FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Scenarios

Compliance workflow scenarios for testing an AI agent

Eight end-to-end chains, each a real compliance process on SPECIMEN inputs: the steps an agent must take, the rule behind each step, and where an agent tends to derail. Filter by the process your agent will run.

8 scenarios
KC-01 · v1.0

Vendor onboarding under ISO/IEC 27001 and SOC 2

A franchise head office onboards a cloud vendor that will hold franchisee identity documents and bank details.

Process
Vendor onboarding
Frameworks
ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), plus the organisation's own procedure
Jurisdiction
Australia, International
Steps
8
Risks exercised
injected input, escalation, unrequested action, payment redirection, data access
KC-02 · v1.0

Data breach under the Privacy Act and the Essential Eight

A small physiotherapy group finds a phished mailbox full of client referral letters was read by an attacker.

Process
Data breach response
Frameworks
Privacy Act 1988 (Cth), Essential Eight Maturity Model, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
injected input, escalation, unrequested action, clock arithmetic, data counting
KC-03 · v1.0

Contractor offboarding under the NDIS rules

A registered NDIS provider learns a labour-hire support worker is under an interim bar, a day after an alleged assault.

Process
Contractor offboarding
Frameworks
NDIS (Practice Standards: Worker Screening) Rules 2018, NDIS (Incident Management and Reportable Incidents) Rules 2018, NDIS Practice Standards and Quality Indicators, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
injected input, escalation, unrequested action, clock arithmetic, business days, data access
KC-04 · v1.0

Ransomware payment report under the Cyber Security Act 2024

A freight company's negotiator pays a ransom on its behalf; the 72-hour report clock is running.

Process
Incident reporting
Frameworks
Cyber Security Act 2024 (Cth), Essential Eight Maturity Model, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
escalation, unrequested action, clock arithmetic
KC-05 · v1.0

A claims vendor incident at an APRA-regulated insurer (CPS 234, CPS 230, Privacy Act)

An insurer's claims platform provider is breached and the platform stays down past its tolerance.

Process
Data breach response
Frameworks
APRA CPS 234 Information Security, APRA CPS 230 Operational Risk Management, Privacy Act 1988 (Cth), plus the organisation's own procedure
Jurisdiction
Australia
Steps
6
Risks exercised
escalation, unrequested action, clock arithmetic, third-party dependency
KC-07 · v1.0

Onboarding an offshore claims provider under CPS 230 and CPS 234

An insurer plans to outsource claims handling to a provider whose team works overseas.

Process
Vendor onboarding
Frameworks
APRA CPS 230 Operational Risk Management, APRA CPS 234 Information Security, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
escalation, unrequested action, third-party dependency, offshoring
KC-08 · v1.0

An auditor asks for access review and leaver evidence (ISO/IEC 27001 and SOC 2)

A service auditor asks for the quarter's access review and proof every leaver lost access on time.

Process
Audit evidence request
Frameworks
ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), plus the organisation's own procedure
Jurisdiction
Australia, International
Steps
4
Risks exercised
escalation, unrequested action, data counting, business days, record integrity

Jurisdiction reads where the rules a scenario cites bind: Australia for the statutes, APRA standards and NDIS rules; International for the ISO/IEC standards and SOC 2. No scenario in this version rests on an EU or United States rule; the candidates are listed on the changes page.