Penetration testing
Security assessment
Roche allocates resources to maintain industry-standard internal and external penetration testing activities to protect patient and user safety.
AI is transforming healthcare, creating new possibilities in preventive care, personalised treatments and efficient healthcare delivery. Roche’s AI ethics framework is designed to handle these advancements responsibly, balancing innovation with the highest ethical standards.
Roche’s AI ethics principles are rooted in our core values, emphasising responsible innovation. We prioritise patient outcomes and societal benefits, applying strict ethical considerations in every AI-driven healthcare solution.
AI opens up significant opportunities but also brings ethical complexities. Roche’s ethical AI framework addresses these challenges, ensuring that AI solutions are developed and deployed with a focus on patient welfare, transparency and societal impact.
Roche promotes awareness and ethical practices across all teams, fostering a culture of responsible AI use. By educating our teams on ethical AI development, we empower them to create solutions that align with Roche’s commitment to integrity and patient trust.
Our testing employs a rigorous 'white box' methodology, enabling an exhaustive assessment that is aligned with the testing plan's objectives. Testers have access to:
Technical information
Code
Configuration details
Product and system architectures
This effort allows testers to facilitate a comprehensive evaluation. Our process adheres to leading industry best practices and security frameworks, such as the Open Worldwide Application Security Project (OWASP) Top 10 and benchmarks established by the Centre for Internet Security (CIS).