C1 — Product & Solution Documentation
What the product does, where it is used, and how it uses AI. A product deck, overview or website usually covers this whole category.
c1-1 — Purpose, problem and who it serves
0 = no evidence at all, 10 = fully met, backed by hard evidence
c1-2 — Where it is used
0 = no evidence at all, 10 = fully met, backed by hard evidence
c1-3 — AI functions and their limits
0 = no evidence at all, 10 = fully met, backed by hard evidence
C3 — Privacy & Data Governance
How personal and organisational data is collected, kept, transferred and deleted. A privacy policy and a data-retention policy usually answer most of this category.
c3-1 — Why the data is collected, and on what basis
0 = no evidence at all, 10 = fully met, backed by hard evidence
c3-2 — Retention and deletion
0 = no evidence at all, 10 = fully met, backed by hard evidence
c3-3 — Correction and deletion requests
0 = no evidence at all, 10 = fully met, backed by hard evidence
c3-4 — Data leaving the country
0 = no evidence at all, 10 = fully met, backed by hard evidence
c3-5 — Use of user data to train AI
0 = no evidence at all, 10 = fully met, backed by hard evidence
C4 — Security & Access Control
The controls that protect the product, its systems and its data. An information security policy, access-control screenshots, or an ISO 27001 or SOC 2 report are all accepted; external certification is not required.
c4-1 — Access control
0 = no evidence at all, 10 = fully met, backed by hard evidence
c4-2 — Protecting sensitive information
0 = no evidence at all, 10 = fully met, backed by hard evidence
c4-3 — Incidents, security and AI
0 = no evidence at all, 10 = fully met, backed by hard evidence
c4-4 — Testing and corrective action
0 = no evidence at all, 10 = fully met, backed by hard evidence
Nothing you enter here is saved or sent to AIFOD.
See my indicative score