Scenario Lab
Every module of every course ends in a real-life situation you can put the training into practice on — mark the email, fill the report, weigh the file, hold the gate — and every scenario carries an AI governance angle, tied to the same canon the governed tutorials are built from. Work the situation, then reveal the notes to check your judgement against the controls the course cites. Each course's governed-response scenario shows the full ai.heart canon: eight layers, a verdict, Node 9, and an append-only audit trail.
BY-BX1 — Governing AI: Duties of Boards and Responsible Persons
Printable governed response → · the course's capstone as a standalone worksheet
The board paper that isn't enough
Setup
A board paper (fictional) asks approval for an AI-supported system, describing efficiency gains in three paragraphs and technology in two. It does not say which decisions the system will substantially support. You are a director at the table.
Task
Write the three questions you ask before the paper can be approved — framed as 'the decision, not the model' — and the one question you ask about the board's own literacy for this decision.
Judgement tested
Board literacy is about the decisions AI supports, not the technology (APRA-EXP-2026; ASIC-912A).
Common errors
Asking about the model's accuracy; asking no questions; deferring to 'management knows best'.
Debrief
Which question would management find hardest to answer, and why?
Feeds the governed tutorial
Yes
Controls: APRA-EXP-2026; ASIC-912A
Who answers?
Setup
A regulated group (fictional) spans aged care, an AML/CTF-regulated business and a health service — all adopting AI tools. A chair asks: 'which of our duties apply to which business, and who personally carries them?'
Task
Map the duties: responsible persons in aged care (acquire and maintain knowledge), governing-body oversight in AML/CTF, safety and quality training including the governing body in health. Then role-play the chair's questions to the responsible persons.
Judgement tested
Personal and governing-body duties attach differently by sector (AgedCare-s180; AMLCTF-s26H; NSQHS-1.19).
Common errors
Treating all three businesses as one 'AI duty'; assigning duties to staff rather than the responsible person.
Debrief
What changes about a board's agenda when duties are personal rather than corporate?
Feeds the governed tutorial
Yes
Controls: AgedCare-s180; AMLCTF-s26H; NSQHS-1.19
The disclosure check
Setup
A draft privacy policy (fictional) describes 'automated decision-making' generally, and the system it covers makes decisions 'by computer program' under the December 2026 Privacy Act obligation. The policy says nothing about disclosing that a computer program was substantially involved in decisions.
Task
Check the policy against APP 1.7: what must be disclosed, to whom, and — just as important — what the obligation does NOT require. Draft the disclosure clause and mark the limits the board should not over-read into it.
Judgement tested
APP 1.7 is a disclosure obligation; 'technology-neutral' means computer program; know what it does not require (APP-1.7).
Common errors
Treating APP 1.7 as a general 'explainability' duty; or as a trivial footnote.
Debrief
Where is the line between disclosing and over-claiming under APP 1.7?
Feeds the governed tutorial
Yes
Controls: APP-1.7
The empty cadence
Setup
The board's oversight record (fictional) for an AML/CTF-regulated business shows one AI item reviewed eighteen months ago, no agenda slot since, and no record of challenge or resource questions. The system has been extended twice in that time.
Task
Find the gap in the cadence, name the two things the record must show for oversight to be evidenced (ongoing rhythm; adequate resources and risk systems), and design the standing agenda item that fixes it.
Judgement tested
Ongoing AML/CTF oversight is a cadence (AMLCTF-s26H); adequate resources and risk systems are board issues (ASIC-912A); training is a control only when linked to actual use (APRA-EXP-2026).
Common errors
Counting one past review as oversight; approving 'training records exist' without use evidence.
Debrief
What would a reviewer look for to confirm the cadence is real and not ceremonial?
Feeds the governed tutorial
Yes
Controls: AMLCTF-s26H; ASIC-912A; APRA-EXP-2026
The approval minute
Setup
The board (fictional) has decided to approve an AI-supported system in principle. Your task: turn the decision into an approval minute that carries the conditions — personal knowledge before approval in aged care, safety and quality escalation paths in health, and approval conditions for the financial services system.
Task
Draft the minute: the conditions attached to approval, what management must return with, and what triggers escalation back to the board. Compare minutes across the group and merge the strongest conditions.
Judgement tested
Approval conditions and escalation paths give the approval its teeth (AgedCare-s180; NSQHS-1.19; ASIC-912A).
Common errors
Approving without conditions; conditions without return dates; no escalation trigger.
Debrief
What makes a condition enforceable rather than decorative?
Feeds the governed tutorial
Yes
Controls: AgedCare-s180; NSQHS-1.19; ASIC-912A
Input under review: The board decision on the AI-supported customer and patient prioritisation system — and the minute that records it.
Classification of the event: A governing-body release. The minute is the output: approve-in-principle is not approval, and conditions are what make the decision governable.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | The paper's gaps verified: no decision inventory, no APP 1.7 assessment, no resourcing or risk assessment, no safety-and-quality governance plan. | PASS |
| L2 · Context analysis | Approval in principle is the board's option — but only with conditions that carry return dates and escalation triggers. | HOLD |
| L3 · Harm / loss | Unconditional approval releases a system without evidence gates; deferral protects customers and patients. | PASS |
| L4 · Equity weighting | Responsible persons carry personal duties — the minute names them, and the board records its challenge. | PASS |
| L5 · Coherence check | APRA-EXP-2026, ASIC-912A, AgedCare-s180, NSQHS-1.19, APP-1.7 — each limb of the decision maps to a cited duty. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: decision inventory, disclosure, resourcing, safety and quality — all four return with evidence. | PASS |
| L7 · Audit generation | The minute records conditions, return dates and escalation triggers — append-only. | PASS |
| L8 · Output certification | The chair signs; the board is Node 9 — management returns with evidence, not assurances. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — conditional approval, with the conditions in the minute.
The board holds release authority. Management returns with a decision inventory, a privacy disclosure assessment, a risk and resourcing assessment, and a safety-and-quality governance plan — or the release does not proceed.
Governed answer
Approve in principle only with conditions that carry return dates and escalation triggers — management returns with a decision inventory, a privacy disclosure assessment (APP 1.7), a resourcing and risk assessment (ASIC-912A), and a safety-and-quality governance plan (NSQHS-1.19), with responsible persons named where duties are personal (AgedCare-s180). The minute is the record of the board's challenge — the board is Node 9, and management returns with evidence, not assurances.
Cited controls: APRA-EXP-2026 · ASIC-912A · AgedCare-s180 · NSQHS-1.19 · APP-1.7
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
BY-G1 — PSPF 2026 Fundamentals
Printable governed response → · the course's capstone as a standalone worksheet
Printable artifact pack → · the course's scenario artefacts as printable hand-outs
The induction checklist
Setup
You join a six-month contract in an agency policy branch. Your line manager ticks 'security induction' as complete so you can start sooner, and tells you the annual course is for permanent staff. A colleague shows you the actual checklist — the training row is unchecked, with a handwritten note 'contractor — skip'.
Task
Role-play the conversation: you have 60 seconds to respond to your manager. Then tick or fix the checklist and add one line saying what the framework actually requires for you.
Judgement tested
Training at engagement and annually applies to personnel including contractors (Req 24); culture is led by the Accountable Authority and CSO (Req 23); your part is noticing, reporting, following procedure — not investigating (RA §3.5.2).
Common errors
Agreeing to skip; doing the training secretly instead of raising the record; lecturing the manager about culture.
Debrief
What is 'yours to do' vs 'carried for you'? Who fixes the record? What would you say to a manager who says 'just catch up later'?
Feeds the governed tutorial
No
Controls: PSPF Req 24; PSPF Req 23; PSPF Recommended Approach §3.5.2
The conference connection
Setup
After a conference you accept a LinkedIn request from a consultant who sat at your table. They send a friendly message: 'Great talking — always keen to swap notes on policy work. Happy to buy coffee next time I'm in town.'
Task
Use the SOUP four-letter check on this contact, then complete the one-page contact report form: what you include, what you leave out, and what you deliberately do NOT do next.
Judgement tested
Recognise a contact worth reporting (RA §3.5.1); report factually and stop — never investigate, never probe the person (RA §3.5.2).
Common errors
Waiting for 'something more'; googling the consultant first; confronting them; deciding it's 'probably nothing' without reporting.
Debrief
What does 'report, don't investigate' protect? Where does the form go? What if you are unsure — what does the framework prefer?
Feeds the governed tutorial
Yes
Controls: PSPF Recommended Approach §3.5.1; §3.5.2
Input under review: The five-month professional contact and the decision whether — and what — to report.
Classification of the event: A contact event under the reporting obligation. The output under governance is the contact report itself; the reporter's authority ends at submission.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | The facts as known — sequence, venues, asks — captured and verified against what actually happened, nothing embellished. | PASS |
| L2 · Context analysis | Intent is unknown by design — the framework does not require the reporter to interpret. State fit: report, don't investigate. | HOLD |
| L3 · Harm / loss | Under-reporting risks missing interference; over-reporting a false alarm is cheap. The report resolves the asymmetry. | PASS |
| L4 · Equity weighting | The reporter is not accused of anything — reporting is the duty, not the judgement. No adverse inference for raising it. | PASS |
| L5 · Coherence check | Matches RA §3.5.1/§3.5.2: educate on SOUP, submit the report, stop. Verify the entity's actual form is the one used. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: factual report, no investigation limb, no follow-up promise. | PASS |
| L7 · Audit generation | The report is logged, dated, signed — append-only. The security mailbox receives it; nothing is deleted. | PASS |
| L8 · Output certification | The report is released to the security function — Node 9 decides what happens next; the reporter does not follow up. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
OBSERVE → PASS · CERTIFIED RELEASE — the report is submitted; release authority sits with the security function.
The security function holds release authority over what the report means and what happens next. The reporter's authority ends at submission — noticing and telling, never investigating.
Governed answer
A good governed answer reports the whole five-month sequence factually and stops: no investigation, no probing, no 'wait for something more'. Any single SOUP letter — Suspicious, Ongoing, Unusual, Persistent — is enough. The report is the output; the security function holds release authority for what happens next.
Cited controls: PSPF RA §3.5.1 · §3.5.2 · Req 219
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
Sort the pattern
Setup
Eight cards, each describing one interaction with the same person over a year: praised your work at a meeting; asked what your team is working on 'out of interest'; bought coffee three times; offered a paid speaking spot; asked about a colleague's overseas trip; sent articles on your program area; invited you to dinner; asked for a copy of an unclassified policy before it is published.
Task
Sort each card into three piles — 'report', 'not report', 'unsure' — and write one sentence of reasoning for the unsure pile. Compare piles as a table.
Judgement tested
Foreign interference and cultivation are gradual and rarely dramatic (Req 219); the recognition connects to the contact report you already know (RA §3.5.1) — same report, same stop point.
Common errors
Judging each card in isolation; treating 'friendship' as proof of safety; sorting by how the person made you feel.
Debrief
Which single card is reportable on its own? Which only in sequence? Why does the course call the sequence the 'new 2026 content'?
Feeds the governed tutorial
Yes
Controls: PSPF Req 219; PSPF Recommended Approach §3.5.1
The lost laptop
Setup
A colleague calls you from an airport: their work laptop is missing after security screening. The device held OFFICIAL:Sensitive material. They ask you what to do, and add 'I've already checked my emails — nothing sensitive in there'.
Task
Walk the first steps in order on the incident timeline cards: follow the defined procedure, report, and stop. Then play the 90-second call you would make to the security hotline — what you say, what you don't say.
Judgement tested
A defined incident procedure exists — follow it and report (Req 26); serious incidents reach the right authority in time (Req 28); you do not investigate or assess damage yourself.
Common errors
Offering to 'search the cloud logs'; deciding it's minor because the colleague says so; delaying to 'be sure'.
Debrief
What is the first step when you don't know the procedure? What makes an incident 'serious' for Req 28 — and who decides?
Feeds the governed tutorial
No
Controls: PSPF Req 26; PSPF Req 28
What's mine, what's carried
Setup
A security bulletin lands in your inbox: heightened emergency risk for your area; also attached is the roster of specialist training for high-risk roles. You are not in a high-risk role.
Task
Split the bulletin's contents into two columns — 'mine' and 'carried for me' — then write the three things the bulletin changes about your day, and the one thing that stays the same.
Judgement tested
Personnel are warned of heightened emergency risk (Req 57); targeted training applies to specialist and high-risk roles (Req 25); your steady part stays noticing, reporting, following procedure.
Common errors
Taking on duties that belong to others; ignoring the bulletin because you're not high-risk; treating the warning as optional reading.
Debrief
What does being 'warned' require of you that reading an email doesn't? Why is the division of duties a relief rather than a gap?
Feeds the governed tutorial
No
Controls: PSPF Req 57; PSPF Req 25
BY-G3 — Protective Markings
Printable governed response → · the course's capstone as a standalone worksheet
Printable artifact pack → · the course's scenario artefacts as printable hand-outs
Three documents, three rungs
Setup
Three one-page documents sit on your desk: (A) a meeting agenda for a routine internal catch-up; (B) a draft media release containing unannounced figures on a program's performance; (C) a staff list with personal contact details for an office move.
Task
For each document, write the damage answer — 'if this were seen by the wrong person, what could result?' — then choose the marking level the damage honestly justifies, and sign the originator line.
Judgement tested
The originator judges sensitivity by potential damage (Req 59); the level is set at the lowest reasonable level (Req 60); a named person stands behind the label (Req 58).
Common errors
Marking by habit or template ('we always mark this PROTECTED'); marking by topic rather than the actual document; leaving the originator line blank.
Debrief
Why does 'lowest reasonable' protect the marking system itself? What damage does over-marking cause?
Feeds the governed tutorial
No
Controls: PSPF Req 59; PSPF Req 60; PSPF Req 58
The ladder game
Setup
Twelve cards describe information ('staff birthdays in a team calendar', 'the draft budget before Cabinet decision', 'a colleague's personal email address in a distribution list'...). The six marking values are laid out on the table.
Task
Match each card to the lowest rung that honestly covers the potential damage, then swap cards and challenge one of your partner's choices. End with the quick-fire round: eight mini-documents, ten seconds each.
Judgement tested
Recall the six values in order and choose the lowest honest rung (Req 59, 60) — the rung is a promise, not a guess.
Common errors
Matching to the topic's importance instead of the document's content; defaulting everything up one rung 'to be safe'.
Debrief
Which pairing was hardest? What did the disagreements teach about 'consistent judgement'?
Feeds the governed tutorial
No
Controls: PSPF Req 59; PSPF Req 60
Subject line surgery
Setup
Ten draft email subject lines, each with exactly one or two flaws: marking missing, wrong position, wrong case, doubled space, a caveat without a classification, or a marking on the wrong line.
Task
Red-line each subject line and write the corrected form in the exact syntax, including the one spacing rule that trips people up. Then pair each caveat with the classification it must travel with.
Judgement tested
Markings are readable text in the correct email subject-line form (Req 61, 67); caveats never travel alone (Req 64).
Common errors
'Fixing' the wording of a marking; treating a missing caveat as minor; forgetting the exact spacing.
Debrief
Why is the syntax fixed rather than 'close enough'? What does a caveat without a classification invite?
Feeds the governed tutorial
Yes
Controls: PSPF Req 61; PSPF Req 67; PSPF Req 64
The system that won't tell you
Setup
In the practice mailbox you receive a message whose attachment is marked PROTECTED, but the mail client shows no marking field anywhere and your colleague says 'the tool usually adds it'. The message itself is unclassified routine text.
Task
Mark the email to the highest sensitivity it contains, record what the tool did and did not do on the check sheet, and state what you would rely on before sending a reply that quotes the attachment.
Judgement tested
Mark to the highest sensitivity present (Req 67); markings are carried as structured fields on systems (Req 68; ISM-0270, 0271); the tool will not make the judgement for you.
Common errors
Trusting the tool to mark; treating the routine body as the whole email; forwarding the attachment 'as is' without checking the reply's own marking.
Debrief
Where does the marking live on a system, and why does that matter for records? When is 'the tool usually adds it' not good enough?
Feeds the governed tutorial
Yes
Controls: PSPF Req 68; ISM-0270; ISM-0271; PSPF Req 67
Input under review: The email whose attachment is marked PROTECTED, while the mail client shows no marking field at all.
Classification of the event: An output awaiting a marking decision — the tool's silence is not a verdict, and 'the tool usually adds it' is not evidence.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Attachment header verified PROTECTED; body routine; client view shows no marking field. | PASS |
| L2 · Context analysis | The easy read ('routine body') is the wrong read — mark to the highest sensitivity present. | HOLD |
| L3 · Harm / loss | Under-marking exposes the PROTECTED content; over-marking buries it in noise. The attachment decides. | PASS |
| L4 · Equity weighting | No shortcuts because 'the tool usually adds it' — the person sending owns the care. | PASS |
| L5 · Coherence check | Req 67/68 + ISM-0270/0271: tool suggests, human decides. Verify the records field carries the marking. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: highest sensitivity, tool limits, records property all agree. | PASS |
| L7 · Audit generation | The reply's marking and the tool check are recorded with the message. | PASS |
| L8 · Output certification | The officer certifies the marking before send — the human signs, not the tool. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — the silence of the tool changes nothing; the human certifies.
The originator holds marking authority — never the tool, never 'what it usually does'. Release of the reply carries the officer's certification.
Governed answer
Mark the email PROTECTED, note exactly what the tool did and did not do, record the structured field, and carry the level into any reply that quotes the attachment. The tool's silence — or its guess — is never a verdict; the officer certifies the marking before release.
Cited controls: PSPF Req 67 · Req 68 · ISM-0270 · ISM-0271
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
The open-plan briefing
Setup
Six situations: discussing a PROTECTED matter at your desk in an open-plan area with visitors nearby; taking the same discussion into the booked secure room; reading a marked document on the train; discussing it on a video call from home with family present; photocopying a marked document; leaving a marked printout face-up on the shared printer.
Task
For each situation, decide 'right place / wrong place / depends' and name the minimum care the marking triggers. Defend one 'depends' to the group.
Judgement tested
The marking sets the minimum care (Req 62); classified discussions happen only in approved locations (Req 70).
Common errors
Treating 'depends' as 'anything goes'; thinking the marking matters only at the moment of sending.
Debrief
Why does the minimum care continue after the email is sent? What does a 'wrong place' choice cost in practice?
Feeds the governed tutorial
No
Controls: PSPF Req 62; PSPF Req 70
BY-GX3 — Email Protective Marking
Printable governed response → · the course's capstone as a standalone worksheet
Printable artifact pack → · the course's scenario artefacts as printable hand-outs
The unmarked thread
Setup
Five emails in the practice inbox. One is a reply inside an internal thread with no marking ('internal mail doesn't need one'), one is marked only by a coloured flag, one is marked by a phone call you received beforehand, one is correctly marked, and one has the marking in the signature block.
Task
Sweep the inbox: which messages are not properly marked, and in one line each, what makes each one wrong?
Judgement tested
Email in and between entities carries a text marking (Email Req 0067); text is the requirement because a person and a machine read it the same way (Email Req 0061).
Common errors
Accepting a colour or a call as a marking; treating internal mail as exempt; accepting a signature-block marking.
Debrief
Why does 'internal mail is exempt' fail the standard's own wording? What does the phone call not do?
Feeds the governed tutorial
No
Controls: Email Req 0067; Email Req 0061
Mark to the highest thing inside
Setup
Three variants of the same email: (A) body only — routine; (B) body plus an OFFICIAL:Sensitive attachment; (C) body plus a PROTECTED attachment.
Task
For each variant, choose the one SEC value and say which part of the email drove it. Then do the reverse: given the value, infer what must be inside.
Judgement tested
Select the SEC value by reading every part and marking to the highest sensitivity present (Email Req 0061; ISM-0270).
Common errors
Marking to the body only; marking to the topic; choosing by recipient seniority.
Debrief
What is the smallest component that can lift a whole email's value?
Feeds the governed tutorial
Yes
Controls: Email Req 0061; ISM-0270
The syntax clinic
Setup
Eight email headers and subject lines, each malformed: wrong case, wrong bracket, marking in the body, missing space, an invented value, a caveat on its own, a header written as 'X-PROTECTIVE-MARKING: PROTECTED' without SEC=, and one correct example hidden among them.
Task
Rewrite each in the exact fixed syntax — both the Subject Field Marking and the Internet Message Header Extension — and match the four caveat types to their uses.
Judgement tested
Both forms use exact fixed syntax (Email Req 0061); four caveat types attach to values, never alone.
Common errors
'Close enough' syntax; mixing the two forms; inventing values or caveats.
Debrief
Why does a machine-readable form matter for systems that route, filter and record email?
Feeds the governed tutorial
No
Controls: Email Req 0061
The header that wins
Setup
A message arrives with subject [SEC=OFFICIAL] but header X-Protective-Marking: SEC=PROTECTED, ACCESS=Legal-Privilege. A colleague says 'the subject is what people see, so treat it as OFFICIAL'. The records system also shows the Information Management Marker is missing.
Task
State which form wins, what the Information Management Marker floor requires, and what you record before replying. Pair up: one of you argues the colleague's line, the other responds with the standard.
Judgement tested
Where both forms appear the header wins (EM-7.precedence); the IMM floor still applies (EM-IMM.floor); the marking connects to the records property (Email Req 0068).
Common errors
Trusting the visible subject; treating the clash as 'someone else's problem'; replying without recording.
Debrief
What does a clash between forms tell you about the message's journey?
Feeds the governed tutorial
Yes
Controls: EM-7.precedence; EM-IMM.floor; Email Req 0068
Input under review: The incoming message whose subject reads [SEC=OFFICIAL] while the X-Protective-Marking header reads SEC=PROTECTED, ACCESS=Legal-Privilege.
Classification of the event: A contradictory inbound output — the clash between the two forms is itself the signal, not a detail to paper over.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Both forms captured; header verified against the raw message; attachment header page confirmed PROTECTED. | PASS |
| L2 · Context analysis | Where both forms appear, the header wins — EM-7.precedence. The visible subject is the trap. | HOLD |
| L3 · Harm / loss | Treating it at OFFICIAL would mis-handle privileged legal material; the header value protects the counterpart. | PASS |
| L4 · Equity weighting | Correct handling protects the originator's entity too — the clash is recorded, not blamed. | PASS |
| L5 · Coherence check | EM-7.precedence + the Information Management Marker floor + the records property (Email Req 0068) all apply. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: header wins, floor applies, record carries it. | PASS |
| L7 · Audit generation | The clash and the decision are recorded with the message — append-only. | PASS |
| L8 · Output certification | Any onward summary is certified at PROTECTED with the caveat, to cleared recipients only. | VERIFY |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — the message stands at PROTECTED, Legal-Privilege; onward release is bounded.
The originating entity holds release authority for changes to the message's standing; the recipient handles at the header value and may not quietly downgrade.
Governed answer
Treat the message at SEC=PROTECTED with ACCESS=Legal-Privilege — the header wins where both forms appear (EM-7.precedence). Apply the Information Management Marker floor and record the message and its marking as a property of the record (Email Req 0068). Any summary quoting the advice carries PROTECTED and the caveat, to cleared recipients only. The clash is itself a flag about the message's journey — note it, don't paper over it.
Cited controls: EM-7.precedence · EM-IMM.floor · Email Req 0068
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
Tool limits, human decisions
Setup
Three observations from the help desk: (1) the client suggests a marking but a user overrode it; (2) a reply draft refused to downgrade the value of a quoted original; (3) the mail server bounced a message whose header did not match policy.
Task
Classify each as 'tool doing its job', 'user error', or 'tool failure' — and for each, write who remains accountable for the final marking decision.
Judgement tested
Tools suggest, never decide (ISM-0271); quiet downgrades of replies are blocked (ISM-1089); the server is the last calm check (ISM-0565) — the person stays accountable.
Common errors
Blaming the tool for a human judgement; treating a blocked downgrade as a bug.
Debrief
Why is it desirable that the tool cannot mark for you?
Feeds the governed tutorial
No
Controls: ISM-0271; ISM-1089; ISM-0565
Send it properly
Setup
A brief: send a two-paragraph status update on a joint program, quoting one figure from an attached PROTECTED partner report, to three internal colleagues and one external counterpart. (Practice mailbox only.)
Task
Compose the complete email — subject marking, body, header marking, attachment note — then run the five-point self-check card before 'send'.
Judgement tested
The full sequence: read everything, choose the value, write the syntax, respect precedence and the floor (ISM-0270; Email Req 0067) — a single honest send.
Common errors
Skipping the header; marking only the attachment; sending before the self-check.
Debrief
What did composing the whole message surface that reading about it did not?
Feeds the governed tutorial
Yes
Controls: ISM-0270; Email Req 0067
BY-G7 — Fraud Prevention
Printable governed response → · the course's capstone as a standalone worksheet
One wall or five?
Setup
A diagram of an accounts-payable control stack: segregation of duties, three-way match, exception report, duplicate-payment review, monthly reconciliation. A colleague says 'the three-way match is our wall — the rest is ceremony'. The diagram shows the three-way match is currently the only check on one payment path.
Task
On the diagram, label which layer each control is, then answer: if the three-way match is removed from that path tonight, what is actually left? Write the one-line answer to the colleague.
Judgement tested
Fraud prevention is defence-in-depth, T0-T3 (IPSFF Prevention Tiers); a control described without its layer invites the assumption it is the only defence.
Common errors
Ranking controls by cost or glamour; accepting 'one strong check covers everything'.
Debrief
Which of your entity's layers would you miss most if it quietly stopped?
Feeds the governed tutorial
Yes
Controls: IPSFF Prevention Tiers T0-T3
Place the control
Setup
Eight control cards: staff vetting; tone-from-the-top message; three-way match; exception report; fraud loss measurement; hotline; post-payment data analytics; board fraud committee. The T0-T1 boundary is where the group always argues.
Task
Place each card in its tier on the wall, then fight the two boundary cases deliberately: which card is T0, which is T1, and why does the distinction matter for who owns it?
Judgement tested
Distinguish the four tiers and place a real control correctly, especially T0 vs T1 (IPSFF Prevention Tiers).
Common errors
Treating tiers as a ranking of importance; putting measurement controls 'outside' prevention.
Debrief
What changes operationally if a control is really in a different tier than everyone assumed?
Feeds the governed tutorial
No
Controls: IPSFF Prevention Tiers T0-T3
The stand-down request
Setup
Finance asks to stand down the duplicate-payment review for six months to free staff for year-end. Their email is persuasive: 'no fraud found in two years'. The last fraud risk assessment predates the change.
Task
Write the one-page response: what must happen before any control is changed or removed, what residual risk means here, and who signs off on it. End with the single sentence you would actually send.
Judgement tested
Residual fraud risk must be assessed; the FRA comes before changing or removing a control (IPSFF FRA); someone signs off on residual risk.
Common errors
Approving 'temporarily'; accepting 'no fraud found' as 'no fraud'; leaving the sign-off unnamed.
Debrief
Why does order matter — assessment first, then change? What does a quiet stand-down do to every other layer?
Feeds the governed tutorial
Yes
Controls: IPSFF FRA (measurement-scoped)
The quiet ledger
Setup
A one-page fictional ledger: 400 payments. The exception report flags 6; full review of a 50-payment sample finds 4 irregular payments, 3 of which the exception report never flagged. A colleague says 'we only lost a handful, so we're fine'.
Task
Work the numbers: what does the sample imply about the 400? What is the difference between 'detected fraud' and 'actual fraud' here? Draft the one-paragraph note the audit committee should see.
Judgement tested
Detected fraud is not the same as actual fraud (IPSFF FLM); low detection is not low fraud; FRA and FLM answer different questions together.
Common errors
Extrapolating with false precision; reporting the detected figure as the fraud figure; deciding 'fine' from a small flagged set.
Debrief
What makes an estimate honest rather than alarmist? Who should see the measured figure?
Feeds the governed tutorial
Yes
Controls: IPSFF FLM (measurement-scoped)
Input under review: The measured fraud-loss estimate versus the detected figure — and the question of what the audit committee is told.
Classification of the event: A measurement output that must never be dressed as certainty — and a decision that must not hide behind either number alone.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Sample design, method and calculation verified; the full-sample review is reproducible. | PASS |
| L2 · Context analysis | Detected fraud is not actual fraud — FRA and FLM answer different questions. The measured estimate is best available, not gospel. | HOLD |
| L3 · Harm / loss | Reporting only the detected figure understates; a single point estimate overstates. Present both, with the uncertainty. | PASS |
| L4 · Equity weighting | Honest numbers protect the public purse and the staff who run the controls — no smoothing to comfort anyone. | PASS |
| L5 · Coherence check | Stay inside the measurement scope of the course — entity-level duties live in the PGPA Act and the Rule, not here. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: both figures, method, and the reason they differ. | PASS |
| L7 · Audit generation | Method, sample, estimate and wide confidence bounds appended — append-only. | PASS |
| L8 · Output certification | The committee brief is certified by the accountable officer before release. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — both figures go to the committee, with method and wide bounds.
The accountable officer signs the committee brief. The estimate is released with its uncertainty — never alone, never as a verdict on any individual.
Governed answer
Report the measured estimate as the entity's best available figure alongside the published detected figure, with the method and the wide confidence bounds, and say plainly why they differ. The audit committee gets both numbers — and the reason — not one dressed as the truth. The measurement is scoped to the IPSFF measurement controls; entity-level fraud duties live in the PGPA Act regime and your fraud control plan, not in this brief.
Cited controls: IPSFF FLM (measurement-scoped) · FRA
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
The quiet change
Setup
A data-pipeline change log (fictional): 'field FRA_RISK renamed; three legacy sources decommissioned; reconciliation job now runs monthly'. Nobody told the fraud team. The next FLM silently covers 60% of the population.
Task
Find the break in the log, name the two duties it offends (conduct and data governance), and draft the two-line fix request to the data owner.
Judgement tested
The measurement-scoped conduct duty and the data-governance duty underpin every number (IPSFF); quiet changes break measurement.
Common errors
Treating the change as IT's business; accepting the renamed field at face value.
Debrief
Why do numbers only mean what the data governance underneath lets them mean?
Feeds the governed tutorial
No
Controls: IPSFF conduct + data-governance duties (measurement-scoped)
The new detector
Setup
A vendor demo shows an AI detection tool catching 'fraud patterns humans miss'. Procurement asks you to sign off. The demo ran on the vendor's own data; there is no test plan for your entity's data; the tool would auto-hold payments without review.
Task
Place the tool in the tier stack, write the three tests it must pass before it operates on your data, and name the human decision that must remain in the loop.
Judgement tested
AI-enabled detection is one more control inside existing tiers, to be tested like any other, with a checkable human in the loop (IPSFF AI application).
Common errors
Treating the demo as assurance; letting the tool auto-decide 'hold' with no review; placing AI outside the tiers.
Debrief
What does 'trust you can check' require you to build before the tool goes live?
Feeds the governed tutorial
No
Controls: IPSFF AI application (measurement-scoped)
BY-G2 — ISM 2026
Printable governed response → · the course's capstone as a standalone worksheet
Who owns it?
Setup
An org chart (fictional): a CIO, three security teams, a training function — but no named CISO, and the awareness-training program has no named owner. An incident has just occurred that training was meant to prevent, and nobody can say who is accountable.
Task
Mark the gap on the chart, draft the one-paragraph accountability statement that names the person and what they own, and write what you would say if asked 'who answers for the training program?'
Judgement tested
Cyber security leadership sits with a named accountable person who owns the awareness training program (ISM governance controls).
Common errors
Accepting 'the team owns it'; naming a committee; leaving the statement vague about the training program.
Debrief
Why does a named person change behaviour where a committee does not?
Feeds the governed tutorial
Yes
Controls: ISM governance: accountability
Three profiles, two duties
Setup
Three staff profiles: a new graduate (no admin rights), a system administrator with privileged access, and a contractor engaged for nine months with standard access.
Task
Build the training row for each profile in the matrix: what training applies, how often, and what the privileged user gets beyond the annual course. Then write the one-line rule that holds both duties together.
Judgement tested
Annual awareness training for all personnel plus tailored training for privileged users (ISM training controls).
Common errors
Giving everyone the same course; treating 'privileged' as optional; forgetting contractors.
Debrief
What does 'tailored' mean for a privileged user's day-to-day decisions?
Feeds the governed tutorial
No
Controls: ISM training controls
The policy you can't find
Setup
A user asks whether personal web browsing is allowed at work. The system usage policy exists; the web usage policy was 'approved last year' but no one can find a version, a publish date, or evidence staff were told. The help desk answers differently every time.
Task
Read the sample system usage policy and check it against the three verbs — developed, implemented, maintained. Produce the gap list and the one sentence that should answer the user's question today.
Judgement tested
System usage and web usage policies must be developed, implemented and maintained (ISM policy controls) — 'maintained' means current, findable and told to people.
Common errors
Answering from memory; accepting 'approved' as 'implemented'; treating a missing policy as a minor paperwork issue.
Debrief
Which of the three verbs is cheapest to skip and most expensive to lose?
Feeds the governed tutorial
No
Controls: ISM policy controls (system usage, web usage)
Two reports, one incident
Setup
An incident timeline (fictional): 09:00 anomaly detected; 09:20 confirmed as a suspected compromise; 10:00 executive asks 'who needs to know?'. The incident involves a system that handles sensitive information.
Task
Plot the two reporting paths on the timeline — internal to the CISO, and external to ASD — with the timing each expects, and draft the notification lines for both.
Judgement tested
Internal and external reporting paths exist with timing expectations (ISM reporting controls); two reports, one incident, both made.
Common errors
Reporting internally and stopping; waiting for 'full facts'; confusing the two recipients' timing.
Debrief
Why does the framework want both reports rather than one? What goes in an initial report vs a follow-up?
Feeds the governed tutorial
Yes
Controls: ISM reporting controls
Input under review: The confirmed security incident — and the two notifications it requires.
Classification of the event: An incident output requiring two governed releases: one internal to the CISO, one external to ASD, each within its timing.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Incident facts verified: 09:00 anomaly, 09:20 confirmation, systems and data involved. | PASS |
| L2 · Context analysis | Both reporting paths apply — internal and external are two reports for one incident, not alternatives. | HOLD |
| L3 · Harm / loss | Delay to the ASD notification is reportable in itself; internal-only leaves the CISO blind. | PASS |
| L4 · Equity weighting | The report carries facts and timing, not blame — people report faster when reporting is safe. | PASS |
| L5 · Coherence check | ISM reporting controls set the paths and timing; if AI was involved, the AI incident is reported like any other. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: one incident, two reports, both timed, both recorded. | PASS |
| L7 · Audit generation | Both notifications timestamped and logged — append-only, with the reference numbers. | PASS |
| L8 · Output certification | The CISO certifies the internal report; the designated officer certifies the ASD notification. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
OBSERVE → CERTIFIED RELEASE — two reports, one incident, both within their timing.
The CISO holds release authority for the internal report; the designated reporting officer for the ASD notification. The incident owner never decides alone.
Governed answer
Make both reports: internal to the CISO and external to ASD, each within the timing its path expects, with an initial report before 'full facts' and a follow-up after. If the incident involves an AI system acting outside its lane, it is reported like any other incident. The internal report is certified by the CISO; the external notification by the designated officer — the incident owner never decides alone.
Cited controls: ISM reporting controls · ISM AI control set (June 2026)
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
What changed in June 2026
Setup
Five cards describe the June 2026 changes — hardening user applications, removing temporary installation files, vulnerability assessments and penetration tests — written in 'before' language. A second set describes the 'after' requirement.
Task
Match each before to its after, then for each change write who in your entity must act and by when (Release 2026 start: 1 July 2026).
Judgement tested
Recognise the five new or modified items in the June 2026 release and state what each requires (ISM June 2026 changes).
Common errors
Treating the changes as vendor notes; assuming 'someone in ICT' covers it.
Debrief
Which change touches the most roles in your entity? Which is most likely to be skipped quietly?
Feeds the governed tutorial
Yes
Controls: ISM June 2026 release items
The build review and the question that outlasts it
Setup
A procurement is buying a new business application. The draft contract has no secure software development policy requirement, and the security section still uses the old cryptographic-protection naming. Meanwhile the vendor mentions the system 'will get more autonomous over time'.
Task
Mark the two contract gaps (secure development policy; the PRO-08 rename), then apply the durable governance question — who is accountable, what is it allowed to do, how do we know — to the vendor's 'more autonomous' claim.
Judgement tested
A secure software development policy is required; the cryptographic protection control was renamed; the governance question outlasts any release (ISM).
Common errors
Fixing only the naming; accepting 'more autonomous' as a future problem; leaving the policy gap to legal.
Debrief
How does the same three-question test survive a release, a rename and an autonomy upgrade?
Feeds the governed tutorial
No
Controls: ISM secure development; PRO-08
BY-G4 — Personnel Security
Printable governed response → · the course's capstone as a standalone worksheet
Printable case-file pack → · the course's scenario case files as printable hand-outs
Access before suitability?
Setup
A program director wants a temporary specialist to start tomorrow and asks for system access 'now, while the screening paperwork catches up'. The role will handle OFFICIAL:Sensitive case files. Access can be provisioned in ten minutes today.
Task
Role-play the two-minute conversation: you hold the line on suitability before access. Then write the two-part check on the access form — suitability established, and need-to-know confirmed — and mark what is still missing.
Judgement tested
Suitability is established before a person touches government resources (PSPF Req 120); screening and system access are linked (ISM-0434); access rides on need-to-know (PSPF Req 131).
Common errors
Compromising 'just this once'; treating the director's urgency as authority; skipping the need-to-know half of the check.
Debrief
What is lost when access precedes suitability — even for ten minutes?
Feeds the governed tutorial
Yes
Controls: PSPF Req 120; ISM-0434; PSPF Req 131
Which level, whose call?
Setup
Four roles: a policy officer handling PROTECTED material; a records officer who may occasionally handle SECRET; an executive with need-to-know across several classifications; a contractor who only handles OFFICIAL.
Task
Match each role to the clearance level the work actually requires, mark where the hiring team's responsibility ends and the vetting authority's begins, and draft the handover note for the two that need a clearance.
Judgement tested
Clearance matches the classification a role actually handles (PSPF Req 132); vetting is the authority's job, not the hiring team's (Personnel Std Req 0140).
Common errors
Clearing to the role's title rather than the material; the hiring team 'starting vetting' informally; clearing higher than needed 'to be safe'.
Debrief
Why does the boundary between hiring team and vetting authority protect the applicant too?
Feeds the governed tutorial
No
Controls: PSPF Req 132; Personnel Std Req 0140
The waiver file
Setup
A case file for a specialist role vacant eleven months: strong applicant, permanent resident not yet a citizen, seven-year overseas period that is difficult to check. The hiring delegate proposes an eligibility waiver, citing scarce skills. The file includes the six integrity traits and the two safeguards.
Task
Work the file in order: which traits can be assessed today, which cannot, and what the two safeguards require. Then write the recommendation — waiver, no waiver, or a redesign of the role — with the reasoning a reviewer can check.
Judgement tested
The standard assesses integrity (Personnel Std Req 0154); an eligibility waiver is an amended, escalated risk decision, not a routine fix (PSPF Req 148-151).
Common errors
Treating the waiver as the default for scarce skills; deciding on the unverifiable period alone; skipping the escalation step.
Debrief
What would make you change your recommendation? What information is missing from the file?
Feeds the governed tutorial
Yes
Controls: Personnel Std Req 0154; PSPF Req 148/149/150/151
The annual check
Setup
A clearance holder's year-in-review file (fictional): no flag last year; this year contains a new long-term relationship with a foreign national, an extended overseas trip to a high-risk region, and a gambling-related debt mentioned in passing by a colleague.
Task
Run the annual security check as a routine, calm obligation: what in the file has changed, what you note, what you escalate and to whom, and which parts belong to the entity vs the vetting authority.
Judgement tested
Ongoing suitability is managed by the entity (PSPF Req 164); the authority formally reassesses (Personnel Std Req 0172); the annual check is routine (PSPF Req 168).
Common errors
Treating changes as 'personal matters'; escalating everything; or dismissing the gambling note entirely.
Debrief
What makes a change 'suitability-relevant'? How do you keep the check calm and non-judgemental?
Feeds the governed tutorial
No
Controls: PSPF Req 164; Personnel Std Req 0172; PSPF Req 168
The LinkedIn post and the clean exit
Setup
Two situations: (1) a clearance holder posts their clearance level on LinkedIn 'celebrating five years of trust'; (2) a departing officer hands back their pass but asks to keep system access 'for two weeks, in case anything comes up', and asks what they can still say about their work.
Task
For (1): draft the response the 2026 requirement expects. For (2): complete the separation checklist — debrief and withdrawal of access — and the two lines the officer can and cannot say after they leave.
Judgement tested
Clearance information must not be posted online (ISM-2104; new 2026); separation has two halves — debrief and access withdrawal (PSPF Req 182, 186).
Common errors
Letting the post stand 'because it's true'; granting the two-week access extension; skipping the debrief as 'we already said goodbye'.
Debrief
Why is the debrief a security control and not a formality?
Feeds the governed tutorial
No
Controls: ISM-2104; PSPF Req 182; PSPF Req 186
Input under review: The public post — 'Celebrating five years of trust — proud to hold my security clearance. Great place to work.'
Classification of the event: An output that crossed the containment boundary without a release certificate. The holder does not hold release authority for clearance information; the entity's security function does. The response is therefore governed, not improvised.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Post text captured and verified — hash · schema · source: public profile, no doctoring. | PASS |
| L2 · Context analysis | Intent celebratory, not malicious — but state fit fails: public platform, uncontrolled audience, no state in which clearance disclosure is authorised. | HOLD |
| L3 · Harm / loss | Loss cap: clearance level, agency and tenure exposed to open collection; harm floor: personal pride does not outweigh exposure. | HOLD |
| L4 · Equity weighting | Corrective and supportive, not punitive — no adverse inference against integrity; proportionate, non-public response. | PASS |
| L5 · Coherence check | Consistent with ISM-2104 and entity comms policy; residual: verify the entity's own guidance tells staff what may not be posted. | VERIFY |
| L6 · Integration gate | Cross-layer consistency: corrective (L4), bounded (L3), matched to the 2026 rule (L5). | PASS |
| L7 · Audit generation | Proof: screenshot, timestamp, action taken, holder's acknowledgement — logged, signed, append-only. | PASS |
| L8 · Output certification | The response text is certified for release by the designated officer before it goes out — release certificate required. | VERIFY |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — the event already egressed; the governed object is the response, which is fully controllable.
Authority for any external communication about a clearance matter sits with the designated security function — not the holder, not comms alone, not the poster's manager. External outputs are blocked unless Node 9 issues a certified release. The corrective conversation is itself an output: held until verified, bounded, certified and released.
Governed answer
A good governed answer starts by naming what the post is: an output that left the containment boundary without a release certificate. The clearance holder does not hold release authority for clearance information — the entity's security function does — so the first action is to treat the post as an unauthorised external disclosure to be corrected, logged and learned from, not as a personal failing to be punished. Under ISM-2104, clearance information must not be posted online; the truth of the claim is not the issue — exposure to open collection is. The response has two halves: engage the holder factually and support them to remove or correct the post, and verify whether any further clearance information has been shared elsewhere. The response is released only after the layers verify and certify it — a corrective conversation is itself an output that must not be improvised. Separately, if the entity's own guidance does not already tell staff what may not be posted, that gap is part of the finding.
Cited controls: ISM-2104 · PSPF Req 182 · PSPF Req 186
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
BY-G5 — AI Governance in Government Systems
Printable governed response → · an extension scenario beyond the course tutorial, as a printable worksheet
The name on the register
Setup
Three AI tools (fictional) are in use in your team: an approved drafting assistant whose AI use register entry names an accountable executive who left four months ago; a triage feature that arrived inside a routine software update, with no register entry at all; and a pilot chatbot whose entry names the vendor as the accountable party.
Task
For each tool, answer question one — who is accountable — and write the one-line fix: update the stale name, raise the missing entry, or correct the vendor-as-accountable error. Then draft the short note to your security contact covering all three findings.
Judgement tested
Accountability for AI sits with a named human at executive level (GOV-08); the register entry and the usage policy are where it is written down (ISM-2074); a stale name, a missing entry or a vendor in the accountable field is a finding to raise, not a variant answer.
Common errors
Accepting the vendor as accountable; treating the departed executive's name as close enough; missing the tool that arrived inside an update because nobody procured it.
Debrief
Which of the three gaps is the most dangerous — and why is it the one nobody notices?
Feeds the governed tutorial
No
Controls: GOV-08; ISM-2074
The pause console
Setup
An approval console (simulated) holds six AI-proposed actions waiting for your decision: send a draft reply to an external stakeholder; release a de-identified data extract; change a client record; send eleven replies as a batch; post to a public channel; and one action that executed without ever pausing.
Task
Approve or decline each action with one line of reasoning, then find the sixth action — the one that skipped the pause — and write what you do about it.
Judgement tested
Risky actions are held for human approval before execution (ISM-2113); the pause is the control working — declining is a normal, correct outcome; a missing pause is reportable.
Common errors
Approving the batch you can't review; treating 'decline' as failure; ignoring the action that never paused.
Debrief
Who defines the risky-action list, and why must it exist before the console matters?
Feeds the governed tutorial
Yes
Controls: ISM-2113
Input under review: The six AI actions waiting in the approval console — and the one that executed without ever pausing.
Classification of the event: Autonomous outputs held at the human gate. The console is the control working; a missing pause is a governance failure to report, not a quirk.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Each action and its classification verified against the organisation's defined risky-action list. | PASS |
| L2 · Context analysis | A batch of eleven replies you have not read cannot be approved — reading the pause is the job. | HOLD |
| L3 · Harm / loss | An approved batch cannot be un-sent; declining is free. The missing-pause action may already have caused harm. | PASS |
| L4 · Equity weighting | Declining is a normal, correct outcome — no pressure to wave actions through because they look routine. | PASS |
| L5 · Coherence check | ISM-2113: the organisation defines risky actions; the application must hold them before execution. Verify the list is current. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: approve what you read, decline what you cannot, report what never paused. | PASS |
| L7 · Audit generation | Every decision logged with its reason — append-only. | PASS |
| L8 · Output certification | Executed actions carry the officer's approval record; the missing-pause action is escalated, not absorbed. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — per action, by the human at the gate.
The human officer is the release authority for risky actions. The machine never self-releases — a lane is only a lane if something can stop inside it.
Governed answer
Approve only what you have actually read; decline the batch you cannot review; decline is a normal, correct outcome under ISM-2113. Report the action that executed without pausing — the missing pause is the control failing, and the organisation defines the risky-action list, not the model. The console is the human gate made visible: the machine stops, the person releases, and the record shows both.
Cited controls: ISM-2113 · ISM-2112
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
The home laptop
Setup
A colleague summarises OFFICIAL:Sensitive case files on her own laptop using a consumer AI assistant in the evenings, because the approved tool 'can't be used from home and summarises poorly anyway'. She has raised it openly and nothing has been entered into the public tool yet — she says she only pasted summaries she wrote herself.
Task
Decide the response: what must stop now, whether this is an assessment request or an incident report, and what the approved-tool gap says about the agency itself. Draft the two messages — to her, and to the system owner.
Judgement tested
Organisational data is not training data; approved tools only; personal devices and unapproved agents are out of bounds; the approved tool's inadequacy is itself a finding to escalate (ISM AI controls).
Common errors
Treating it as purely disciplinary; 'it's only her own summaries'; escalating the tool gap as an afterthought.
Debrief
Which of the two messages is harder to write, and why?
Feeds the governed tutorial
Yes
Controls: ISM AI control set (data boundaries)
The model card we can't read
Setup
A model card and usage policy arrive with a new government AI tool (fictional). The model card describes the model family but not the deployment; the usage policy is one page of permissions; neither mentions content filtering, adversarial input detection, or what the tool may not be used for.
Task
Audit the two documents against the four things a knowable system needs: outward guard (content filtering), inward guard (adversarial input detection), model card, usage policy. Produce the missing-items list and the question you send to the vendor.
Judgement tested
Guards in both directions and documentation that makes a system knowable (ISM AI controls).
Common errors
Accepting the vendor's model card at face value; treating the usage policy as complete because it exists.
Debrief
What does 'knowing what you run' change about how the tool gets used on Monday?
Feeds the governed tutorial
No
Controls: ISM AI control set (guards, documentation)
The drift nobody flagged
Setup
A deviation-monitoring chart (fictional) shows an AI tool's behaviour drifting from baseline over three weeks — response length, refusal rate, and one output category drifting together. The log shows no one reviewed the weekly alert; the tool is also being used to assist security detection, and training records show the team's AI training is two years old.
Task
Read the chart, write the one-paragraph notification to the system owner (what drifted, since when, why it matters), and state what 'training that keeps up' means for the team.
Judgement tested
Baselines and deviation monitoring make abnormal behaviour visible; AI can augment human-led detection; training is expected to be refreshed (ISM AI controls).
Common errors
Dismissing the drift as 'the model just changed'; reviewing the alert but not acting; treating stale training as someone else's item.
Debrief
What would 'normal' look like on this chart, and who decides?
Feeds the governed tutorial
No
Controls: ISM AI control set (monitoring, training)
Thirteen coats, one idea
Setup
A wall shows the thirteen AI controls as cards with their names only. A new tool proposal arrives: an automated triage assistant for citizen enquiries that will draft responses and (on one pathway) decide next steps itself.
Task
Map the thirteen cards onto the one idea — governed human-machine trust with a person keeping the final say — then apply the three questions to the new proposal: who is accountable, what is it allowed to do, how do we know it does only that.
Judgement tested
The whole control set restates one durable principle (ISM AI control set; GOV-08); the three questions survive any capability advance.
Common errors
Treating the proposal as 'a tooling question'; applying controls one at a time without the governing idea.
Debrief
Which control becomes the hardest to hold as systems get more capable — and why?
Feeds the governed tutorial
No
Controls: ISM AI control set; GOV-08
BY-GX1 — Gateway Security
Printable governed response → · the course's capstone as a standalone worksheet
Name your door
Setup
A one-page network diagram (fictional) shows your entity's environment and a dotted line where the world begins: email, web, remote access, partner connections, and an unlabelled 'something' that everything crosses.
Task
Draw the boundary, list every flow that crosses it, and name the governed door that must stand at that edge. Write one sentence a colleague could use to explain why the door exists.
Judgement tested
A security domain boundary has a governed door at its edge (Gateway Security Standard, eff. 1 Jul 2026).
Common errors
Naming systems instead of the boundary; forgetting 'everything crosses through one door'.
Debrief
What happens to flows that cross without the door knowing?
Feeds the governed tutorial
Yes
Controls: Gateway Standard: governed boundary
The 'must' audit
Setup
A list of twelve clauses from a gateway agreement (fictional): some say 'must', some 'should', some are silent. One clause requires a yearly notification to the Department of Home Affairs about your gateway arrangements. A colleague says 'should is negotiable, must is not'.
Task
Sort the clauses into must / should / silent, and mark on the annual calendar when the Home Affairs notification is due and who owns it.
Judgement tested
Every 'must' binds your entity; the annual arrangement notification is a standing obligation (Gateway Standard).
Common errors
Treating 'should' as 'must' or vice versa; losing the annual notification in a calendar gap.
Debrief
Why does the standard make the notification annual rather than one-off?
Feeds the governed tutorial
Yes
Controls: Gateway Standard GW-2.1; annual notification
The expiring IRAP
Setup
A gateway's IRAP assessment certificate (fictional) expires in 60 days. The assessor is booked, but the evidence pack is incomplete and the program manager says 'nothing has changed since last time'.
Task
Mark the evidence clock: what must be true on day 60, what the 24-month freshness requirement means for operations after that date, and draft the two-line briefing that names the risk if the clock lapses.
Judgement tested
Assurance evidence is renewed on a clock — the 24-month IRAP assessment freshness requirement (Gateway Standard GW-5.x).
Common errors
Accepting 'nothing changed' as a reason to defer; treating the certificate date as administrative.
Debrief
Why does evidence expire even when the system hasn't changed?
Feeds the governed tutorial
Yes
Controls: Gateway Standard GW-5.x (24-month IRAP)
The unsigned ATO
Setup
A system goes live in three weeks; its gateway capability has no current signed Authority to Operate — drafted before a machinery-of-government change, never signed, authorising officer moved on. The IRAP assessment is current and hosting is certified.
Task
Write the escalation memo: the state of the authorisation package, who must decide, and the options (hold, time-bounded acceptance, partial). Then name the person whose signature makes the residual risk someone's.
Judgement tested
The ATO is formal acceptance of residual risk (Gateway Standard GW-5.1); a human name stands behind the door; hosting certification is required for sensitive gateways (GW-6.x).
Common errors
Going live on technical soundness alone; treating the missing signature as paperwork; leaving the acceptance unnamed.
Debrief
What does the signed ATO actually buy the entity that the technical checks don't?
Feeds the governed tutorial
Yes
Controls: Gateway Standard GW-5.1; GW-6.2b
Input under review: The go-live decision for a gateway whose Authority to Operate was never signed.
Classification of the event: A release pending authorisation — technical soundness is not authority, and no signature means no one has accepted the residual risk.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Authorisation package contents verified; signature absent; IRAP current; hosting certified. | PASS |
| L2 · Context analysis | GW-5.1 is a 'must': the ATO is formal acceptance of residual risk. The authorising officer moved on — the duty did not. | HOLD |
| L3 · Harm / loss | Go-live without acceptance leaves residual risk unnamed; a public system without a signed authorisation is an avoidable exposure. | PASS |
| L4 · Equity weighting | A named officer must accept the risk — no anonymous acceptance, no committee of nobody. | PASS |
| L5 · Coherence check | IRAP freshness and hosting certification are satisfied but are separate 'musts' — neither signs the ATO. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: escalate, hold or time-bound — never go live on technical soundness alone. | PASS |
| L7 · Audit generation | The acceptance decision and its signatory are recorded — append-only. | PASS |
| L8 · Output certification | Release only with a signed ATO or a formal, time-bounded acceptance by an officer with the authority to give it. | VERIFY |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — with a signature, or a time-bounded acceptance that names who owns it.
The authorising officer holds release authority for the gateway. The system owner escalates and supplies evidence — they do not self-certify.
Governed answer
Hold the go-live until the authorisation package is complete and signed — or escalate immediately for a formal, time-bounded acceptance by an officer with the authority to give it, and let that decision, not the delivery date, set the risk. Technical soundness (current IRAP, certified hosting) is real but is not the ATO: GW-5.1 is a 'must', and a human name must stand behind the door. Partial go-live for flows that do not cross the boundary is a legitimate option; crossing flows wait for the signature.
Cited controls: Gateway Standard GW-5.1 · GW-6.2b · GW-2.1
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
The SMS code problem
Setup
A remote-access proposal (fictional) says users will authenticate with password plus SMS code. Separately, the outbound email gateway has no protective-marking enforcement, and a colleague asks 'why would email leaving the building need a marking anyway?'
Task
Review the proposal against the phishing-resistant factor requirement, then explain — in one paragraph a non-technical manager can read — what outbound email marking enforcement is for.
Judgement tested
Remote access requires a phishing-resistant factor; outbound email leaves the building marked (Gateway Standard).
Common errors
Accepting SMS as 'two-factor, good enough'; treating email marking as inbound-only.
Debrief
Why does phishing-resistant matter more for remote access than for the office network?
Feeds the governed tutorial
No
Controls: Gateway Standard: phishing-resistant factor; outbound email marking
Any boundary you own
Setup
A blank 'boundary I own' sheet: name a real boundary from your own work (a system, a connection, a service). Three columns: who is accountable, what is it allowed to do, how do we know.
Task
Complete the sheet for your boundary, then mark which of the three columns you could not answer today — that blank is the finding to take back to work.
Judgement tested
The durable accountability question applies to any boundary you operate (Gateway Standard).
Common errors
Leaving a column blank without flagging it; answering all three from memory without checking.
Debrief
Which column was hardest, and what does that say about your boundary's governance?
Feeds the governed tutorial
No
Controls: Gateway Standard (whole)
BY-GX2 — Hosting Certification
Printable governed response → · the course's capstone as a standalone worksheet
Three facilities, one answerable agency
Setup
Three data-centre shortlist entries (fictional): a certified Strategic facility, a certified Assured facility, and an uncertified facility offering 'great price and local presence'. The data is OFFICIAL:Sensitive government information.
Task
For each option, write who remains answerable for the data inside it, and name the one obligation that anchors that duty. Then mark which options survive the first cut and why.
Judgement tested
The agency choosing the data centre is accountable for the data inside it (HCF-A5).
Common errors
Treating certification as transferring accountability to the provider; picking on price alone.
Debrief
What does 'answerable' mean the agency must keep doing after the contract is signed?
Feeds the governed tutorial
Yes
Controls: HCF-A5
Write it into the approach
Setup
An approach-to-market is being drafted for a hosted solution. The team has left the certification requirement blank 'to keep the market broad'. The workload is OFFICIAL:Sensitive heading toward PROTECTED.
Task
Write the certification requirement clause for the approach document — the level, where it lands in the procurement timeline, and the sentence that tells the market what is not negotiable. Distinguish the three levels in one line each.
Judgement tested
The level of certification required is named at the point of going to market (HCF-A1); the date is history, not a deadline.
Common errors
Leaving the level to negotiation; defining levels vaguely; naming the level after responses arrive.
Debrief
Why does the requirement land when you go to market, not when you choose?
Feeds the governed tutorial
Yes
Controls: HCF-A1
The workload that grows
Setup
A case-management workload (fictional) sits at OFFICIAL:Sensitive today; the agency's own forward plan shows it will hold PROTECTED and whole-of-government data within two years. Procurement proposes an Uncertified facility 'for now, since it's only OFFICIAL today'.
Task
Assess the trajectory, not just today: which hosting levels are available for this workload, what 'sovereign' means for it, and what must be verified before assuming Uncertified is on the table.
Judgement tested
Uncertified hosting is not available for some workloads (HCF-A4); choose for where the data is heading (HCF-A3); assess before you assume.
Common errors
Buying for today's classification; assuming 'sovereign' means 'any Australian facility'; skipping the assessment.
Debrief
What changes about this decision if the forward plan slips by a year?
Feeds the governed tutorial
Yes
Controls: HCF-A4; HCF-A3
The sub-subcontractor
Setup
A Certified Strategic provider (fictional) delivers its assurance pack. Buried in it: the physical security screening and vetting for site staff is performed by a subcontractor, which in turn uses an overseas supplier for background checking. The pack says 'vetting performed in accordance with provider policy'.
Task
Trace the chain: what must be true of the individuals and of the suppliers' suppliers for Certified Strategic to hold? List the two evidence gaps in the pack and the question you send back.
Judgement tested
Certified Strategic reaches down to individuals and to the provider's own suppliers (CS-vet; CS-scr1).
Common errors
Accepting 'provider policy' as evidence; stopping the trace at the first subcontractor.
Debrief
Why does the standard reach past the provider's front door?
Feeds the governed tutorial
No
Controls: CS-vet; CS-scr1
The ownership change
Setup
News breaks that a certified hosting provider has been acquired by an overseas group (fictional). Your contract has a 'material change' clause; the provider has not contacted you. Your data is at rest in their facility.
Task
Identify the trigger in the continuous-disclosure obligation, draft the notice you send the provider (what must surface, by when), and write the two things your agency checks in parallel while the notice is pending.
Judgement tested
Certification is an ongoing state, not a pass-once event; circumstances changes must surface (CS-d).
Common errors
Waiting for the provider to volunteer; treating ownership change as 'commercial, not security'.
Debrief
What would you accept as a satisfactory response from the provider — and by when?
Feeds the governed tutorial
Yes
Controls: CS-d
Holding the gate
Setup
A competitive process stipulated Certified Assured. The preferred respondent's facility is in final certification assessment, determination expected in eight weeks; contract execution is scheduled next week ahead of a minister-referenced delivery date. The next-ranked respondent already meets the level.
Task
Rehearse the gate: execute now with an undertaking, delay until determination, proceed to the next-ranked respondent, or restructure the contract into preparatory and hosting components. Choose, and write the one-paragraph recommendation a delegate can sign.
Judgement tested
The bracket is set at the start and gated at the end (HCF-A2; HCF-A1); fail closed at the contract — hold the gate under pressure.
Common errors
Letting a public delivery date decide a certification question; accepting an undertaking where the standard says a level.
Debrief
What does the restructure option preserve that the others don't?
Feeds the governed tutorial
Yes
Controls: HCF-A2; HCF-A1
Input under review: The contract-execution decision for a hosted solution whose preferred facility is still in certification assessment.
Classification of the event: A procurement release gated on certification — the level was stipulated at market; an undertaking is not a level.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Approach-to-market verified: Certified Assured was stipulated; respondent's facility is in final assessment; next-ranked respondent already meets the level. | PASS |
| L2 · Context analysis | The bracket: condition set at the start, contract gated at the end. Execution next week is inside the bracket. | HOLD |
| L3 · Harm / loss | Executing below the stipulated level fails closed the wrong way — the certification question is not a scheduling detail. | PASS |
| L4 · Equity weighting | A public delivery date referenced by a minister does not change the standard — no pressure test outranks the gate. | PASS |
| L5 · Coherence check | HCF-A2/A1 set the bracket; the restructure option preserves both the schedule and the level. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: delay, next-ranked respondent, or restructure — never an undertaking in place of a level. | PASS |
| L7 · Audit generation | The gate decision and its delegate are recorded — append-only. | PASS |
| L8 · Output certification | Execution proceeds only when the level is met, or the contract is restructured so hosting is conditional. | VERIFY |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → VERIFY — the gate holds; the level is not negotiable by calendar.
The delegate holds the gate. A public delivery date does not outrank the stipulated certification level — fail closed at the contract.
Governed answer
Hold the gate: execute only when the stipulated level is determined, proceed with the next-ranked compliant respondent, or restructure the contract so execution covers preparatory and non-hosting work while the data-centre component is held back and conditional on certification. An undertaking — even a ninety-day one — is not the level that was stipulated at market. The delegate holds the gate, and no public delivery date outranks the standard.
Cited controls: HCF-A2 · HCF-A1 · HCF-A4
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
BY-G6 — Cyber Resilience & Critical Infrastructure
Printable governed response → · the course's capstone as a standalone worksheet
The authorisation file
Setup
A system holding information up to SECRET (fictional) is up for authorisation to operate. The file has the risk assessment and the system description — but the evidence linking the decision to the standard is thin, and two pages of the file are unsigned.
Task
Work through the authorisation decision: what must the decision be anchored to, what does the missing evidence mean, and whose sign-off completes the file? Draft the record of decision with the two conditions you would attach.
Judgement tested
Systems are authorised to operate up to SECRET under the PSPF Technology Lifecycle Management domain, anchored to a standard (PSPF Sec 13-15; Req 221 context).
Common errors
Signing off on the risk assessment alone; treating unsigned pages as admin detail.
Debrief
Why does anchoring the decision to a standard make it durable?
Feeds the governed tutorial
Yes
Controls: PSPF Req 221 (TLM); PSPF Sec 13-15
Share or not?
Setup
Your team completes a product risk assessment for a web service used across several entities. The wording of the sharing obligation says the entity 'must consider' sharing to the Centralised Risk Sharing Capability. A colleague reads it as 'must share'.
Task
Read the requirement wording exactly: what the obligation is, what it is not, and draft the recommendation your entity should minute — including the record of the consideration either way.
Judgement tested
The policy obligation is to consider sharing risk assessments to the Centralised Risk Sharing Capability — read the wording accurately (PSPF Sec 13-15).
Common errors
Over-reading into 'must share'; or under-reading into 'optional, no record'.
Debrief
What does a recorded 'we considered it and did not share' look like?
Feeds the governed tutorial
No
Controls: PSPF Sec 13-15 (TECH)
The renewal you can't defer
Setup
A cryptography module reaches end of support. The replacement on the catalogue supports post-quantum algorithms; the cheaper option does not and 'can be upgraded later'. The procurement cycle is the only one this year. A colleague argues 'post-quantum is a 2030 problem'.
Task
Work the renewal: what does the planning obligation require of the transition plan, and what does the procurement obligation require of this purchase? Write the two-line decision note for the delegate.
Judgement tested
Plan the post-quantum transition; procure equipment that supports post-quantum algorithms — the transition happens through ordinary purchasing (PSPF Sec 13-15; ISM cryptography).
Common errors
Deferring on '2030 problem'; separating planning from purchasing.
Debrief
Why does the transition run through routine purchasing rather than a special program?
Feeds the governed tutorial
Yes
Controls: PSPF Sec 13-15 (TECH); ISM cryptography
The unrecorded replica
Setup
During a routine review you find: a disaster-recovery replica of a SECRET-classified system sits on a hosting service added during a migration, never recorded against the original hosting decision, certification status unverified; and an identity-aware access capability at the gateway has no assessment on file.
Task
Triage the two findings — same severity or different? What must be verified, what must be escalated, and what do you say to the delivery team that added the replica 'as a temporary measure'? Draft the governance notice.
Judgement tested
Certified hosting applies to classified and government-significant information; gateway capabilities including Secure Service Edge require assessment (PSPF Sec 13-15).
Common errors
Treating the replica as temporary; escalating only one finding; re-deriving registers instead of acting.
Debrief
Why does an unrecorded replica defeat the hosting decision entirely?
Feeds the governed tutorial
Yes
Controls: PSPF Sec 13-15 (TECH); Hosting Certification
Input under review: Two findings: a disaster-recovery replica of a SECRET-classified system on unrecorded hosting, and an identity-aware gateway capability with no assessment on file.
Classification of the event: A systemic discovery requiring triage and a governed release to security governance — one limb urgent, one parallel, neither buried in re-derivation.
| Layer | Check on this case | Verdict |
|---|---|---|
| L1 · Input validation | Both findings verified against the hosting decision record and the gateway register — they are absent from both. | PASS |
| L2 · Context analysis | The replica is classified data at rest on unverified hosting — the urgent limb; the gateway capability needs assessment in parallel. | HOLD |
| L3 · Harm / loss | SECRET data at rest where certification was never checked is the highest loss; the gateway is a boundary with no evidence. | PASS |
| L4 · Equity weighting | The delivery team acted in good faith during migration — the record gap is the finding, not the people. | PASS |
| L5 · Coherence check | Hosting certification and gateway assessment obligations apply; evidence requests are the next move, not re-deriving registers. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: escalate the replica now, assess the gateway in parallel, correct the registers after. | PASS |
| L7 · Audit generation | Findings logged with timestamps and owners — append-only; the corrected registers follow. | PASS |
| L8 · Output certification | The governance notice is certified before release to the accountable forum. | PASS |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE
HOLD → CERTIFIED RELEASE — differentiate, escalate, and let governance decide what happens next.
Security governance owns the acceptance of residual risk. The delivery team does not self-certify and does not re-derive the estate before acting.
Governed answer
Raise both findings to security governance now, with the facts as they stand: escalate the unrecorded replica immediately because classified information is at rest on hosting whose certification was never verified, and commission the gateway assessment in parallel. Request certification and assessment evidence from both providers rather than spending weeks re-deriving registers — evidence first, registers corrected after. The delivery team acted in good faith; the record gap is the finding, and governance owns the acceptance.
Cited controls: PSPF Sec 13–15 (TECH) · Hosting Certification · Gateway assessment
Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course applies as stated on its course page. Nothing here is legal advice.
No quiet corners
Setup
A data-flow inventory (fictional) lists: web traffic to a public portal (TLS only, legacy cipher allowed); database backups at rest on disk (unencrypted); a file transfer to a partner (signed but not encrypted); and an internal API (high assurance).
Task
Sweep the inventory against the widened June 2026 high-assurance requirements for all data in transit and at rest; mark each flow compliant / gap / unclear, and write the fix note for the two gaps.
Judgement tested
High-assurance protocol and algorithm requirements now cover all data-in-transit and all data-at-rest scenarios — no quiet corners (PSPF Sec 13-15; ISM cryptography, June 2026).
Common errors
Treating backups as 'internal, not in transit'; accepting legacy ciphers on public-facing flows.
Debrief
Which 'quiet corner' is easiest to miss in your own estate?
Feeds the governed tutorial
No
Controls: ISM cryptography (June 2026 widening)
The indicator
Setup
Threat intelligence (fictional) flags a technique matching activity seen on your network three weeks ago; the log review then confirms a compromise of a non-critical system holding OFFICIAL data. The entity is not in the critical infrastructure regime, but the briefing notes 'similar entities are listed'.
Task
Run the motion: detection from intelligence, confirmation, then the report — to whom, in what time, with what content. Draft the report line and note what changes (and what doesn't) if the entity were a critical infrastructure asset.
Judgement tested
Threat intelligence supports detection; confirmed incidents are reported to ASD; the critical-infrastructure regime is a separate context (PSPF Sec 13-15; SOCI context).
Common errors
Reporting before confirmation or waiting for 'full facts'; conflating the two regimes.
Debrief
What does 'seeing early, reporting fast' cost when done properly — and what does it save?
Feeds the governed tutorial
No
Controls: PSPF Sec 13-15 (TECH); ISM reporting
How to use this lab: work each scenario before the governed tutorial — the module scenarios deliberately pre-train the exact judgement the tutorial then formalises. Practice is formative and never evidence; the completion record stays "a training record, not assurance evidence". Every scenario's AI governance angle is practice too: the AI suggests, the human decides, and the governed response shows the release authority. All agencies, people and documents are fictional.