VaulithNine questions, free
The canon · Governance · AIS-1.1

Describe the AI Systems Program, including governance structure, named accountability, and the process by which AI systems are approved for production use.

This is one of the twenty-five questions a carrier reviewer sends a vendor, in the words an examiner uses. Below it: the answers that make a reviewer stop on this item, derived by running Vaulith's rules engine on an estate that gets everything wrong, and the free questions that reach it.

What stops a reviewer here

4 findings reach this item.

Will escalateR-CONTRADICTION-IMPACT · blocks this item

Your policy commits to a recorded impact determination that is missing

AI policy (3.4) commits to determining and recording the consumer impact of every system. MDL-001 Claims triage has no recorded determination. The determination is the first thing an examiner asks for on any system, because it decides which questions apply to it, and a policy that promises the record makes its absence a governance failure rather than a paperwork gap.

To fix: Write the determination for each system, have it approved by whoever owns the policy, and keep it with the model record. One page per system is enough.

Will escalateR-CONTRADICTION-BIAS · blocks this item

Your policy commits to scheduled fairness testing the estate does not show

AI policy (3.3) commits to testing fairness or disparate impact on a set schedule. MDL-001 Claims triage does not meet it, because no test is on record at all. A reviewer who reads the policy first expects a test result from the last ninety days to be in the file, and its absence tells them the schedule exists on paper. Once they have found one control that exists only on paper, they check the others the same way.

To fix: Run the test the policy already requires and record the date, or amend the policy to the cadence you actually keep. A commitment you do not meet costs more than one you never made.

Will escalateR-CONTRADICTION-SUBPROCESSOR · blocks this item

Your policy commits to naming subprocessors that are not named

AI policy (3.2) commits to naming the third parties inside your product. MDL-001 Claims triage has no named provider. A reviewer reading the policy first will treat the register as something that exists, then find it does not.

To fix: Build the subprocessor register your policy already promises, and have it approved by whoever owns that policy.

Will escalateR-CONTRADICTION-VALIDATION · blocks this item

Your own policy requires validation the estate does not have

AI policy (3.1) commits to independent validation of the models that reach a consumer. That is your own commitment, and MDL-001 Claims triage does not meet it. A missing validation on its own is one finding. This is worse than that, because a reviewer who reads your policy and then looks at your estate learns that the policy describes a practice you do not follow. Once they have found one control that exists only on paper, they start checking the others the same way.

To fix: Close the gap or amend the policy. Leaving a commitment in force that the estate does not meet is the more expensive of the two options.

How it is scored

Credit per verdict, times the weight.

A critical item carries weight 3. A pass earns 1.00 of it, a questioned answer 0.60, an escalated one 0.20 and a stop 0.00. An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by leaving an inconvenient question blank. The whole arithmetic is shown on the homepage and in every assessment.

Try it in ninety seconds

The free snapshot asks about this.