Risk tier
Moderate: internal use with possible operational consequences but no autonomous action.
Representative AI use case
A fictional organization is evaluating an internal assistant over approved policy material.
Moderate: internal use with possible operational consequences but no autonomous action.
Permission-aware retrieval, cited answers, refusal thresholds, evaluation, and incident ownership.
Unauthorized-access, deleted-source, and policy-exception tests must pass.
Policy owners remain responsible for interpretation and updates.
Important limitation
The organization, records, findings, and decisions are representative. Real work begins with qualified inputs and documents its evidence and limitations.
01No customer identity or data
02No promised result
03Structure shown for evaluation only