Illustrative report

Follow the evidence all the way to the finding.

This fictional sample shows how scope, procedures, evidence, judgment, limitations, references, and sign-off fit together. It is not a completed client assessment.

ILLUSTRATIVE THROUGHOUT · FICTIONAL ORGANIZATION · NOT FOR RELIANCE
AYLIEA / SAMPLE-001 / ILLUSTRATIVE

AI Security
Assessment

Prepared for: Fictional Healthcare Vendor, Inc.

Illustrative example · Not a completed assessment · Not for reliance
01

ILLUSTRATIVE SAMPLE

Scope, procedures, and intended use

Assessment ID
SAMPLE-001
Illustrative date
15 June 2026
System in scope
Fictional clinical-note summarization workflow
Intended readers
Fictional vendor security team and receiving healthcare reviewer
Procedures shown
Document review and stakeholder interview
Not performed
Penetration test, source-code review, or direct provider-configuration validation

This example is designed to demonstrate report structure only. It does not describe an Ayliea customer, actual evidence, or an operating system.

02

ILLUSTRATIVE SAMPLE

System record and sensitive-data flow

USE CASE

Draft a visit-summary note for clinician review.

DATA CATEGORY

Illustrative clinical text that could contain ePHI.

PROVIDER

Fictional third-party language-model service.

HUMAN OVERSIGHT

Clinician review represented as required before use.

  1. 1

    Authorized user submits in-scope text through the fictional application.

  2. 2

    The application sends a prompt through its AI gateway to the fictional model provider.

  3. 3

    The provider returns a draft summary for human review.

  4. 4

    The application stores the approved output according to its represented retention process.

03

ILLUSTRATIVE SAMPLE

Evidence register excerpt

Illustrative evidence reviewed for SAMPLE-F-01
IDArtifactSource / dateReview methodStatus
E-01AI system inventoryClient supplied / 10 Jun 2026Document reviewSupplied
E-02AI data-flow diagramClient supplied / 11 Jun 2026Document reviewSupplied
E-03Provider-retention statementProduct owner / 12 Jun 2026InterviewRepresented
E-04Current provider configurationNot providedNoneNot tested
SAMPLE-F-01 · DATA PROTECTION

Third-party retention setting was not supported by current configuration evidence.

MODERATE
Observed condition
The supplied data-flow record described a zero-retention provider configuration, but no current provider setting, export, or contractual term was available for review.
Evidence basis
E-01 through E-03 were reviewed. E-04 was unavailable. The zero-retention condition is therefore represented, not independently established.
Risk
Without current evidence, the organization may be unable to demonstrate whether sensitive healthcare information is retained by the fictional provider as intended.
Severity rationale
Impact: High because the illustrative workflow may handle ePHI. Likelihood: Possible because the setting was not evidenced. Evidence confidence: Limited. These factors support a Moderate illustrative finding rather than a conclusion that retention occurred.
Recommendation
Obtain current configuration or contractual evidence, record permitted data categories and retention behavior, and re-evaluate the finding after evidence review.
Owner / status
Fictional product-security owner · Open for evidence
05

ILLUSTRATIVE SAMPLE

Framework references

HIPAA SECURITY RULE

Risk analysis and business-associate arrangements

Potentially relevant safeguards may be cited when applicable. Mapping is not certification or a legal conclusion.

NIST AI RMF 1.0

MAP and MANAGE functions

Risk context and treatment concepts may support the assessment narrative. NIST does not endorse Ayliea or any assessor.

ISO/IEC 42001:2023

AI management system concepts

Illustrative findings may be assessed against ISO/IEC 42001 concepts. Mapping is not certification; Ayliea is not a certification body.

06

ILLUSTRATIVE SAMPLE

Limitations and sign-off

  • No production data or patient records were reviewed.
  • No penetration testing, source-code review, or provider-console validation was performed.
  • The fictional workflow and evidence are fabricated solely to show report structure.
  • A real assessment is point-in-time and limited to its written scope and evidence cutoff.
  • The receiving organization determines whether a completed report is sufficient for its purpose.
ILLUSTRATIVE SIGN-OFF SHOWN · NOT A COMPLETED ASSESSMENTDaviyon Daniels, CISSP

In an actual report, the assessor would sign the documented scope, evidence basis, findings, limitations, and conclusion.

How to read the sample

Evidence is separated from interpretation.

O

Observed

The assessor directly inspected an in-scope artifact, setting, workflow, or demonstration.

S

Supplied

The client or a provider supplied documentation that the assessor reviewed within the agreed scope.

R

Represented

A stakeholder described a practice or condition that was not independently established by other evidence.

N

Not tested

The item was in scope for discussion, but technical validation or another procedure was not performed.

Next step

Want to scope the assessment behind your report?

Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.

  • Clarify the review request
  • Identify systems and evidence
  • Define a defensible scope