Step 12 of 13Evidence
PRACTICE MODELoading

Restoring your saved mode and lab work…

12 · Evidence review

Review your evidence pack

Demo mode — sign in to save your work

Review the record before export. Gaps remain visible so a decision-maker can distinguish completed evidence from unanswered questions.

WEEK 2 COMPLETION CHECK

Can you now do each of these?

  • Identify affected people, including groups who do not operate the system
  • Describe individual, group, organisational and societal harm
  • Explain where bias can enter across the AI lifecycle
  • Challenge the claim that 87% overall accuracy proves fairness
  • Assess probability and severity and select a mitigation response
  • Test transparency, explainability, accountability, privacy, safety and security
  • Design meaningful human oversight that prevents automation bias
  • State which unresolved issues should block launch
STRUCTURED ARTEFACT

Risk → control → evidence traceability

Build an auditable decision trail. A risk without a control—or a control without evidence—remains visible as a gap.

No traceability rows yet. Add the first priority risk and connect it to a control, test and evidence.

SCENARIO INJECT

The situation has changed

Choose an event and update the governance response as if the system were already operating.

NEW EVENT

Unannounced model change

The supplier upgrades the underlying model and cannot confirm whether prior validation remains representative.

The business wants to keep the original approval because users have not complained.

Write at least 40 characters to unlock the response criteria.

PRACTITIONER MATURITYLevel 1 · Initial

Work has started, but material evidence and ownership are missing.

Why this level?
  • Workflow is 0% complete.
  • Worksheet answer coverage is 0%.
  • No complete risk-control-evidence row is ready for review.
  • Rubric ratings are not yet consistently strong or competent.
READINESS GATENot ready
Workflow
0%
Answers
0%
Traceability
0 rows
Why this gate?
  • Workflow completion is 0%.
  • Answer coverage is 0%.
  • Add at least one traceability row marked ready for review.
TRAINER FEEDBACK

What to strengthen next

  • Name the affected people and explain the pathway from system behaviour to impact.
  • Assign an accountable human role; responsibility cannot sit with the AI system.
  • Define the evidence and acceptance criteria needed to support the conclusion.
  • Add post-deployment monitoring, escalation thresholds and a reassessment trigger.
AI governance evidence pack

HireAI deployment review

Northstar People Operations · Junior Product Analyst scenario

Prepared by
Learner name not added
Date generated
Preparing date…
Training simulation only. Not for live recruitment use.

Scenario summary

Northstar People Operations proposes using HireAI for first-pass CV screening. This review assesses a fictional system that compares applications with a job description, generates scores and recommends whether candidates should be shortlisted.

1. AI system description

System name
Not completed
Business purpose
Not completed
Main users and AI actors
Not completed
Affected people
Not completed
AI capability and model type
Not completed
Data used
Not completed
Decision supported and human role
Not completed
Potential harms and assumptions
Not completed
Evidence and governance questions
Not completed

2. Stakeholder and harm assessment

Stakeholder group
Not completed
Level of harm
Not completed
How are they affected?
Not completed
Possible harm
Not completed
Severity
Not completed
Likelihood
Not completed
Existing control
Not completed
Additional control and communication
Not completed
Mitigation response
Not completed
Evidence needed
Not completed
Owner
Not completed
Should this block launch?
Not completed

3. Risk register

Risk title
Not completed
Cause
Not completed
Risk event
Not completed
Impact
Not completed
Likelihood
Not completed
Severity
Not completed
Inherent risk
Not completed
Controls
Not completed
Residual risk
Not completed
Risk owner
Not completed
Evidence
Not completed
Status
Not completed

4. Human oversight, privacy and vendor review

Where human review happens
Not completed
Who reviews, and what they see
Not completed
Override and audit trail
Not completed
Reviewer training
Not completed
Decisions AI cannot make
Not completed
Escalation, appeal and redress
Not completed
How rubber-stamping is prevented
Not completed
Privacy / DPIA screening
Not completed
Transparency and meaningful explanation
Not completed
Safety and reliability checks
Not completed
Security checks
Not completed
Vendor evidence questions
Not completed

5. Final recommendation

Recommendation
Not completed
Summary reasoning
Not completed
Top three risks
Not completed
Required controls
Not completed
Evidence required before launch
Not completed
Residual risk
Not completed
Monitoring after launch
Not completed
Conditions for approval
Not completed
Who signs off
Not completed

Selected controls

No controls selected.

6. Assurance testing workpaper

Assurance objective
Not completed
Population and period
Not completed
Sampling approach
Not completed
Test procedure
Not completed
Exceptions and root cause
Not completed
Finding and severity
Not completed
Management action
Not completed
Board / audit summary
Not completed
Training simulation only. Not for live recruitment use. This pack records a learner’s assessment and is not a compliance guarantee.
ASSURANCE WORKPAPER

Test whether the controls actually operate

Move beyond policy design: define a population, select a defensible sample, test evidence, document exceptions and write the conclusion an audit committee would need.

01Define

Objective, population and period.

02Sample

Risk-based and representative items.

03Test

Inspect, observe and reperform.

04Conclude

Rate findings and communicate.

TRAINER REVIEW

Sign in to submit this evidence

Demo work stays in this browser. A registered account can submit a fixed version to a cohort trainer.

Sign in or create account