Bedrock custom prompt router has no fallback model configured

Severity
Medium
Service
Bedrock
Check ID
BEDROCK_PROMPT_ROUTER_NO_FALLBACK

What this check finds

A custom Bedrock prompt router does not have a fallback model. If all routed models are unavailable or capacity-constrained, requests will fail with no automatic recovery path.

Passing looks like: Bedrock prompt router has a fallback model.

How to fix it

Edit the prompt router and set a fallback model. Bedrock console → Prompt routers → select router → Edit → Fallback model.

AI risk mappings

AI risk taxonomies mapped to Bedrock custom prompt router has no fallback model configured
FrameworkControls
OWASP Top 10 for LLM Applications (2025)
  • LLM10 Unbounded Consumption
MITRE ATLAS (Adversarial Threat Landscape for AI Systems)
  • AML.T0029 Denial of ML Service

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More Bedrock checks

All Bedrock checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only