Foundation → Practitioner
Case 1 · HireRightly
A UK SaaS company sells an AI CV-ranking tool to employers in France and Germany. The product uses a third-party US model but is sold under HireRightly's brand. Customers decide who progresses to interview.
Your tasks
- □Map likely provider/deployer roles.
- □Identify the intended purpose and likely high-risk pathway.
- □List the minimum vendor/model evidence you would request.
- □Explain what remains the employer customer's responsibility.
Practitioner
Case 2 · CareFlow Hospital
A hospital uses third-party AI for staff recruitment, patient appointment prioritisation and a public chatbot. The three tools come from different vendors and have different functions.
Your tasks
- □Do not classify the hospital once: map each system separately.
- □Run high-risk and Article 50 analyses by use case.
- □Identify privacy and fundamental-rights questions needing specialist input.
- □Create an evidence-request list for human oversight and monitoring.
Practitioner → Implementer
Case 3 · LendWise
A lender uses an AI model to support consumer credit decisions. The vendor says the model is ‘fair and explainable’, but provides only aggregate accuracy figures. Staff accept 99% of recommendations.
Your tasks
- □Identify the classification and evidence questions.
- □Challenge the vendor's fairness evidence.
- □Assess whether human oversight looks meaningful.
- □Draft three remediation actions with owners and evidence of completion.
Implementer
Case 4 · BuildCo Copilot
A 600-person engineering consultancy has approved one enterprise AI assistant, but staff also use public chatbots, browser extensions and low-cost AI subscriptions. Commercially sensitive client documents may be included in prompts.
Your tasks
- □Design a Shadow AI discovery plan.
- □Separate AI Act classification from broader confidentiality, privacy and security risk.
- □Create an acceptable-use and notification control.
- □Define what evidence would show the control operates after launch.
Implementer → Client Ready
Case 5 · CivicBenefits
A public-sector organisation plans to use AI to prioritise applications for a social-benefit programme. The system may affect vulnerable people and uses personal information from several government data sources.
Your tasks
- □Map affected people and decision influence.
- □Triage high-risk, FRIA and privacy/DPIA considerations without merging them into one undefined assessment.
- □Design human oversight and complaint/escalation evidence.
- □Prepare an executive summary of the unresolved decisions.
Implementer → Lead
Case 6 · NovaAssist Product Change
A vendor's approved customer-service SaaS quietly adds automated emotion analysis, lead scoring and a new GPAI model. The client discovers the changes during annual renewal rather than through change notification.
Your tasks
- □Identify feature-drift and supplier-governance failures.
- □Re-run intended-purpose, role, classification and transparency analysis for each new feature.
- □Define contractual/change-notification controls.
- □Write an assurance finding and corrective-action plan.