AI Vendor Readiness Scorecard

For AI vendors selling to banks, credit unions, insurers, hospitals and health systems. Answer 14 questions about the documents you hold. See where a buyer's review is likely to stall, and which document closes each gap.

Your answers stay in your browser. Nothing is sent unless you choose to send it.

Who are you selling to?
0 of 14 answered
Question 1: Do you have a one-to-two-page written description of each AI system you sell: what it does, which model or provider it uses, and the version?
Question 2: Is there a named person accountable for each AI system?
Question 3: Do you have a written statement of intended use, and of uses you do not support?
Question 4: Can you state in writing whether customer data is used to train or improve any model, yours or a provider's?
Question 5: Do you keep a current list of the providers that touch customer data, including model providers, with the country where each processes it?
Question 6: Can you state where the AI processing happens, and is that statement true for every provider in the chain?
Question 7: Do you have dated test results for accuracy or quality on a task like the customer's?
Question 8: Do you have a written list of known limitations and failure modes?
Question 9: Have you tested for unfair outcomes across groups, where the system affects people?
Question 10: Do you monitor the system in production, with a named reviewer and a set frequency?
Question 11: Do you tell customers before you change the model or the provider?
Question 12: Is there a defined point where a person reviews or can override the output?
Question 13: Do you hold a current independent security report (SOC 2 Type II, ISO 27001 or HITRUST) that covers the AI system?
Question 14: Do you keep your past questionnaire answers in one place, each linked to the document that supports it?
This is a self-assessment. It is not an audit, a certification or legal advice.