fixed at scoping and does not move. Capacity is two assessments a month.

Start with the free 45 minute diagnostic

Forty five minutes, no charge. You keep the one-page roadmap either way.

WHAT YOU GET

One document

  • An executive summary a director can read.
  • Findings by severity, with reproduction steps and fixes.
  • A mapping table to the ISO/IEC 42001 Annex A controls on verification and validation (A.6.2.4), deployment (A.6.2.5), operation and monitoring (A.6.2.6) and event logging (A.6.2.8), and the ISO/IEC 27001 controls on the secure development life cycle (8.25), security testing (8.29), logging (8.15) and monitoring (8.16).
  • A retest statement confirming which findings are closed.

Written for the evidence folder.

What this is not

  • Not a guarantee that the system is secure. The report states what was tested, and what was found, on those dates.
  • Not certification, which only an accredited certification body issues.
  • Not an independent audit where Goldline implemented your ISO 42001. In that case it is verification evidence, which your certification body audits.

Common questions

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.