VaulithNine questions, free
The canon · Inventory · AIS-2.3

Describe the risk classification applied to each AI system and the criteria that place a system in the highest tier.

This is one of the twenty-five questions a carrier reviewer sends a vendor, in the words an examiner uses. Below it: the answers that make a reviewer stop on this item, derived by running Vaulith's rules engine on an estate that gets everything wrong, and the free questions that reach it.

What stops a reviewer here

3 findings reach this item.

Will escalateR-CONTRADICTION-IMPACT · degrades this item

Your policy commits to a recorded impact determination that is missing

AI policy (3.4) commits to determining and recording the consumer impact of every system. MDL-001 Claims triage has no recorded determination. The determination is the first thing an examiner asks for on any system, because it decides which questions apply to it, and a policy that promises the record makes its absence a governance failure rather than a paperwork gap.

To fix: Write the determination for each system, have it approved by whoever owns the policy, and keep it with the model record. One page per system is enough.

Will escalateR-CONTRADICTION-BIAS · degrades this item

Your policy commits to scheduled fairness testing the estate does not show

AI policy (3.3) commits to testing fairness or disparate impact on a set schedule. MDL-001 Claims triage does not meet it, because no test is on record at all. A reviewer who reads the policy first expects a test result from the last ninety days to be in the file, and its absence tells them the schedule exists on paper. Once they have found one control that exists only on paper, they check the others the same way.

To fix: Run the test the policy already requires and record the date, or amend the policy to the cadence you actually keep. A commitment you do not meet costs more than one you never made.

Will escalateR-NO-HUMAN-OVERRIDE · degrades this item

No human review before a consumer outcome on MDL-001

The model can reach a consumer without a person able to review or override it first. This is the question a carrier asks earliest about anything touching claims or underwriting, because it decides whether the insurer or the vendor owns the outcome. An answer of no does not end a review, but it moves the conversation from your controls to their appetite, and that is a conversation held at a level you are not in the room for.

To fix: Put a person in the path, or document precisely where the boundary sits: which decisions are advisory, which are automatic, and what the reviewable population is. A reviewer can accept an automated path that is bounded and described. They cannot accept one that is neither.

How it is scored

Credit per verdict, times the weight.

A standard item carries weight 2. A pass earns 1.00 of it, a questioned answer 0.60, an escalated one 0.20 and a stop 0.00. An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by leaving an inconvenient question blank. The whole arithmetic is shown on the homepage and in every assessment.

Try it in ninety seconds

The free snapshot asks about this.