Transparency

Assessment methodology and scoring rubric

AIFOD publishes in full the rubric every application is scored against, the points allocated to each pillar and sub-indicator, and the role and limits of AI in the assessment. The assessment process is itself designed to comply with the FAIR principles it certifies. You can also score your own organisation against this rubric before applying.

Framework FAIR v2.1 · Procedure v2.1 · published 8 Oct 2026

The role and limits of AI in this assessment

Assessment combines a structured documentation review, AI-assisted scoring against the rubric below, and a confirmatory interview conducted by human examiners.

AI-generated scores are advisory. They triage, structure and inform the examination. They set a provisional tier and nothing more. No application is finally declined, and no rating is finally awarded, without human review and sign-off. Every decline and every rating carries the signature of the responsible human reviewer or examiners.

To reduce variance, each application is scored in three independent runs and the median score per pillar is adopted. For each pillar the engine produces a score out of 25, sub-indicator scores, the specific evidence it relied upon with document references, the evidence gaps it identified, and a list of questions recommended for the examiner interview. The full output, including its reasoning, is retained in the case file and is auditable.

An examiner may adjust the provisional tier by one level in either direction, with written reasons. An adjustment of more than one level requires the countersignature of a second examiner not previously involved in the case. Where two examiners disagree, a senior examiner decides.

Pillars and weights

Every application is assessed against four pillars of equal weight. Each pillar carries a maximum of 0 points, for a total score of 100.

C1
Product & Solution Documentation
What the product does, where it is used, and how it uses AI. A product deck, overview or website usually covers this whole category.
0 pts
c1-1 Purpose, problem and who it serves 0
c1-2 Where it is used 0
c1-3 AI functions and their limits 0
C2
Technical Architecture & Data Flow
How data moves through the system: where it comes from, what is processed, where it is stored and who can reach it. A simple data-flow or architecture diagram is the ideal evidence.
0 pts
c2-1 How data moves through the system 0
c2-2 Where data is stored and who can access it 0
c2-3 External integrations 0
C3
Privacy & Data Governance
How personal and organisational data is collected, kept, transferred and deleted. A privacy policy and a data-retention policy usually answer most of this category.
0 pts
c3-1 Why the data is collected, and on what basis 0
c3-2 Retention and deletion 0
c3-3 Correction and deletion requests 0
c3-4 Data leaving the country 0
c3-5 Use of user data to train AI 0
C4
Security & Access Control
The controls that protect the product, its systems and its data. An information security policy, access-control screenshots, or an ISO 27001 or SOC 2 report are all accepted; external certification is not required.
0 pts
c4-1 Access control 0
c4-2 Protecting sensitive information 0
c4-3 Incidents, security and AI 0
c4-4 Testing and corrective action 0
C5
AI Models, Cloud Services & Third-Party Dependencies
The AI models, cloud services and other providers the product depends on. One table — provider, purpose, data, region — answers this category.
0 pts
c5-1 Dependency inventory 0
c5-2 Critical dependencies 0
C6
User & Stakeholder Engagement
How intended users and affected communities shaped the product, including language, culture and accessibility.
0 pts
c6-1 Stakeholders and consultation 0
c6-2 Language, culture and accessibility 0
c6-3 What feedback changed 0
C7
Complaints, Incidents, Appeals & Human Review
What happens when something goes wrong for a user: complaints, challenges to AI-supported decisions, and human review.
0 pts
c7-1 Complaints and feedback after launch 0
c7-2 Decisions about people, and human review 0
C8
Sustainability & Social / Local Impact
The difference the product makes for users, local jobs and skills, and the environment. Small and early-stage teams are not expected to have formal impact reports.
0 pts
c8-1 Benefits and measurable outcomes 0
c8-2 Effects on jobs and local skills 0
c8-3 Environmental and computing footprint 0

A pillar score is the sum of its sub-indicator scores. The total score is the sum of the four pillar scores. Detailed level descriptors for each sub-indicator are provided to applicants in the Applicant Portal.

Rating tiers

Ratings are awarded on total score and pillar floors. A weakness in any single pillar limits the overall rating — the weakest-pillar principle. Where the total meets a tier threshold but a pillar floor is not met, the rating is the highest tier whose floors are satisfied.

TierTotal scorePillar floor
FAIR Certified 0 – 100 Every pillar at least 0 / 0
Not certified Below 0 Or any pillar below 0 / 0

Applicants that are not certified may reapply after 0 months. The decision notice states the pillar-level reasons and the improvements required.

Documentation requirements

Core documentation is mandatory. Where the core documentation for a pillar is missing or materially incomplete, the score for that pillar is capped at 15 points regardless of the quality of other evidence, which in most cases precludes a Gold or Silver rating. Supplementary documents are optional, maximum two per pillar.

C1
Product & Solution Documentation
C2
Technical Architecture & Data Flow
C3
Privacy & Data Governance
C4
Security & Access Control
C5
AI Models, Cloud Services & Third-Party Dependencies
C6
User & Stakeholder Engagement
C7
Complaints, Incidents, Appeals & Human Review
C8
Sustainability & Social / Local Impact

Accepted formats are PDF, DOC/DOCX and common image formats. Each file must not exceed 15 MB. Documents may be submitted in any official UN language; AIFOD may request certified translations where necessary.

Process and safeguards
  • Stage 1 — completeness check. Automated review of mandatory fields, attachment readability, contact-email consistency, and the presence of core documentation. The assessment clock starts only when this passes.
  • Stage 2 — AI-assisted scoring. Three independent runs, median per pillar adopted. Advisory only.
  • Stage 3 — examiner interview. Intensity is proportionate to the provisional tier. Gold cases are interviewed by two examiners — one from the applicant's sector, one from the applicant's region.
  • Impartiality. No examiner may assess an application from an organisation with which they have a current or recent professional, financial or family relationship. All examiners file a conflict-of-interest declaration before assignment.
  • Auditability. The complete case file — application, attachments, AI assessment runs, interview records and examiner conclusions — is retained for the validity period of the certification plus two years.
  • Appeals. An applicant may appeal a decline or a tier award within 30 days. Appeals are reviewed by an examiner with no prior involvement in the case. The appeal decision is final.
  • Service standard. The target from completeness check to final decision is four to 6 weeks.
  • Publication. Certified systems are entered in the public registry showing the organisation, the AI system, the tier awarded and a four-pillar profile. Numeric scores are not published.