VIPRE® Statement of Work for AI Assurance Testing Services

Last updated July 15, 2026

Table of Contents

This SOW is entered into between you (referred to as you, your, or Customer) and VIPRE Security Group, Inc. (referred to as VIPRE). VIPRE is offering comprehensive VIPRE AI Assurance Testing services through five distinct packages, each designed to meet diverse AI assurance needs. Customers will select one of the packages shown in Table 1: VIPRE AI Assurance Testing — Packages based on their specific requirements and desired scope of assessment. 

VIPRE AI Assurance Testing employs a structured approach to discover, assess, and validate the trustworthiness of AI systems—including large language models, commercial AI applications, autonomous agents, and predictive models. Depending on the purchased package tier, assessments combine automated evaluation with expert analyst review to score systems across relevant trust dimensions and map findings to globally recognized AI risk and regulatory frameworks (such as the EU AI Act, NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, and MITRE ATLAS). This independent, platform-driven methodology delivers context-adjusted insights, regulatory alignment, and prioritized remediation guidance. 

VIPRE will adhere to the testing timelines, testing windows, and scope boundaries confirmed in the Technical Scoping Document, and will deliver a report outlining (depending on the purchased package) identified trust gaps, compliance deficiencies, and security vulnerabilities, together with prioritized and actionable remediation recommendations. The specific package, testing scope, AI systems in scope, and deliverables that apply to any given Customer are set out in the Order Form and Technical Scoping Document executed between VIPRE and that Customer.

The following capitalized terms will have the definitions set forth below. All other capitalized terms that are not defined herein shall have the meanings accorded to them in the MSA (as defined below).

Adversarial Testing: Structured probing of an AI system using crafted inputs designed to expose safety failures, security vulnerabilities, bias, or harmful outputs that would not surface during normal use.

Agentic AI System: An AI system capable of executing multi-step tasks autonomously, calling external tools or APIs, and taking actions with real-world consequences, including but not limited to file operations, transactions, and communications.

AI System: Any model, application, agent, or automated workflow in which an artificial intelligence or machine learning component materially influences an output or decision. This includes large language models, fine-tuned models, commercial AI SaaS applications, autonomous agents, and predictive or classification models.

Bias & Fairness Audit: A structured, documented assessment of an AI system’s outputs for systematic differences based on protected characteristics, producing findings suitable for regulatory submission.

Customer: An individual, company, or other legal entity that contracts with VIPRE and agrees to purchase VIPRE AI Assurance Testing services.

EU AI Act: Regulation (EU) 2024/1689 of the European Parliament and of the Council, laying down harmonized rules on artificial intelligence.

Final AI Trust Assessment Report: A report containing the consolidated results of all assessment, testing, and analysis phases completed under an engagement. Depending on the package purchased, the Final AI Trust Assessment Report comprises a Technical Findings report and, where applicable, an Executive Summary.

ISO/IEC 42001: The international standard for AI Management Systems, providing a framework for organizations to manage AI-related risks and demonstrate responsible AI governance.

MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems — a globally recognized knowledge base of adversarial tactics, techniques, and case studies targeting AI systems.

MSA: The VIPRE Master Services Agreement that this SOW is subject to, which is available at Master Services Agreement – VIPRE.

NIST AI RMF: The NIST AI Risk Management Framework (AI RMF 1.0), providing guidance for managing risks associated with AI systems across Govern, Map, Measure, and Manage functions.

OWASP LLM Top 10: The Open Worldwide Application Security Project’s Top 10 critical security risks for Large Language Model applications, including prompt injection, sensitive information disclosure, and excessive agency.

Order Form: A document issued by VIPRE to a Customer that records the specific package selected commercial terms, and any additional parameters applicable to that Customer’s engagement. Each Order Form references and is subject to this SOW and the MSA.

Deployment Recommendation: The overall readiness verdict included in the Final AI Trust Assessment Report, based on the weighted Overall Score. Verdicts are: Approved (90-100), Ready with Standard Monitoring (80-89), Conditional Deployment with Safeguards (70-79), Limited Deployment with Enhanced Oversight (60-69), or Not Recommended for Production (0-59).

Protected Attribute: A characteristic of an individual protected under applicable anti-discrimination law, including but not limited to race, ethnicity, sex, age, disability, religion, and national origin.

Questionnaire: Provided to Customer, which will need to be completed to provide information on AI systems to be assessed.

Revalidation: VIPRE will perform one revalidation check to confirm that Critical and High trust gaps, compliance deficiencies, and security vulnerabilities identified in the Final AI Trust Assessment Report are resolved. Customer must request Revalidation from VIPRE within 90 days from the date that VIPRE provides the Final AI Trust Assessment Report to Customer.

SCQA Framework: Situation-Complication-Question-Answer: a structured communication framework used in the Executive Brief section of the Final AI Trust Assessment Report to present evaluation findings in a clear, executive-friendly format.

SOW: This Statement of Work.

Sub-Dimension: A specific aspect evaluated within a broader trust dimension. For example, Jailbreak Resistance, Data Leakage Prevention, Boundary Enforcement, and Prompt Injection Resistance are sub-dimensions of Security & Vulnerability. Each sub-dimension is individually scored and contributes to the parent dimension score.

Technical Scoping Document: The supplementary document provided by VIPRE prior to engagement commencement that details the specific AI systems in scope, testing parameters, access requirements, and confirmed engagement timeline. The Technical Scoping Document forms part of this SOW once countersigned by both parties.

10-Dimension Trust Framework: VIPRE’s structured AI assessment methodology evaluating every in-scope AI system across ten dimensions: Accuracy, Bias & Safety, Context Awareness, Enterprise Alignment, Hallucination Resistance, Instruction Adherence, Reasoning, Security & Vulnerability, Specialization, and Cost & Latency. Each dimension is scored on a 0-100 scale and carries a context-adjusted weight based on the AI system’s application type, user persona, and deployment domain.

AI Assurance Bench: VIPRE’s automated adversarial evaluation capability that assesses AI systems against an extensive curated library of evaluation prompts spanning difficulty levels (Easy, Medium, Hard, Expert), domains, task types, and adversarial edge cases. Each response is scored by an expert LLM judge across five criteria: Task Completion, Accuracy/Quality, Safety/Compliance, Format/Structure, and Context Awareness.

AI Assurance Certification: An independent certification awarded to AI systems that successfully satisfy the defined trust evaluation standards. Certification is not guaranteed and is reserved exclusively for systems that fully meet all evaluation criteria. Availability is subject to the package purchased. 

VIPRE AI Assurance Testing is offered through five packages. Each option is designed to address a different assessment need — from a targeted scan of a single AI system through to a fully managed annual assurance program covering an organization’s entire AI estate. The applicable package is confirmed in the Order Form.

All services are delivered remotely by VIPRE unless otherwise agreed in the Technical Scoping Document. All testing is non-destructive, non-intrusive, and will have minimal impact on performance.

Table 1: VIPRE AI Assurance Testing — Packages
CustomQuick ScanStandardComprehensiveAnnual Plan
Credits102550100600
Dimensions AssessedChoose one dimension3 dimensions5 dimensionsAll 10 dimensionsAll 10 dimensions — (10 credits / dimension) 
Report TypeDimension ReportRaw Scores OnlySummary ReportFull ReportFull Report (10-dim runs) or Dimension-specific (partial runs) 
Executive ReportIncludedIncluded for 10-dimension runs
Compliance MappingTargeted to selected dimensionBasic (1 framework)Full — all applicable frameworksFull — all applicable frameworks
Dedicated Technical Account ManagerOptional1Optional2Included
One Revalidation TestIncluded when >100 credits purchasedIncluded1 per year included (0 credits) 
AI Assurance CertificationIncluded w/passing scoreIncluded w/passing scoreIncluded w/passing score
1 Dedicated Technical Account Manager can be purchased as an add-on to the service.
2 Dedicated Technical Account Manager can be purchased as an add-on to the service.


Commercial Terms & Credit Rules

  • Upfront Payment & Fee Structure: All fees for VIPRE AI Assurance Testing packages (including one-time report packages and annual credit allocations) are invoiced and payable 100% upfront. All upfront fees paid are fully earned upon receipt and are strictly non-refundable. 
  • Packages 1–4 Expiration: For all one-time run/report packages (Quick Scan, Standard, Comprehensive, and Custom), testing activities must be initiated by the Customer within ninety (90) days of the Order Form effective date. Because underlying compliance frameworks and threat parameters undergo continuous updates, failure to initiate testing within this window results in package expiration without a right to refund or credit rollover.
  • Package 5 Annual Plan Credit Expiration: The annual term, renewal terms, and any credit allocations are as set out in the Order Form. The 600 credits provided under the Annual Plan are valid strictly for a period of twelve (12) months from the Order Form effective date. Any credits remaining unconsumed at the conclusion of this 12-month period automatically expire and are forfeited. No refunds, credits, rollovers, or offsets will be issued for unconsumed annual pool credits. 
  • Overage Trigger: If the Customer consumes the allotted 600 credits prior to the expiration of the 12-month annual plan term, active testing and evaluation capabilities will be paused. To resume testing services, the Customer must purchase an additional block of credits at VIPRE’s volumetric pricing via a written amendment or change order to the Order Form. 


Custom

A targeted, dimension-level assessment for organizations that need focused insight into one or more specific areas of AI trust — rather than a full ten-dimension evaluation. Custom allows the assessment to be directed precisely at the dimensions most relevant to a specific risk or compliance concern.

  • Choose any dimension(s) from the 10-Dimension AI Trust Framework.
  • Dimension Report — targeted findings and insights for each selected dimension, with specific remediation guidance.
  • Applicable to any AI system type.
  • Compliance mapping targeted to the regulatory requirements relevant to the selected dimension(s).

Custom is also suited to organizations that have completed a prior VIPRE AI Assurance Testing engagement and wish to re-assess a specific dimension following remediation, or to assess a new dimension in response to a changed regulatory requirement.

Quick Scan

A rapid, targeted scan provides an immediate view of AI risk across three trust dimensions for a single AI system. Quick Scan is designed for organizations that need a fast, cost-effective first look at a specific AI system — whether ahead of deployment, in response to a regulatory query, or as a preliminary step before commissioning a fuller assessment.

  • 3 trust dimensions assessed — selected by VIPRE based on the system type and use case, or as directed by you.
  • Raw Scores Report — dimension-level trust scores with risk highlights. Does not include detailed finding narratives or remediation guidance.
  • Applicable to any AI system type: LLM, predictive model, COTS application, or autonomous agent.

Standard

A structured assessment covering up to five trust dimensions, with basic compliance mapping and a summary report. Standard is suited to organizations seeking a broader view of AI risk than a Quick Scan provides, with an initial indication of compliance posture against a relevant regulatory framework.

  • Up to 5 trust dimensions assessed — selected in the Technical Scoping Document based on the system’s risk profile and regulatory context.
  • Summary Report — findings across selected dimensions with risk ratings and basic compliance mapping.
  • Basic compliance mapping against one applicable regulatory framework.

Comprehensive

A comprehensive full-estate assessment covering all ten trust dimensions, with a full report, executive summary, complete compliance mapping, and 30 days of post-delivery analyst support. Comprehensive is the primary choice for organizations with active regulatory obligations, pre-deployment validation requirements, or the need to demonstrate structured AI assurance evidence to internal or external stakeholders.

  • All 10 trust dimensions are assessed.
  • Full Report — detailed findings across all dimensions; severity-rated findings with specific remediation recommendations.
  • Executive Report — a non-technical summary of overall AI risk posture and top findings, suitable for board and executive audiences.
  • Full compliance mapping across all applicable regulatory frameworks confirmed in the Technical Scoping Document.
  • 30 days of post-delivery analyst support — access to the VIPRE AI Assurance Testing team to discuss findings, clarify recommendations, and advise on remediation priorities.
  • Revalidation — one revalidation check within 90 days of Final AI Trust Assessment Report delivery to re-assess the in-scope trust dimensions and measure score optimization following the Customer’s implementation of the provided remediation recommendations. 

Annual Plan

A structured annual AI assurance program for organizations requiring continuous, programmatic evaluation across their AI estate. The Annual Plan provides an annual allocation of six hundred (600) credits to be consumed dynamically throughout the term, custom benchmarks tailored to your industry, and dedicated advisory support via an assigned Technical Account Manager (TAM) to help orchestrate your assessment portfolio. 

  • 600-Credit Annual Pool — All evaluation and testing workloads are drawn directly from a dedicated annual bank of 600 credits. 
  • Comprehensive Assessments — Full-estate reviews evaluate all 10 trust dimensions, consuming 100 credits per system evaluation. 
  • Scaled Reporting Deliverables — Full Report and Executive Report deliverables are provided for comprehensive 10-dimension evaluations. For partial or custom runs evaluating a limited subset of dimensions, reporting will be scaled accordingly to cover only the selected dimensions. 
  • Full Compliance Mapping — Tailored mapping against all applicable regulatory and industry frameworks based on full-estate assessments. 
  • Custom Benchmarks — Assessment baselines configured specifically to your organization’s industry, risk profile, and internal governance standards. 
  • Annual Revalidation Allowance — Includes one (1) comprehensive revalidation run during the annual term to confirm the optimization of identified trust gaps. This single annual revalidation run does not consume credits from the Customer’s annual pool. 

Technical Account Management (TAM)

To maximize the utility and strategic distribution of the 600-credit annual allocation, Annual Plan customers are partnered with a dedicated VIPRE Technical Account Manager. The TAM acts as a collaborative advisory partner, working alongside the Customer’s internal teams to coordinate assessment pacing, map system coverage, and help translate evaluation metrics into actionable model optimization.

Core TAM Responsibilities:

  • Estate Mapping & Assessment Architecture: The TAM collaborates with internal stakeholder teams to catalog your expanding AI footprint, identify high-risk implementations, and advise on optimal scoping strategies (e.g., executing a full 100-credit evaluation on production-bound, customer-facing agents versus a targeted 10-credit single-dimension evaluation on internal tools).
  • Credit Pacing & Consumption Strategy: To prevent year-end credit expiration or premature depletion, the TAM develops a customized quarterly consumption roadmap aligned with your engineering product release cycles and deployment schedules.
  • Delta Assessment Planning: Following system updates, prompt-engineering modifications, or model fine-tuning, the TAM aids in structuring targeted “delta assessments” to re-verify specific affected dimensions without necessitating a complete multi-dimension audit.
  • Guardrail Guidance: The TAM reviews evaluation outputs with your teams, sharing findings to help inform possible tuning recommendations.

VIPRE AI Assurance Testing is delivered through a combination of structured assessment methodologies, automated evaluation, and expert analyst review. The testing options and methods described in this section represent the full range of activities available under VIPRE AI Assurance Testing services.

All testing is performed remotely by VIPRE analysts. All testing is non-destructive and conducted within the agreed testing windows and scope boundaries.

1. 10-Dimension AI Trust Assessment

The 10-Dimension AI Trust Assessment is the foundation of every VIPRE AI Assurance Testing engagement. Each AI system confirmed in scope is evaluated across one or more (depending on the selected package) of the ten structured trust dimensions using a combination of automated evaluation and expert analyst review. The assessment produces a dimension-by-dimension trust score for each system, together with specific, evidenced findings and remediation recommendations.

The ten dimensions are:

Dimension 1 — Safety

Evaluation of whether the AI system can be induced to produce outputs that cause physical, psychological, financial, legal, or reputational harm. Testing includes: harmful output generation probing; resistance testing against bypass techniques; refusal behavior analysis; context persistence testing across multi-turn interactions; and attempts to override operational guardrails.

Dimension 2 — Fairness & Bias

Assessment of whether the AI system produces systematically different outcomes for individuals or groups based on protected attributes. Testing includes: counterfactual fairness testing; stereotype elicitation; and proxy variable analysis. Where a Bias & Fairness Audit is in scope, full statistical disparate impact analysis and adverse action review are also performed. See Testing Option 4.

Dimension 3 — Reliability & Accuracy

Evaluation of output consistency, hallucination rates, factual accuracy against domain-relevant benchmarks, and performance stability across repeated and varied inputs, including edge cases and boundary conditions.

Dimension 4 — Privacy & Data Protection

Testing for personally identifiable information (PII) exposure, information leakage from system context, cross-session data contamination, and alignment with applicable data protection obligations including UK GDPR and EU GDPR.

Dimension 5 — Security

Assessment across recognized AI security risk categories, covering: prompt injection (direct and indirect); sensitive information disclosure; supply chain risks; improper output handling; excessive agency; system configuration leakage; retrieval pipeline weaknesses; misinformation generation; and resource exhaustion. Mapped to OWASP LLM Top 10 (2025 edition) and MITRE ATLAS. See Testing Option 3 for extended adversarial security evaluation.

Dimension 6 — Transparency & Explainability

Review of AI disclosure practices, system documentation completeness, explainability of decisions, and accuracy of confidence or uncertainty communication to users and affected individuals.

Dimension 7 — Accountability & Governance

Assessment of governance structures, system ownership mapping, human oversight mechanisms, audit trail completeness, AI incident response readiness, and third-party AI governance controls.

Dimension 8 — Robustness & Resilience

Evaluation of performance under distributional shift, adversarial stress, out-of-distribution inputs, and simulated drift conditions. Includes performance baseline establishment for use in ongoing monitoring.

Dimension 9 — Regulatory Compliance

Structured mapping of assessment findings to the regulatory frameworks applicable to the engagement, as confirmed in the Technical Scoping Document. Produces a control-by-control compliance assessment identifying compliant, partially compliant, and non-compliant controls, with supporting evidence. See Appendix A for the full list of available frameworks.

Dimension 10 — Ethical Alignment

Assessment of whether the AI system’s observed behavior is consistent with your organization’s stated AI ethics policies, values, and published commitments, including value-sensitive scenario testing and stakeholder impact review.

2. AI System Discovery & Inventory

Prior to assessment, VIPRE conducts a structured discovery and inventory phase to catalogue every AI system confirmed in scope and establish the baseline for testing. This is included in all packages.

  • Structured inventory of all in-scope AI systems, based on Questionnaire responses and automated discovery where access permits.
  • Risk tier classification for each system in line with applicable regulatory frameworks including the EU AI Act.
  • Identification of governance documentation gaps — systems lacking documentation, ownership records, or formal risk assessments.
  • Identification of ungoverned AI — tools or systems in active use without formal organizational approval or governance processes.

Deliverable: AI System Inventory Report.

3. AI Assurance Bench — Adversarial Evaluation

AI Assurance Bench is an automated adversarial evaluation capability that assesses AI models against an extensive library of test scenarios, organized by attack category, harm type, regulatory concern, and industry context. AI Assurance Bench is applicable to large language models, generative AI systems, and conversational AI applications.

VIPRE configures each evaluation to reflect the specific deployment context of the system being assessed. A system deployed for clinical decision support will be evaluated against a different adversarial profile from one deployed in customer service or financial advice. Configuration includes:

  • Scenario definition — the use case, intended users, and regulatory context of the system.
  • Attack profile selection — drawn from categories including safety bypasses, prompt injection, information extraction, bias elicitation, hallucination induction, and harmful content generation.
  • Scope and rate controls — all evaluations are conducted within the rate limits and scope boundaries confirmed with you in the Technical Scoping Document.

Each evaluation produces an audit-ready report detailing trust scores by category, findings for critical failures, success rates by attack type, and a methodology statement suitable for regulatory or third-party review.

Deliverable: AI Assurance Bench Evaluation Report (incorporated into the Final AI Trust Assessment Report).

4. Bias & Fairness Audit

The Bias & Fairness Audit is a formal, documented assessment applicable to AI systems that make or materially influence consequential decisions affecting people — including in hiring, credit, insurance, healthcare, education, or public services. It produces findings structured for regulatory submission and third-party audit, designed to satisfy the requirements of mandatory AI bias audit regimes including NYC Local Law 144 and applicable federal and international guidance.

  • Protected attribute selection — identification of legally relevant protected characteristics for the system’s deployment context and jurisdiction, including race, ethnicity, sex, age, disability, religion, and national origin.
  • Outcome disparity analysis — statistical measurement of outcome differences across demographic groups, with application of applicable legal standards.
  • Indirect discrimination detection — identification of input features that may serve as statistical proxies for protected characteristics.
  • Intersectional analysis — evaluation of disparities at the intersection of multiple protected attributes.
  • Counterfactual testing — substitution of protected attribute values in otherwise identical inputs to measure output divergence.
  • Adverse action review — for credit, lending, insurance, and hiring contexts: review of adverse action rates, notification adequacy, and dispute rights compliance.

For Bias & Fairness Audit engagements, you must provide or facilitate access to appropriately prepared test data in the format and within the timeline confirmed in the Technical Scoping Document.

Deliverable: Bias & Fairness Audit Report — a structured report per audited system documenting methodology, statistical findings, legal standard application, and conclusions in a format suitable for regulatory submission.

5. Agentic AI Security Testing

Agentic AI Security Testing addresses the specific risk vectors that arise when an AI system can act — not merely respond. It applies to autonomous AI agents, multi-agent systems, and AI-augmented workflows where the AI component can execute tool calls, API interactions, or multi-step tasks with real-world consequences. Standard evaluation methods do not capture these risks; dedicated agentic testing is required.

  • Tool misuse — whether the agent can be induced to invoke tools with unintended parameters, in unintended sequences, or to achieve unintended outcomes.
  • Privilege escalation — whether the agent can acquire access beyond its granted permissions through chains of legitimate-seeming actions.
  • Indirect instruction injection — whether adversarial content embedded in external sources (tool outputs, retrieved documents, web content) can redirect agent behavior without the user’s knowledge.
  • Excessive agency — whether the agent takes consequential actions without appropriate human confirmation or scope boundary enforcement.
  • Audit trail adequacy — whether every agent action can be attributed, timestamped, and reviewed after the fact.
  • Multi-agent integrity — in systems where multiple agents communicate, whether influence from one agent can propagate unintended instructions to others in the chain.

Deliverable: Agentic AI Security Testing findings incorporated into the Final AI Trust Assessment Report — Technical Findings.

6. Regulatory Compliance Mapping

Regulatory Compliance Mapping translates assessment findings into the language of the specific legal and regulatory obligations that apply to your AI systems. Available for any combination of the frameworks listed in Appendix A.

  • Control-by-control assessment for each selected framework: compliant, partially compliant, or non-compliant.
  • Evidence citations linking each control determination to specific findings in the Technical Findings Report.
  • Gap list identifying the specific requirements not currently met, with severity ratings.
  • Regulatory readiness score per framework.

Deliverable: Regulatory Gap Analysis.

7. AI Assurance Certification

AI Assurance Certification is an independent certification awarded to AI systems that meet a defined 40-point trust evaluation standard. Certified systems receive a VIPRE AI Assurance Certification, which can be referenced in procurement, regulatory, and commercial contexts as evidence of independent third-party AI assurance.

VIPRE manages the certification evaluation and submission process on your behalf. Certification is not guaranteed — it is awarded only to systems that meet the required standard across all evaluation criteria. Where a system does not qualify, VIPRE will document the specific criteria not met and the remediation required to achieve certification on re-assessment.

Certified status is valid for 12 months from the date of certification, subject to no material changes to the assessed system. Annual renewal is managed by VIPRE where included in the package purchased.

Deliverable: AI Assurance Certification documentation for qualifying systems.

8. Engagement Phases

All VIPRE AI Assurance Testing engagements follow a structured phased approach regardless of the package selected. The phases applicable to any given engagement and their expected duration are confirmed in the Technical Scoping Document.

Table 2: AI Assurance — Engagement Phases
PhaseNameDescriptionApplicable To
1Planning & PreparationOnboarding call to review logistics, timelines, and technical scoping. Questionnaire issued and completed. Evaluation context confirmed: application type, user persona, and deployment domain. Access and credential provisioning. Testing window confirmation.All engagements
2AI System Discovery & InventoryStructured discovery and inventory of all in-scope AI systems. Risk classification. Governance gap identification. Ungoverned AI identification.All engagements
3Evaluation ExecutionAI Assurance Bench evaluation of each in-scope system. Prompts selected from curated library filtered to application type, user persona, and domain. Expert LLM judge scores each response. Statistical aggregation and normalization of dimension scores.All engagements
4Bias & Fairness AuditFormal bias audit for high-risk AI systems — outcome disparity analysis, protected attribute testing, intersectional analysis, adverse action review.Where purchased
5Agentic AI Security TestingDedicated security testing for autonomous agent systems — tool misuse, privilege escalation, indirect instruction injection, excessive agency evaluation.Where purchased
6Analysis, Benchmarking & ReportingConsolidated analysis of evaluation data, benchmarked against industry standards or custom criteria, and compiled into the applicable report format (e.g., Raw Scores, Summary, or Full Report with Executive Summary) as determined by the selected package.All engagements
7CertificationAI Assurance Certification level determination and documentation.Where purchased

9. Deliverables

Upon completion of the assessment, VIPRE will provide you with the deliverables applicable to the package purchased, as confirmed in the Order Form. The following table describes the full range of deliverables available across all packages. All final deliverables under this SOW are provided solely as secure, static electronic text documents (e.g., PDFs or secure file transfers). The services provided consist strictly of independent backend evaluation scans and expert analyst review performed by VIPRE or its affiliates, licensors or partners. This SOW does not grant the Customer or its personnel direct administrative access, individual platform logins, standalone API token generation rights, or dashboard credentials to any underlying multi-tenant software-as-a-service (SaaS) console infrastructure.

Table 3: AI Assurance — Deliverables
DeliverableDescriptionIncluded When
AI System Inventory ReportCatalogue of all assessed AI systems — risk classification, ownership, data sensitivity, governance gaps, and ungoverned AI findings.All engagements
Final AI Trust Assessment Report — Technical FindingsDimension-by-dimension findings per system; severity ratings; evidence; AI Assurance Bench results; Bias Audit findings; Agentic Security findings — as applicable to the package.All engagements
Final AI Trust Assessment Report — Executive ReportNon-technical overview of findings and overall AI risk posture, suitable for executive and board audiences.Comprehensive and Annual
Regulatory Gap AnalysisControl-by-control compliance mapping per selected regulatory framework; gap list; readiness score.Standard and above
Remediation RoadmapPrioritized action plan covering all finding severities; specific remediation steps; effort guidance; re-test guidance.Standard and above (Critical & High only for Quick Scan)
Bias & Fairness Audit ReportStructured audit report per assessed high-risk system; statistical findings; legal standard application; suitable for regulatory submission.Where Bias Audit purchased
Audit-Ready Compliance Evidence PackCollated evidence package for external auditors, regulators, or procurement teams; includes VIPRE engagement attestation statement.Comprehensive and Annual
AI Assurance Certification DocumentationCertification for systems meeting the qualifying standard; valid for 12 months.Where Certification purchased
Revalidation ReportConfirms resolution of Critical and High findings. Must be requested within 90 days of Final AI Trust Assessment Report delivery.Comprehensive and Annual

The following requirements are essential for the successful delivery of VIPRE AI Assurance Testing services and are supplemental to the terms stated in the MSA. The specific requirements applicable to any engagement will vary depending on the package purchased and the testing activities in scope and Technical Scoping Document. Failure to meet the applicable requirements may impair service delivery and may adversely affect any applicable SLA and the established timeline.

  • You must provide accurate details in the Questionnaire, in a timely manner, including but not limited to: a list of all AI systems to be assessed; system types, hosting environments, and access methods; any systems or environments that are explicitly excluded from scope.
  • You must provide the following, depending on the systems in scope: API keys or access tokens; OAuth client credentials where applicable; cloud platform access credentials for cloud-hosted AI systems; VPN or environment access for on-premises or private cloud deployments; and test accounts with appropriate privilege levels where required.
  • The Customer warrants that it has full legal authority to authorize VIPRE to conduct testing against all AI systems listed in the Technical Scoping Document, including any systems supplied by third-party vendors where your commercial agreements with those vendors permit security testing.
  • You must perform the following to avoid service disruptions and ensure legal compliance: confirm testing windows and blackout periods; provide points of contact for communication during testing; and approve or restrict any testing techniques applicable to your environment.
  • You must appoint a primary point of contact for all service interactions.
  • You must schedule and attend a kick-off meeting with VIPRE and ensure your technical team is available to assist with access provisioning, documentation, and connectivity requirements.
  • You must provide relevant existing AI documentation — including model cards, data sheets, risk assessments, and data flow diagrams — within five business days of engagement commencement.
  • For Bias & Fairness Audit engagements: the Customer must provide or facilitate access to appropriately anonymized and demographically annotated test data in the format specified by VIPRE, within the timeline agreed in the Technical Scoping Document.
  • If included with your package, you must request Revalidation in writing from VIPRE within 90 days of the date VIPRE delivers the Final AI Trust Assessment Report, and only once you have addressed the reported Critical and High findings.
  • You should plan to interact with the VIPRE AI Assurance Testing team for around one week prior to the scheduled commencement of testing activities.
  • You may need to interact with the VIPRE AI Assurance Testing team for around one week prior to the scheduled Revalidation.
  • VIPRE AI Assurance Testing services are delivered once per Order Form term unless a continuous or recurring package has been purchased.
  • VIPRE’s ability to successfully execute evaluation scans, generate deliverables, or perform the single revalidation run within established timelines is strictly contingent upon the Customer providing timely, complete, and secure access to the in-scope AI models, application endpoints, documentation, and required datasets. Any project delays, missed validation windows, or impacts on agreed technical response schedules resulting from the Customer’s failure or lag in provisioning these necessary inputs shall not constitute a breach by VIPRE, and VIPRE shall be granted an equitable extension of time to perform.

Roles and responsibilities for the Customer and VIPRE are set out in the table below. These apply to all packages. Specific activities will vary based on the package purchased.

Additionally, VIPRE will adhere to the following guidelines.

  • VIPRE will perform all testing activities within the agreed testing windows and scope boundaries confirmed in the Technical Scoping Document.
  • All testing will be non-destructive. VIPRE will not delete, modify, or permanently alter any data, model weights, or system configurations as part of the assessment.
  • Testing schedules will be planned and communicated to you at least 24 hours prior to initial testing.
  • VIPRE will notify you immediately if any testing activity produces an unexpected result that may indicate a live security incident or system failure.
  • All credentials and access provided by the Customer will be stored in VIPRE’s approved credential management system, used solely for the purposes of the relevant engagement, and confirmed as revoked or deleted within five business days of engagement closure.
  • VIPRE will deliver all deliverables through agreed secure channels of communication.
  • VIPRE strictly prohibits its processing infrastructure and downstream architectural subprocessors from using any data, inputs, prompts, codebases, or model outputs provided by the Customer to train, retrain, fine-tune, or structurally improve any foundational AI models or automated evaluation algorithms. All Customer inputs and evaluation data shall remain completely isolated from general or public training datasets.
Table 4: Responsibilities
VIPREYou
Provide qualified VIPRE AI Assurance Testing analysts with experience in AI security assessment, regulatory compliance, bias auditing, and adversarial evaluation.

Issue the Questionnaire and Technical Scoping Document to Customer.

Provide confirmed testing start date to Customer.

Work with Customer to establish system access and connectivity required for assessment.

Conduct all assessment, testing, and analysis activities across the 10-Dimension Trust Framework (actual number of dimensions depends on selected package).

Where applicable: execute AI Assurance Bench adversarial evaluation; conduct Bias & Fairness Audit; conduct Agentic AI Security Testing.

Map all findings to applicable regulatory frameworks as selected.

Deliver a secured, encrypted Final AI Trust Assessment Report to Customer by the agreed date or via the secure portal.

For applicable packages, perform one Revalidation check to confirm resolution of Critical and High findings, when requested within 90 days of Final AI Trust Assessment Report delivery.

For applicable packages, provide a Revalidation Report detailing the results of the revalidation check.

Confirm revocation or deletion of all Customer credentials within 5 business days of engagement closure.
Appoint a primary point of contact and a technical contact for all service interactions.

Schedule and attend a kick-off meeting with VIPRE.

Complete the Questionnaire and provide supporting documentation by the agreed date.

Provide API keys, credentials, and system access required for testing.

Confirm testing windows, blackout periods, and any access restrictions.

Whitelist VIPRE testing IP addresses in firewalls and API gateways as required.

Provide written authorization confirming VIPRE is permitted to test all in-scope systems.

For Bias & Fairness Audit: provide or facilitate access to required test datasets.

Promptly respond to VIPRE queries to facilitate assessment and testing activities.

Confirm receipt of the Final AI Trust Assessment Report.

For applicable packages, optionally request one Revalidation check within 90 days of Final AI Trust Assessment Report delivery.

Revoke or rotate all credentials provided to VIPRE upon confirmation of engagement closure.

Customer acknowledges that AI system evaluation, adversarial testing, and compliance framework mapping are inherently probabilistic, subjective, and based on rapidly shifting global regulatory requirements and threat landscapes. The Final AI Trust Assessment Report, raw scores, and associated risk determinations represent a point-in-time assessment updated on a best-effort basis.

VIPRE does not warrant or guarantee that the services will identify one hundred percent (100%) of all potential security vulnerabilities, biases, hallucinations, or compliance gaps. Furthermore, an “Approved” deployment recommendation or the awarding of an “AI Assurance Certification” level does not guarantee that the Customer’s AI systems will operate without error in production environments or maintain absolute compliance with applicable local, state, federal, or international laws. The findings provided are advisory in nature, do not constitute formal legal advice, and the Customer retains sole operational responsibility and legal liability for the deployment, governance, and real-world performance of their AI applications.

VIPRE can map assessment findings to any of the following regulatory frameworks. The frameworks applicable to a given engagement are confirmed in the Technical Scoping Document. The number of frameworks included within a package is set out in the Package Overview section. Additional frameworks may be added by written agreement between VIPRE and the Customer.

Table 5: Regulatory Frameworks
FrameworkJurisdictionPrimary Applicability
EU AI Act (Regulation (EU) 2024/1689)European UnionOrganizations placing AI systems on the EU market or affecting EU persons
NIST AI Risk Management Framework (AI RMF 1.0)Forenede StaterUS federal agencies, regulated industries, and voluntary global adoption
NIST AI 100-2 E2025 / AI 600-1Forenede StaterAdversarial machine learning and generative AI risk
ISO/IEC 42001:2023 — AI Management SystemsInternationalCertification to the international AI governance standard
NYC Local Law 144New York City, USAEmployers using automated employment decision tools
ECOA / Regulation BForenede StaterCredit and lending AI models — disparate impact in decisioning
Fair Credit Reporting Act (FCRA)Forenede StaterConsumer reporting and AI-driven credit decisions
SR 11-7 (Federal Reserve / OCC)Forenede StaterModel risk management in US banking and financial services
UK ICO AI and Data Protection GuidanceDet Forenede KongerigeUK organizations using AI to process personal data
UK FCA / PRA Model Risk ManagementDet Forenede KongerigeAI in UK financial services decision-making
HIPAA / HITECHForenede StaterHealthcare AI systems processing Protected Health Information
EU GDPR / UK GDPR (Article 22)EU / UKAutomated decision-making affecting individuals
Digital Operational Resilience Act (DORA)European UnionFinancial entities managing ICT and AI risk
OWASP LLM Top 10 (2025 edition)InternationalLLM and generative AI security assessment
MITRE ATLASInternationalAdversarial threat landscape for AI systems

VIPRE AI Assurance Testing applies the methodologies and activities listed below across assessment and adversarial testing phases. The specific activities applied within any engagement are confirmed in the Technical Scoping Document and will vary based on the AI system type, the package purchased, and any agreed scope parameters.

Table 6: Assessment Activities
Assessment AreaActivitiesApplicable System Types
Safety EvaluationHarmful output generation probing; jailbreak resistance testing; refusal behavior analysis; context persistence testing; system prompt extraction and override attemptsLLMs, generative AI, conversational agents
Security — OWASP LLM Top 10Prompt injection (LLM01); sensitive information disclosure (LLM02); supply chain review (LLM03); data poisoning susceptibility (LLM04); improper output handling (LLM05); excessive agency (LLM06); system prompt leakage (LLM07); vector/embedding weaknesses (LLM08); misinformation probing (LLM09); resource exhaustion (LLM10)LLMs, RAG systems, AI-powered applications
Adversarial Testing (AI Assurance Bench)Automated adversarial evaluation across 7M+ prompts; scenario-configured by use case and industry; attack profile selection by harm category; audit-ready trust report outputLLMs, generative AI systems
Bias & Fairness AuditDisparate impact analysis; proxy variable detection; intersectional bias testing; counterfactual fairness testing; adverse action analysis; test dataset evaluationHigh-risk AI systems in hiring, credit, healthcare, insurance, housing
Agentic Security TestingTool misuse testing; privilege escalation probing; indirect prompt injection via tool outputs and retrieved documents; excessive agency evaluation; audit trail completeness review; multi-agent trust assessmentAutonomous AI agents, multi-step workflow systems
Privacy AssessmentPII extraction probing; training data leakage testing; cross-session data contamination; membership inference simulation; data minimization reviewAll AI systems processing personal data
Reliability TestingConsistency testing; hallucination rate measurement; factual accuracy benchmarking; context window degradation testing; output variance under paraphraseLLMs, generative AI, decision-support systems
Robustness TestingDistribution shift testing; adversarial robustness probing; model drift simulation; out-of-distribution input handling; performance baseline establishmentAll ML models and AI systems
Governance & Accountability ReviewGovernance documentation review; ownership and accountability mapping; human oversight mechanism evaluation; audit trail completeness; incident response readiness; AI register assessmentAll AI systems
Transparency ReviewDisclosure adequacy assessment; model card completeness review; explainability analysis; confidence and uncertainty communication evaluationAll AI systems
Regulatory MappingAutomated control-by-control compliance mapping; gap identification; evidence citation; readiness scoring per frameworkAll AI systems — framework selection per Technical Scoping Document