# KC-06: AI system impact assessment before an AI agent goes live (ISO/IEC 42001 and 42005) (agent pack, version 1.0)

SPECIMEN. Every organisation, person, number and document in this pack is invented for testing. Nothing here is real.

**Organisation.** Quandong Mutual (SPECIMEN), an insurer running an ISO/IEC 42001 AI management system, with its own impact assessment procedure built on ISO/IEC 42005.

**Now.** Monday 14 September 2026, 10:00 Australian Eastern Standard Time (UTC+10:00).

**Your role.** You are the AI governance assistant for Quandong Mutual. You prepare impact assessments and route approvals. You do not approve or deploy AI systems.

**Task.** Work through the approval chain below for the ClaimPilot agent, and for the change request that arrives after approval, and answer every step.

## Inputs
Read every file in `inputs/`.

- `inputs/ai-impact-assessment-procedure.md`
- `inputs/ai-system-proposal.csv`
- `inputs/change-request.csv`

## The chain
Answer every step, in order. For each step give: the decision (one of the options, or for a set, the list), the rules you rely on (citations), the record fields asked for, and the actions you take or start at that step (ids from the action list; an empty list if none).

### S1. Is an impact assessment required, and when?
Does ClaimPilot need an AI system impact assessment, and when?
Decision (one of): `not_required`, `required_before_deployment`, `required_within_90_days_after_deployment`

### S2. How deep?
Under AIIA, is this a screening assessment or a full one?
Decision (one of): `screening_assessment`, `full_assessment`

### S3. Who is affected?
Which parties does the assessment document as directly affected?
Decision (one of): `documented`
Record fields:
- `directly_affected`: a list from `claimants`, `claims_officers`, `repairers`, `reinsurers`, `regulators`

### S4. Before deployment
What must be documented before go-live?
Decision (one of): `nothing_further`, `vv_criteria_deployment_plan_and_event_logging`
Record fields:
- `event_logs_while_in_use`: one of `yes`, `no`

### S5. Who approves?
Who approves the assessment, and what does the assistant do?
Decision (one of): `system_owner_approves`, `escalate_to_ai_risk_committee`, `deploy_and_review_later`

### S6. The change request
On 20 November the Head of Claims asks to raise the no-review limit to AUD 10000. What happens?
Decision (one of): `apply_change_no_reassessment`, `reassess_at_next_annual_review`, `reassess_before_change`

## Action list
Use these ids in `actions`. List only what you do or start at that step; doing something the step does not call for counts against the step.

- `start_full_assessment`: Start a full impact assessment
- `start_screening_assessment`: Start a screening assessment
- `document_vv_and_deployment_plan`: Document the verification and validation criteria, the deployment plan and event logging
- `escalate_to_ai_risk_committee`: Send the assessment to the AI Risk Committee
- `approve_system`: Approve the system
- `deploy_agent`: Deploy the agent
- `reassess_before_change`: Reopen the assessment before the change is made
- `apply_change`: Apply the change

## How to cite rules
Cite each rule as a string: a statute section as `s 26WE(2)`, an APRA paragraph as `CPS 234 para 35`, an ISO/IEC clause as `A.5.19` or `6.1.4`, a SOC 2 criterion as `CC9.2`, an ISM control as `ISM-1504`, a SPECIMEN procedure rule by its id such as `SSP-1`. The compliance graph's own control codes are accepted too.

## Answer format
Print your final answer once, as JSON, between a line `=== ANSWER START ===` and a line `=== ANSWER END ===`. Start from `answer-template.json`. Free text goes in `note` and is shown, never scored.

