Step 5 of 5Evidence
05 · Practitioner output · SaaS

Issue the GenAI security release decision

Demo mode — sign in to save your work

Your conclusion should show whether security, contractual and operational evidence supports launch to customers.

PRACTICE MODELoading

Restoring your saved mode and lab work…

SAAS WORKING CONTEXT

Write the SaaS release record

A fast-growing software provider is embedding third-party AI into a multi-tenant product. Enterprise customers expect security, reliability and contractual clarity.

Evidence bar
  • Release decision
  • Security sign-off
  • Customer assurance pack
REVIEW CHECKPOINTS

GenAI Release Evidence Pack

GenAI Release Evidence Pack

Complete the fields against the saas operating context. Your work saves automatically in this browser.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Loading saved answers…

ASSURANCE WORKPAPER

Test whether the controls actually operate

Move beyond policy design: define a population, select a defensible sample, test evidence, document exceptions and write the conclusion an audit committee would need.

01Define

Objective, population and period.

02Sample

Risk-based and representative items.

03Test

Inspect, observe and reperform.

04Conclude

Rate findings and communicate.

STRUCTURED ARTEFACT

Risk → control → evidence traceability

Build an auditable decision trail. A risk without a control—or a control without evidence—remains visible as a gap.

No traceability rows yet. Add the first priority risk and connect it to a control, test and evidence.

SCENARIO INJECT

The situation has changed

Choose an event and update the governance response as if the system were already operating.

NEW EVENT

Unannounced model change

The supplier upgrades the underlying model and cannot confirm whether prior validation remains representative.

The business wants to keep the original approval because users have not complained.

Write at least 40 characters to unlock the response criteria.

PRACTITIONER MATURITYLevel 1 · Initial

Work has started, but material evidence and ownership are missing.

Why this level?
  • Workflow is 0% complete.
  • Worksheet answer coverage is 0%.
  • No complete risk-control-evidence row is ready for review.
  • Rubric ratings are not yet consistently strong or competent.
READINESS GATENot ready
Workflow
0%
Answers
0%
Traceability
0 rows
Why this gate?
  • Workflow completion is 0%.
  • Answer coverage is 0%.
  • Add at least one traceability row marked ready for review.
TRAINER FEEDBACK

What to strengthen next

  • Name the affected people and explain the pathway from system behaviour to impact.
  • Assign an accountable human role; responsibility cannot sit with the AI system.
  • Define the evidence and acceptance criteria needed to support the conclusion.
  • Add post-deployment monitoring, escalation thresholds and a reassessment trigger.
SELF-ASSESS BEFORE EXPORT

Practitioner quality rubric

Rate the work honestly. “Needs revision” is a useful result when it identifies what to strengthen before review.

Context and scope

Strong: States the system, decision, actors, people affected, boundaries and material assumptions.

Improve: Avoid generic statements or conclusions that depend on unstated facts.

Risk reasoning

Strong: Links a credible cause and event to a specific impact, then assesses likelihood, severity and uncertainty.

Improve: Do not list harms without explaining how they could arise in this scenario.

Proportionate controls

Strong: Selects preventive, detective and corrective controls that address the identified risks and assigns owners.

Improve: Avoid control lists with no connection to a risk, trigger or responsible role.

Evidence and decision

Strong: Defines testable evidence, acceptance criteria, residual risk and a clear, conditional recommendation.

Improve: A confident conclusion is not defensible when evidence, thresholds or escalation routes are missing.

EVIDENCE-QUALITY GATES
Practitioner evidence pack

SecureGenAI

Helix Advisory Cloud · SaaS overlay · GenAI, RAG and agent security

Prepared by
Learner name not added
Course coverage
Weeks 10–11
Training simulation only · Fictional scenario and data

Executive assignment

Helix Advisory Cloud plans a multi-tenant AI assistant that retrieves customer documents, drafts answers and prepares CRM tasks after user confirmation. It uses a hosted proprietary language model, embeddings and role-filtered retrieval.

In simple terms: The software company wants an AI assistant that can search each customer's private files, draft work and prepare actions. Users confirm actions, but weak permissions or malicious instructions could expose data or trigger the wrong task.

Assignment: Threat-model the RAG and agent architecture, define security controls and decide whether the pilot is safe to release.

Sector overlay: SaaS

Decision pressure: The steering committee meets in 10 working days. The launch slot will be lost if the decision is deferred beyond this meeting.

Ownership gap: Product, Risk and Operations each believe another function owns final residual-risk acceptance. The governance charter is silent.

Known facts

  • The assistant retrieves documents from separate customer tenants
  • A hosted proprietary model generates answers and draft actions
  • Role permissions should filter retrieval before content reaches the model
  • Users must confirm CRM or email actions
  • Tenant-isolation, prompt-injection and rollback testing are incomplete

Architecture & System Card

LLM application architecture
Not completed
Model and hosting trade-offs
Not completed
RAG retrieval pipeline
Not completed
Agent autonomy and permissions
Not completed
System card
Not completed

RAG & Agent Risk Checklists

RAG risk checklist
Not completed
LLM output risks
Not completed
Agentic AI control checklist
Not completed
Security threat scenarios
Not completed
Priority incident scenario
Not completed

Security Test & Incident Plan

AI testing and evaluation plan
Not completed
Acceptance criteria and benchmarks
Not completed
Guardrails and output validation
Not completed
AI incident report form
Not completed
External incident communication plan
Not completed
Kill switch and rollback
Not completed

GenAI Release Evidence Pack

Pilot recommendation
Not completed
Security and safety summary
Not completed
Release restrictions
Not completed
Agent behaviour monitoring
Not completed
Change and retest triggers
Not completed

Assurance testing workpaper

Assurance objective
Not completed
Population and period
Not completed
Sampling approach
Not completed
Test procedure
Not completed
Exceptions and root cause
Not completed
Finding and severity
Not completed
Management action
Not completed
Board / audit summary
Not completed

Quality review and sign-off

Reviewer: AI security review board

Decision challenge: Can the RAG or agent system resist untrusted content and prevent unauthorised actions?

Context and scope
Not rated
Risk reasoning
Not rated
Proportionate controls
Not rated
Evidence and decision
Not rated

Reviewer sign-off: ____________________   Date: __________   Version: 1.0

Prepared as a learning artefact. Validate legal and regulatory conclusions against current authoritative sources before real-world use.
TRAINER REVIEW

Sign in to submit this evidence

Demo work stays in this browser. A registered account can submit a fixed version to a cohort trainer.

Sign in or create account