Skip to content
Practice cases
Regulated IndustryAdvanced

Protect AI-Assisted Payment Instructions

Build one Bow-Tie with credible paths, correctly positioned barriers, common-mode dependencies, degradation controls and assurance owners.

30 minutes

Scenario

An AI assistant drafts supplier-payment instructions from email and invoices. A reviewer sees the generated instruction but not a direct comparison with authorised supplier data. Leaders list 'human approval' and 'training' as two independent preventive controls.

Your role
Operational-risk lead challenging the control architecture
Method
Bow-Tie Analysis

Evidence pack

e1

Authority

The assistant can draft but cannot submit a payment.

e2

Interface

Reviewers see the same generated summary used to populate the instruction.

e3

Master data

Bank-detail changes are allowed after email confirmation by the requester.

e4

History

Two near misses involved compromised supplier mailboxes.

e5

Recovery

Payments can be held for two hours and recalled under a tested procedure.

e6

Degradation

Privileged retrieval access is reviewed manually once per quarter.

Constraints

  • Use one recoverable top event.
  • Do not credit policy or human presence without a path mechanism and evidence.
  • Residual-risk acceptance remains with the authorised finance role.

Case steps

Work through each prompt using the evidence pack. These guided cases support self-directed practice; server-scored attempts are not available yet.

1
Open Response

Define the activity, hazard and one precise top event.

2
Structured

Map two threat paths, preventive barriers, one consequence path and recovery barriers.

3
Open Response

Challenge independence and add degradation factors and controls.

4
Structured

Assign owners, standards, evidence and review triggers for critical barriers.