Write down an answer to every question. Do not fill a gap with "the vendor handles that." If nobody can name the purpose, source, decision boundary, accountable person, failure process, or exit plan, the system is not ready to be trusted.
The printed version removes navigation and keeps the eight questions together for review.
-
01
What exact problem are we solving?
Name the problem in one sentence without using the words AI, innovation, transformation, or efficiency. Then ask whether a simpler process, more staff, better training, or a non-AI tool would solve it with less risk.
- What outcome should improve?
- How will we know whether it actually improved?
- What will we stop doing if it does not work?
-
02
Whose work and data made it possible?
Identify the training data, customer data, employee data, student work, creative material, recordings, or other inputs the system depends on. Ask what the people behind those inputs were told and what choice they had.
- Can the source be explained in plain language?
- Were permissions specific to this use?
- Can data or work be removed later?
-
03
Who is affected but missing from the room?
List the people who will live with the system, not only the people buying it. Include workers, applicants, customers, students, creators, contractors, and communities whose access or treatment may change.
- Have affected people seen the proposal?
- Can they raise a concern without retaliation?
- Does refusal remove access to something essential?
-
04
What is the system allowed to decide?
Draw a visible line between assistance, recommendation, ranking, monitoring, and final authority. High-stakes decisions need more than a vague promise that a person remains involved.
- Which decisions always require a person?
- What information does that person receive?
- Can they override the system without penalty?
-
05
What evidence supports this use?
Ask for evidence that matches the real setting, population, language, and consequence. A polished demo is not evidence that the system is accurate, fair, secure, or useful in your context.
- What was tested, by whom, and against what baseline?
- What failures were found?
- How will performance be monitored after launch?
-
06
Who owns the failure?
Name the person with authority and responsibility when the system is wrong, discriminatory, unsafe, or simply unhelpful. A vendor support address is not an accountability structure.
- How does a person report a problem?
- How quickly must somebody respond?
- Can a decision be corrected and its effects repaired?
-
07
Who gets the value and who carries the cost?
Follow time saved, money made, jobs changed, creative work used, errors corrected, and new monitoring back to the people involved. Do not call a system efficient when its unpaid cleanup is hidden.
- Will workloads, staffing, pay, or credit change?
- Who performs correction and quality control?
- Do affected people share in the gain?
-
08
How do we stop, appeal, or leave?
Set review dates, stop conditions, an appeal route, and a way to return to a human process. A system becomes harder to question once budgets, jobs, and records depend on it.
- What triggers a pause or shutdown?
- Can people choose a non-AI route?
- Who reviews renewal, expansion, or removal?
Three stop signs.
Pause the decision when nobody can identify the accountable owner, when an affected person has no way to appeal, or when the organization cannot explain what data and work the system uses. Those are not details to solve after launch. They are the conditions that decide whether the system deserves to launch.
Why this checklist is human-first.
The checklist is deliberately stricter than a feature comparison. It draws from the same basic risk-management ideas found in the NIST AI Risk Management Framework: defined responsibility, documented boundaries, ongoing review, and meaningful oversight. It adds a public-interest question that procurement forms often miss: did the people carrying the consequences get a real say?
This is not a compliance certification. It is a way to make hidden assumptions visible before speed and sunk cost turn them into policy.
Sources and further reading.
- 01NIST AI Risk Management Framework Core
- 02International Labour Organization: GenAI, jobs, productivity, and work organization
- 03U.S. Copyright Office: Copyright and Artificial Intelligence initiative