| Information | |
| Title document: | AI Governance – Pre-assessment Cybersecurity |
| Version: | 1.3 |
| Status: | Live – June 15, 2026 |
| Document owner: | Cybersecurity - Lukasz Nowogrodzki |
| Target group and purpose | This document is intended for Business Process Owners (BPO), Procurement Teams, AI System Developers as its primary users. Information and answers to the following questions are needed to start the Cybersecurity Assessment. If further information and documentation is needed, the responsible assessment giver contacts the BPO. |
| Scope | |
| AI Tool Name & AI-REP No.: | |
| BPO Name: | |
| Date: |
| Specific information | ||
|---|---|---|
| # | Question | Answer (more than one can apply) |
| 1 | Application Provider | Company name / Fresenius (please describe) |
| 2 | Provider of the AI application | ☐ Fresenius development: Own in-house development |
| ☐ Third-Party provider (Packaged Software): Out of box/Custom-off-the-shelf Software Package | ||
| ☐ Fresenius Development (with Partner): Fresenius managed and developed with Partner support or using Partner provided AI components | ||
| ☐ Other: please describe | ||
| 3 | What is the primary hosting environment for this application and the data it processes? | ☐ Public cloud (e.g. AWS, Azure, Google Cloud) |
| ☐ Vendor private cloud/colocation (third party data center) | ||
| ☐ Fresenius owned/managed environment (on-prem) | ||
| ☐ Fresenius owned/managed environment (cloud) | ||
| ☐ | ||
| 4 | How is data provided to the AI system for processing or inference? | ☐ Manual input/conversation: prompt, chat interface. |
| ☐ File uploads: PDF, XLSX, images, audio... | ||
| ☐ Automated API/ETL integration from internal systems | ||
| ☐ Integrations: M365, SharePoint, Teams, Workday, ServiceNow, ERP, etc. | ||
| ☐ Other: please describe | ||
| 5 | AI model provider, hosting and inference control | ☐ External model provider API: e.g. OpenAI, Anthropic, Google, xAI |
| ☐ External model via managed cloud service: e.g. Azure OpenAI, AWS Bedrock, Google Vertex AI | ||
| ☐ Third-party/vendor-hosted model or AI application | ||
| ☐ Fresenius owned/managed environment (on-prem) | ||
| ☐ Fresenius owned/managed environment (cloud) | ||
| ☐ Partner-supported Fresenius deployment | ||
| ☐ Other: please describe model provider, hosting location and inference control | ||
| 6 | AI model types | LLMs, ML, embedding models, classification models etc. (please describe) |
| 7 | AI System capabilities | ☐ Prediction/Classification: Assigns categories or scores to input data (e.g., fraud detection, sentiment analysis) |
| ☐ Recommendation: Suggests items or actions based on data patterns (e.g., product or candidate matching) | ||
| ☐ Text generation: Produces written content (e.g., summaries, translations, chatbot responses) | ||
| ☐ Image generation: Creates or modifies visuals (e.g., marketing graphics, design prototypes) | ||
| ☐ Audio/Video generation: Produces or transforms audio/video (e.g., text-to-speech, synthetic media) | ||
| ☐ Code generation: Writes, reviews, or transforms source code (e.g., code assistants, test generation) | ||
| ☐ Decision support: Provides insights to support human decision-makers; user makes the final call | ||
| ☐ Agentic/orchestration: Executes multi-step tasks autonomously, calling tools or APIs without user's approval | ||
| ☐ Other: please provide the details in "Describe type of output" field | ||
| 8 | Does the AI system use AI agents or agentic workflows? | ☐ No agentic functionality: model only responds to direct user input |
| ☐ Single-step assistant: model provides output but does not perform actions | ||
| ☐ Semi-agentic workflow: model can suggest next steps or prepare actions for human approval | ||
| ☐ Agent with tool access: model can use approved tools, APIs, plugins or connectors | ||
| ☐ Autonomous agent: model can plan and execute multi-step tasks with limited human involvement | ||
| ☐ Multi-agent system: multiple AI agents interact or coordinate tasks | ||
| ☐ Other: please describe |
| Conditional agentic branch | ||
|---|---|---|
| Complete Q9-Q11 only if Q8 indicates agentic capability | ||
| # | Question | Answer |
| 9 | What level of autonomy does the AI agent have? | ☐ Human-in-the-loop: all actions require explicit human approval |
| ☐ Human-on-the-loop: agent acts automatically, but human supervision is available | ||
| ☐ Human-out-of-the-loop: agent acts without human approval during normal operation | ||
| ☐ Read-only agent: agent can retrieve/analyze data but cannot modify systems | ||
| ☐ Write-capable agent: agent can create, update, delete or submit information | ||
| ☐ External action-capable agent: agent can send emails, create tickets, call APIs, interact with third parties | ||
| ☐ Other: please describe | ||
| 10 | Which tools, systems or actions can the AI agent access? | ☐ No tools: model has no external tool or system access |
| ☐ Internal knowledge sources: SharePoint, Confluence, Teams, file repositories, knowledge bases | ||
| ☐ Business systems: ERP, CRM, Workday, ServiceNow, ticketing systems | ||
| ☐ Communication tools: email, Teams, etc. | ||
| ☐ Productivity tools: M365, documents, etc. | ||
| ☐ Developer /technical tools: code repositories, CI/CD, cloud consoles, monitoring systems | ||
| ☐ External APIs: third-party APIs, vendor APIs, public services | ||
| ☐ Other: please describe | ||
| 11 | Can the AI agent make changes to systems or data? | ☐ No: read-only access only |
| ☐ Draft only: agent prepares changes but a user must approve/submit | ||
| ☐ Limited write access: agent can update predefined fields or records | ||
| ☐ Full write access: agent can create, modify or delete records within approved scope | ||
| ☐ Transactional actions: agent can initiate purchases, payments, orders, approvals or operational workflows | ||
| ☐ Other: please describe |
| General controls - Q12 and Q13 | ||
|---|---|---|
| # | Question | Answer |
| 12 | Are guardrails implemented for the AI system? | ☐ No guardrails implemented ☐ Basic guardrails: system prompts, usage instructions, blocked topics ☐ Input guardrails: validation, filtering, prompt injection detection, PII detection ☐ Output guardrails: content filtering, data leakage checks, hallucination checks ☐ Tool-use guardrails: restrictions on tools, APIs, permissions and actions ☐ Policy-based guardrails: rules aligned with internal policies, legal, compliance or security requirements ☐ Runtime guardrails: real-time monitoring, blocking, escalation or fallback ☐ Other: please describe |
| 13 | Monitoring & alerting | Who monitors the system: Fresenius, application provider. What happens when guardrails block or flag content/action? (please describe) |