VaulithNine questions, free
The canon · Governance · AIS-1.3

Describe how AI governance decisions, including approvals and exceptions, are recorded and retained.

This is one of the twenty-five questions a carrier reviewer sends a vendor, in the words an examiner uses. Below it: the answers that make a reviewer stop on this item, derived by running Vaulith's rules engine on an estate that gets everything wrong, and the free questions that reach it.

What stops a reviewer here

One finding reaches this item.

Will escalateR-CONTRADICTION-VALIDATION · degrades this item

Your own policy requires validation the estate does not have

AI policy (3.1) commits to independent validation of the models that reach a consumer. That is your own commitment, and MDL-001 Claims triage does not meet it. A missing validation on its own is one finding. This is worse than that, because a reviewer who reads your policy and then looks at your estate learns that the policy describes a practice you do not follow. Once they have found one control that exists only on paper, they start checking the others the same way.

To fix: Close the gap or amend the policy. Leaving a commitment in force that the estate does not meet is the more expensive of the two options.

How it is scored

Credit per verdict, times the weight.

A contextual item carries weight 1. A pass earns 1.00 of it, a questioned answer 0.60, an escalated one 0.20 and a stop 0.00. An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by leaving an inconvenient question blank. The whole arithmetic is shown on the homepage and in every assessment.

Try it in ninety seconds

The free snapshot asks about this.