Unique Check IDs
109
Distinct Check_ID values represented
Report Rows
406
Visible rows across 3 regions
Open Action Items
5
Direct failed service rows
Lens / Compliance Rows
196
1 failed; may map to service rows
Failed High
4
3 of 27 direct high rows passed
Failed Medium / Low
1/0
Direct Medium / Low failed rows

Priority Recommendations

3
Marketplace Subscription Access Check
Bedrock
1
Cross-Account Guardrails Enforcement Check
Bedrock
1
AgentCore Service-Linked Role Missing
AgentCore

Severity Legend

View full methodology
SeverityMeaningRecommended Action
HighDirect security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposureRemediate within 7 days
MediumDefense-in-depth gaps - encryption, logging, or configuration issues that reduce security postureRemediate within 30 days
LowBest practice deviations - optimization opportunities that improve security hygieneRemediate within 90 days
InformationalNot applicable, unavailable, no resources found, or advisory-only rowsNo action required
Risk Distribution

Direct Service Scored Row Results by Severity

HIGH
11.1%
3 of 27 scored rows passed
MEDIUM
38.5%
10 of 26 scored rows passed
LOW
30.0%
3 of 10 scored rows passed
Overall
25.4%
16 of 63 scored rows passed

Direct Failed Rows by Region / Scope

eu-west-1
0
0 High · 0 Med · 0 Low
us-east-1
0
0 High · 0 Med · 0 Low
us-west-2
0
0 High · 0 Med · 0 Low
Global
5
4 High · 1 Med · 0 Low

Findings by Assessment Area

Bedrock
92
4 Failed · 2 Passed
SageMaker
82
0 Failed · 13 Passed
AgentCore
33
1 Failed · 1 Passed
Agentic AI Security
75
1 Failed · 1 Passed · 73 N/A
Financial Services Risk
3
0 Failed · 0 Passed · 3 N/A
OWASP Top 10 LLM
121
0 Failed · 9 Passed · 112 N/A
All Security Findings
Amazon Bedrock Findings
Failed
4
Open findings
Passed
2
Controls met
N/A
86
Not applicable
Total
92
Rows in report
Amazon SageMaker Findings
Failed
0
Open findings
Passed
13
Controls met
N/A
69
Not applicable
Total
82
Rows in report
Amazon Bedrock AgentCore Findings
Failed
1
Open findings
Passed
1
Controls met
N/A
31
Not applicable
Total
33
Rows in report
Agentic AI Security Findings

Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.

Failed
1
Open findings
Passed
1
Controls met
N/A
73
Not applicable
Total
75
Rows in report
Financial Services GenAI Risk Findings

Scope: this assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology.

Failed
0
Open findings
Passed
0
Controls met
N/A
3
Not applicable
Total
3
Rows in report
OWASP Top 10 for LLM Findings

Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.

Failed
0
Open findings
Passed
9
Controls met
N/A
112
Not applicable
Total
121
Rows in report
Assessment Methodology

Assessment Notes

Point-in-time: Security posture changes as resources are modified. Scope limited: Passed checks verify tested controls only. Context matters: Adjust severity for compliance requirements and environment type.

Assessment Scope

Amazon Bedrock
Amazon SageMaker
Amazon Bedrock AgentCore
Agentic AI Security
Agentic AI Security Lens Mapping
Industry
Financial Services GenAI Risk
By Compliance Standard
OWASP Top 10 LLM

Bedrock, SageMaker, and AgentCore checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Financial Services GenAI Risk checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. OWASP Top 10 LLM references OWASP Top 10 LLM.