← Consultant Academy
PRACTICE CASE LIBRARY

Learn the judgement before the client meeting

Use these cases as workshop exercises. The aim is not to guess a single answer quickly; it is to identify facts, evidence, legal pathways, assumptions and escalation questions in a repeatable way.

Foundation → Practitioner

Case 1 · HireRightly

A UK SaaS company sells an AI CV-ranking tool to employers in France and Germany. The product uses a third-party US model but is sold under HireRightly's brand. Customers decide who progresses to interview.

Your tasks
  • □Map likely provider/deployer roles.
  • □Identify the intended purpose and likely high-risk pathway.
  • □List the minimum vendor/model evidence you would request.
  • □Explain what remains the employer customer's responsibility.
Practitioner

Case 2 · CareFlow Hospital

A hospital uses third-party AI for staff recruitment, patient appointment prioritisation and a public chatbot. The three tools come from different vendors and have different functions.

Your tasks
  • □Do not classify the hospital once: map each system separately.
  • □Run high-risk and Article 50 analyses by use case.
  • □Identify privacy and fundamental-rights questions needing specialist input.
  • □Create an evidence-request list for human oversight and monitoring.
Practitioner → Implementer

Case 3 · LendWise

A lender uses an AI model to support consumer credit decisions. The vendor says the model is ‘fair and explainable’, but provides only aggregate accuracy figures. Staff accept 99% of recommendations.

Your tasks
  • □Identify the classification and evidence questions.
  • □Challenge the vendor's fairness evidence.
  • □Assess whether human oversight looks meaningful.
  • □Draft three remediation actions with owners and evidence of completion.
Implementer

Case 4 · BuildCo Copilot

A 600-person engineering consultancy has approved one enterprise AI assistant, but staff also use public chatbots, browser extensions and low-cost AI subscriptions. Commercially sensitive client documents may be included in prompts.

Your tasks
  • □Design a Shadow AI discovery plan.
  • □Separate AI Act classification from broader confidentiality, privacy and security risk.
  • □Create an acceptable-use and notification control.
  • □Define what evidence would show the control operates after launch.
Implementer → Client Ready

Case 5 · CivicBenefits

A public-sector organisation plans to use AI to prioritise applications for a social-benefit programme. The system may affect vulnerable people and uses personal information from several government data sources.

Your tasks
  • □Map affected people and decision influence.
  • □Triage high-risk, FRIA and privacy/DPIA considerations without merging them into one undefined assessment.
  • □Design human oversight and complaint/escalation evidence.
  • □Prepare an executive summary of the unresolved decisions.
Implementer → Lead

Case 6 · NovaAssist Product Change

A vendor's approved customer-service SaaS quietly adds automated emotion analysis, lead scoring and a new GPAI model. The client discovers the changes during annual renewal rather than through change notification.

Your tasks
  • □Identify feature-drift and supplier-governance failures.
  • □Re-run intended-purpose, role, classification and transparency analysis for each new feature.
  • □Define contractual/change-notification controls.
  • □Write an assurance finding and corrective-action plan.
Review standard

A strong response separates facts from assumptions, maps roles system-by-system, follows the correct classification pathway, requests evidence before closing a control and identifies specialist questions rather than bluffing through them.