Can your AI system answer these fifteen questions?

Each question asks whether your system can produce one record an auditor would ask for. Answer for the system as it runs today. Your answers never leave this page: nothing is sent, and a reload clears them.

§01

First, three questions about the system

They shape the result and decide whether the last two questions apply. They are not scored.

Where does the model run?
Does the system take actions on its own, such as calling tools, APIs or internal services?
Does the system take in data from outside sources you do not own?

§02

The fifteen questions

Can you produce a dated list of every paid model call the system made last month, each with the subject it concerned, the model version that answered, and what it cost?
If someone edited or deleted a line in your audit log, would you be able to tell?
For the last consequential output the system produced, can you show who approved it, when, and exactly what they saw at the time?
Is every message, document or notice that leaves the organisation released by a person, with a record that they did?
Has anyone stopped the system on purpose, on a date you can name, with a record of what happened to the work already in flight?
Is there a hard ceiling on what the system can spend or call in twenty-four hours, and is each call the ceiling refused on record?
Can you say which model version answered which part of the system three months ago, and why it changed?
Can you list every external endpoint the system can reach, and prove that nothing else is reachable?
Is every model output checked against a versioned schema before anything acts on it, with rejections logged rather than quietly corrected?
Is there a test in your build that fails if raw personal data reaches your logs?
If the system did something nobody can explain, is there a written path from that moment to your incident process, and has anyone followed it?
Can you show why a control was changed, by whom and when, back to the start of the system?
Do you know, in writing, which of these your organisation has decided not to do, and who owns each one instead?
Is every tool, API or MCP call the system makes metered, logged, gated where it matters, and stoppable?

Scored unless you said the system takes no actions on its own.

For every outside source, is there a written contract recording where each record came from, updated in the same commit as the code?

Scored unless you said the system takes in no data from outside sources you do not own.

§03

Your result

The result appears when every question has an answer.

§04

What this check does not cover

What the offer does not do, and who does it instead.

Fundamental rights impact assessment
Client's legal / DPO
Conformity assessment and CE marking
Provider; notified body
Training data governance
Model provider
Bias and fairness testing of the underlying model
Model provider; client's model-risk function
Registration in the EU database
Client's compliance function
Watermarking of generated content
Model provider
Legal opinion on high-risk classification
Client's legal
DPIA authorship
Client's DPO
Threat-led penetration testing
Client's security function; TLPT provider
ISO/IEC 42001 certification
Accredited certification body
Independent model validation
Client's model validation function
Employer consultation on workplace AI
Client's HR

§05

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.