Our Approach

The Telbi
Evidence Model

Most tools generate raw findings. Telbi transforms testing results into structured technical evidence that CTOs, CISOs, DPOs, boards, auditors, and enterprise customers can use for informed decision-making.

From Raw Output to Defensible Evidence

1

Raw Test Output

Tool logs, API responses, screenshots

2

Structured Evidence

Classified, mapped, and attributed

3

Findings Database

Severity, ownership, framework links

4

Executive Report

Actionable decisions for leadership

Each evidence item captures not just what was found, but why it matters to the business, who owns the fix, how it maps to relevant frameworks, and how to prove the remediation worked.

Evidence Record Schema

Every evidence item in a Telbi assessment contains 12 structured fields across four logical groups

Identification

3 fields

Evidence IDUnique identifier for traceability across the entire assessment lifecycle
Test IDLinks to specific test execution for reproducibility
Scenario IDLinks to risk/misuse scenario that triggered this test

Context

3 fields

ComponentAffected system component (model, API, pipeline, UI)
Tool SourceTesting tool or methodology used to generate output
Raw OutputJSON payloads, logs, screenshots, request/response pairs

Impact & Mapping

3 fields

Business ImpactWhy this matters to management and commercial outcomes
Framework MappingEU AI Act article, OWASP category, MITRE ATLAS technique
SeverityCritical / High / Medium / Low based on exploitability and impact

Remediation

3 fields

OwnerResponsible role (CTO, ML Lead, DevOps) for remediation
Recommended FixPractical, prioritised remediation step
Retest CriteriaSpecific conditions to prove the fix works

How Your Organisation Uses This Evidence

CEO / Board

Go/no-go decisions, risk ownership clarity, budget justification for remediation

CTO / CISO

Prioritized remediation roadmap, technical findings, retest criteria

DPO / Compliance

Evidence for regulatory engagement, framework mapping, audit support

Enterprise Customers

Third-party security proof, due diligence documentation, vendor risk assessment

Get structured evidence for your AI risk decisions

See how our evidence model applies to your specific AI system and use case.

View Assessment Details

Book an AI Resilience Triage

Ready to understand your AI system risks? Let us help you generate the technical evidence you need for confident decision-making.

info@telbi.eu

Email us directly

Google Cloud Certified Professional Cloud Security Engineer
Google Cloud Certified Professional Cloud Architect

Telbi provides technical evidence and remediation recommendations. We do not provide legal advice, conformity assessments, certifications, or guaranteed compliance.