Zulia Shavaeva← Back to Zulia
Free AI and security guide/Learn

Learn / Advisory and customer-facing delivery skills

Advisory and customer-facing delivery skills

Explaining AI risk and controls to clients and leadership, and delivering advisory work they can act on.

Researched on 2026-09-26 with AI assistance. Links and summaries can change; verify details with the original source. Not yet reviewed by a person.

What it is

Advisory and customer-facing delivery is the work of turning AI security findings into decisions other people can make: scoping an engagement, writing the assessment, and briefing product owners, risk committees and boards. Public guidance exists for exactly this gap: the UK NCSC Cyber Security Toolkit for Boards is built around the Cyber Governance Code of Practice and is designed to support the discussions between a board and its technical experts.3

The writing and speaking part is a learnable craft, not a personality trait. Google's free Technical Writing One course teaches the specific moves that make advisory documents usable: state key points at the start, identify what your audience already knows and needs to learn, prefer active voice, and break long topics into sections.8

Credible advice is anchored to published references the client can check for themselves, rather than to your opinion. In practice that means NIST's AI Risk Management Framework, which is voluntary and organised around four functions (govern, map, measure, manage), ISO/IEC 42001:2023 for an AI management system, and the article-by-article obligations of Regulation (EU) 2024/1689.29

It also means being straight about what your testing does and does not prove. Microsoft's write-up of red teaming over 100 generative AI products states plainly that AI red teaming is not safety benchmarking, that responsible AI harms are pervasive but hard to measure, and that the work of securing AI systems is never complete.5

Why postings ask for it

7 of 48 postings (15%) ask for advisory and customer-facing delivery skills, and the concentration matters more than the average: 40% of the 5 consulting and field delivery postings and 29% of the 7 AI security architect postings ask for it.P

Demand is near zero in the hands-on testing clusters (0% of 9 AI red team postings and 0% of 4 research postings) but present in AI/agent security engineering (12% of 16) and AI governance and GRC (14% of 7), which reflects who has to defend a decision in front of a client or a risk committee rather than only produce findings.P

The underlying work is documentation and scoping: deciding whether a client is a provider or a deployer, writing the risk management, technical documentation, human oversight and transparency story the regulation expects, and handing over something auditable.9P

Concepts you should be able to explain

If you can say each of these out loud in two minutes, with an example, you are ready for the technical part of an interview on this skill.

Audience-first document structure

Advisory documents fail when the reader has to hunt for the decision. Technical Writing One's rules are the minimum bar: state key points at the start of the document, state scope and audience explicitly, work out what the target audience already knows, and watch for the curse of knowledge that makes you skip the context they need.8

Board-level risk conversation

Boards need to govern AI and cyber risk without becoming engineers. The NCSC toolkit is organised around five principles of the Cyber Governance Code of Practice (risk management, strategy, people, incident planning and response, assurance and oversight) and includes modules on identifying critical assets and on supply chain risk, which gives you a ready agenda structure for an executive session.3

Shared risk vocabulary from AI RMF

The AI RMF Core has four functions: govern, map, measure and manage, with govern described as cross-cutting and infused through the others. NIST is explicit that the actions are not a checklist and not an ordered set of steps, so in advisory work you use the functions to structure findings and gaps, not to score a client. NIST also published NIST-AI-600-1, a generative AI profile, in July 2024.21

Provider versus deployer scoping

Under Regulation (EU) 2024/1689 the obligations differ by role: Article 16 covers providers of high-risk AI systems and Article 26 covers deployers, with Article 27 adding a fundamental rights impact assessment for some high-risk uses. The Commission's own AI Act Compliance Checker, currently in beta, helps users work out which rules may apply to providers, deployers and other operators, which is a defensible starting point for a scoping memo.910

Control mapping instead of a homemade framework

The CSA AI Controls Matrix v1.1 contains 247 control objectives across 18 security domains and ships mappings to ISO 42001, ISO 27001, BSI AIC4, the EU AI Act and NIST AI RMF, plus role-specific implementation and auditing guidance for model provider, orchestrated service provider, application provider, AI customer and cloud service provider. NIST also publishes a crosswalk from AI RMF to ISO/IEC 42001 clauses, so you can show a client that one piece of evidence answers several frameworks.714

Findings mapped to a named taxonomy

Clients challenge findings that look invented. The 2025 OWASP Top 10 for LLM and generative AI applications gives named entries you can cite, including prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation and unbounded consumption. For attack narrative and threat framing, MITRE ATLAS data as of its 2026.08 release contains 16 tactics, 114 techniques, 83 sub-techniques, 39 mitigations and 72 case studies.413

Honest limits on assurance

The lessons from red teaming over 100 generative AI products include: understand what the system can do and where it is applied, you do not need gradients to break an AI system, red teaming is not safety benchmarking, automation extends coverage but the human element is crucial, and LLMs both amplify existing security risks and introduce new ones. Saying this up front prevents a client reading your report as a clean bill of health.5

Deliverable artefacts that survive handover

Model cards, proposed by Mitchell and colleagues, are short documents accompanying a trained model that record intended use context, benchmarked evaluation across relevant groups and conditions, and the evaluation procedures used. On the data protection side the ICO's AI and data protection risk toolkit sets out controls, control objectives, risk indicators and suggested evidence or documentation, which is the level of specificity a client can actually action.612

Use fictional data and authorised sandboxes. Remove employer details and secrets from any portfolio write-up. Time estimates exclude setup. Check model and cloud costs before running tests, set spending limits, and delete lab resources afterwards.

Three exercises

In order of difficulty. Free tools. Keep what you build; it is evidence.

1One-page risk brief for a non-technical sponsorabout 3 h

A single page that names three risks in an LLM feature, their business consequence and the decision you are asking for, written to a stated audience and scope.485

  1. Pick a concrete feature, for example a support chatbot with access to a ticket database.
  2. Choose three entries from the 2025 OWASP Top 10 for LLM and generative AI applications and write each in one sentence of plain English.
  3. Work the Technical Writing One rules through a draft: key points first, stated scope and audience, active voice, short sentences.
  4. Add one paragraph on what your assessment did not cover, using the point that red teaming is not safety benchmarking.
  5. Read it aloud to a non-specialist and cut anything you have to verbally explain.

Tools: web browser, text editor, Google Technical Writing One (free), OWASP Top 10 for LLM and Gen AI (free)

2Scoping and control-mapping memo for a client use caseabout 5 h

A two-page memo that states whether the client acts as provider or deployer, lists likely obligations, maps them to named controls and asks for specific evidence.1097

  1. Write a short use case description, including who builds the model, who deploys it and which users are affected.
  2. Run the description through the Commission's AI Act Compliance Checker beta and record which rules it flags for providers and deployers.
  3. Open the relevant articles in the AI Act Explorer, for example Article 9 risk management, Article 11 technical documentation, Article 14 human oversight and Article 26 deployer obligations, and quote the obligation you rely on.
  4. Select the matching control objectives from the CSA AI Controls Matrix and use its ISO 42001 and NIST AI RMF mappings to show one evidence item covering several frameworks.
  5. Close with an evidence request list and a list of open questions you would escalate to legal counsel rather than answer yourself.

Tools: web browser, EU AI Act Compliance Checker (free beta), AI Act Explorer (free), CSA AI Controls Matrix v1.1 (free download), spreadsheet

3Run a stakeholder tabletop on an AI agent incidentabout 8 h

A 60-minute facilitated exercise plus an after-action note with prioritised actions and named owners.111343

  1. Take a CISA Tabletop Exercise Package as your structure; the packages are designed so stakeholders can adapt scenarios and conduct their own planning exercises.
  2. Build the scenario from a named taxonomy: an indirect prompt injection reaching an agent with excessive agency, leading to sensitive information disclosure.
  3. Add two injects grounded in MITRE ATLAS case studies and mitigations so participants argue about real technique classes.
  4. Recruit three to five people in different roles (engineering, legal or privacy, communications, an executive) and facilitate without solving the problem for them.
  5. Write the after-action note using board-level framing from the NCSC toolkit principles, with at most five actions, each with an owner and a date.
  6. Send it within 48 hours and ask one participant whether they could act on it unaided.

Tools: CISA CTEP (free), MITRE ATLAS data (free), OWASP Top 10 for LLM and Gen AI (free), NCSC Cyber Security Toolkit for Boards (free), video call and text editor

Practice questions

Written from the concepts above, not collected from a named employer. Open one, answer it out loud, then tick the points you covered; the score stays in this browser.

A product team wants to add an LLM assistant to a customer portal. How would you scope the advisory engagement in the first week?Shared risk vocabulary from AI RMF; Honest limits on assurance

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

Explain prompt injection to an executive who controls the budget, in under a minute.Findings mapped to a named taxonomy

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

A client says: we had a red team test the chatbot, so are we safe now? What do you tell them?Lessons From Red Teaming 100 Generative AI Products

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

How do provider and deployer obligations differ under the EU AI Act, and why does that change your advice?Provider versus deployer scoping

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

A client asks you to build them an AI control framework from scratch. What do you do instead?Control mapping instead of a homemade framework

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

What documentation would you ask an AI vendor for before approving their model in a client environment?Deliverable artefacts that survive handover

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

Your findings report keeps getting no response from the client. How do you rewrite it?Audience-first document structure

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

You have 45 minutes with a board on AI risk. How do you structure it and how do you know it worked?Board-level risk conversation

Say your answer out loud or write it down, then tick what you covered:

0 of 4 covered

Sources

Every numbered claim above links here. P = the platform's own coding of 48 job postings.

  1. AI Risk Management Framework NIST
  2. AI RMF Core (AI RMF 1.0, section 5) NIST Trustworthy and Responsible AI Resource Center
  3. Cyber Security Toolkit for Boards UK National Cyber Security Centre
  4. 2025 Top 10 Risk and Mitigations for LLMs and Gen AI Apps OWASP Gen AI Security Project
  5. Lessons From Red Teaming 100 Generative AI Products arXiv (Microsoft AI Red Team)
  6. Model Cards for Model Reporting arXiv
  7. AI Controls Matrix (AICM) v1.1 with AI-CAIQ Cloud Security Alliance
  8. Technical Writing One introduction Google for Developers
  9. AI Act Explorer, Regulation (EU) 2024/1689 full text Future of Life Institute
  10. EU AI Act Compliance Checker (official, beta) European Commission AI Act Service Desk
  11. CISA Tabletop Exercise Packages CISA
  12. AI and data protection risk toolkit UK Information Commissioner's Office
  13. atlas-data CHANGELOG (content release v2026.08) MITRE ATLAS
  14. NIST AI RMF to ISO/IEC 42001 AI Management System Crosswalk NIST

Resources

Free first. Levels: intro means no prior knowledge of this skill; working means you can apply it on a project; advanced means research depth or specialist tooling.

Level Format

Gaps the research could not fill with a good free source: ISO/IEC 42001 itself: iso.org returned HTTP 403 today, so we could not confirm the price or link the standard page, and the full text is paywalled. The CSA AICM download includes an ISO 42001 mapping as a free substitute.; No free course specifically on running AI security advisory engagements: scoping, stakeholder interviews, presenting findings to a board. Free courses found teach governance content, not delivery craft.; No AI-specific tabletop exercise scenario pack from a standards body. CISA CTEP has over 100 scenarios but the page names none for AI or LLM incidents, so you have to write the injects yourself.; No free, primary-source template for an AI security assessment report or client-ready control gap report; only impact assessment and questionnaire templates.; No free book-format resource on communicating AI risk to non-technical executives that we could verify from a primary source today.; Search and repository tool budget ran out before we could verify a free AI incident reporting or AI incident database tool for use in client briefings.