Unique Check IDs
208
Distinct Check_ID values represented
Report Rows
653
Visible rows across 3 regions
Open Action Items
36
Direct failed service rows
Lens / Compliance Rows
312
33 failed; may map to service rows
Failed High
19
Direct High failed service rows
Failed Medium / Low
16/1
Direct Medium / Low failed rows

Priority Recommendations

3
Marketplace Subscription Access Check
Bedrock
1
Cross-Account Guardrails Enforcement Check
Bedrock
1
AgentCore Service-Linked Role Missing
AgentCore

Severity Legend

View full methodology
SeverityMeaningRecommended Action
HighDirect security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposureRemediate within 7 days
MediumDefense-in-depth gaps - encryption, logging, or configuration issues that reduce security postureRemediate within 30 days
LowBest practice deviations - optimization opportunities that improve security hygieneRemediate within 90 days
InformationalNot applicable, unavailable, no resources found, or advisory-only rowsNo action required
Risk Distribution

Direct Service Scored Control Results by Severity

HIGH
31.2%
5 of 16 scored controls passed
MEDIUM
39.1%
9 of 23 scored controls passed
LOW
100.0%
1 of 1 scored controls passed
Overall
37.5%
15 of 40 scored controls passed

Direct Failed Rows by Region / Scope

us-east-1
4
3 High · 1 Med · 0 Low
us-east-2
4
3 High · 1 Med · 0 Low
us-west-2
4
3 High · 1 Med · 0 Low
Global
24
10 High · 13 Med · 1 Low

Findings by Assessment Area

Bedrock
113
7 Failed · 2 Passed
SageMaker
94
3 Failed · 13 Passed
AgentCore
45
7 Failed · 1 Passed
AWS Agent Registry
20
0 Failed · 1 Passed · 19 N/A
Agentic AI Security
108
7 Failed · 1 Passed · 100 N/A
Responsible AI GRC
69
19 Failed · 7 Passed · 43 N/A
OWASP Top 10 LLM
204
26 Failed · 17 Passed · 161 N/A
All Security Findings
Amazon Bedrock Findings
Failed
7
Open findings
Passed
2
Controls met
N/A
104
Not applicable
Total
113
Rows in report
Amazon SageMaker Findings
Failed
3
Open findings
Passed
13
Controls met
N/A
78
Not applicable
Total
94
Rows in report
Amazon Bedrock AgentCore Findings
Failed
7
Open findings
Passed
1
Controls met
N/A
37
Not applicable
Total
45
Rows in report
AWS Agent Registry Findings
Failed
0
Open findings
Passed
1
Controls met
N/A
19
Not applicable
Total
20
Rows in report
Agentic AI Security Findings

Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.

Failed
7
Open findings
Passed
1
Controls met
N/A
100
Not applicable
Total
108
Rows in report
Responsible AI GRC Findings

Scope: Responsible AI GRC comprises 64 automated checks that evaluate selected AWS configuration evidence against project-authored technical controls informed by the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption and by AWS financial-services generative-AI risk guidance. The controls originated as financial-services controls and were found applicable across multiple industries. They do not establish regulatory compliance, certify a system as responsible AI, or provide complete Responsible AI or GRC coverage. Regulatory framework mappings are preliminary. Manual legal, policy, model-risk, fairness, and use-case review remains required. This assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment.

Failed
19
Open findings
Passed
7
Controls met
N/A
43
Not applicable
Total
69
Rows in report
OWASP Top 10 for LLM Findings

Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.

Failed
26
Open findings
Passed
17
Controls met
N/A
161
Not applicable
Total
204
Rows in report
Assessment Methodology

Assessment Notes

Point-in-time: Security posture changes as resources are modified. Scope limited: Passed checks verify tested controls only. Scoring: Direct service rows are aggregated by unique Check ID; any failed assessable row fails the control, a control passes only when all assessable rows pass, and N/A rows are excluded. Context matters: Adjust severity for compliance requirements and environment type.

Assessment Scope

Amazon Bedrock
Amazon SageMaker
Amazon Bedrock AgentCore
AWS Agent Registry
Agentic AI Security
Agentic AI Security Lens Mapping
Governance Framework
Responsible AI GRC
By Compliance Standard
OWASP Top 10 LLM

Bedrock, SageMaker, AgentCore, and AWS Agent Registry checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Responsible AI GRC checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment. OWASP Top 10 LLM references OWASP Top 10 LLM.