Supported Compliance Frameworks

Asenion AI Red Teaming maps every attack plugin to one or more industry frameworks, so your test results line up with the controls those frameworks define — not just raw security data. When you run a test suite, the results dashboard shows pass/fail rates per framework control, and you can export framework-aligned reports.


Framework Selector


OWASP LLM Top 10 (2025)

The OWASP LLM Top 10 is the most widely adopted framework for identifying and mitigating common security risks in large language model applications.

Control Name Attack Plugins
LLM01 Prompt Injection indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override, special-token-injection
LLM02 Sensitive Information Disclosure cross-session-leak, prompt-extraction, data-exfil, rag-document-exfiltration, pii:*
LLM03 Supply Chain shell-injection, sql-injection, ssrf, mcp, tool-discovery, coding-agent:*
LLM04 Data and Model Poisoning agentic:memory-poisoning, rag-poisoning, divergent-repetition, harmbench, beavertails
LLM05 Improper Output Handling hallucination, overreliance, unverifiable-claims, imitation, politics, religion
LLM06 Excessive Agency excessive-agency, goal-misalignment, tool-discovery, mcp, coding-agent:*
LLM07 System Prompt Leakage prompt-extraction, system-prompt-override, debug-access, model-identification
LLM08 Vector and Embedding Weaknesses rag-poisoning, rag-source-attribution, cross-session-leak, data-exfil
LLM09 Misinformation hallucination, harmful:misinformation-disinformation, politics, unverifiable-claims
LLM10 Unbounded Consumption reasoning-dos, divergent-repetition, excessive-agency

OWASP Top 10 for Agentic Applications (v1)

Covers risks specific to autonomous, tool-using, and multi-agent AI systems.

Control Name Attack Plugins
A01 Autonomous Decision Making Failure excessive-agency, goal-misalignment, hijacking
A02 Tool Misuse tool-discovery, mcp, shell-injection, sql-injection, ssrf
A03 Memory and Context Poisoning agentic:memory-poisoning, cross-session-leak, rag-poisoning
A04 Insufficient Guardrails system-prompt-override, debug-access, rbac, prompt-extraction
A05 Identity and Access Control bola, bfla, rbac, telecom:account-takeover
A06 Prompt Hijacking indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override
A07 Secret and Data Exfiltration data-exfil, rag-document-exfiltration, cross-session-leak, pii:*, coding-agent:*
A08 Sandbox and Boundary Escape coding-agent:*
A09 Unsafe Automation and Persistence coding-agent:*
A10 Insufficient Logging and Monitoring debug-access, divergent-repetition, agentic:memory-poisoning

NIST AI Risk Management Framework (AI RMF 1.0)

The NIST AI RMF provides a structured approach for organizations to govern, map, measure, and manage AI risks.

Function Name Attack Plugins
GOVERN Governance contracts, excessive-agency, politics, religion
MAP Risk Identification harmbench, beavertails, donotanswer, harmful:*
MEASURE-BIAS Bias Measurement imitation, donotanswer, bias:*
MEASURE-PRIVACY Privacy Measurement cross-session-leak, prompt-extraction, pii:*
MEASURE-ROBUSTNESS Robustness Measurement indirect-prompt-injection, hallucination, overreliance, reasoning-dos
MANAGE Risk Management debug-access, agentic:memory-poisoning, ssrf, mcp

EU AI Act

The European Union AI Act establishes risk-tiered obligations for AI systems, with strict requirements for high-risk applications covering prohibited practices, transparency, human oversight, and accuracy.

Article Name Attack Plugins
Art. 5 Prohibited Practices politics, religion, imitation, goal-misalignment, harmful:*, teen-safety:*
Art. 10 Data and Governance harmbench, beavertails, agentic:memory-poisoning, bias:*
Art. 13 Transparency prompt-extraction, system-prompt-override, hallucination, model-identification
Art. 14 Human Oversight excessive-agency, contracts, rbac
Art. 15 Accuracy and Robustness hallucination, overreliance, unverifiable-claims, reasoning-dos

ISO/IEC 42001 (2023)

The international standard for AI Management Systems. Asenion AI Red Teaming maps tests to key controls in the standard’s risk assessment, operation, monitoring, and accountability domains.

Control Name Attack Plugins
6.1.2 AI Risk Assessment contracts, excessive-agency, overreliance, hallucination, harmful:*
8.4 AI System Operation hallucination, unverifiable-claims, overreliance, reasoning-dos
8.5 AI System Impact imitation, politics, religion, bias:*
9.1 Monitoring and Measurement debug-access, divergent-repetition, agentic:memory-poisoning
10.1 Continual Improvement cross-session-leak, prompt-extraction, system-prompt-override, pii:*
A.6.2 Data Quality harmbench, beavertails, agentic:memory-poisoning, rag-poisoning
A.9.3 System Transparency prompt-extraction, system-prompt-override, model-identification
A.10.3 Accountability and Access Control rbac, bfla, bola, debug-access

GDPR

The General Data Protection Regulation. Asenion AI Red Teaming covers privacy, data minimization, security of processing, and data protection by design.

Article Name Attack Plugins
Art. 5 Principles Relating to Processing cross-session-leak, data-exfil, prompt-extraction, pii:*
Art. 25 Data Protection by Design rbac, bfla, bola, debug-access
Art. 32 Security of Processing ssrf, sql-injection, shell-injection, cross-session-leak, coding-agent:*

MITRE ATLAS

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) catalogs adversarial tactics and techniques targeting AI systems.

Technique Name Attack Plugins
AML.T0000 Reconnaissance tool-discovery, debug-access, model-identification
AML.T0051 Prompt Injection indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override
AML.T0044 Memory Poisoning agentic:memory-poisoning, rag-poisoning
AML.T0025 Model Inversion and Exfiltration prompt-extraction, cross-session-leak, data-exfil, rag-document-exfiltration, pii:*
AML.T0020 Data Poisoning harmbench, beavertails, divergent-repetition, agentic:memory-poisoning
AML.T0054 Defense Evasion pliny, ascii-smuggling, system-prompt-override, special-token-injection, coding-agent:*
AML.T0018 Privilege Escalation rbac, bfla, bola, excessive-agency, telecom:account-takeover

MIT AI Ethics

Responsible AI principles aligned to fairness, transparency, privacy, safety, oversight, accountability, and robustness — derived from MIT’s AI Ethics framework.

Principle Name Attack Plugins
FAIRNESS Fairness and Non-Discrimination imitation, donotanswer, bias:*
TRANSPARENCY Transparency prompt-extraction, system-prompt-override, hallucination, model-identification
PRIVACY Privacy cross-session-leak, data-exfil, prompt-extraction, pii:*
SAFETY Safety beavertails, harmbench, donotanswer, harmful:*, teen-safety:*
HUMAN_OVERSIGHT Human Oversight excessive-agency, contracts, rbac
ACCOUNTABILITY Accountability bola, bfla, rbac, debug-access
ROBUSTNESS Robustness indirect-prompt-injection, ascii-smuggling, divergent-repetition, reasoning-dos

Additional Domain Frameworks

Some plugins are mapped to sector-specific regulations and standards:

Framework Sector Relevant Plugins
Fair Housing Act Real Estate realestate:fair-housing-discrimination, realestate:steering
CPNI (FCC) Telecommunications telecom:cpni-disclosure
TCPA Telecommunications telecom:tcpa-violation
Youth Safety Consumer / Teen Products teen-safety:dangerous-content, teen-safety:dangerous-roleplay
Safety Benchmark General xstest, harmbench-copyright, harmful:copyright-violations, harmful:intellectual-property

Running a Framework-Scoped Test

You can restrict a test run to the plugins mapped to a specific framework:

  1. Navigate to TestsNew Test Run
  2. Under Plugin Selection, click By Framework
  3. Select the framework (e.g. OWASP LLM Top 10)
  4. Optionally select specific controls within the framework
  5. Asenion AI Red Teaming activates only the plugins that map to the selected controls
  6. After the run, the report is pre-organized by framework control