(Pre-procurement / contract renewal / integration review)

Purpose:
To assess whether a proposed or existing AI vendor introduces structural epistemic, governance, or institutional risk, beyond ordinary product risk.

Each item is Yes / No / Unknown.
“Unknown” is a material risk indicator in procurement contexts.


I. Authority & Scope Definition

  1. Does the vendor clearly specify the epistemic role of the system (advisory vs authoritative)?
    ☐ Yes ☐ No ☐ Unknown
  2. Are there explicit domain exclusions where the system will not provide conclusive outputs (e.g. medical, legal, eligibility)?
    ☐ Yes ☐ No ☐ Unknown
  3. Are these boundaries enforced technically, not just described in documentation?
    ☐ Yes ☐ No ☐ Unknown
  4. Does the vendor accept responsibility for epistemic harms within the defined scope of use?
    ☐ Yes ☐ No ☐ Unknown

II. Interface & Output Design

  1. Does the default interface present single synthesized answers in high-stakes contexts?
    ☐ Yes ☐ No ☐ Unknown
  2. Are uncertainty, disagreement, or evidence strength visible in default outputs?
    ☐ Yes ☐ No ☐ Unknown
  3. Can the interface be configured to require comparison, secondary review, or source inspection?
    ☐ Yes ☐ No ☐ Unknown
  4. Has the vendor treated interface design as a risk factor rather than a purely UX concern?
    ☐ Yes ☐ No ☐ Unknown

III. Compression & Summarization Risks

  1. Is the system used for summarization, triage, or case condensation?
    ☐ Yes ☐ No ☐ Unknown
  2. Does the vendor document what types of information are most likely to be omitted or downweighted?
    ☐ Yes ☐ No ☐ Unknown
  3. Are safeguards in place to preserve urgency, severity, and edge cases?
    ☐ Yes ☐ No ☐ Unknown
  4. Can users inspect source material or reconstruction paths behind summaries?
    ☐ Yes ☐ No ☐ Unknown

IV. Bias & Differential Impact

  1. Has the vendor conducted model- and task-specific bias testing relevant to your use case?
    ☐ Yes ☐ No ☐ Unknown
  2. Are results of bias testing shared in a usable, auditable form?
    ☐ Yes ☐ No ☐ Unknown
  3. Does the vendor monitor for bias arising through omission or framing, not just explicit outputs?
    ☐ Yes ☐ No ☐ Unknown
  4. Is bias reassessed after model updates or retraining?
    ☐ Yes ☐ No ☐ Unknown

V. Transparency, Provenance & Change Control

  1. Can the vendor clearly identify the model(s), versions, and update cadence in use?
    ☐ Yes ☐ No ☐ Unknown
  2. Are model changes communicated before deployment, not after incidents?
    ☐ Yes ☐ No ☐ Unknown
  3. Is there a changelog describing behavioral differences, not just technical upgrades?
    ☐ Yes ☐ No ☐ Unknown
  4. Can the institution pause, roll back, or sandbox updates?
    ☐ Yes ☐ No ☐ Unknown

VI. Governance, Enforcement & Remedies

  1. Do contractual terms include enforceable safeguards (pause rights, audit rights, penalties)?
    ☐ Yes ☐ No ☐ Unknown
  2. Are incident-response obligations time-bound and operationally specific?
    ☐ Yes ☐ No ☐ Unknown
  3. Does the vendor provide mechanisms for rapid containment if harm is detected?
    ☐ Yes ☐ No ☐ Unknown
  4. Are public assurances matched by contractual obligations?
    ☐ Yes ☐ No ☐ Unknown

VII. Scale & Propagation Risk

  1. Does the system propagate outputs beyond the institution’s control (APIs, downstream integrations)?
    ☐ Yes ☐ No ☐ Unknown
  2. Is correction slower or weaker than dissemination?
    ☐ Yes ☐ No ☐ Unknown
  3. Can erroneous or harmful outputs be fully withdrawn downstream?
    ☐ Yes ☐ No ☐ Unknown
  4. Has the vendor demonstrated successful containment in prior incidents?
    ☐ Yes ☐ No ☐ Unknown

Due-Diligence Readout Guide

  • High “Unknown” count → vendor opacity risk
  • Yes in I + No in VI → authority without accountability
  • Yes in III + No in IV → compression-driven bias risk
  • Yes in VII + No in V → irreversibility risk

A vendor that scores well on performance but poorly here is not “immature”—it is structurally misaligned with institutional risk.