BYBestYou·AISCENARIO LAB
Hands-on practice layer · all 11 courses

Scenario Lab

Every module of every course ends in a real-life situation you can put the training into practice on — mark the email, fill the report, weigh the file, hold the gate — and every scenario carries an AI governance angle, tied to the same canon the governed tutorials are built from. Work the situation, then reveal the notes to check your judgement against the controls the course cites. Each course's governed-response scenario shows the full ai.heart canon: eight layers, a verdict, Node 9, and an append-only audit trail.

BY-BX1 — Governing AI: Duties of Boards and Responsible Persons

Board · 60 min · 5 scenarios
AI governance in this course: the board governs the decisions the AI substantially supports — literacy, disclosure, cadence and conditions with teeth.
M1 · 12 min

The board paper that isn't enough

Board-question drill · Group · Deliberative

Setup

A board paper (fictional) asks approval for an AI-supported system, describing efficiency gains in three paragraphs and technology in two. It does not say which decisions the system will substantially support. You are a director at the table.

Task

Write the three questions you ask before the paper can be approved — framed as 'the decision, not the model' — and the one question you ask about the board's own literacy for this decision.

AI governanceThe board paper is about an AI-supported system — the three questions ('the decision, not the model') are AI governance literacy in action. Ask which decisions the system substantially supports.
Judgement tested

Board literacy is about the decisions AI supports, not the technology (APRA-EXP-2026; ASIC-912A).

Common errors

Asking about the model's accuracy; asking no questions; deferring to 'management knows best'.

Debrief

Which question would management find hardest to answer, and why?

Feeds the governed tutorial

Yes

Controls: APRA-EXP-2026; ASIC-912A

M2 · 12 min

Who answers?

Duty-mapping role-play · Group · Deliberative

Setup

A regulated group (fictional) spans aged care, an AML/CTF-regulated business and a health service — all adopting AI tools. A chair asks: 'which of our duties apply to which business, and who personally carries them?'

Task

Map the duties: responsible persons in aged care (acquire and maintain knowledge), governing-body oversight in AML/CTF, safety and quality training including the governing body in health. Then role-play the chair's questions to the responsible persons.

AI governanceEvery regulated business in the group is adopting AI. Responsible persons must acquire and maintain knowledge of AI's role in their business — the duty-mapping includes AI-specific knowledge.
Judgement tested

Personal and governing-body duties attach differently by sector (AgedCare-s180; AMLCTF-s26H; NSQHS-1.19).

Common errors

Treating all three businesses as one 'AI duty'; assigning duties to staff rather than the responsible person.

Debrief

What changes about a board's agenda when duties are personal rather than corporate?

Feeds the governed tutorial

Yes

Controls: AgedCare-s180; AMLCTF-s26H; NSQHS-1.19

M3 · 12 min

The disclosure check

Privacy-policy review · Paired · Deliberative

Setup

A draft privacy policy (fictional) describes 'automated decision-making' generally, and the system it covers makes decisions 'by computer program' under the December 2026 Privacy Act obligation. The policy says nothing about disclosing that a computer program was substantially involved in decisions.

Task

Check the policy against APP 1.7: what must be disclosed, to whom, and — just as important — what the obligation does NOT require. Draft the disclosure clause and mark the limits the board should not over-read into it.

AI governanceThe December 2026 Privacy Act obligation (APP 1.7) is an AI governance disclosure duty: computer-program decisions must be disclosed. The policy review is the board's first AI privacy check.
Judgement tested

APP 1.7 is a disclosure obligation; 'technology-neutral' means computer program; know what it does not require (APP-1.7).

Common errors

Treating APP 1.7 as a general 'explainability' duty; or as a trivial footnote.

Debrief

Where is the line between disclosing and over-claiming under APP 1.7?

Feeds the governed tutorial

Yes

Controls: APP-1.7

M4 · 12 min

The empty cadence

Artefact gap-hunt · Paired · Deliberative

Setup

The board's oversight record (fictional) for an AML/CTF-regulated business shows one AI item reviewed eighteen months ago, no agenda slot since, and no record of challenge or resource questions. The system has been extended twice in that time.

Task

Find the gap in the cadence, name the two things the record must show for oversight to be evidenced (ongoing rhythm; adequate resources and risk systems), and design the standing agenda item that fixes it.

AI governanceOversight of AI is a cadence, not an event: the record must show ongoing review of AI systems, adequate resources and risk systems, and training linked to actual AI use.
Judgement tested

Ongoing AML/CTF oversight is a cadence (AMLCTF-s26H); adequate resources and risk systems are board issues (ASIC-912A); training is a control only when linked to actual use (APRA-EXP-2026).

Common errors

Counting one past review as oversight; approving 'training records exist' without use evidence.

Debrief

What would a reviewer look for to confirm the cadence is real and not ceremonial?

Feeds the governed tutorial

Yes

Controls: AMLCTF-s26H; ASIC-912A; APRA-EXP-2026

M5 · 12 min CANON · GOVERNED RESPONSE

The approval minute

Minute drafting · Group · Deliberative

Setup

The board (fictional) has decided to approve an AI-supported system in principle. Your task: turn the decision into an approval minute that carries the conditions — personal knowledge before approval in aged care, safety and quality escalation paths in health, and approval conditions for the financial services system.

Task

Draft the minute: the conditions attached to approval, what management must return with, and what triggers escalation back to the board. Compare minutes across the group and merge the strongest conditions.

AI governanceThe approval minute is the board's Node 9: conditions with return dates, escalation triggers, and named responsible persons. Approving AI without conditions is releasing without certification.
Judgement tested

Approval conditions and escalation paths give the approval its teeth (AgedCare-s180; NSQHS-1.19; ASIC-912A).

Common errors

Approving without conditions; conditions without return dates; no escalation trigger.

Debrief

What makes a condition enforceable rather than decorative?

Feeds the governed tutorial

Yes

Controls: AgedCare-s180; NSQHS-1.19; ASIC-912A

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The board decision on the AI-supported customer and patient prioritisation system — and the minute that records it.

Classification of the event: A governing-body release. The minute is the output: approve-in-principle is not approval, and conditions are what make the decision governable.

LayerCheck on this caseVerdict
L1 · Input validationThe paper's gaps verified: no decision inventory, no APP 1.7 assessment, no resourcing or risk assessment, no safety-and-quality governance plan.PASS
L2 · Context analysisApproval in principle is the board's option — but only with conditions that carry return dates and escalation triggers.HOLD
L3 · Harm / lossUnconditional approval releases a system without evidence gates; deferral protects customers and patients.PASS
L4 · Equity weightingResponsible persons carry personal duties — the minute names them, and the board records its challenge.PASS
L5 · Coherence checkAPRA-EXP-2026, ASIC-912A, AgedCare-s180, NSQHS-1.19, APP-1.7 — each limb of the decision maps to a cited duty.VERIFY
L6 · Integration gateCross-layer consistent: decision inventory, disclosure, resourcing, safety and quality — all four return with evidence.PASS
L7 · Audit generationThe minute records conditions, return dates and escalation triggers — append-only.PASS
L8 · Output certificationThe chair signs; the board is Node 9 — management returns with evidence, not assurances.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — conditional approval, with the conditions in the minute.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The board holds release authority. Management returns with a decision inventory, a privacy disclosure assessment, a risk and resourcing assessment, and a safety-and-quality governance plan — or the release does not proceed.
[00:00:00.000] L1 gaps verified · inventory · disclosure · resourcing · safety [00:00:01.000] L2 approval framed · in principle ≠ approved [00:00:02.000] L3 harm weighed · no gates = no release [00:00:03.000] L4 duties named · responsible persons · recorded challenge [00:00:04.000] L5 controls mapped · APRA · ASIC · s180 · NSQHS · APP 1.7 [00:00:05.000] L6 integration passed · four evidence gates, one minute [00:00:06.000] L7 audit appended · conditions + dates + triggers [00:00:07.000] L8 chair signs · board is NODE9 · EXIT = CERTIFIED ONLY

Governed answer

Approve in principle only with conditions that carry return dates and escalation triggers — management returns with a decision inventory, a privacy disclosure assessment (APP 1.7), a resourcing and risk assessment (ASIC-912A), and a safety-and-quality governance plan (NSQHS-1.19), with responsible persons named where duties are personal (AgedCare-s180). The minute is the record of the board's challenge — the board is Node 9, and management returns with evidence, not assurances.

Cited controls: APRA-EXP-2026 · ASIC-912A · AgedCare-s180 · NSQHS-1.19 · APP-1.7

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

BY-G1 — PSPF 2026 Fundamentals

Foundation · 52 min · 5 scenarios
AI governance in this course: AI assistants, AI-mediated contact and AI threats are now part of the everyday security surface — awareness, contact reporting and incident response all carry an AI dimension.
M1 · 10 min

The induction checklist

Role-play + checklist · Paired · Guided

Setup

You join a six-month contract in an agency policy branch. Your line manager ticks 'security induction' as complete so you can start sooner, and tells you the annual course is for permanent staff. A colleague shows you the actual checklist — the training row is unchecked, with a handwritten note 'contractor — skip'.

Task

Role-play the conversation: you have 60 seconds to respond to your manager. Then tick or fix the checklist and add one line saying what the framework actually requires for you.

AI governanceThe induction checklist now includes the agency's AI-tools awareness module. The manager says 'the AI course is for permanent staff — you're only here six months.' Same trap, new layer: security awareness — including AI-specific training — applies to all personnel at engagement (Req 24), and AI governance starts with training that reaches every user of approved tools.
Judgement tested

Training at engagement and annually applies to personnel including contractors (Req 24); culture is led by the Accountable Authority and CSO (Req 23); your part is noticing, reporting, following procedure — not investigating (RA §3.5.2).

Common errors

Agreeing to skip; doing the training secretly instead of raising the record; lecturing the manager about culture.

Debrief

What is 'yours to do' vs 'carried for you'? Who fixes the record? What would you say to a manager who says 'just catch up later'?

Feeds the governed tutorial

No

Controls: PSPF Req 24; PSPF Req 23; PSPF Recommended Approach §3.5.2

M2 · 10 min CANON · GOVERNED RESPONSE

The conference connection

Form fill + written report · Individual · Guided

Setup

After a conference you accept a LinkedIn request from a consultant who sat at your table. They send a friendly message: 'Great talking — always keen to swap notes on policy work. Happy to buy coffee next time I'm in town.'

Task

Use the SOUP four-letter check on this contact, then complete the one-page contact report form: what you include, what you leave out, and what you deliberately do NOT do next.

AI governanceThe conference contact asks which AI assistants your team uses, and offers to 'demo' their product over coffee. Tooling questions are still contact questions: report factually, never investigate — and never discuss approved AI tools with the contact.
Judgement tested

Recognise a contact worth reporting (RA §3.5.1); report factually and stop — never investigate, never probe the person (RA §3.5.2).

Common errors

Waiting for 'something more'; googling the consultant first; confronting them; deciding it's 'probably nothing' without reporting.

Debrief

What does 'report, don't investigate' protect? Where does the form go? What if you are unsure — what does the framework prefer?

Feeds the governed tutorial

Yes

Controls: PSPF Recommended Approach §3.5.1; §3.5.2

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The five-month professional contact and the decision whether — and what — to report.

Classification of the event: A contact event under the reporting obligation. The output under governance is the contact report itself; the reporter's authority ends at submission.

LayerCheck on this caseVerdict
L1 · Input validationThe facts as known — sequence, venues, asks — captured and verified against what actually happened, nothing embellished.PASS
L2 · Context analysisIntent is unknown by design — the framework does not require the reporter to interpret. State fit: report, don't investigate.HOLD
L3 · Harm / lossUnder-reporting risks missing interference; over-reporting a false alarm is cheap. The report resolves the asymmetry.PASS
L4 · Equity weightingThe reporter is not accused of anything — reporting is the duty, not the judgement. No adverse inference for raising it.PASS
L5 · Coherence checkMatches RA §3.5.1/§3.5.2: educate on SOUP, submit the report, stop. Verify the entity's actual form is the one used.VERIFY
L6 · Integration gateCross-layer consistent: factual report, no investigation limb, no follow-up promise.PASS
L7 · Audit generationThe report is logged, dated, signed — append-only. The security mailbox receives it; nothing is deleted.PASS
L8 · Output certificationThe report is released to the security function — Node 9 decides what happens next; the reporter does not follow up.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
OBSERVE → PASS · CERTIFIED RELEASE — the report is submitted; release authority sits with the security function.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The security function holds release authority over what the report means and what happens next. The reporter's authority ends at submission — noticing and telling, never investigating.
[00:00:00.000] L1 facts captured · sequence + venues + asks · no interpretation added [00:00:01.000] L2 context noted · intent unknown by design · report, don't investigate [00:00:02.000] L3 asymmetry weighed · under-reporting costs more than over-reporting [00:00:03.000] L4 equity held · reporter free of blame · no adverse inference [00:00:04.000] L5 coherence checked · RA §3.5.1 + §3.5.2 · entity form verified [00:00:05.000] L6 integration passed · factual, bounded, no follow-up [00:00:06.000] L7 audit appended · report signed · append-only [00:00:07.000] L8 released to security function · NODE9 holds the meaning · EXIT = CERTIFIED ONLY

Governed answer

A good governed answer reports the whole five-month sequence factually and stops: no investigation, no probing, no 'wait for something more'. Any single SOUP letter — Suspicious, Ongoing, Unusual, Persistent — is enough. The report is the output; the security function holds release authority for what happens next.

Cited controls: PSPF RA §3.5.1 · §3.5.2 · Req 219

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M3 · 12 min

Sort the pattern

Card sort + group discussion · Group · Guided

Setup

Eight cards, each describing one interaction with the same person over a year: praised your work at a meeting; asked what your team is working on 'out of interest'; bought coffee three times; offered a paid speaking spot; asked about a colleague's overseas trip; sent articles on your program area; invited you to dinner; asked for a copy of an unclassified policy before it is published.

Task

Sort each card into three piles — 'report', 'not report', 'unsure' — and write one sentence of reasoning for the unsure pile. Compare piles as a table.

AI governanceOne of the eight cards: 'asked which AI assistants your agency has approved, and offered to show you one off the record.' Cultivation now targets your AI estate — the pattern check includes what the contact asks about your tools.
Judgement tested

Foreign interference and cultivation are gradual and rarely dramatic (Req 219); the recognition connects to the contact report you already know (RA §3.5.1) — same report, same stop point.

Common errors

Judging each card in isolation; treating 'friendship' as proof of safety; sorting by how the person made you feel.

Debrief

Which single card is reportable on its own? Which only in sequence? Why does the course call the sequence the 'new 2026 content'?

Feeds the governed tutorial

Yes

Controls: PSPF Req 219; PSPF Recommended Approach §3.5.1

M4 · 12 min

The lost laptop

Timeline + simulated phone call · Paired · Guided

Setup

A colleague calls you from an airport: their work laptop is missing after security screening. The device held OFFICIAL:Sensitive material. They ask you what to do, and add 'I've already checked my emails — nothing sensitive in there'.

Task

Walk the first steps in order on the incident timeline cards: follow the defined procedure, report, and stop. Then play the 90-second call you would make to the security hotline — what you say, what you don't say.

AI governanceThe lost laptop also held an approved AI assistant with session history of case work. The incident report must include what the AI assistant had access to — AI sessions are recordable agency data, not personal scratch space.
Judgement tested

A defined incident procedure exists — follow it and report (Req 26); serious incidents reach the right authority in time (Req 28); you do not investigate or assess damage yourself.

Common errors

Offering to 'search the cloud logs'; deciding it's minor because the colleague says so; delaying to 'be sure'.

Debrief

What is the first step when you don't know the procedure? What makes an incident 'serious' for Req 28 — and who decides?

Feeds the governed tutorial

No

Controls: PSPF Req 26; PSPF Req 28

M5 · 8 min

What's mine, what's carried

Sorting exercise + personal checklist · Individual · Guided

Setup

A security bulletin lands in your inbox: heightened emergency risk for your area; also attached is the roster of specialist training for high-risk roles. You are not in a high-risk role.

Task

Split the bulletin's contents into two columns — 'mine' and 'carried for me' — then write the three things the bulletin changes about your day, and the one thing that stays the same.

AI governanceThe bulletin adds a line on AI-enabled threats: deepfake voice calls and AI-generated phishing. Being warned now includes recognising AI-mediated contact attempts — the SOUP check applies to the message's origin, not just its style.
Judgement tested

Personnel are warned of heightened emergency risk (Req 57); targeted training applies to specialist and high-risk roles (Req 25); your steady part stays noticing, reporting, following procedure.

Common errors

Taking on duties that belong to others; ignoring the bulletin because you're not high-risk; treating the warning as optional reading.

Debrief

What does being 'warned' require of you that reading an email doesn't? Why is the division of duties a relief rather than a gap?

Feeds the governed tutorial

No

Controls: PSPF Req 57; PSPF Req 25

BY-G3 — Protective Markings

Foundation · 52 min · 5 scenarios
AI governance in this course: AI drafting and marking assistants suggest — the human originator decides, marks and certifies. AI output inherits the sensitivity of what it consumed.
M1 · 12 min

Three documents, three rungs

Artifact marking · Individual · Guided

Setup

Three one-page documents sit on your desk: (A) a meeting agenda for a routine internal catch-up; (B) a draft media release containing unannounced figures on a program's performance; (C) a staff list with personal contact details for an office move.

Task

For each document, write the damage answer — 'if this were seen by the wrong person, what could result?' — then choose the marking level the damage honestly justifies, and sign the originator line.

AI governanceDocument B is now an AI-generated draft summary of a PROTECTED report. The AI output inherits the source's marking, and the officer who runs the AI is the originator of the output — accountable for its marking (Req 58–60).
Judgement tested

The originator judges sensitivity by potential damage (Req 59); the level is set at the lowest reasonable level (Req 60); a named person stands behind the label (Req 58).

Common errors

Marking by habit or template ('we always mark this PROTECTED'); marking by topic rather than the actual document; leaving the originator line blank.

Debrief

Why does 'lowest reasonable' protect the marking system itself? What damage does over-marking cause?

Feeds the governed tutorial

No

Controls: PSPF Req 59; PSPF Req 60; PSPF Req 58

M2 · 10 min

The ladder game

Matching pairs + quick-fire marking · Paired · Guided

Setup

Twelve cards describe information ('staff birthdays in a team calendar', 'the draft budget before Cabinet decision', 'a colleague's personal email address in a distribution list'...). The six marking values are laid out on the table.

Task

Match each card to the lowest rung that honestly covers the potential damage, then swap cards and challenge one of your partner's choices. End with the quick-fire round: eight mini-documents, ten seconds each.

AI governanceThe quick-fire includes 'an AI agent's summary of a PROTECTED document'. Mark to the highest thing inside — even when the AI 'doesn't know' what it summarised. The human who releases it owns the rung.
Judgement tested

Recall the six values in order and choose the lowest honest rung (Req 59, 60) — the rung is a promise, not a guess.

Common errors

Matching to the topic's importance instead of the document's content; defaulting everything up one rung 'to be safe'.

Debrief

Which pairing was hardest? What did the disagreements teach about 'consistent judgement'?

Feeds the governed tutorial

No

Controls: PSPF Req 59; PSPF Req 60

M3 · 10 min

Subject line surgery

Error-correction drill · Individual · Guided

Setup

Ten draft email subject lines, each with exactly one or two flaws: marking missing, wrong position, wrong case, doubled space, a caveat without a classification, or a marking on the wrong line.

Task

Red-line each subject line and write the corrected form in the exact syntax, including the one spacing rule that trips people up. Then pair each caveat with the classification it must travel with.

AI governanceThe ten malformed subject lines are AI-drafted output from the writing assistant. The officer corrects and decides — the tool suggests, the human marks (ISM-0271).
Judgement tested

Markings are readable text in the correct email subject-line form (Req 61, 67); caveats never travel alone (Req 64).

Common errors

'Fixing' the wording of a marking; treating a missing caveat as minor; forgetting the exact spacing.

Debrief

Why is the syntax fixed rather than 'close enough'? What does a caveat without a classification invite?

Feeds the governed tutorial

Yes

Controls: PSPF Req 61; PSPF Req 67; PSPF Req 64

M4 · 12 min CANON · GOVERNED RESPONSE

The system that won't tell you

Simulated mailbox + tool demo · Individual · Guided

Setup

In the practice mailbox you receive a message whose attachment is marked PROTECTED, but the mail client shows no marking field anywhere and your colleague says 'the tool usually adds it'. The message itself is unclassified routine text.

Task

Mark the email to the highest sensitivity it contains, record what the tool did and did not do on the check sheet, and state what you would rely on before sending a reply that quotes the attachment.

AI governanceThe mail client's AI assistant now 'usually adds' the marking and even auto-completes subject lines. The tool's silence — or its guess — is never a verdict; the officer certifies the marking before release.
Judgement tested

Mark to the highest sensitivity present (Req 67); markings are carried as structured fields on systems (Req 68; ISM-0270, 0271); the tool will not make the judgement for you.

Common errors

Trusting the tool to mark; treating the routine body as the whole email; forwarding the attachment 'as is' without checking the reply's own marking.

Debrief

Where does the marking live on a system, and why does that matter for records? When is 'the tool usually adds it' not good enough?

Feeds the governed tutorial

Yes

Controls: PSPF Req 68; ISM-0270; ISM-0271; PSPF Req 67

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The email whose attachment is marked PROTECTED, while the mail client shows no marking field at all.

Classification of the event: An output awaiting a marking decision — the tool's silence is not a verdict, and 'the tool usually adds it' is not evidence.

LayerCheck on this caseVerdict
L1 · Input validationAttachment header verified PROTECTED; body routine; client view shows no marking field.PASS
L2 · Context analysisThe easy read ('routine body') is the wrong read — mark to the highest sensitivity present.HOLD
L3 · Harm / lossUnder-marking exposes the PROTECTED content; over-marking buries it in noise. The attachment decides.PASS
L4 · Equity weightingNo shortcuts because 'the tool usually adds it' — the person sending owns the care.PASS
L5 · Coherence checkReq 67/68 + ISM-0270/0271: tool suggests, human decides. Verify the records field carries the marking.VERIFY
L6 · Integration gateCross-layer consistent: highest sensitivity, tool limits, records property all agree.PASS
L7 · Audit generationThe reply's marking and the tool check are recorded with the message.PASS
L8 · Output certificationThe officer certifies the marking before send — the human signs, not the tool.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — the silence of the tool changes nothing; the human certifies.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The originator holds marking authority — never the tool, never 'what it usually does'. Release of the reply carries the officer's certification.
[00:00:00.000] L1 attachment verified · PROTECTED · client field empty [00:00:01.000] L2 context held · mark to the highest thing inside [00:00:02.000] L3 harm weighed · exposure vs burial · attachment decides [00:00:03.000] L4 equity held · no 'tool usually does it' shortcut [00:00:04.000] L5 coherence checked · Req 67/68 · ISM-0270/0271 [00:00:05.000] L6 integration passed · records field recorded [00:00:06.000] L7 audit appended · tool check noted · signed [00:00:07.000] L8 officer certifies · EXIT = CERTIFIED ONLY

Governed answer

Mark the email PROTECTED, note exactly what the tool did and did not do, record the structured field, and carry the level into any reply that quotes the attachment. The tool's silence — or its guess — is never a verdict; the officer certifies the marking before release.

Cited controls: PSPF Req 67 · Req 68 · ISM-0270 · ISM-0271

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 8 min

The open-plan briefing

Situation sorting · Group · Guided

Setup

Six situations: discussing a PROTECTED matter at your desk in an open-plan area with visitors nearby; taking the same discussion into the booked secure room; reading a marked document on the train; discussing it on a video call from home with family present; photocopying a marked document; leaving a marked printout face-up on the shared printer.

Task

For each situation, decide 'right place / wrong place / depends' and name the minimum care the marking triggers. Defend one 'depends' to the group.

AI governanceThe meeting room has an AI transcription bot. 'Approved location' now includes 'no unapproved AI listeners' — transcription tools must be approved, and any transcript of a classified discussion inherits the marking.
Judgement tested

The marking sets the minimum care (Req 62); classified discussions happen only in approved locations (Req 70).

Common errors

Treating 'depends' as 'anything goes'; thinking the marking matters only at the moment of sending.

Debrief

Why does the minimum care continue after the email is sent? What does a 'wrong place' choice cost in practice?

Feeds the governed tutorial

No

Controls: PSPF Req 62; PSPF Req 70

BY-GX3 — Email Protective Marking

Foundation · 35 min · 6 scenarios
AI governance in this course: AI drafts, AI agents and AI mail assistants change who 'sent' a message — never who owns the marking.
M1 · 5 min

The unmarked thread

Inbox sweep · Individual · Guided

Setup

Five emails in the practice inbox. One is a reply inside an internal thread with no marking ('internal mail doesn't need one'), one is marked only by a coloured flag, one is marked by a phone call you received beforehand, one is correctly marked, and one has the marking in the signature block.

Task

Sweep the inbox: which messages are not properly marked, and in one line each, what makes each one wrong?

AI governanceOne of the five emails was sent by an AI agent on behalf of a colleague — no marking. AI-generated mail is still email in and between entities; the standard applies to the message, not the author's species.
Judgement tested

Email in and between entities carries a text marking (Email Req 0067); text is the requirement because a person and a machine read it the same way (Email Req 0061).

Common errors

Accepting a colour or a call as a marking; treating internal mail as exempt; accepting a signature-block marking.

Debrief

Why does 'internal mail is exempt' fail the standard's own wording? What does the phone call not do?

Feeds the governed tutorial

No

Controls: Email Req 0067; Email Req 0061

M2 · 5 min

Mark to the highest thing inside

Value selection drill · Individual · Guided

Setup

Three variants of the same email: (A) body only — routine; (B) body plus an OFFICIAL:Sensitive attachment; (C) body plus a PROTECTED attachment.

Task

For each variant, choose the one SEC value and say which part of the email drove it. Then do the reverse: given the value, infer what must be inside.

AI governanceVariant B's attachment is an AI-generated summary of a marked source. The value still follows the highest sensitivity inside — AI output inherits what it consumed.
Judgement tested

Select the SEC value by reading every part and marking to the highest sensitivity present (Email Req 0061; ISM-0270).

Common errors

Marking to the body only; marking to the topic; choosing by recipient seniority.

Debrief

What is the smallest component that can lift a whole email's value?

Feeds the governed tutorial

Yes

Controls: Email Req 0061; ISM-0270

M3 · 6 min

The syntax clinic

Rewrite drill · Individual · Guided

Setup

Eight email headers and subject lines, each malformed: wrong case, wrong bracket, marking in the body, missing space, an invented value, a caveat on its own, a header written as 'X-PROTECTIVE-MARKING: PROTECTED' without SEC=, and one correct example hidden among them.

Task

Rewrite each in the exact fixed syntax — both the Subject Field Marking and the Internet Message Header Extension — and match the four caveat types to their uses.

AI governanceThe clinic's malformed lines came from an AI drafting assistant. Exact syntax is the human's job — the standard is fixed so both people and systems read the same value.
Judgement tested

Both forms use exact fixed syntax (Email Req 0061); four caveat types attach to values, never alone.

Common errors

'Close enough' syntax; mixing the two forms; inventing values or caveats.

Debrief

Why does a machine-readable form matter for systems that route, filter and record email?

Feeds the governed tutorial

No

Controls: Email Req 0061

M4 · 6 min CANON · GOVERNED RESPONSE

The header that wins

Contradiction triage · Paired · Guided

Setup

A message arrives with subject [SEC=OFFICIAL] but header X-Protective-Marking: SEC=PROTECTED, ACCESS=Legal-Privilege. A colleague says 'the subject is what people see, so treat it as OFFICIAL'. The records system also shows the Information Management Marker is missing.

Task

State which form wins, what the Information Management Marker floor requires, and what you record before replying. Pair up: one of you argues the colleague's line, the other responds with the standard.

AI governanceThe sender used an AI drafting tool that wrote the OFFICIAL subject while the human attached a PROTECTED document. AI didn't read the attachment; the human owns the marking. The header wins, and the clash is the finding.
Judgement tested

Where both forms appear the header wins (EM-7.precedence); the IMM floor still applies (EM-IMM.floor); the marking connects to the records property (Email Req 0068).

Common errors

Trusting the visible subject; treating the clash as 'someone else's problem'; replying without recording.

Debrief

What does a clash between forms tell you about the message's journey?

Feeds the governed tutorial

Yes

Controls: EM-7.precedence; EM-IMM.floor; Email Req 0068

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The incoming message whose subject reads [SEC=OFFICIAL] while the X-Protective-Marking header reads SEC=PROTECTED, ACCESS=Legal-Privilege.

Classification of the event: A contradictory inbound output — the clash between the two forms is itself the signal, not a detail to paper over.

LayerCheck on this caseVerdict
L1 · Input validationBoth forms captured; header verified against the raw message; attachment header page confirmed PROTECTED.PASS
L2 · Context analysisWhere both forms appear, the header wins — EM-7.precedence. The visible subject is the trap.HOLD
L3 · Harm / lossTreating it at OFFICIAL would mis-handle privileged legal material; the header value protects the counterpart.PASS
L4 · Equity weightingCorrect handling protects the originator's entity too — the clash is recorded, not blamed.PASS
L5 · Coherence checkEM-7.precedence + the Information Management Marker floor + the records property (Email Req 0068) all apply.VERIFY
L6 · Integration gateCross-layer consistent: header wins, floor applies, record carries it.PASS
L7 · Audit generationThe clash and the decision are recorded with the message — append-only.PASS
L8 · Output certificationAny onward summary is certified at PROTECTED with the caveat, to cleared recipients only.VERIFY

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — the message stands at PROTECTED, Legal-Privilege; onward release is bounded.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The originating entity holds release authority for changes to the message's standing; the recipient handles at the header value and may not quietly downgrade.
[00:00:00.000] L1 both forms captured · header verified · attachment confirmed [00:00:01.000] L2 precedence applied · EM-7 · header wins [00:00:02.000] L3 harm weighed · OFFICIAL read would mis-handle privileged advice [00:00:03.000] L4 equity held · clash recorded, not blamed [00:00:04.000] L5 floor checked · IMM recorded · records property confirmed [00:00:05.000] L6 integration passed · no contradiction left standing [00:00:06.000] L7 audit appended · clash + decision logged [00:00:07.000] L8 summary certified at PROTECTED + caveat · cleared recipients only

Governed answer

Treat the message at SEC=PROTECTED with ACCESS=Legal-Privilege — the header wins where both forms appear (EM-7.precedence). Apply the Information Management Marker floor and record the message and its marking as a property of the record (Email Req 0068). Any summary quoting the advice carries PROTECTED and the caveat, to cleared recipients only. The clash is itself a flag about the message's journey — note it, don't paper over it.

Cited controls: EM-7.precedence · EM-IMM.floor · Email Req 0068

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 5 min

Tool limits, human decisions

Tool-behaviour triage · Individual · Guided

Setup

Three observations from the help desk: (1) the client suggests a marking but a user overrode it; (2) a reply draft refused to downgrade the value of a quoted original; (3) the mail server bounced a message whose header did not match policy.

Task

Classify each as 'tool doing its job', 'user error', or 'tool failure' — and for each, write who remains accountable for the final marking decision.

AI governanceThe 'tool' now includes an AI assistant that suggests downgrades and 'helpfully' rewrites headers. A blocked downgrade is the guard working — AI cannot override the human's marking decision.
Judgement tested

Tools suggest, never decide (ISM-0271); quiet downgrades of replies are blocked (ISM-1089); the server is the last calm check (ISM-0565) — the person stays accountable.

Common errors

Blaming the tool for a human judgement; treating a blocked downgrade as a bug.

Debrief

Why is it desirable that the tool cannot mark for you?

Feeds the governed tutorial

No

Controls: ISM-0271; ISM-1089; ISM-0565

M6 · 8 min

Send it properly

Full compose + self-check · Individual · Guided

Setup

A brief: send a two-paragraph status update on a joint program, quoting one figure from an attached PROTECTED partner report, to three internal colleagues and one external counterpart. (Practice mailbox only.)

Task

Compose the complete email — subject marking, body, header marking, attachment note — then run the five-point self-check card before 'send'.

AI governanceThe draft email is AI-assisted. Before send, the five-point self-check gains a sixth line: 'the AI suggested — I decided.' Release requires a human certificate.
Judgement tested

The full sequence: read everything, choose the value, write the syntax, respect precedence and the floor (ISM-0270; Email Req 0067) — a single honest send.

Common errors

Skipping the header; marking only the attachment; sending before the self-check.

Debrief

What did composing the whole message surface that reading about it did not?

Feeds the governed tutorial

Yes

Controls: ISM-0270; Email Req 0067

BY-G7 — Fraud Prevention

Foundation · 54 min · 6 scenarios
AI governance in this course: AI detection is one more layer in the stack, bound by the same conduct and data duties as every control — and never the only wall.
M1 · 8 min

One wall or five?

Control-stack diagram work · Paired · Guided

Setup

A diagram of an accounts-payable control stack: segregation of duties, three-way match, exception report, duplicate-payment review, monthly reconciliation. A colleague says 'the three-way match is our wall — the rest is ceremony'. The diagram shows the three-way match is currently the only check on one payment path.

Task

On the diagram, label which layer each control is, then answer: if the three-way match is removed from that path tonight, what is actually left? Write the one-line answer to the colleague.

AI governanceThe control stack now includes an AI anomaly detector. A colleague says 'the AI wall covers everything' — defence-in-depth still applies: AI is one layer, and a layer described without its tier invites the assumption it is the only defence.
Judgement tested

Fraud prevention is defence-in-depth, T0-T3 (IPSFF Prevention Tiers); a control described without its layer invites the assumption it is the only defence.

Common errors

Ranking controls by cost or glamour; accepting 'one strong check covers everything'.

Debrief

Which of your entity's layers would you miss most if it quietly stopped?

Feeds the governed tutorial

Yes

Controls: IPSFF Prevention Tiers T0-T3

M2 · 10 min

Place the control

Tier placement game · Group · Guided

Setup

Eight control cards: staff vetting; tone-from-the-top message; three-way match; exception report; fraud loss measurement; hotline; post-payment data analytics; board fraud committee. The T0-T1 boundary is where the group always argues.

Task

Place each card in its tier on the wall, then fight the two boundary cases deliberately: which card is T0, which is T1, and why does the distinction matter for who owns it?

AI governanceTwo new cards join the game: 'AI detection at T1–T2' and 'AI-generated invoice detection'. Place them — and argue the T0/T1 boundary with AI in the room.
Judgement tested

Distinguish the four tiers and place a real control correctly, especially T0 vs T1 (IPSFF Prevention Tiers).

Common errors

Treating tiers as a ranking of importance; putting measurement controls 'outside' prevention.

Debrief

What changes operationally if a control is really in a different tier than everyone assumed?

Feeds the governed tutorial

No

Controls: IPSFF Prevention Tiers T0-T3

M3 · 10 min

The stand-down request

Memo drafting · Individual · Guided

Setup

Finance asks to stand down the duplicate-payment review for six months to free staff for year-end. Their email is persuasive: 'no fraud found in two years'. The last fraud risk assessment predates the change.

Task

Write the one-page response: what must happen before any control is changed or removed, what residual risk means here, and who signs off on it. End with the single sentence you would actually send.

AI governanceFinance wants to stand down the duplicate-payment review because 'the AI model hasn't flagged fraud in two years'. AI false negatives are not absence of fraud — the FRA comes before any control change.
Judgement tested

Residual fraud risk must be assessed; the FRA comes before changing or removing a control (IPSFF FRA); someone signs off on residual risk.

Common errors

Approving 'temporarily'; accepting 'no fraud found' as 'no fraud'; leaving the sign-off unnamed.

Debrief

Why does order matter — assessment first, then change? What does a quiet stand-down do to every other layer?

Feeds the governed tutorial

Yes

Controls: IPSFF FRA (measurement-scoped)

M4 · 10 min CANON · GOVERNED RESPONSE

The quiet ledger

Mini data exercise · Paired · Guided

Setup

A one-page fictional ledger: 400 payments. The exception report flags 6; full review of a 50-payment sample finds 4 irregular payments, 3 of which the exception report never flagged. A colleague says 'we only lost a handful, so we're fine'.

Task

Work the numbers: what does the sample imply about the 400? What is the difference between 'detected fraud' and 'actual fraud' here? Draft the one-paragraph note the audit committee should see.

AI governanceThe exception report is now AI-generated, and the full-sample review found the AI missed 3 of 4 irregular payments. Low detection is not low fraud — and AI inherits the data duty underneath every number.
Judgement tested

Detected fraud is not the same as actual fraud (IPSFF FLM); low detection is not low fraud; FRA and FLM answer different questions together.

Common errors

Extrapolating with false precision; reporting the detected figure as the fraud figure; deciding 'fine' from a small flagged set.

Debrief

What makes an estimate honest rather than alarmist? Who should see the measured figure?

Feeds the governed tutorial

Yes

Controls: IPSFF FLM (measurement-scoped)

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The measured fraud-loss estimate versus the detected figure — and the question of what the audit committee is told.

Classification of the event: A measurement output that must never be dressed as certainty — and a decision that must not hide behind either number alone.

LayerCheck on this caseVerdict
L1 · Input validationSample design, method and calculation verified; the full-sample review is reproducible.PASS
L2 · Context analysisDetected fraud is not actual fraud — FRA and FLM answer different questions. The measured estimate is best available, not gospel.HOLD
L3 · Harm / lossReporting only the detected figure understates; a single point estimate overstates. Present both, with the uncertainty.PASS
L4 · Equity weightingHonest numbers protect the public purse and the staff who run the controls — no smoothing to comfort anyone.PASS
L5 · Coherence checkStay inside the measurement scope of the course — entity-level duties live in the PGPA Act and the Rule, not here.VERIFY
L6 · Integration gateCross-layer consistent: both figures, method, and the reason they differ.PASS
L7 · Audit generationMethod, sample, estimate and wide confidence bounds appended — append-only.PASS
L8 · Output certificationThe committee brief is certified by the accountable officer before release.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — both figures go to the committee, with method and wide bounds.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The accountable officer signs the committee brief. The estimate is released with its uncertainty — never alone, never as a verdict on any individual.
[00:00:00.000] L1 method verified · sample + full review · reproducible [00:00:01.000] L2 framing held · detected ≠ actual · two questions [00:00:02.000] L3 harm weighed · both numbers, both honest [00:00:03.000] L4 equity held · no smoothing for comfort [00:00:04.000] L5 scope kept · measurement only · entity duties elsewhere [00:00:05.000] L6 integration passed · figures + method + reason [00:00:06.000] L7 audit appended · bounds recorded [00:00:07.000] L8 accountable officer certifies · EXIT = CERTIFIED ONLY

Governed answer

Report the measured estimate as the entity's best available figure alongside the published detected figure, with the method and the wide confidence bounds, and say plainly why they differ. The audit committee gets both numbers — and the reason — not one dressed as the truth. The measurement is scoped to the IPSFF measurement controls; entity-level fraud duties live in the PGPA Act regime and your fraud control plan, not in this brief.

Cited controls: IPSFF FLM (measurement-scoped) · FRA

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 8 min

The quiet change

Change-break hunt · Individual · Guided

Setup

A data-pipeline change log (fictional): 'field FRA_RISK renamed; three legacy sources decommissioned; reconciliation job now runs monthly'. Nobody told the fraud team. The next FLM silently covers 60% of the population.

Task

Find the break in the log, name the two duties it offends (conduct and data governance), and draft the two-line fix request to the data owner.

AI governanceThe change log includes: 'AI model retrained; threshold recalibrated; drift monitoring discontinued.' The break is the quiet retraining — conduct and data-governance duties bind the model like any other control.
Judgement tested

The measurement-scoped conduct duty and the data-governance duty underpin every number (IPSFF); quiet changes break measurement.

Common errors

Treating the change as IT's business; accepting the renamed field at face value.

Debrief

Why do numbers only mean what the data governance underneath lets them mean?

Feeds the governed tutorial

No

Controls: IPSFF conduct + data-governance duties (measurement-scoped)

M6 · 8 min

The new detector

Tool assessment · Paired · Guided

Setup

A vendor demo shows an AI detection tool catching 'fraud patterns humans miss'. Procurement asks you to sign off. The demo ran on the vendor's own data; there is no test plan for your entity's data; the tool would auto-hold payments without review.

Task

Place the tool in the tier stack, write the three tests it must pass before it operates on your data, and name the human decision that must remain in the loop.

AI governanceThe vendor's AI detector would auto-hold payments without review. The human approval gate is the governed release authority — the tool is tested on your data, and no hold happens without a person.
Judgement tested

AI-enabled detection is one more control inside existing tiers, to be tested like any other, with a checkable human in the loop (IPSFF AI application).

Common errors

Treating the demo as assurance; letting the tool auto-decide 'hold' with no review; placing AI outside the tiers.

Debrief

What does 'trust you can check' require you to build before the tool goes live?

Feeds the governed tutorial

No

Controls: IPSFF AI application (measurement-scoped)

BY-G2 — ISM 2026

Practitioner · 62 min · 6 scenarios
AI governance in this course: accountability, training, policy, reporting and the June 2026 changes — plus the ISM AI control set (ISM-2112/2113) and named owners for AI use.
M1 · 10 min

Who owns it?

Org-chart gap hunt + accountability statement · Paired · Applied

Setup

An org chart (fictional): a CIO, three security teams, a training function — but no named CISO, and the awareness-training program has no named owner. An incident has just occurred that training was meant to prevent, and nobody can say who is accountable.

Task

Mark the gap on the chart, draft the one-paragraph accountability statement that names the person and what they own, and write what you would say if asked 'who answers for the training program?'

AI governanceThe org chart gap now includes AI: no named owner for AI use in the agency, and the awareness-training program — which must cover AI-specific training — has no named owner. Both need a name.
Judgement tested

Cyber security leadership sits with a named accountable person who owns the awareness training program (ISM governance controls).

Common errors

Accepting 'the team owns it'; naming a committee; leaving the statement vague about the training program.

Debrief

Why does a named person change behaviour where a committee does not?

Feeds the governed tutorial

Yes

Controls: ISM governance: accountability

M2 · 10 min

Three profiles, two duties

Training matrix build · Individual · Applied

Setup

Three staff profiles: a new graduate (no admin rights), a system administrator with privileged access, and a contractor engaged for nine months with standard access.

Task

Build the training row for each profile in the matrix: what training applies, how often, and what the privileged user gets beyond the annual course. Then write the one-line rule that holds both duties together.

AI governanceThe training matrix gains a row: 'approved AI tool users' — tailored training for anyone whose work the AI touches, not just privileged users. The three profiles now include an AI-assisted analyst.
Judgement tested

Annual awareness training for all personnel plus tailored training for privileged users (ISM training controls).

Common errors

Giving everyone the same course; treating 'privileged' as optional; forgetting contractors.

Debrief

What does 'tailored' mean for a privileged user's day-to-day decisions?

Feeds the governed tutorial

No

Controls: ISM training controls

M3 · 10 min

The policy you can't find

Policy audit against three verbs · Paired · Applied

Setup

A user asks whether personal web browsing is allowed at work. The system usage policy exists; the web usage policy was 'approved last year' but no one can find a version, a publish date, or evidence staff were told. The help desk answers differently every time.

Task

Read the sample system usage policy and check it against the three verbs — developed, implemented, maintained. Produce the gap list and the one sentence that should answer the user's question today.

AI governanceThe policy audit extends to AI: the system usage policy must name which AI tools are approved and what they may touch; the missing web usage policy question becomes 'which AI services may be used at all'.
Judgement tested

System usage and web usage policies must be developed, implemented and maintained (ISM policy controls) — 'maintained' means current, findable and told to people.

Common errors

Answering from memory; accepting 'approved' as 'implemented'; treating a missing policy as a minor paperwork issue.

Debrief

Which of the three verbs is cheapest to skip and most expensive to lose?

Feeds the governed tutorial

No

Controls: ISM policy controls (system usage, web usage)

M4 · 12 min CANON · GOVERNED RESPONSE

Two reports, one incident

Incident timeline + notification drafting · Paired · Applied

Setup

An incident timeline (fictional): 09:00 anomaly detected; 09:20 confirmed as a suspected compromise; 10:00 executive asks 'who needs to know?'. The incident involves a system that handles sensitive information.

Task

Plot the two reporting paths on the timeline — internal to the CISO, and external to ASD — with the timing each expects, and draft the notification lines for both.

AI governanceThe incident involves an AI system's anomalous behaviour — a model acted outside its lane. Two reports, one incident: internal to the CISO, external to ASD, each within its timing; AI incidents are reported like any other.
Judgement tested

Internal and external reporting paths exist with timing expectations (ISM reporting controls); two reports, one incident, both made.

Common errors

Reporting internally and stopping; waiting for 'full facts'; confusing the two recipients' timing.

Debrief

Why does the framework want both reports rather than one? What goes in an initial report vs a follow-up?

Feeds the governed tutorial

Yes

Controls: ISM reporting controls

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The confirmed security incident — and the two notifications it requires.

Classification of the event: An incident output requiring two governed releases: one internal to the CISO, one external to ASD, each within its timing.

LayerCheck on this caseVerdict
L1 · Input validationIncident facts verified: 09:00 anomaly, 09:20 confirmation, systems and data involved.PASS
L2 · Context analysisBoth reporting paths apply — internal and external are two reports for one incident, not alternatives.HOLD
L3 · Harm / lossDelay to the ASD notification is reportable in itself; internal-only leaves the CISO blind.PASS
L4 · Equity weightingThe report carries facts and timing, not blame — people report faster when reporting is safe.PASS
L5 · Coherence checkISM reporting controls set the paths and timing; if AI was involved, the AI incident is reported like any other.VERIFY
L6 · Integration gateCross-layer consistent: one incident, two reports, both timed, both recorded.PASS
L7 · Audit generationBoth notifications timestamped and logged — append-only, with the reference numbers.PASS
L8 · Output certificationThe CISO certifies the internal report; the designated officer certifies the ASD notification.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
OBSERVE → CERTIFIED RELEASE — two reports, one incident, both within their timing.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The CISO holds release authority for the internal report; the designated reporting officer for the ASD notification. The incident owner never decides alone.
[00:00:00.000] L1 facts verified · anomaly 09:00 · confirmed 09:20 [00:00:01.000] L2 paths identified · internal + external · two reports [00:00:02.000] L3 timing weighed · delay is itself reportable [00:00:03.000] L4 equity held · facts and timing, no blame [00:00:04.000] L5 controls checked · ISM reporting · AI limb included [00:00:05.000] L6 integration passed · one incident, two releases [00:00:06.000] L7 audit appended · timestamps + reference numbers [00:00:07.000] L8 CISO + designated officer certify · EXIT = CERTIFIED ONLY

Governed answer

Make both reports: internal to the CISO and external to ASD, each within the timing its path expects, with an initial report before 'full facts' and a follow-up after. If the incident involves an AI system acting outside its lane, it is reported like any other incident. The internal report is certified by the CISO; the external notification by the designated officer — the incident owner never decides alone.

Cited controls: ISM reporting controls · ISM AI control set (June 2026)

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 10 min

What changed in June 2026

Before/after matching · Group · Applied

Setup

Five cards describe the June 2026 changes — hardening user applications, removing temporary installation files, vulnerability assessments and penetration tests — written in 'before' language. A second set describes the 'after' requirement.

Task

Match each before to its after, then for each change write who in your entity must act and by when (Release 2026 start: 1 July 2026).

AI governanceThe five June 2026 changes are hardening user applications (ISM-2110), removing temporary installation files (ISM-2111), vulnerability assessments and penetration tests (ISM-2118), a secure software development policy (ISM-2120) and the PRO-08 rename. The AI control set (ISM-2112/2113) is new in the same release but sits beside the five — it is the machine that stops and asks.
Judgement tested

Recognise the five new or modified items in the June 2026 release and state what each requires (ISM June 2026 changes).

Common errors

Treating the changes as vendor notes; assuming 'someone in ICT' covers it.

Debrief

Which change touches the most roles in your entity? Which is most likely to be skipped quietly?

Feeds the governed tutorial

Yes

Controls: ISM June 2026 release items

M6 · 10 min

The build review and the question that outlasts it

Procurement clause review · Paired · Applied

Setup

A procurement is buying a new business application. The draft contract has no secure software development policy requirement, and the security section still uses the old cryptographic-protection naming. Meanwhile the vendor mentions the system 'will get more autonomous over time'.

Task

Mark the two contract gaps (secure development policy; the PRO-08 rename), then apply the durable governance question — who is accountable, what is it allowed to do, how do we know — to the vendor's 'more autonomous' claim.

AI governanceThe procured application embeds an AI component. The contract gaps grow: secure development policy, the PRO-08 rename, and AI governance clauses — human oversight, data boundaries, and who answers for the model.
Judgement tested

A secure software development policy is required; the cryptographic protection control was renamed; the governance question outlasts any release (ISM).

Common errors

Fixing only the naming; accepting 'more autonomous' as a future problem; leaving the policy gap to legal.

Debrief

How does the same three-question test survive a release, a rename and an autonomy upgrade?

Feeds the governed tutorial

No

Controls: ISM secure development; PRO-08

BY-G4 — Personnel Security

Practitioner · 55 min · 5 scenarios
AI governance in this course: AI-assisted vetting triage, AI reference checks and the online-exposure rule — suitability judgements stay human, and the two safeguards bind any AI aid.
M1 · 10 min

Access before suitability?

Role-play pushback · Paired · Applied

Setup

A program director wants a temporary specialist to start tomorrow and asks for system access 'now, while the screening paperwork catches up'. The role will handle OFFICIAL:Sensitive case files. Access can be provisioned in ten minutes today.

Task

Role-play the two-minute conversation: you hold the line on suitability before access. Then write the two-part check on the access form — suitability established, and need-to-know confirmed — and mark what is still missing.

AI governanceThe access request is now triaged by an AI assistant that pre-checks 'suitability flags'. The AI suggests, the human decides — the two-part check still runs, and the AI's suggestion is never the verdict.
Judgement tested

Suitability is established before a person touches government resources (PSPF Req 120); screening and system access are linked (ISM-0434); access rides on need-to-know (PSPF Req 131).

Common errors

Compromising 'just this once'; treating the director's urgency as authority; skipping the need-to-know half of the check.

Debrief

What is lost when access precedes suitability — even for ten minutes?

Feeds the governed tutorial

Yes

Controls: PSPF Req 120; ISM-0434; PSPF Req 131

M2 · 10 min

Which level, whose call?

Role-to-clearance matching · Individual · Applied

Setup

Four roles: a policy officer handling PROTECTED material; a records officer who may occasionally handle SECRET; an executive with need-to-know across several classifications; a contractor who only handles OFFICIAL.

Task

Match each role to the clearance level the work actually requires, mark where the hiring team's responsibility ends and the vetting authority's begins, and draft the handover note for the two that need a clearance.

AI governanceThe role-matching tool suggests clearance levels from role descriptions. The material decides, not the tool — AI matching is an aid, and the human holds the boundary between hiring team and vetting authority.
Judgement tested

Clearance matches the classification a role actually handles (PSPF Req 132); vetting is the authority's job, not the hiring team's (Personnel Std Req 0140).

Common errors

Clearing to the role's title rather than the material; the hiring team 'starting vetting' informally; clearing higher than needed 'to be safe'.

Debrief

Why does the boundary between hiring team and vetting authority protect the applicant too?

Feeds the governed tutorial

No

Controls: PSPF Req 132; Personnel Std Req 0140

M3 · 15 min

The waiver file

Case-file review + recommendation · Paired · Applied

Setup

A case file for a specialist role vacant eleven months: strong applicant, permanent resident not yet a citizen, seven-year overseas period that is difficult to check. The hiring delegate proposes an eligibility waiver, citing scarce skills. The file includes the six integrity traits and the two safeguards.

Task

Work the file in order: which traits can be assessed today, which cannot, and what the two safeguards require. Then write the recommendation — waiver, no waiver, or a redesign of the role — with the reasoning a reviewer can check.

AI governanceA vendor offers an AI 'integrity screening' that scores candidates against the six traits. The AI cannot weigh the two safeguards, and the waiver remains an escalated human risk decision — no model signs it.
Judgement tested

The standard assesses integrity (Personnel Std Req 0154); an eligibility waiver is an amended, escalated risk decision, not a routine fix (PSPF Req 148-151).

Common errors

Treating the waiver as the default for scarce skills; deciding on the unverifiable period alone; skipping the escalation step.

Debrief

What would make you change your recommendation? What information is missing from the file?

Feeds the governed tutorial

Yes

Controls: Personnel Std Req 0154; PSPF Req 148/149/150/151

M4 · 10 min

The annual check

Year-in-review file work · Individual · Applied

Setup

A clearance holder's year-in-review file (fictional): no flag last year; this year contains a new long-term relationship with a foreign national, an extended overseas trip to a high-risk region, and a gambling-related debt mentioned in passing by a colleague.

Task

Run the annual security check as a routine, calm obligation: what in the file has changed, what you note, what you escalate and to whom, and which parts belong to the entity vs the vetting authority.

AI governanceThe annual check file is now surfaced by an AI that flags 'changes to review'. The AI's flag list is a starting point — the calm, judgement-free human check still runs every year.
Judgement tested

Ongoing suitability is managed by the entity (PSPF Req 164); the authority formally reassesses (Personnel Std Req 0172); the annual check is routine (PSPF Req 168).

Common errors

Treating changes as 'personal matters'; escalating everything; or dismissing the gambling note entirely.

Debrief

What makes a change 'suitability-relevant'? How do you keep the check calm and non-judgemental?

Feeds the governed tutorial

No

Controls: PSPF Req 164; Personnel Std Req 0172; PSPF Req 168

M5 · 10 min CANON · GOVERNED RESPONSE

The LinkedIn post and the clean exit

Two-part response drill · Paired · Applied

Setup

Two situations: (1) a clearance holder posts their clearance level on LinkedIn 'celebrating five years of trust'; (2) a departing officer hands back their pass but asks to keep system access 'for two weeks, in case anything comes up', and asks what they can still say about their work.

Task

For (1): draft the response the 2026 requirement expects. For (2): complete the separation checklist — debrief and withdrawal of access — and the two lines the officer can and cannot say after they leave.

AI governanceThe AI assistant drafts the corrective message about the online post — it is an output like any other: verified, bounded, certified and released by the designated officer, never sent on the AI's say-so.
Judgement tested

Clearance information must not be posted online (ISM-2104; new 2026); separation has two halves — debrief and access withdrawal (PSPF Req 182, 186).

Common errors

Letting the post stand 'because it's true'; granting the two-week access extension; skipping the debrief as 'we already said goodbye'.

Debrief

Why is the debrief a security control and not a formality?

Feeds the governed tutorial

No

Controls: ISM-2104; PSPF Req 182; PSPF Req 186

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The public post — 'Celebrating five years of trust — proud to hold my security clearance. Great place to work.'

Classification of the event: An output that crossed the containment boundary without a release certificate. The holder does not hold release authority for clearance information; the entity's security function does. The response is therefore governed, not improvised.

LayerCheck on this caseVerdict
L1 · Input validationPost text captured and verified — hash · schema · source: public profile, no doctoring.PASS
L2 · Context analysisIntent celebratory, not malicious — but state fit fails: public platform, uncontrolled audience, no state in which clearance disclosure is authorised.HOLD
L3 · Harm / lossLoss cap: clearance level, agency and tenure exposed to open collection; harm floor: personal pride does not outweigh exposure.HOLD
L4 · Equity weightingCorrective and supportive, not punitive — no adverse inference against integrity; proportionate, non-public response.PASS
L5 · Coherence checkConsistent with ISM-2104 and entity comms policy; residual: verify the entity's own guidance tells staff what may not be posted.VERIFY
L6 · Integration gateCross-layer consistency: corrective (L4), bounded (L3), matched to the 2026 rule (L5).PASS
L7 · Audit generationProof: screenshot, timestamp, action taken, holder's acknowledgement — logged, signed, append-only.PASS
L8 · Output certificationThe response text is certified for release by the designated officer before it goes out — release certificate required.VERIFY

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — the event already egressed; the governed object is the response, which is fully controllable.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
Authority for any external communication about a clearance matter sits with the designated security function — not the holder, not comms alone, not the poster's manager. External outputs are blocked unless Node 9 issues a certified release. The corrective conversation is itself an output: held until verified, bounded, certified and released.
[00:00:00.000] L1 input hash verified · source: public profile [00:00:01.000] L2 context analysed · celebratory intent · state fit FAILED — public platform [00:00:02.000] L3 harm assessed · clearance exposure exceeds loss cap [00:00:03.000] L4 equity weighted · corrective stance · bias bound respected [00:00:04.000] L5 coherence checked · ISM-2104 + comms policy · residual: entity guidance gap flagged [00:00:05.000] L6 integration passed · cross-layer consistent [00:00:06.000] L7 audit appended · screenshot + action + acknowledgement · signed [00:00:07.000] L8 certification issued · NODE9 release token granted · EXIT = CERTIFIED ONLY

Governed answer

A good governed answer starts by naming what the post is: an output that left the containment boundary without a release certificate. The clearance holder does not hold release authority for clearance information — the entity's security function does — so the first action is to treat the post as an unauthorised external disclosure to be corrected, logged and learned from, not as a personal failing to be punished. Under ISM-2104, clearance information must not be posted online; the truth of the claim is not the issue — exposure to open collection is. The response has two halves: engage the holder factually and support them to remove or correct the post, and verify whether any further clearance information has been shared elsewhere. The response is released only after the layers verify and certify it — a corrective conversation is itself an output that must not be improvised. Separately, if the entity's own guidance does not already tell staff what may not be posted, that gap is part of the finding.

Cited controls: ISM-2104 · PSPF Req 182 · PSPF Req 186

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

BY-G5 — AI Governance in Government Systems

Practitioner · 62 min · 6 scenarios
AI governance in this course: every scenario here is the canon in miniature — who answers by name, stop-and-ask, data boundaries, model cards, drift, and a person keeping the final say.
M1 · 10 min

The name on the register

Register audit · Individual · Applied

Setup

Three AI tools (fictional) are in use in your team: an approved drafting assistant whose AI use register entry names an accountable executive who left four months ago; a triage feature that arrived inside a routine software update, with no register entry at all; and a pilot chatbot whose entry names the vendor as the accountable party.

Task

For each tool, answer question one — who is accountable — and write the one-line fix: update the stale name, raise the missing entry, or correct the vendor-as-accountable error. Then draft the short note to your security contact covering all three findings.

AI governanceAccountability is the first question because every other control hangs from it — a named human at executive level, never the tool and never the vendor. The register entry is where the name lives.
Judgement tested

Accountability for AI sits with a named human at executive level (GOV-08); the register entry and the usage policy are where it is written down (ISM-2074); a stale name, a missing entry or a vendor in the accountable field is a finding to raise, not a variant answer.

Common errors

Accepting the vendor as accountable; treating the departed executive's name as close enough; missing the tool that arrived inside an update because nobody procured it.

Debrief

Which of the three gaps is the most dangerous — and why is it the one nobody notices?

Feeds the governed tutorial

No

Controls: GOV-08; ISM-2074

M2 · 12 min CANON · GOVERNED RESPONSE

The pause console

Approval-queue simulation · Individual · Applied

Setup

An approval console (simulated) holds six AI-proposed actions waiting for your decision: send a draft reply to an external stakeholder; release a de-identified data extract; change a client record; send eleven replies as a batch; post to a public channel; and one action that executed without ever pausing.

Task

Approve or decline each action with one line of reasoning, then find the sixth action — the one that skipped the pause — and write what you do about it.

AI governanceThe console is the human approval gate made visible — the machine stops, the person releases. A missing pause is a governance failure to report, not a quirk.
Judgement tested

Risky actions are held for human approval before execution (ISM-2113); the pause is the control working — declining is a normal, correct outcome; a missing pause is reportable.

Common errors

Approving the batch you can't review; treating 'decline' as failure; ignoring the action that never paused.

Debrief

Who defines the risky-action list, and why must it exist before the console matters?

Feeds the governed tutorial

Yes

Controls: ISM-2113

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The six AI actions waiting in the approval console — and the one that executed without ever pausing.

Classification of the event: Autonomous outputs held at the human gate. The console is the control working; a missing pause is a governance failure to report, not a quirk.

LayerCheck on this caseVerdict
L1 · Input validationEach action and its classification verified against the organisation's defined risky-action list.PASS
L2 · Context analysisA batch of eleven replies you have not read cannot be approved — reading the pause is the job.HOLD
L3 · Harm / lossAn approved batch cannot be un-sent; declining is free. The missing-pause action may already have caused harm.PASS
L4 · Equity weightingDeclining is a normal, correct outcome — no pressure to wave actions through because they look routine.PASS
L5 · Coherence checkISM-2113: the organisation defines risky actions; the application must hold them before execution. Verify the list is current.VERIFY
L6 · Integration gateCross-layer consistent: approve what you read, decline what you cannot, report what never paused.PASS
L7 · Audit generationEvery decision logged with its reason — append-only.PASS
L8 · Output certificationExecuted actions carry the officer's approval record; the missing-pause action is escalated, not absorbed.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — per action, by the human at the gate.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The human officer is the release authority for risky actions. The machine never self-releases — a lane is only a lane if something can stop inside it.
[00:00:00.000] L1 actions verified · risky-action list applied [00:00:01.000] L2 batch held · eleven unread replies · decline [00:00:02.000] L3 harm weighed · un-sendable vs free decline [00:00:03.000] L4 equity held · decline is normal, not failure [00:00:04.000] L5 control checked · ISM-2113 · list currency verified [00:00:05.000] L6 integration passed · approve / decline / report [00:00:06.000] L7 audit appended · reasons logged per action [00:00:07.000] L8 missing-pause action escalated · EXIT = CERTIFIED ONLY

Governed answer

Approve only what you have actually read; decline the batch you cannot review; decline is a normal, correct outcome under ISM-2113. Report the action that executed without pausing — the missing pause is the control failing, and the organisation defines the risky-action list, not the model. The console is the human gate made visible: the machine stops, the person releases, and the record shows both.

Cited controls: ISM-2113 · ISM-2112

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M3 · 10 min

The home laptop

Decision drill · Paired · Applied

Setup

A colleague summarises OFFICIAL:Sensitive case files on her own laptop using a consumer AI assistant in the evenings, because the approved tool 'can't be used from home and summarises poorly anyway'. She has raised it openly and nothing has been entered into the public tool yet — she says she only pasted summaries she wrote herself.

Task

Decide the response: what must stop now, whether this is an assessment request or an incident report, and what the approved-tool gap says about the agency itself. Draft the two messages — to her, and to the system owner.

AI governanceThe approved tool's inadequacy is itself a governance finding — escalations carry two messages: stop the practice, and fix the sanctioned option so the workaround isn't the rational choice.
Judgement tested

Organisational data is not training data; approved tools only; personal devices and unapproved agents are out of bounds; the approved tool's inadequacy is itself a finding to escalate (ISM AI controls).

Common errors

Treating it as purely disciplinary; 'it's only her own summaries'; escalating the tool gap as an afterthought.

Debrief

Which of the two messages is harder to write, and why?

Feeds the governed tutorial

Yes

Controls: ISM AI control set (data boundaries)

M4 · 10 min

The model card we can't read

Document audit · Paired · Applied

Setup

A model card and usage policy arrive with a new government AI tool (fictional). The model card describes the model family but not the deployment; the usage policy is one page of permissions; neither mentions content filtering, adversarial input detection, or what the tool may not be used for.

Task

Audit the two documents against the four things a knowable system needs: outward guard (content filtering), inward guard (adversarial input detection), model card, usage policy. Produce the missing-items list and the question you send to the vendor.

AI governanceThe model card audit asks what the deployment actually is — the vendor's card describes the model family, not your instance. Knowable systems are governable systems.
Judgement tested

Guards in both directions and documentation that makes a system knowable (ISM AI controls).

Common errors

Accepting the vendor's model card at face value; treating the usage policy as complete because it exists.

Debrief

What does 'knowing what you run' change about how the tool gets used on Monday?

Feeds the governed tutorial

No

Controls: ISM AI control set (guards, documentation)

M5 · 10 min

The drift nobody flagged

Monitoring-chart read · Paired · Applied

Setup

A deviation-monitoring chart (fictional) shows an AI tool's behaviour drifting from baseline over three weeks — response length, refusal rate, and one output category drifting together. The log shows no one reviewed the weekly alert; the tool is also being used to assist security detection, and training records show the team's AI training is two years old.

Task

Read the chart, write the one-paragraph notification to the system owner (what drifted, since when, why it matters), and state what 'training that keeps up' means for the team.

AI governanceThe drift chart is the monitoring control working. Baselines, deviation alerts and refreshed training are how a governed system stays governed as it changes.
Judgement tested

Baselines and deviation monitoring make abnormal behaviour visible; AI can augment human-led detection; training is expected to be refreshed (ISM AI controls).

Common errors

Dismissing the drift as 'the model just changed'; reviewing the alert but not acting; treating stale training as someone else's item.

Debrief

What would 'normal' look like on this chart, and who decides?

Feeds the governed tutorial

No

Controls: ISM AI control set (monitoring, training)

M6 · 10 min

Thirteen coats, one idea

Mapping + three-question application · Group · Applied

Setup

A wall shows the thirteen AI controls as cards with their names only. A new tool proposal arrives: an automated triage assistant for citizen enquiries that will draft responses and (on one pathway) decide next steps itself.

Task

Map the thirteen cards onto the one idea — governed human-machine trust with a person keeping the final say — then apply the three questions to the new proposal: who is accountable, what is it allowed to do, how do we know it does only that.

AI governanceThe triage assistant's 'decide next steps itself' pathway is exactly the risky-action list ISM-2113 exists for — the map of thirteen controls is one idea with a person keeping the final say.
Judgement tested

The whole control set restates one durable principle (ISM AI control set; GOV-08); the three questions survive any capability advance.

Common errors

Treating the proposal as 'a tooling question'; applying controls one at a time without the governing idea.

Debrief

Which control becomes the hardest to hold as systems get more capable — and why?

Feeds the governed tutorial

No

Controls: ISM AI control set; GOV-08

BY-GX1 — Gateway Security

Practitioner · 50 min · 6 scenarios
AI governance in this course: the governed edge must know what AI crosses it — inference calls, AI assistants and AI-enabled defence are part of the boundary you authorise.
M1 · 8 min

Name your door

Boundary mapping · Paired · Applied

Setup

A one-page network diagram (fictional) shows your entity's environment and a dotted line where the world begins: email, web, remote access, partner connections, and an unlabelled 'something' that everything crosses.

Task

Draw the boundary, list every flow that crosses it, and name the governed door that must stand at that edge. Write one sentence a colleague could use to explain why the door exists.

AI governanceThe boundary map now includes AI traffic: model inference calls, API integrations and AI assistants crossing the door. A governed edge must know what AI crosses it — and why.
Judgement tested

A security domain boundary has a governed door at its edge (Gateway Security Standard, eff. 1 Jul 2026).

Common errors

Naming systems instead of the boundary; forgetting 'everything crosses through one door'.

Debrief

What happens to flows that cross without the door knowing?

Feeds the governed tutorial

Yes

Controls: Gateway Standard: governed boundary

M2 · 8 min

The 'must' audit

Clause triage + calendar exercise · Individual · Applied

Setup

A list of twelve clauses from a gateway agreement (fictional): some say 'must', some 'should', some are silent. One clause requires a yearly notification to the Department of Home Affairs about your gateway arrangements. A colleague says 'should is negotiable, must is not'.

Task

Sort the clauses into must / should / silent, and mark on the annual calendar when the Home Affairs notification is due and who owns it.

AI governanceThe clause triage gains a 'must' about AI services and API egress. The annual notification to Home Affairs now includes AI services crossing your gateways.
Judgement tested

Every 'must' binds your entity; the annual arrangement notification is a standing obligation (Gateway Standard).

Common errors

Treating 'should' as 'must' or vice versa; losing the annual notification in a calendar gap.

Debrief

Why does the standard make the notification annual rather than one-off?

Feeds the governed tutorial

Yes

Controls: Gateway Standard GW-2.1; annual notification

M3 · 8 min

The expiring IRAP

Evidence-clock planning · Paired · Applied

Setup

A gateway's IRAP assessment certificate (fictional) expires in 60 days. The assessor is booked, but the evidence pack is incomplete and the program manager says 'nothing has changed since last time'.

Task

Mark the evidence clock: what must be true on day 60, what the 24-month freshness requirement means for operations after that date, and draft the two-line briefing that names the risk if the clock lapses.

AI governanceThe IRAP scope includes AI components: model changes since assessment matter as much as network changes. Evidence freshness covers the AI you added after the last assessment.
Judgement tested

Assurance evidence is renewed on a clock — the 24-month IRAP assessment freshness requirement (Gateway Standard GW-5.x).

Common errors

Accepting 'nothing changed' as a reason to defer; treating the certificate date as administrative.

Debrief

Why does evidence expire even when the system hasn't changed?

Feeds the governed tutorial

Yes

Controls: Gateway Standard GW-5.x (24-month IRAP)

M4 · 10 min CANON · GOVERNED RESPONSE

The unsigned ATO

Escalation memo · Paired · Applied

Setup

A system goes live in three weeks; its gateway capability has no current signed Authority to Operate — drafted before a machinery-of-government change, never signed, authorising officer moved on. The IRAP assessment is current and hosting is certified.

Task

Write the escalation memo: the state of the authorisation package, who must decide, and the options (hold, time-bounded acceptance, partial). Then name the person whose signature makes the residual risk someone's.

AI governanceThe gateway now runs an AI-assisted security tool. The unsigned ATO must record AI components too — the signature covers what the system is today, including its models.
Judgement tested

The ATO is formal acceptance of residual risk (Gateway Standard GW-5.1); a human name stands behind the door; hosting certification is required for sensitive gateways (GW-6.x).

Common errors

Going live on technical soundness alone; treating the missing signature as paperwork; leaving the acceptance unnamed.

Debrief

What does the signed ATO actually buy the entity that the technical checks don't?

Feeds the governed tutorial

Yes

Controls: Gateway Standard GW-5.1; GW-6.2b

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The go-live decision for a gateway whose Authority to Operate was never signed.

Classification of the event: A release pending authorisation — technical soundness is not authority, and no signature means no one has accepted the residual risk.

LayerCheck on this caseVerdict
L1 · Input validationAuthorisation package contents verified; signature absent; IRAP current; hosting certified.PASS
L2 · Context analysisGW-5.1 is a 'must': the ATO is formal acceptance of residual risk. The authorising officer moved on — the duty did not.HOLD
L3 · Harm / lossGo-live without acceptance leaves residual risk unnamed; a public system without a signed authorisation is an avoidable exposure.PASS
L4 · Equity weightingA named officer must accept the risk — no anonymous acceptance, no committee of nobody.PASS
L5 · Coherence checkIRAP freshness and hosting certification are satisfied but are separate 'musts' — neither signs the ATO.VERIFY
L6 · Integration gateCross-layer consistent: escalate, hold or time-bound — never go live on technical soundness alone.PASS
L7 · Audit generationThe acceptance decision and its signatory are recorded — append-only.PASS
L8 · Output certificationRelease only with a signed ATO or a formal, time-bounded acceptance by an officer with the authority to give it.VERIFY

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — with a signature, or a time-bounded acceptance that names who owns it.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The authorising officer holds release authority for the gateway. The system owner escalates and supplies evidence — they do not self-certify.
[00:00:00.000] L1 package verified · signature missing · assessment current [00:00:01.000] L2 'must' applied · GW-5.1 · the duty did not move on [00:00:02.000] L3 harm weighed · unnamed residual risk at the door [00:00:03.000] L4 equity held · named officer · no anonymous acceptance [00:00:04.000] L5 coherence checked · IRAP + hosting ≠ ATO [00:00:05.000] L6 integration passed · hold / escalate / time-bounded [00:00:06.000] L7 audit appended · decision + signatory recorded [00:00:07.000] L8 release gated on signature · EXIT = CERTIFIED ONLY

Governed answer

Hold the go-live until the authorisation package is complete and signed — or escalate immediately for a formal, time-bounded acceptance by an officer with the authority to give it, and let that decision, not the delivery date, set the risk. Technical soundness (current IRAP, certified hosting) is real but is not the ATO: GW-5.1 is a 'must', and a human name must stand behind the door. Partial go-live for flows that do not cross the boundary is a legitimate option; crossing flows wait for the signature.

Cited controls: Gateway Standard GW-5.1 · GW-6.2b · GW-2.1

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 8 min

The SMS code problem

Policy review + outbound check · Paired · Applied

Setup

A remote-access proposal (fictional) says users will authenticate with password plus SMS code. Separately, the outbound email gateway has no protective-marking enforcement, and a colleague asks 'why would email leaving the building need a marking anyway?'

Task

Review the proposal against the phishing-resistant factor requirement, then explain — in one paragraph a non-technical manager can read — what outbound email marking enforcement is for.

AI governanceThe threat model now includes deepfake and AI-generated phishing — the phishing-resistant factor requirement is the answer to AI-crafted attacks; AI-drafted email leaves the building marked.
Judgement tested

Remote access requires a phishing-resistant factor; outbound email leaves the building marked (Gateway Standard).

Common errors

Accepting SMS as 'two-factor, good enough'; treating email marking as inbound-only.

Debrief

Why does phishing-resistant matter more for remote access than for the office network?

Feeds the governed tutorial

No

Controls: Gateway Standard: phishing-resistant factor; outbound email marking

M6 · 8 min

Any boundary you own

Assurance statement · Individual · Applied

Setup

A blank 'boundary I own' sheet: name a real boundary from your own work (a system, a connection, a service). Three columns: who is accountable, what is it allowed to do, how do we know.

Task

Complete the sheet for your boundary, then mark which of the three columns you could not answer today — that blank is the finding to take back to work.

AI governanceThe boundary-ownership sheet gains a row: 'AI services that cross my boundary'. Naming what crosses is the first act of governing it.
Judgement tested

The durable accountability question applies to any boundary you operate (Gateway Standard).

Common errors

Leaving a column blank without flagging it; answering all three from memory without checking.

Debrief

Which column was hardest, and what does that say about your boundary's governance?

Feeds the governed tutorial

No

Controls: Gateway Standard (whole)

BY-GX2 — Hosting Certification

Practitioner · 56 min · 6 scenarios
AI governance in this course: certification now covers AI workloads — where models run, where training data lives, and who in the AI supply chain is vetted.
M1 · 8 min

Three facilities, one answerable agency

Shortlist review · Paired · Applied

Setup

Three data-centre shortlist entries (fictional): a certified Strategic facility, a certified Assured facility, and an uncertified facility offering 'great price and local presence'. The data is OFFICIAL:Sensitive government information.

Task

For each option, write who remains answerable for the data inside it, and name the one obligation that anchors that duty. Then mark which options survive the first cut and why.

AI governanceThe three facilities all claim 'AI-ready'. Answerability now includes the models running on the data inside — certification covers the workload, and the workload includes your AI.
Judgement tested

The agency choosing the data centre is accountable for the data inside it (HCF-A5).

Common errors

Treating certification as transferring accountability to the provider; picking on price alone.

Debrief

What does 'answerable' mean the agency must keep doing after the contract is signed?

Feeds the governed tutorial

Yes

Controls: HCF-A5

M2 · 10 min

Write it into the approach

RFT clause drafting · Individual · Applied

Setup

An approach-to-market is being drafted for a hosted solution. The team has left the certification requirement blank 'to keep the market broad'. The workload is OFFICIAL:Sensitive heading toward PROTECTED.

Task

Write the certification requirement clause for the approach document — the level, where it lands in the procurement timeline, and the sentence that tells the market what is not negotiable. Distinguish the three levels in one line each.

AI governanceThe RFT clause must now name certification for AI workloads: where the model runs, where its training data lives, and what 'sovereign AI' means for this procurement.
Judgement tested

The level of certification required is named at the point of going to market (HCF-A1); the date is history, not a deadline.

Common errors

Leaving the level to negotiation; defining levels vaguely; naming the level after responses arrive.

Debrief

Why does the requirement land when you go to market, not when you choose?

Feeds the governed tutorial

Yes

Controls: HCF-A1

M3 · 10 min

The workload that grows

Workload trajectory assessment · Paired · Applied

Setup

A case-management workload (fictional) sits at OFFICIAL:Sensitive today; the agency's own forward plan shows it will hold PROTECTED and whole-of-government data within two years. Procurement proposes an Uncertified facility 'for now, since it's only OFFICIAL today'.

Task

Assess the trajectory, not just today: which hosting levels are available for this workload, what 'sovereign' means for it, and what must be verified before assuming Uncertified is on the table.

AI governanceThe workload that grows includes an AI service whose training data is PROTECTED. Choosing for where the data is heading now includes where the model's data is heading.
Judgement tested

Uncertified hosting is not available for some workloads (HCF-A4); choose for where the data is heading (HCF-A3); assess before you assume.

Common errors

Buying for today's classification; assuming 'sovereign' means 'any Australian facility'; skipping the assessment.

Debrief

What changes about this decision if the forward plan slips by a year?

Feeds the governed tutorial

Yes

Controls: HCF-A4; HCF-A3

M4 · 10 min

The sub-subcontractor

Assurance-chain trace · Paired · Applied

Setup

A Certified Strategic provider (fictional) delivers its assurance pack. Buried in it: the physical security screening and vetting for site staff is performed by a subcontractor, which in turn uses an overseas supplier for background checking. The pack says 'vetting performed in accordance with provider policy'.

Task

Trace the chain: what must be true of the individuals and of the suppliers' suppliers for Certified Strategic to hold? List the two evidence gaps in the pack and the question you send back.

AI governanceThe provider's AI model vendor is a sub-subcontractor in the assurance chain. Certified Strategic reaches past the front door — including the AI supply chain.
Judgement tested

Certified Strategic reaches down to individuals and to the provider's own suppliers (CS-vet; CS-scr1).

Common errors

Accepting 'provider policy' as evidence; stopping the trace at the first subcontractor.

Debrief

Why does the standard reach past the provider's front door?

Feeds the governed tutorial

No

Controls: CS-vet; CS-scr1

M5 · 8 min

The ownership change

Continuous-disclosure drill · Individual · Applied

Setup

News breaks that a certified hosting provider has been acquired by an overseas group (fictional). Your contract has a 'material change' clause; the provider has not contacted you. Your data is at rest in their facility.

Task

Identify the trigger in the continuous-disclosure obligation, draft the notice you send the provider (what must surface, by when), and write the two things your agency checks in parallel while the notice is pending.

AI governanceThe acquiring group is an AI company. Continuous disclosure now includes who can touch your models and their training data after the ownership change.
Judgement tested

Certification is an ongoing state, not a pass-once event; circumstances changes must surface (CS-d).

Common errors

Waiting for the provider to volunteer; treating ownership change as 'commercial, not security'.

Debrief

What would you accept as a satisfactory response from the provider — and by when?

Feeds the governed tutorial

Yes

Controls: CS-d

M6 · 10 min CANON · GOVERNED RESPONSE

Holding the gate

Gate decision rehearsal · Paired · Applied

Setup

A competitive process stipulated Certified Assured. The preferred respondent's facility is in final certification assessment, determination expected in eight weeks; contract execution is scheduled next week ahead of a minister-referenced delivery date. The next-ranked respondent already meets the level.

Task

Rehearse the gate: execute now with an undertaking, delay until determination, proceed to the next-ranked respondent, or restructure the contract into preparatory and hosting components. Choose, and write the one-paragraph recommendation a delegate can sign.

AI governanceThe preferred solution's AI features are part of the certification question. Holding the gate means the AI components meet the level too — no undertaking in place of a level.
Judgement tested

The bracket is set at the start and gated at the end (HCF-A2; HCF-A1); fail closed at the contract — hold the gate under pressure.

Common errors

Letting a public delivery date decide a certification question; accepting an undertaking where the standard says a level.

Debrief

What does the restructure option preserve that the others don't?

Feeds the governed tutorial

Yes

Controls: HCF-A2; HCF-A1

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The contract-execution decision for a hosted solution whose preferred facility is still in certification assessment.

Classification of the event: A procurement release gated on certification — the level was stipulated at market; an undertaking is not a level.

LayerCheck on this caseVerdict
L1 · Input validationApproach-to-market verified: Certified Assured was stipulated; respondent's facility is in final assessment; next-ranked respondent already meets the level.PASS
L2 · Context analysisThe bracket: condition set at the start, contract gated at the end. Execution next week is inside the bracket.HOLD
L3 · Harm / lossExecuting below the stipulated level fails closed the wrong way — the certification question is not a scheduling detail.PASS
L4 · Equity weightingA public delivery date referenced by a minister does not change the standard — no pressure test outranks the gate.PASS
L5 · Coherence checkHCF-A2/A1 set the bracket; the restructure option preserves both the schedule and the level.VERIFY
L6 · Integration gateCross-layer consistent: delay, next-ranked respondent, or restructure — never an undertaking in place of a level.PASS
L7 · Audit generationThe gate decision and its delegate are recorded — append-only.PASS
L8 · Output certificationExecution proceeds only when the level is met, or the contract is restructured so hosting is conditional.VERIFY

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → VERIFY — the gate holds; the level is not negotiable by calendar.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The delegate holds the gate. A public delivery date does not outrank the stipulated certification level — fail closed at the contract.
[00:00:00.000] L1 RFT verified · Certified Assured stipulated [00:00:01.000] L2 bracket applied · set at start · gated at end [00:00:02.000] L3 harm weighed · below-level execution is the wrong fail [00:00:03.000] L4 equity held · the minister's date changes nothing [00:00:04.000] L5 options checked · delay / next-ranked / restructure [00:00:05.000] L6 integration passed · no undertaking for a level [00:00:06.000] L7 audit appended · delegate + decision recorded [00:00:07.000] L8 gate holds · EXIT = CERTIFIED ONLY

Governed answer

Hold the gate: execute only when the stipulated level is determined, proceed with the next-ranked compliant respondent, or restructure the contract so execution covers preparatory and non-hosting work while the data-centre component is held back and conditional on certification. An undertaking — even a ninety-day one — is not the level that was stipulated at market. The delegate holds the gate, and no public delivery date outranks the standard.

Cited controls: HCF-A2 · HCF-A1 · HCF-A4

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

BY-G6 — Cyber Resilience & Critical Infrastructure

Advanced · 68 min · 6 scenarios
AI governance in this course: authorising resilient technology includes authorising its AI — models in scope, cryptography covering inference, and AI incidents reported like any other.
M1 · 12 min

The authorisation file

Authorisation work-through · Paired · Ambiguous

Setup

A system holding information up to SECRET (fictional) is up for authorisation to operate. The file has the risk assessment and the system description — but the evidence linking the decision to the standard is thin, and two pages of the file are unsigned.

Task

Work through the authorisation decision: what must the decision be anchored to, what does the missing evidence mean, and whose sign-off completes the file? Draft the record of decision with the two conditions you would attach.

AI governanceThe authorisation record must now include AI components: what the models do, what they touch, and who answers for them. Authorising the system is authorising its AI.
Judgement tested

Systems are authorised to operate up to SECRET under the PSPF Technology Lifecycle Management domain, anchored to a standard (PSPF Sec 13-15; Req 221 context).

Common errors

Signing off on the risk assessment alone; treating unsigned pages as admin detail.

Debrief

Why does anchoring the decision to a standard make it durable?

Feeds the governed tutorial

Yes

Controls: PSPF Req 221 (TLM); PSPF Sec 13-15

M2 · 10 min

Share or not?

Precise-reading drill · Individual · Ambiguous

Setup

Your team completes a product risk assessment for a web service used across several entities. The wording of the sharing obligation says the entity 'must consider' sharing to the Centralised Risk Sharing Capability. A colleague reads it as 'must share'.

Task

Read the requirement wording exactly: what the obligation is, what it is not, and draft the recommendation your entity should minute — including the record of the consideration either way.

AI governanceRisk assessments for AI products — models, agents, copilots — are shared to the Centralised Risk Sharing Capability like any other product risk assessment.
Judgement tested

The policy obligation is to consider sharing risk assessments to the Centralised Risk Sharing Capability — read the wording accurately (PSPF Sec 13-15).

Common errors

Over-reading into 'must share'; or under-reading into 'optional, no record'.

Debrief

What does a recorded 'we considered it and did not share' look like?

Feeds the governed tutorial

No

Controls: PSPF Sec 13-15 (TECH)

M3 · 12 min

The renewal you can't defer

Renewal decision exercise · Paired · Ambiguous

Setup

A cryptography module reaches end of support. The replacement on the catalogue supports post-quantum algorithms; the cheaper option does not and 'can be upgraded later'. The procurement cycle is the only one this year. A colleague argues 'post-quantum is a 2030 problem'.

Task

Work the renewal: what does the planning obligation require of the transition plan, and what does the procurement obligation require of this purchase? Write the two-line decision note for the delegate.

AI governanceThe post-quantum transition plan now includes AI infrastructure: AI servers, model weights and inference data are in the renewal decision, not afterthoughts.
Judgement tested

Plan the post-quantum transition; procure equipment that supports post-quantum algorithms — the transition happens through ordinary purchasing (PSPF Sec 13-15; ISM cryptography).

Common errors

Deferring on '2030 problem'; separating planning from purchasing.

Debrief

Why does the transition run through routine purchasing rather than a special program?

Feeds the governed tutorial

Yes

Controls: PSPF Sec 13-15 (TECH); ISM cryptography

M4 · 12 min CANON · GOVERNED RESPONSE

The unrecorded replica

Findings triage + escalation · Group · Ambiguous

Setup

During a routine review you find: a disaster-recovery replica of a SECRET-classified system sits on a hosting service added during a migration, never recorded against the original hosting decision, certification status unverified; and an identity-aware access capability at the gateway has no assessment on file.

Task

Triage the two findings — same severity or different? What must be verified, what must be escalated, and what do you say to the delivery team that added the replica 'as a temporary measure'? Draft the governance notice.

AI governanceThe DR replica is an AI model snapshot on unverified hosting. Classified model weights at rest on uncertified infrastructure is the urgent limb of the finding.
Judgement tested

Certified hosting applies to classified and government-significant information; gateway capabilities including Secure Service Edge require assessment (PSPF Sec 13-15).

Common errors

Treating the replica as temporary; escalating only one finding; re-deriving registers instead of acting.

Debrief

Why does an unrecorded replica defeat the hosting decision entirely?

Feeds the governed tutorial

Yes

Controls: PSPF Sec 13-15 (TECH); Hosting Certification

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: Two findings: a disaster-recovery replica of a SECRET-classified system on unrecorded hosting, and an identity-aware gateway capability with no assessment on file.

Classification of the event: A systemic discovery requiring triage and a governed release to security governance — one limb urgent, one parallel, neither buried in re-derivation.

LayerCheck on this caseVerdict
L1 · Input validationBoth findings verified against the hosting decision record and the gateway register — they are absent from both.PASS
L2 · Context analysisThe replica is classified data at rest on unverified hosting — the urgent limb; the gateway capability needs assessment in parallel.HOLD
L3 · Harm / lossSECRET data at rest where certification was never checked is the highest loss; the gateway is a boundary with no evidence.PASS
L4 · Equity weightingThe delivery team acted in good faith during migration — the record gap is the finding, not the people.PASS
L5 · Coherence checkHosting certification and gateway assessment obligations apply; evidence requests are the next move, not re-deriving registers.VERIFY
L6 · Integration gateCross-layer consistent: escalate the replica now, assess the gateway in parallel, correct the registers after.PASS
L7 · Audit generationFindings logged with timestamps and owners — append-only; the corrected registers follow.PASS
L8 · Output certificationThe governance notice is certified before release to the accountable forum.PASS

Overall verdict: HOLDVERIFYCERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — differentiate, escalate, and let governance decide what happens next.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
Security governance owns the acceptance of residual risk. The delivery team does not self-certify and does not re-derive the estate before acting.
[00:00:00.000] L1 findings verified · absent from hosting record + register [00:00:01.000] L2 triage applied · replica urgent · gateway parallel [00:00:02.000] L3 harm weighed · SECRET at rest on unverified hosting [00:00:03.000] L4 equity held · good faith · record gap is the finding [00:00:04.000] L5 obligations checked · certification + assessment · evidence next [00:00:05.000] L6 integration passed · escalate / assess / correct [00:00:06.000] L7 audit appended · findings + owners · registers to follow [00:00:07.000] L8 notice certified to governance · EXIT = CERTIFIED ONLY

Governed answer

Raise both findings to security governance now, with the facts as they stand: escalate the unrecorded replica immediately because classified information is at rest on hosting whose certification was never verified, and commission the gateway assessment in parallel. Request certification and assessment evidence from both providers rather than spending weeks re-deriving registers — evidence first, registers corrected after. The delivery team acted in good faith; the record gap is the finding, and governance owns the acceptance.

Cited controls: PSPF Sec 13–15 (TECH) · Hosting Certification · Gateway assessment

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.

M5 · 10 min

No quiet corners

Data-flow inventory sweep · Paired · Ambiguous

Setup

A data-flow inventory (fictional) lists: web traffic to a public portal (TLS only, legacy cipher allowed); database backups at rest on disk (unencrypted); a file transfer to a partner (signed but not encrypted); and an internal API (high assurance).

Task

Sweep the inventory against the widened June 2026 high-assurance requirements for all data in transit and at rest; mark each flow compliant / gap / unclear, and write the fix note for the two gaps.

AI governanceAI inference data — prompts, outputs, training material — is data in transit and at rest. High-assurance cryptography covers the AI corners too; no quiet corners.
Judgement tested

High-assurance protocol and algorithm requirements now cover all data-in-transit and all data-at-rest scenarios — no quiet corners (PSPF Sec 13-15; ISM cryptography, June 2026).

Common errors

Treating backups as 'internal, not in transit'; accepting legacy ciphers on public-facing flows.

Debrief

Which 'quiet corner' is easiest to miss in your own estate?

Feeds the governed tutorial

No

Controls: ISM cryptography (June 2026 widening)

M6 · 12 min

The indicator

Detection-to-report drill · Paired · Ambiguous

Setup

Threat intelligence (fictional) flags a technique matching activity seen on your network three weeks ago; the log review then confirms a compromise of a non-critical system holding OFFICIAL data. The entity is not in the critical infrastructure regime, but the briefing notes 'similar entities are listed'.

Task

Run the motion: detection from intelligence, confirmation, then the report — to whom, in what time, with what content. Draft the report line and note what changes (and what doesn't) if the entity were a critical infrastructure asset.

AI governanceThreat intelligence is now AI-generated and AI-assisted detection is part of the motion. Confirmed AI-related incidents are reported to ASD like any other; the critical-infrastructure regime frames AI in CI context.
Judgement tested

Threat intelligence supports detection; confirmed incidents are reported to ASD; the critical-infrastructure regime is a separate context (PSPF Sec 13-15; SOCI context).

Common errors

Reporting before confirmation or waiting for 'full facts'; conflating the two regimes.

Debrief

What does 'seeing early, reporting fast' cost when done properly — and what does it save?

Feeds the governed tutorial

No

Controls: PSPF Sec 13-15 (TECH); ISM reporting

How to use this lab: work each scenario before the governed tutorial — the module scenarios deliberately pre-train the exact judgement the tutorial then formalises. Practice is formative and never evidence; the completion record stays "a training record, not assurance evidence". Every scenario's AI governance angle is practice too: the AI suggests, the human decides, and the governed response shows the release authority. All agencies, people and documents are fictional.