| Initial Step – Determine your Scope | ||
| AI Tool Name & AI-REP No.: | ||
| BPO Name: | ||
| Date: | ||
| Scope 1 – Standard | Scope 2 – Enhanced | |
| ALL of the following are true: | If ANY ONE of the following is true: | |
| * + The AI system is used purely internally within Fresenius + It does not affect external stakeholders (patients, customers, or third parties) + It does not influence critical or high-stakes decisions + Users retain full control and a meaningful opt-out option exists + It is deployed at limited scale (fewer than 1,000 users initially) | * + It affects external stakeholders (patients, customers, or third parties) + It supports or directly influences decisions with material consequences + Participation is mandatory or there is no meaningful opt-out + It is deployed at large scale or planned to scale significantly + It operates with limited human control over its outputs | |
| Complete Mandatory Questions | Complete Mandatory and Questions for Scope 2 | |
| Scope Results: | [ ] Scope 1 [ ] Scope 2 |
| How to Complete This Questionnaire | ||||
| Each row contains a screening question, what is required, and what evidence you must provide. Record your answer in the Outcome column. MANDATORY – Answering these questions is required for all applications. ONLY IF SCOPE 2 – Answering these questions is required for Scope 2 only. * Yes = Answer Yes if the requirement is met and evidence is either named, linked or provided. * No = Answer No if the requirement is not met. * N/A = Answer Not applicable if you consider that the question would not appear to be relevant for the AI Tool because of its intended use. Also, include a brief reason why the question is not applicable. | ||||
| Scope | Screening Question | Required Evidence | Outcome | |
| 1. Fairness & Non-Discrimination Ensure AI systems do not discriminate against protected groups and treat all users fairly across demographic characteristics. | ||||
| MANDATORY | Does the training data include diverse and representative samples across all key demographic groups (e.g. age, gender, ethnicity, language)? | Purchased: Training data sources, diversity, and representativeness documentation. Developed: Training data sources, diversity, and representativeness documentation. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Has bias testing been performed across all relevant user groups, and are results available? | Purchased: Bias testing reports or attestation with results. Developed: Bias testing reports, attestation with results, or documentation for flagging and addressing. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Is there a clear and accessible process for users to raise a complaint about discriminatory or unfair outputs? | Purchased: Grievance mechanisms and reporting channels description. Developed: Grievance mechanisms and reporting channels. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Is there an active mechanism to detect biased outputs during operation (not only at build or procurement stage)? | Purchased: Description of monitoring process and responsible party. Developed: Description of monitoring process and responsible party. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Has the system been tested for performance degradation with specific vulnerable populations (e.g. elderly, low-literacy users, minority groups)? | Purchased: Vulnerability assessments or attestation. Developed: Design documentation and attestation. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| 2. Transparency & Explainability Ensure AI decision-making processes are understandable, documented, and auditable by relevant stakeholders. | ||||
| MANDATORY | Can the AI model's decision-making logic be explained in plain, non-technical terms to users and affected persons? | Purchased: Clear documentation of the model's logic and decision-making process. Developed: Detailed documentation of the model's architecture, logic, and decision rules. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Are all data sources, documents, and inputs inventoried, versioned, and dated — with the active version confirmed? | Purchased: Written documentation of active version and applied decision rules. Developed: Detailed documentation of architecture, decision rules, and logic across versions, plus update logs. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Are audit trails maintained for key outputs and decisions, with a defined retention period and named access rights? | Purchased: Audit trail implementation details, retention period, and access rights. Developed: Audit trail implementation details. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Are users clearly informed before any interaction that they are engaging with an AI system? (EU AI Act Art. 50 — legal obligation) | Purchased: Screenshot or description of disclosure screen. If absent — STOP. Developed: User guides and accessible explanations. Opt-in/opt-out mechanisms. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Is the AI nature of the system visibly indicated throughout the interaction, and is all output clearly labelled as AI-generated? | Purchased: Screenshot or confirmation of labelling. Developed: Documentation on in-session indicator and output labelling. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Is information about the system's purpose, known limitations, and benefits readily available to all affected stakeholders in a language they can understand? | Purchased: User-friendly explanations for stakeholders. Developed: User guides and accessible explanations for stakeholders. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| 3. Accountability Establish clear ownership, responsibility structures, and procedures for AI governance, error handling, and risk management. | ||||
| MANDATORY | Is there a clearly defined accountability structure with a named individual (not just a team) responsible for the AI system's operation, outputs, and compliance? | Purchased: Named BPO for Fresenius. Developed: Accountability structure documentation with named individual. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Is there a documented process for reporting, escalating, and resolving AI errors or adverse outputs — including a defined response time for critical issues? | Purchased: Error reporting and resolution procedures. Developed: Error reporting and resolution procedures. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Does the vendor contract require advance written notification (minimum 30 days) before any material change to the AI model, scoring logic, data practices, or system architecture? | Purchased: Relevant clause in the vendor contract. Developed: N/A — applies to purchased solutions only. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Are fallback procedures defined for AI system failures — including a manual process to continue operations without the AI, and a method to detect post-update deviations? | Purchased: Fallback procedures including baseline benchmark documentation. Developed: Fallback procedures. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Is ongoing testing and monitoring implemented, including for emerging risks or unexpected changes in data or model behavior? | Purchased: Risk management plans. Developed: Risk management plans. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Is there a dedicated, named team or person for AI risk oversight with the authority and capacity to act on concerns? | Purchased: Accountability structure documentation. Developed: Accountability structure documentation. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Has the system undergone independent safety assessment or certification? | Purchased: Independent assessment reports. Developed: Independent assessment reports. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| 4. Human Oversight Ensure meaningful human control over AI systems with clear intervention points, override capabilities, and staff training. | ||||
| MANDATORY | Are there defined boundaries where human intervention is mandatory, and are these communicated to all users before they begin using the system? | Purchased: Human oversight mechanism documentation including intervention points. Developed: Human oversight protocols including intervention points. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Can humans review, override, or halt AI outputs without technical barriers — and is this process simple and immediate, not a multi-step escalation? | Purchased: Override or halt capability documentation. Developed: Override or halt capability documentation. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| MANDATORY | Does the deployment team have structured training on what the tool does, its known limitations, and how to identify unreliable outputs? Training must be completed before go-live. | Purchased: Staff training programs and session confirmation with date. Developed: Staff training programs, materials, and session confirmations. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Are oversight mechanisms regularly evaluated for effectiveness? | Purchased: Oversight mechanism evaluation process. Developed: Oversight mechanism evaluation process. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Is there a defined process for updating deployment team training when the tool changes materially or deployment scope expands? | Purchased: Staff training programs. Developed: Staff training programs and materials. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| 5. Social & Environmental Impact Assess and mitigate broader societal consequences and environmental impacts of AI deployment. | ||||
| MANDATORY | What is the system's energy consumption and carbon footprint? Are there energy consumption thresholds and alerts in place? | Purchased: Energy consumption data. Developed: Energy consumption data. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Have potential effects on communities, indirect users, and broader societal groups been assessed? | Purchased: Social impact assessments or stakeholder engagement records. Developed: Social impact assessments or stakeholder engagement records. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Are there mechanisms to monitor unintended social consequences? | Purchased: Social impact assessments, stakeholder feedback, and mitigation plans. Developed: Social impact assessments, stakeholder feedback, and mitigation plans. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Have workforce impacts (deskilling, job displacement) been evaluated, and are reskilling or upskilling programs available for affected workers? | Purchased: Workforce impact assessment. Developed: Workforce impact assessment. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) | |
| ONLY IF SCOPE 2 | Are sustainable energy sources used where possible? | Purchased: Sustainability measures documentation. Developed: Sustainability measures documentation. | ☐ Yes (please provide evidence) ☐ No ☐ Evidence provided ☐ N/A (please explain) |