Chapter 3 Lab is the operational reality check. You will classify your own AI use cases into the AI Law's risk tiers, write the Do-Not-Paste briefing you'll give your team, build your CAPA incident-response checklist, and name the governance roles for your department. Everything you write here goes into your Phase 2 Capstone folder.
4 quizzes โ Golden Rules, Do-Not-Paste, AI Law tiers, incident response 72-hr.
Tier your AI use cases (Prohibited/High/Medium/Low) and build mitigations.
Write 5-line team briefing, CAPA checklist, governance role map.
The QA Manager uses ChatGPT to draft a customer reply explaining why a delivery is delayed. Which of the 5 Golden Rules is most directly at stake when she clicks Send?
An MPV Supply Chain analyst wants to paste a full supplier contract (Eastern Resin Co., 50-page agreement with prices and payment terms) into free Claude to summarise the renewal terms. What is the right call?
MPV deploys Computer Vision on Line 3 that automatically rejects syringes flagged as defective โ no human review of the AI's reject decisions. Under Vietnam's AI Law (No. 134/2025/QH15, in force since 1 March 2026), what's the risk tier and what changes if you add a human override?
An MPV employee accidentally pastes a customer list (200 hospital purchasing officers with names + emails + order quantities) into free ChatGPT to "ask for a quick summary". She realises 30 minutes later. What's the right sequence?
Take the 5โ6 AI use cases you generated in Chapter 2 Lab (HBR Ideation Sheet). For each, classify it into the AI Law's risk tier and name a mitigation. This becomes your department's AI risk register โ keep it for the 2027 healthcare-grace audit.
| Tier | Typical examples | What it requires |
|---|---|---|
| Prohibited | Social-credit ยท subliminal ยท biometric mass surveillance | Cannot deploy |
| High-Risk | Clinical decisions ยท production decisions without human override ยท recruiting decisions | Registration ยท conformity assessment ยท human oversight ยท transparency ยท post-market monitoring ยท incident reporting |
| Medium-Risk | Customer chatbots ยท CV inspection with human override ยท deepfake-capable | Transparency labelling ยท accountability docs ยท sample audits |
| Low-Risk | Email classification ยท CAPA drafting (human reviews) ยท forecast support ยท summarisation | General accountability ยท monitor incidents/complaints |
Your AI risk register (one row per use case):
You will brief your team on the Do-Not-Paste list in your next stand-up. You have 5 lines. Write the actual briefing โ in Vietnamese or English, whichever your team uses.
Your team's 5-line briefing (adapt the language to your audience):
The 3-step incident response (Contain ยท Assess ยท CAPA) is the framework. Now adapt it to your department: who do you call, who decides, who logs, what gets escalated when. This is the checklist you keep on the wall.
Chapter 3.6 listed five roles. For your department, fill in the actual people (or "to be appointed" if the role doesn't exist yet).
| Role | Person (or "TBA") |
|---|---|
| AI Governance Lead (cross-MPV) | |
| Data Protection Officer (DPO) | |
| QMS Owner (your dept liaison) | |
| Department AI Champion (you?) | |
| Vendor / IT contact |
One concrete action to fill any "TBA" within 2 weeks:
The single Responsible-AI behaviour I want to change this month:
The single thing I want my team to start doing:
Feedback for the Quanskill team on Chapter 3:
Click below to compile your risk-classified use case register, team briefing, incident-response checklist, governance role map, and feedback into one document. Save it โ this is the governance pack you'll bring to Phase 2.
You now have a working governance pack: risk-classified use cases, a team briefing ready for Monday, an incident-response checklist, and named roles. Chapter 4 is the Phase 1 Capstone โ your Opportunity Map for Phase 2.
๐ Chapter 4 Theory โ