Question pack
AI Governance & Safety Question Pack
The governance, safety, bias and human-oversight questions a generic IT questionnaire never asks — and an auditor will.
What it de-risks
- ▸Make model provenance, training-data use, and change control explicit before signing.
- ▸Test the vendor’s safety posture against how your teams will actually use the system.
- ▸Pin down bias evaluation and content provenance rather than accepting a policy PDF.
- ▸Establish where a human must stay in the loop, and what happens when they are not.
What is inside
4 corpus modules, at both RFI and RFP depth, in canonical order. Every question ships with what a strong answer looks like, the red flags to watch for, a response-format hint, and a default weight you can tune.
- Model & data governance
- AI safety & responsible AI
- Bias, fairness & content provenance
- Human oversight & escalation
Sample questions
Confirm that customers can pin usage to a specific, immutable model version identifier. If so, describe your versioning scheme and the guarantee of immutability (i.e., that underlying weights and inference configuration will not change for a pinned version).
Why it matters — Stable, pinnable model versions are foundational for production reliability. Vendors may silently swap model weights behind a stable identifier, breaking customer workflows that were validated against a prior version. This question verifies the vendor's commitment to immutability, a critical control for managing behavioral drift and ensuring repeatable outcomes.
Describe the platform-level controls your product provides to mitigate direct prompt injection (malicious instructions in the user-supplied prompt).
Why it matters — Prompt injection is the most prevalent AI-application vulnerability class identified by OWASP. Vendors that push the entire defense burden to the customer leave buyers exposed and often indicate immature security engineering. Understanding the platform-side mitigations sets a baseline for the shared-responsibility model.
Describe your methodology for evaluating bias in the model(s) powering your product. Include the benchmarks and datasets used, the cadence of re-evaluation, and triggers for out-of-cycle reviews.
Why it matters — Bias claims without documented methodology cannot be validated or compared across vendors. Buyers need to know whether the vendor treats bias evaluation as a continuous process tied to model changes, not a one-off exercise. A vendor that can name specific benchmarks, statistical procedures, and a clear re-evaluation cadence is operating with discipline.
Describe the human-in-the-loop (HITL) controls your platform provides, including the granularity at which a customer administrator can require human review (e.g. per-tenant, per-workflow, per-action, per-decision-type).
Why it matters — Many AI products advertise HITL but only at coarse session or tenant level, which is unworkable for regulated use cases that require per-action review. Granularity determines whether the buyer can actually deploy in higher-risk contexts. The NIST AI RMF treats human oversight as a core function that must be operationally realisable.
One-time purchase · Word questionnaire + Excel scoring matrix · Downloads immediately · Itemized receipt and perpetual organization license · Free account required at checkout