Practical reference

Frequently Asked Questions

Direct answers to common software-assurance questions, with the assumptions and limits kept visible.

Editorial previewTechnical review and author byline approval pending

Is CSA the same as doing less testing?

No. A risk-informed approach can reduce unnecessary repetition and strengthen testing where evidence is weak. The useful outcome is better-supported confidence in the defined use. Test count alone cannot demonstrate that.

Can we use unscripted testing for every lower-risk function?

Choose the activity according to the question, failure, existing evidence, and need for precision. A narrowly scoped scripted check may be the clearest way to test a simple boundary. An exploratory session may help investigate complex interaction. Use a justified combination and retain an appropriate record.

Does every test need a screenshot?

Choose evidence that substantiates the behavior. Logs, structured comparisons, recorded observations, and screenshots can each help. The evidence needs adequate context and integrity. A screenshot requirement may arise from a local procedure, but do not present a blanket rule without its source.

Is commercial software already validated for our use?

Supplier evidence can support standard behavior. Your intended use, configuration, interfaces, data, permissions, and operating process may introduce differences. Explain which evidence applies and what remains to be addressed locally.

Do we need to assess a spreadsheet without macros?

Assess the use and failure consequence. Formula errors, wrong units, overwritten cells, and incorrect references do not require macros. A personal schedule and an acceptance calculation have different dependencies.

Can a person checking every output replace other assurance?

Only assess the control based on what the person actually checks and how independently and reliably they do it. Define coverage, competence, timing, source, and record. A check that only confirms a number is present does not establish that it is correct.

Does human review make an AI tool lower risk automatically?

No. Review can be a control, but users can miss errors or over-rely on generated output. Evaluate representative users performing the actual task, including false findings, omissions, and source checking.

Is 95% accuracy enough to release an AI application?

The answer depends on what was measured, the intended use, failure severity, dataset, uncertainty, controls, and acceptance rationale. A high aggregate result can hide consequential misses. No universal percentage establishes readiness for every quality use.

Is a RAG answer reliable if it includes citations?

Check whether the sources are authorized, current, relevant, and sufficient for the answer. A real citation can point to the wrong site procedure or omit an important exception.

Do we need to reassess an AI application when only the prompt changes?

Assess the potential effect. A prompt can change findings, omissions, output structure, or tool selection. The extent of reassessment should address the affected claims and dependencies.

Are the scenario labs real client projects?

No. They are fictional teaching cases. They are intended to illustrate reasoning and evidence, not claim delivery experience or disclose confidential work.

Are the named frameworks regulatory standards?

No. They are educational structures built around established practices. Use the applicable requirements and your organization’s approved procedures when making real decisions.

Does completing the Academy provide a professional certification?

The material is educational. Do not interpret reading the chapters or completing exercises as an accredited qualification, professional license, or authorization to approve systems.

Can I use these templates in my organization?

You may use the published content under the site’s stated reuse terms. Adapt it to your process and retain your own approvals and evidence. A completed fictional example should never be copied into a project as though its tests had been performed.