rv-2026-0401Submitted by Tomas Berg of People Services Digital11 Sept 2026Google Cloud, scored under CIS Controls v8.1 and Northwind’s own standardsmatched to Internal GenAI assistant with retrieval at 86%read from hr-policy-assistant-lld-v1.2.pdf and hr-policy-assistant-architecture.png
| Maps to | |||||||||
|---|---|---|---|---|---|---|---|---|---|
CAT-2 | Conditional services are used on their termsVertex AI is used outside its conditions of use | Estate fit | Estate fit | Service catalogue | High | Fail | Missing 1 cited, none proving it is built | Cyber Security | 11 Oct 2026 |
LLM01 | Prompt InjectionNothing screens the prompt or the retrieved chunks before they reach Gemini | AI | Security | OWASP LLM Top 10 | High | Fail | Missing 3 cited, none proving it is built | People Services Digital | 11 Oct 2026 |
LLM02 | Sensitive Information DisclosureConfidential manager guidance can be surfaced to any employee, and answers are not screened | AI | Security | OWASP LLM Top 10 | High | Fail | Missing 4 cited, none proving it is built | People Services Digital | 11 Oct 2026 |
LLM08 | Vector and Embedding WeaknessesThe vector index carries no entitlements: every employee can retrieve every chunk | AI | Security | OWASP LLM Top 10 | High | Fail | Missing 4 cited, none proving it is built | People Services Digital | 11 Oct 2026 |
REL-1 | No single point of failure on the critical pathThe primary data store has no standby | Reliability | Reliability | GCP Architecture Framework | High | Fail | Missing | People Services Digital | 11 Oct 2026 |
11.4 | Establish and Maintain an Isolated Instance of Recovery DataNo isolated copy of the conversation history is described | Resilience | Security | PR.DS-11 | Medium | Fail | Missing 2 cited, none proving it is built | Cloud Platform Engineering | 10 Nov 2026 |
AP-2 | Third party in the data pathThird party in the data path: HR Policy Library | Design pattern | Reliability | Design patterns | Medium | Fail | Missing | People Services Digital | 10 Nov 2026 |
COST-4 | Spend is visible and attributedNo budget, alert or cost attribution | Cost | Cost | GCP Architecture Framework | Medium | Fail | Missing | Cloud Platform Engineering | 10 Nov 2026 |
LLM10 | Unbounded ConsumptionNo per-user quota or budget alert on the inference path | AI | Security | OWASP LLM Top 10 | Medium | Fail | Missing 3 cited, none proving it is built | People Services Digital | 10 Nov 2026 |
MBSS-1 | The design names the baselines it is built to5 baselines apply and none is named in the design | Estate fit | Estate fit | MBSS baselines | Medium | Fail | Missing | Cyber Security | 10 Nov 2026 |
REL-5 | Dependencies fail without taking the application downA call to HR Policy Library has no stated failure behaviour | Reliability | Reliability | GCP Architecture Framework | Medium | Fail | Missing | People Services Digital | 10 Nov 2026 |
OPS-4 | Runbooks exist for the likely failuresNo runbooks are referenced | Operations | Operations | GCP Architecture Framework | Low | Fail | Missing | Cloud Platform Engineering | 10 Dec 2026 |
3.10 | Encrypt Sensitive Data in TransitEvery hop uses TLS, including the Graph connection and the private Vector Search endpoint | Data | Security | PR.DS-02 | Low | Pass | Data Platform Engineering | — | |
3.11 | Encrypt Sensitive Data at RestData at rest uses Google default encryption, which the standard accepts for Confidential data | Data | Security | PR.DS-01 | Low | Pass | Data Platform Engineering | — | |
3.12 | Segment Data Processing and Storage Based on SensitivityThe index and the conversation store sit inside a VPC Service Controls perimeter | Data | Security | PR.IR-01 · PR.DS-01 | Low | Pass | Data Platform Engineering | — | |
6.3 | Require MFA for Externally-Exposed ApplicationsIdentity-Aware Proxy enforces corporate sign-in and MFA before requests reach the application | Identity | Security | PR.AA-03 | Low | Pass | Identity Engineering | — | |
6.5 | Require MFA for Administrative AccessProject administrators use 2-Step Verification with security keys | Identity | Security | PR.AA-03 · PR.AA-05 | Low | Pass | Identity Engineering | — | |
8.9 | Centralize Audit LogsAudit logs leave the project through the organisation-level sink | Logging | Security | PR.PS-04 | Low | Pass | Cyber Security | — | |
12.2 | Establish and Maintain a Secure Network ArchitecturePrivate egress, Private Google Access and a single allow-listed external destination | Network | Security | PR.IR-01 | Low | Pass | Network Engineering | — | |
13.10 | Perform Application Layer FilteringCloud Armor with the OWASP rule set is attached to both backend services | Network | Security | PR.IR-01 · DE.CM-01 | Low | Pass | Network Engineering | — | |
16.10 | Apply Secure Design Principles in Application ArchitecturesOne least-privilege service account per workload, no basic roles | Application | Security | PR.PS-06 | Low | Pass | People Services Digital | — | |
AP-1 | Shared databaseNo shared database | Design pattern | Reliability | Design patterns | Low | Pass | Not assessed | People Services Digital | — |
AP-4 | Snowflake environmentThe environment is reproducible | Design pattern | Operations | Design patterns | Low | Pass | Cloud Platform Engineering | — | |
CAT-1 | Every service is in the catalogue and permittedAll 11 services are in the catalogue and permitted | Estate fit | Estate fit | Service catalogue | Low | Pass | Not assessed | Cyber Security | — |
CAT-3 | Nothing depends on a service that is going awayNothing in the design is retiring or unassessed | Estate fit | Estate fit | Service catalogue | Low | Pass | Not assessed | Cyber Security | — |
CAT-4 | Data is held only where its class is permittedEvery store is assessed for the class it holds | Estate fit | Estate fit | Service catalogue | Low | Pass | Not assessed | Cyber Security | — |
COST-1 | Capacity follows demandNothing runs when nothing is happening | Cost | Cost | GCP Architecture Framework | Low | Pass | Not assessed | Cloud Platform Engineering | — |
COST-3 | Traffic that leaves is accounted forTraffic leaving the estate is accounted for | Cost | Cost | GCP Architecture Framework | Low | Pass | Cloud Platform Engineering | — | |
LLM05 | Improper Output HandlingAnswers are rendered as Markdown with raw HTML disabled and links restricted | AI | Security | OWASP LLM Top 10 | Low | Pass | People Services Digital | — | |
LLM06 | Excessive AgencyThe model has no tools and cannot act | AI | Security | OWASP LLM Top 10 | Low | Pass | People Services Digital | — | |
LLM07 | System Prompt LeakageThe system prompt holds instructions only; the one secret lives in Secret Manager | AI | Security | OWASP LLM Top 10 | Low | Pass | People Services Digital | — | |
OPS-1 | Infrastructure is defined as codeThe environment is defined as code | Operations | Operations | GCP Architecture Framework | Low | Pass | Cloud Platform Engineering | — | |
OPS-2 | Releases are staged and reversibleReleases are staged and can be withdrawn | Operations | Operations | GCP Architecture Framework | Low | Pass | Cloud Platform Engineering | — | |
OPS-3 | Monitoring reaches a personAlerts reach a named rota | Operations | Operations | GCP Architecture Framework | Low | Pass | Cloud Platform Engineering | — | |
PERF-1 | Latency and throughput targets are statedThe design states what it is built to serve | Performance | Performance | GCP Architecture Framework | Low | Pass | People Services Digital | — | |
PERF-4 | Scaling bounds are definedScaling bounds are set | Performance | Performance | GCP Architecture Framework | Low | Pass | People Services Digital | — | |
REL-2 | Recovery objectives are statedRecovery objectives are stated | Reliability | Reliability | GCP Architecture Framework | Low | Pass | People Services Digital | — |