Illustrative AI Agent Compliance Readiness Record
Internal Invoice-Triage Assistant
A review-ready compliance-readiness record for one illustrative example agent. The eighteen sections below are the evidence a compliance review needs — what the agent can reach, what evidence exists, what was tested, who owns it, and how you would know if the record stopped being current.
This is an illustrative example of the compliance-readiness record AgentProof helps you build.
- 1
Executive summary
What this shows: A plain-language overview of the agent, its purpose, its current readiness status, and the headline gaps and review flags a stakeholder should know before it is relied on, written so a non-technical reader grasps the decision in a minute.
The Internal Invoice-Triage Assistant is in good early shape and is running as a restricted pilot. It reads invoice data and drafts routing notes, but a person still approves every action before anything is sent or paid. The headline gaps a stakeholder should know: a data-access boundary that is not yet written down, and monitoring evidence that is still being collected. The readiness score below is a starting signal, not a verdict on whether the agent is safe to expand.
- 2
Agent identity, ownership, and estate context
What this shows: What the agent is, who owns it, who built or supplies it, its lifecycle stage, its source, discovered, manual, imported, or linked, and where it fits among the organisation's other AI agents, so provenance is never in doubt and the record is not read in isolation.
- Agent
- Internal Invoice-Triage Assistant
- Owner
- Finance Operations lead (named internal owner)
- Built / supplied by
- Built in-house on Microsoft Copilot Studio (Power Platform)
- Lifecycle stage
- Piloted (approved for pilot with restrictions)
- Source
- Discovered via the Microsoft connector
- Estate context
- One of several finance-team agents in this workspace; sits alongside a manually added HR leave-request assistant.
- 3
Purpose and intended use
What this shows: What the agent is meant to do, the users it serves, the people it affects, and the boundaries of its intended role, so scope is stated rather than assumed.
Reads incoming supplier invoices, extracts the key fields, matches them to open purchase orders, and drafts a routing note for a human approver.
Intended users are the finance operations team. People affected are suppliers and internal approvers. The agent is scoped to triage and drafting only; sending payment instructions is explicitly out of its intended role.
- 4
Capabilities, data, and actions
What this shows: The data the agent can reach, where that data goes, and the tools and actions it can take on its own, the concrete answer to what an agent can actually do that a compliance review most needs written down.
- Data it can reach
- Incoming invoice documents and the open purchase-order list, within the finance environment.
- Where data goes
- Stays inside the connected finance environment; no data leaves for a third-party model.
- Actions it can take on its own
- Extract fields and draft a routing note. It cannot send, approve, or pay on its own.
- Human step
- A named approver reviews and confirms every routing note before anything happens.
- 5
Quick triage outcome
What this shows: The risk-relevant signals detected and the assessment depth set, light, standard, enhanced, or strict, with the reasoning behind the tier and any escalation.
Assessment depth set to standard. The agent reads sensitive finance data but takes no consequential action on its own, so it did not escalate to enhanced or strict.
Signals detected: reads internal financial records; drafts content a person then acts on; no autonomous send or payment capability.
- 6
Readiness score and status
What this shows: The deterministic readiness score and status showing how documented and defensible the agent is on the captured evidence and controls, presented as one clearly labelled section with its basis shown, a starting signal, not a verdict.
Readiness score
64Needs review
A deterministic readiness score of 64 / 100 with status Needs review, showing how documented and defensible the agent is on the captured evidence and controls.
This is one clearly labelled section of the record, with its basis shown — a starting signal, not a verdict on safety, and never the whole story.
- 7
Governance and regulatory lens coverage
What this shows: For each selected lens across EU, UK, US, NIST, ISO 42001, and OWASP, the documentation and evidence coverage: what may apply, what evidence supports review, and what is missing. Coverage, never a scored verdict.
For each selected lens, the pack shows documentation and evidence coverage — what may apply, what evidence supports review, and what is missing. Coverage, never a scored verdict.
- EU AI Act lens — Partial coverage — transparency notes drafted; data-flow evidence outstanding.
- NIST AI RMF lens — Partial coverage — govern and map notes recorded; measure evidence outstanding.
- ISO/IEC 42001 lens — Started — management-system context captured; control evidence outstanding.
- OWASP for agents lens — Partial coverage — prompt-injection test recorded; tool-boundary test outstanding.
- 8
Evidence register and coverage summary
What this shows: The structured index of attached artefacts, permissions, prompts, configuration, data-flow notes, sign-offs, and screenshots, each with its status, missing, requested, received, accepted, stale, or rejected, plus how much of the record is actually backed by accepted evidence versus asserted, the honest measure of how defensible the documentation really is.
The structured index of attached artefacts, each tracked through its lifecycle. Received is not the same as accepted.
- Permissions and scopes export — Accepted
- System prompt and configuration — Accepted
- Data-flow note (allowed data) — Requested
- Approver sign-off screenshot — Received
- 30-day action-log archive — Missing
Coverage summary: roughly two thirds of the record is backed by accepted evidence; the rest is asserted or outstanding — the honest measure of how defensible the documentation is today.
- 9
Control checklist
What this shows: The controls the agent should have, mapped to the lenses and evidence they support, each shown as not started, in progress, implemented, needs evidence, or not applicable.
- Human approval before any consequential action — Implemented
- Written data-access boundary — Needs evidence
- Action logging and retention — In progress
- Named owner assigned — Implemented
- Prompt-injection guardrail — In progress
- 10
Test pack results
What this shows: What was tested and what was found, hallucination, injection, jailbreak, leakage, tool-boundary and unapproved-action checks, and bias, documenting behaviour rather than assuming it.
- Hallucination check (field extraction) — Passed — sampled 50 invoices, notes reviewed.
- Prompt-injection check — Passed — malicious invoice text did not change routing.
- Data-leakage check — In progress — draft outputs being reviewed for over-disclosure.
- Tool-boundary check — Outstanding — confirm the agent cannot reach payment tools.
- Bias check — Not applicable — no person-level decisioning in scope.
- 11
Vendor and model review
What this shows: The model, provider, terms, data handling, version, and dependencies behind the agent, with what is known and what remains to be verified, so the dependency is evidence rather than a brand name.
- Platform
- Microsoft Copilot Studio on Power Platform (the connector, not an endorsement).
- Model
- The platform-provided model used by Copilot Studio for this agent.
- Data handling
- Stays within the connected finance environment; documented in the data-flow note (requested).
- Version / dependencies
- Pinned platform version recorded; a model-version note remains to be verified.
- 12
Missing information and gaps
What this shows: A consolidated, visible list of unknowns, open questions, and evidence gaps, kept visible instead of averaged into a score, because a documented gap is worth more than a false sense of completeness.
- Written data-access boundary — No signed list of which record types the agent may read.
- Action-log archive — No 30-day archive of what the agent read or drafted.
- Tool-boundary test — Not yet confirmed the agent cannot reach payment tools.
- Model-version note — The exact model version behind the agent is not yet verified.
- 13
Legal and specialist review flags
What this shows: Where legal, privacy, security, or procurement review is recommended, and why, flags pointing the right specialists at the right questions, not conclusions AgentProof makes for them.
Privacy review is recommended before widening the data the agent can read, because invoices can carry personal data. A procurement note is flagged to confirm the platform terms cover this use.
These are flags pointing the right specialists at the right questions — not conclusions AgentProof makes for them.
- 14
Approval and decision record
What this shows: The recorded decision and its exact scope, draft, blocked, approved for pilot, approved with restrictions, approved for production, or retired, with who decided, on what basis, and any conditions attached.
- Decision
- Approved for pilot with restrictions.
- Scope
- Triage and drafting only; no send, approve, or pay.
- Who decided
- Finance Operations lead, with the workspace owner recorded as reviewer.
- Conditions
- Human approval on every routing note; reassess before expanding scope.
- 15
Monitoring and incident log
What this shows: How the agent is watched in real use and any incidents recorded when behaviour drifted, so the record reflects the live agent and not only its state at approval.
Monitoring note: approvers spot-check a sample of routing notes each week; action logging is being turned on to make this durable.
Incident log: no incidents recorded to date. One near-miss noted — a malformed invoice produced a low-confidence draft, which the approver caught and rejected as designed.
- 16
Radar reassessment notes
What this shows: Any tracked governance, regulatory, model, or failure-mode developments flagged as potentially relevant to this agent, with a clear reassessment recommendation where one applies, so the record shows it was kept current.
Radar flagged one tracked development as potentially relevant: an update to a governance expectation for agents that read financial records. It is mapped to this agent as reassessment recommended.
Nothing was applied automatically and this frozen pack was not rewritten — the recommendation simply shows the record was kept current.
- 17
Trust boundary and scope of this record
What this shows: A clear statement of what this record is and is not: compliance-readiness and documentation, not legal advice, certification, audit assurance, or regulatory approval, and not a determination that the agent or organisation is compliant, safe, or ready for production, with further review still possibly required.
This record is compliance-readiness and documentation. It is not legal advice, certification, audit assurance, or regulatory approval, and it does not guarantee that the agent is safe or ready for production. Further review may still be required, and the judgement about whether to trust the agent with real work stays with your team.
- 18
Version and source references
What this shows: The version of this frozen record, when it was produced, the assessment date, and the tracked sources and profile versions behind the lenses, so the record is versioned, reproducible, and traceable to its sources rather than a floating claim.
- Pack version
- Sample pack v1 (illustrative)
- Produced
- 1 June 2026 (illustrative date)
- Assessment date
- 1 June 2026 (illustrative date)
- Methodology version
- v1 (illustrative)
- Legal-rules version
- v1 (illustrative)
- Sources and profiles
- In the shipped record, the tracked governance sources and profile versions behind the lenses will be recorded here — full source traceability is in active development.
What this sample shows, and what you can do today
This page shows the target structure of a compliance-readiness record. The underlying workflows — inventory, assessment, evidence, controls, and the versioned in-workspace record — are available today, with the readiness score as one section of the whole story. The fully traceable, downloadable export shown here is in active development.
Scope and limits of this record
What this compliance-readiness record is, and is not
Trust boundary
- AgentProof provides compliance-readiness and documentation. It is not legal advice, not a certification, not audit assurance, and not regulatory approval.
- The governance and regulatory lenses map documentation coverage against expectations; they do not deliver a verdict, and the readiness score is a starting signal, never a verdict on safety.
- Your legal, privacy, security, procurement, and risk teams remain responsible for final review and decisions.
- This is a sample compliance-readiness record. It is illustrative only and is not a real assessment, not a certification, not legal advice, not a regulatory audit, and not a Microsoft approval or endorsement. AgentProof does not speak on behalf of Microsoft or any vendor.