Public rubric ยท version 1.2
How we score
A score you cannot check is worth nothing. The same answers always give the same number, and every question and weight is on this page. No AI decides your score.
The scale
Scores run from 300 to 900. Nobody starts at zero, because even a company with no controls has a risk you can describe. Each of the six areas is worth its share of 600 points, split across the questions inside it.
How much each area counts
The weights follow what actually makes an AI mistake expensive, not what is easy to measure. We review them every quarter and publish any change. We never quietly rewrite your old scores.
- What AI you are running 15%
- Can you list every AI tool your company uses today? Most teams find one or two they forgot about. The ones you forget are the ones that cause the argument later.
- What data you send to AI 20%
- What kind of customer data ends up inside an AI tool? Sending names, health or payment details to an outside AI service is the fastest way to turn a small mistake into a big bill.
- What AI can do on its own 18%
- Can your AI do something that matters without a person saying yes? A wrong suggestion costs you an apology. A wrong action costs you money. This is the part buyers worry about most.
- How you check it works 17%
- Can you show that you test your AI before customers see it? You do not need a lab. You need a test you run every release and a dated record that you ran it.
- What you can prove later 15%
- If someone complains in a year, can you show what your AI actually did? Complaints and claims show up long after the event. Records are the difference between a quick answer and a long fight.
- Who pays if it goes wrong 15%
- If an AI mistake costs a customer money, who ends up paying? Your contracts and your insurance decide that, and most were written before anyone was using AI at work.
The questions
24 questions, each with a weight and the proof worth keeping. If you cannot show it, treat it as not done. Saying so is not the same as proving it.
- 01w 3.00
Where does your AI output end up?
Proof: A short note on who sees AI output: staff, customers, or the public.
- 02w 3.00
Do you have a list of every AI tool your company uses?
Proof: Your list of AI tools with an owner and a last-checked date.
- 03w 2.00
How would you find out if someone started using a new AI tool without asking?
Proof: A login or expense report showing which AI apps your team signs into.
- 04w 2.00
Which AI providers do you build on?
Proof: The providers and model versions you use, and what you would switch to.
- 05w 4.00
What is the most sensitive thing your AI tools see?
Proof: A simple sketch of what data leaves your systems and goes to an AI provider.
- 06w 3.00
Do you remove personal details before sending text to an AI provider?
Proof: A before and after example showing what gets removed.
- 07w 3.00
Do you know if your AI provider keeps or trains on your data?
Proof: The part of your provider agreement covering training and how long they keep data.
- 08w 2.00
Do you know which country your AI requests are processed in?
Proof: The region setting you use and what your customer contracts promise.
- 09w 4.00
What is the biggest thing your AI can do without a person approving it?
Proof: A short description of the most powerful thing your AI can do by itself.
- 10w 3.00
How much access does your AI have to your systems?
Proof: The list of permissions your AI accounts hold.
- 11w 2.00
Could you switch your AI feature off in the next five minutes?
Proof: The off switch, and the date you last tested it.
- 12w 2.00
Do people know when they are talking to AI, and can they reach a human?
Proof: A screenshot showing the notice and the way to reach a person.
- 13w 4.00
Do you test your AI against real examples before each release?
Proof: Your last test run: date, and how many it passed.
- 14w 3.00
Have you checked whether your AI treats different groups of people differently?
Proof: The test you ran, when you ran it, and what you found.
- 15w 3.00
Has anyone tried to break your AI on purpose?
Proof: The findings from the attempt and what you fixed.
- 16w 2.00
Do you track how often your AI gets things wrong in the real product?
Proof: Your current error rate and how you measure it.
- 17w 4.00
Do you keep a record of what your AI was asked and what it answered?
Proof: Where the records live and how long you keep them.
- 18w 3.00
Would you get an alert if your AI started behaving strangely?
Proof: The alerts you have set and who receives them.
- 19w 3.00
Do you have a plan for the day your AI causes a problem?
Proof: The plan, with names, and the last time you walked through it.
- 20w 2.00
Do you write down AI problems and near misses?
Proof: Your list of incidents with dates.
- 21w 4.00
What insurance does your company carry today?
Proof: Your policy documents, or the summary your broker sent.
- 22w 3.00
If your AI provider's model copies someone's work, do they cover you?
Proof: The clause in your provider agreement and proof you meet its conditions.
- 23w 3.00
Do your customer contracts put a limit on what you owe if AI gets it wrong?
Proof: The liability and warranty sections of your standard contract.
- 24w 2.00
Do you check an AI vendor before your team starts using it?
Proof: Your list of vendors and when you last reviewed them.
What this score is not
- It is based on your own answers until you attach proof. Reviewed reports are marked as such and carry a lot more weight.
- It is not a quote, and not a promise that any insurer will cover you.
- It measures how well you handle AI risk, not how good your AI is. A great score with a mediocre model just means your mistakes stay small and you can prove what happened.