(Pre-procurement / contract renewal / integration review)
Purpose:
To assess whether a proposed or existing AI vendor introduces structural epistemic, governance, or institutional risk, beyond ordinary product risk.
Each item is Yes / No / Unknown.
“Unknown” is a material risk indicator in procurement contexts.
I. Authority & Scope Definition
- Does the vendor clearly specify the epistemic role of the system (advisory vs authoritative)?
☐ Yes ☐ No ☐ Unknown - Are there explicit domain exclusions where the system will not provide conclusive outputs (e.g. medical, legal, eligibility)?
☐ Yes ☐ No ☐ Unknown - Are these boundaries enforced technically, not just described in documentation?
☐ Yes ☐ No ☐ Unknown - Does the vendor accept responsibility for epistemic harms within the defined scope of use?
☐ Yes ☐ No ☐ Unknown
II. Interface & Output Design
- Does the default interface present single synthesized answers in high-stakes contexts?
☐ Yes ☐ No ☐ Unknown - Are uncertainty, disagreement, or evidence strength visible in default outputs?
☐ Yes ☐ No ☐ Unknown - Can the interface be configured to require comparison, secondary review, or source inspection?
☐ Yes ☐ No ☐ Unknown - Has the vendor treated interface design as a risk factor rather than a purely UX concern?
☐ Yes ☐ No ☐ Unknown
III. Compression & Summarization Risks
- Is the system used for summarization, triage, or case condensation?
☐ Yes ☐ No ☐ Unknown - Does the vendor document what types of information are most likely to be omitted or downweighted?
☐ Yes ☐ No ☐ Unknown - Are safeguards in place to preserve urgency, severity, and edge cases?
☐ Yes ☐ No ☐ Unknown - Can users inspect source material or reconstruction paths behind summaries?
☐ Yes ☐ No ☐ Unknown
IV. Bias & Differential Impact
- Has the vendor conducted model- and task-specific bias testing relevant to your use case?
☐ Yes ☐ No ☐ Unknown - Are results of bias testing shared in a usable, auditable form?
☐ Yes ☐ No ☐ Unknown - Does the vendor monitor for bias arising through omission or framing, not just explicit outputs?
☐ Yes ☐ No ☐ Unknown - Is bias reassessed after model updates or retraining?
☐ Yes ☐ No ☐ Unknown
V. Transparency, Provenance & Change Control
- Can the vendor clearly identify the model(s), versions, and update cadence in use?
☐ Yes ☐ No ☐ Unknown - Are model changes communicated before deployment, not after incidents?
☐ Yes ☐ No ☐ Unknown - Is there a changelog describing behavioral differences, not just technical upgrades?
☐ Yes ☐ No ☐ Unknown - Can the institution pause, roll back, or sandbox updates?
☐ Yes ☐ No ☐ Unknown
VI. Governance, Enforcement & Remedies
- Do contractual terms include enforceable safeguards (pause rights, audit rights, penalties)?
☐ Yes ☐ No ☐ Unknown - Are incident-response obligations time-bound and operationally specific?
☐ Yes ☐ No ☐ Unknown - Does the vendor provide mechanisms for rapid containment if harm is detected?
☐ Yes ☐ No ☐ Unknown - Are public assurances matched by contractual obligations?
☐ Yes ☐ No ☐ Unknown
VII. Scale & Propagation Risk
- Does the system propagate outputs beyond the institution’s control (APIs, downstream integrations)?
☐ Yes ☐ No ☐ Unknown - Is correction slower or weaker than dissemination?
☐ Yes ☐ No ☐ Unknown - Can erroneous or harmful outputs be fully withdrawn downstream?
☐ Yes ☐ No ☐ Unknown - Has the vendor demonstrated successful containment in prior incidents?
☐ Yes ☐ No ☐ Unknown
Due-Diligence Readout Guide
- High “Unknown” count → vendor opacity risk
- Yes in I + No in VI → authority without accountability
- Yes in III + No in IV → compression-driven bias risk
- Yes in VII + No in V → irreversibility risk
A vendor that scores well on performance but poorly here is not “immature”—it is structurally misaligned with institutional risk.
Member discussion: