02 · Compare the artifacts
Supported work. Visible uncertainty.
This is a fictional, sanitized AI-governance training case. All records are fabricated, and the exercise provides no legal, privacy, employment, medical, financial, security, or model-performance guarantee.
Redwood Assist governed intake workflow
Redwood Assist is a fictional services company considering an AI workflow to summarize new client intake and draft a routing recommendation. The current form receives about 420 submissions each month. It includes name, business email, phone, company, project description, budget range, requested timing, and an optional attachment. In a sample of 60 fabricated records, seven attachments contain government identifiers, four contain medical details unrelated to the service, nine include third-party personal information, and 16 lack enough context for reliable routing. The proposed model vendor offers a standard account with model-improvement use enabled by default and a 30-day content retention statement. No security, privacy, contract, data-location, deletion, or subprocessors review has been completed. A pilot prompt tells the model to identify serious founders and reject low-quality leads. The output labels applicants high, medium, or low potential, but neither potential nor serious is defined. In a 40-record test, the model routes 31 correctly according to one manager, while a second manager disagrees on 11 of those decisions. Two Spanish-language submissions are summarized with missing budget conditions. The team proposes automatically rejecting low-rated applicants and sending their attachment to a funding partner. There is no consent for partner disclosure, no human-review standard, no protected exception path, and no versioned evaluation set. Leadership wants the automation live next week to save eight hours of staff time. Learners must classify risk, constrain instructions and sources, establish data boundaries, design meaningful human review, build an evaluation set, and control exceptions and changes. The exercise cannot establish vendor suitability, lawful processing, fairness, or permission to automate decisions.
Supported example — reference only
- Use-case ID
- AI-RISK-01
- Use purpose
- Proposed automatic rejection using an undefined low-potential label.
- Information class
- Attachments may contain government identifiers; other sensitive-data classes require separate review.
- Decision impact
- Consequential and difficult to reverse for an applicant.
- Human-review boundary
- Restrict to assistive triage until labels, evidence, and meaningful review are approved.
- Prohibited action
- No automatic rejection or uncontrolled processing of identifiers.
- Required approvals
- Accountable workflow owner plus privacy, legal, security, and qualified human-review owners.
- Evidence source IDs
- M01-I02 (F02); M01-I05 (F07); M01-I06 (F10)
- Evidence status
- Confirmed proposal and observed sample conditions; approvals pending
A well-handled evidence gap
- Use-case ID
- AI-RISK-02
- Use purpose
- Proposed attachment transfer to a funding partner.
- Information class
- Submission attachments; minimum necessary fields are not supplied.
- Decision impact
- External disclosure with privacy and control consequences.
- Human-review boundary
- Qualified privacy/legal review must precede any transfer.
- Prohibited action
- Do not send attachments without an approved purpose and authority.
- Required approvals
- Privacy/legal and accountable process owner — not supplied
- Evidence source IDs
- M01-I07 (F11)
- Evidence status
- Blocked — consent or other authorized basis not supplied
Flawed approach — do not copy
Marking this ai use-case and risk card “approved and complete” without the required evidence or reviewer is a flawed submission. Stop external sharing or automatic rejection when consent, classification, defined labels, security review, or meaningful human control is absent.
Repair: Rework the ai use-case and risk card as an evidence-backed draft, not an approved result. Capture monthly volume, missing-context, sensitive-data, undefined-label, rejection, and consent facts with exact source IDs. Separate extraction, summarization, routing assistance, and consequential rejection into distinct proposed uses. Classify information and decision impact before considering automation. Check the revision against this requirement: Every proposed use has purpose, information class, impact, human boundary, and cited source. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.
Full case record, ambiguities and all assignments →