QA Results — Scenario A + B (AI Safety Pack)
Date: 2026-02-24 Pack version under test: v1.0
Method: followed 10-qa-scenarios.md steps (classify → use-case card → risk register → controls → 30-day plan).
Scenario A — HR screening / candidate ranking
Expected: D3 (personal data) / O0 / C2 → Prohibited (default)
Checks
- Classification guidance exists in
02a-ai-use-case-matrix.md: PASS - Policy prohibits automated HR decisions by default (C‑H2): PASS
- Governance exception path exists via EDR template (
08-exception-decision-record-template.md) (C‑G3): PASS - HR-specific controls exist (contestability/appeal path C‑H3, bias testing C‑Q2, audit trail C‑L2, bias review cadence C‑H4): PASS
Scenario B — Data leak via unapproved tool
Expected: D3 / O1 / C1 → Prohibited (default) unless tool is approved w/ DLP + privacy review
Checks
- Policy “never paste restricted data into unapproved tools”: PASS
- Controls include approved-tools-only + incident reporting and near‑miss expectation (C‑D1, C‑I1): PASS
- Policy defines Restricted data with clear examples (PII + secrets): PASS
- 30‑day plan includes approved-tools register + training + DLP/blocks where feasible: PASS
Summary
- Scenario A and B pass against v1.0 with required templates and control references in place.
- If you want a tighter pack, add an explicit “worked example” row for each scenario in the matrix (optional).