Role & product
Who is the provider of the AI system/model, what is the intended purpose, and which version/service is being supplied?
Upstream dependencies
Which third-party models, APIs or material AI components does the service depend on?
Data provenance
What data was used where relevant, what is its provenance, and what governance/quality controls were applied?
Performance
What metrics and test populations support the claimed performance for the intended use?
Bias & impacts
What groups and failure modes were tested, what limitations remain, and how are residual risks communicated?
Human oversight
What information and controls enable the customer to understand, challenge, override or stop the AI where needed?
Logging
What logs are generated, who can access them, how long are they retained and how can the customer use them for monitoring?
Security
What AI-specific security testing, vulnerability management and incident response are in place?
Transparency
What technical or user-facing features help the customer meet applicable transparency duties?
Changes
How will customers be notified of model, data, functionality, intended-purpose or material performance changes?
Incidents
What is the process and timeframe for notifying customers of serious incidents, material failures or relevant regulatory issues?
Conformity evidence
Where relevant, provide applicable technical documentation, instructions for use, declaration/CE evidence and registration information.