Defence assurance test catalogue
This is the generated human-readable view of the canonical assurance-test catalogue. Its 13 scenarios are designs, not executed results. A listed test does not demonstrate system conformance, clinical safety or operational acceptance.
The scenarios use synthetic records and representative workflows. Execution still requires an agreed system boundary, clinical-risk controls, test-data governance, measurable thresholds, named evidence owners and authorised pass/fail decisions.
Test-status definition
| Status | Meaning |
|---|---|
designed_not_executed |
The scenario has been designed, but no evidence of system conformance, clinical safety or operational acceptance has been produced. |
Catalogue
AST-001 — Reconcile identity, physical support location, care responsibility, registration and source coverage for a mobile cohort
Status: designed_not_executed
Candidate requirements: REQ-001
Scenario objective
Reconcile identity, physical support location, care responsibility, registration and source coverage for a mobile cohort
Method
Seed synthetic posted, attached, embarked, deployed, temporary, evacuated, duplicate and wrongly registered records; exercise conflict and correction paths
Evidence required for a pass
Each attribute and source is independently visible; conflicts and missing periods cannot appear silently complete; an accountable correction is recorded with provenance
AST-002 — Demonstrate complete safety-search and recall populations despite location and registration variation
Status: designed_not_executed
Candidate requirements: REQ-002, REQ-001
Scenario objective
Demonstrate complete safety-search and recall populations despite location and registration variation
Method
Run screening and readiness queries over a seeded cohort containing eligible, excluded, non-responder, temporary, stale and wrongly registered people
Evidence required for a pass
Displayed denominator, exclusions, source coverage and freshness reconcile to the seed; every unresolved person has an accountable follow-up state
AST-003 — Retrieve and reconcile recent care and the minimum safety dataset across supported record sources
Status: designed_not_executed
Candidate requirements: REQ-003, REQ-001
Scenario objective
Retrieve and reconcile recent care and the minimum safety dataset across supported record sources
Method
Transfer synthetic allergies, medicines, risks, care plans and recent treatment between permanent, temporary, NHS, Defence and receiving services, including one unavailable source
Evidence required for a pass
The receiving view preserves provenance, identifies the latest authoritative values, discloses the unavailable source and time period, and prevents an incomplete record appearing complete
AST-004 — Close a time-critical result safely during workload, recipient absence and delayed connectivity
Status: designed_not_executed
Candidate requirements: REQ-004, REQ-009
Scenario objective
Close a time-critical result safely during workload, recipient absence and delayed connectivity
Method
Inject graded abnormal laboratory and imaging results during routine, night, surge, wrong-recipient and disconnected scenarios; observe routing, acknowledgement, escalation and closure
Evidence required for a pass
Severity and required action remain salient; an accountable owner acknowledges within the defined time or escalation occurs; clinical action and closure are evidenced without equating viewing or filing with completion
AST-005 — Route safety-relevant patient messages, referrals and recommendations through every supported channel
Status: designed_not_executed
Candidate requirements: REQ-005, REQ-009
Scenario objective
Route safety-relevant patient messages, referrals and recommendations through every supported channel
Method
Submit ambiguous and high-risk synthetic content to administrative and clinical entry points; test rejection, reassignment, non-response and record incorporation
Evidence required for a pass
Users can see destination and responsibility; clinical risk reaches accountable triage; rejection or delay escalates; the record preserves content, decision, action and completion
AST-006 — Deliver and reconcile draft, corrected and final transfer records into the receiving workflow
Status: designed_not_executed
Candidate requirements: REQ-006, REQ-003
Scenario objective
Deliver and reconcile draft, corrected and final transfer records into the receiving workflow
Method
Exercise ambulance, aeromedical, civilian and unit-transfer handovers with late finalisation, correction, duplicate delivery and one unavailable interface
Evidence required for a pass
Receiving staff can distinguish draft from final, see completeness and arrival, acknowledge review, reconcile verbal differences and retain the final record longitudinally
AST-007 — Maintain safe hybrid care and time-bounded medication review during digital unavailability
Status: designed_not_executed
Candidate requirements: REQ-007, REQ-012
Scenario objective
Maintain safe hybrid care and time-bounded medication review during digital unavailability
Method
Record a safety-critical recommendation on paper during outage, suspend a medicine, restore service and reconcile competing updates
Evidence required for a pass
Paper presence and authority are signposted; the suspension has an owner and deadline; all content is attributable; restoration produces one reconciled history without silent loss or duplication
AST-008 — Preserve amendment provenance consistently across live, routine, printed, exported and investigation views
Status: designed_not_executed
Candidate requirements: REQ-008
Scenario objective
Preserve amendment provenance consistently across live, routine, printed, exported and investigation views
Method
Create, correct and late-enter controlled records, then compare every supported representation and audit view
Evidence required for a pass
Every view clearly distinguishes original and amended content, author, event time, entry time and amendment status; no export implies that later text existed at the original time
AST-009 — Evaluate whether high-severity decision support is usable and proportionate under representative workload
Status: designed_not_executed
Candidate requirements: REQ-009, REQ-004, REQ-005
Scenario objective
Evaluate whether high-severity decision support is usable and proportionate under representative workload
Method
Scenario-based usability test with varied severity, repeated low-value alerts, override, absent owner, fatigue and assistive-technology use; measure sensitivity, specificity and downstream action
Evidence required for a pass
High-severity hazards are detected and acted on within target; low-value burden and unsafe override remain within agreed limits; every alert has an actionable owned outcome
AST-010 — Prove that existing safety barriers survive CORTISONE migration or have an accepted residual risk
Status: designed_not_executed
Candidate requirements: REQ-010
Scenario objective
Prove that existing safety barriers survive CORTISONE migration or have an accepted residual risk
Method
Build a pre/post-migration control inventory and execute the same clinical-safety regression cases against source, transitional and target states
Evidence required for a pass
Every barrier maps to equivalent or stronger tested behaviour; differences have named owners, documented clinical-safety assessment and authorised residual-risk acceptance before release
AST-011 — Recover safely from partial failure across independently administered transaction endpoints
Status: designed_not_executed
Candidate requirements: REQ-011
Scenario objective
Recover safely from partial failure across independently administered transaction endpoints
Method
Simulate cancel, reissue, dispense, administer and acknowledgement races with retries, duplicate messages, out-of-order delivery and a disconnected endpoint
Evidence required for a pass
Endpoint states and provenance are observable; replay is idempotent; conflicting action is prevented or contained; unresolved divergence is assigned and reconciled
AST-012 — Restore service after prolonged disconnection without silent data loss, unsafe replay or version conflict
Status: designed_not_executed
Candidate requirements: REQ-012, REQ-011
Scenario objective
Restore service after prolonged disconnection without silent data loss, unsafe replay or version conflict
Method
Run offline care with clock skew, duplicate edits, queued tasks and staged reconnection across multiple endpoints
Evidence required for a pass
Authority and fallback are clear during outage; queued work stays visible; synchronisation detects conflicts, avoids duplication and produces an attributable reconciliation record
AST-013 — Share the minimum necessary safety signal across clinical and operational services lawfully and accountably
Status: designed_not_executed
Candidate requirements: REQ-013
Scenario objective
Share the minimum necessary safety signal across clinical and operational services lawfully and accountably
Method
Exercise detention, evacuation and force-protection scenarios with permitted, prohibited, stale and corrected risk signals and role changes
Evidence required for a pass
Only agreed signals reach authorised roles for the stated purpose; provenance and freshness are visible; access and decisions are audited; an accountable reviewer resolves stale or conflicting information
Evidence expected from execution
An executed test record should identify the configuration and interfaces tested, synthetic-data seed, scenario version, participants and roles, observed event trail, human-factors findings, deviations, clinical-risk decision, evidence owner, date and approval status. A demonstration or screenshot alone is not a pass.
Tests may be split into lower-level cases during programme assurance, but their AST- identifier should remain the parent trace to the candidate requirement.
Maintenance
Edit assurance_tests.csv, then run node scripts/generate-defence-pages.mjs. Do not edit this page directly. Preserve retired identifiers rather than reusing them.