A structured assessment of an AI vendor across EU AI Act value-chain obligations, data protection, model risk, security and DORA overlap. Every score is re-performable: the methodology, weights and per-question points are disclosed on screen and in every export.
The scoring is deliberately simple so that it can be independently re-performed in Excel from the CSV export, which carries points, maxima and weights for every line.
| Answer | Points | Treatment |
|---|---|---|
| Yes | 2 | Requirement met with evidence. |
| Partial | 1 | Partially met, or met without adequate evidence. |
| No | 0 | Not met. Listed as a gap. |
| Unsure | 0 | Scored as 0 on prudential grounds and flagged for follow-up. |
| N/A | — | Excluded from both numerator and denominator. |
Section score = 100 × Σ points ÷ (2 × applicable questions)
Overall score = Σ (section score × weight) ÷ Σ weights of applicable sections
Sections hidden by your scoping answers (e.g. DORA when you are not a financial entity) are excluded entirely and the remaining weights are renormalised. Unanswered questions count as applicable with 0 points, so the score starts low and is earned.
Defaults reflect a regulated-financial-sector risk appetite: documentation and data obligations carry the most weight. Adjust to your own appetite — entries are renormalised to 100% and every export records the weights actually used.
| Section | Weight | Effective |
|---|
| Overall score | Tier |
|---|---|
| ≥ 80 | Low residual risk |
| 60 – 79 | Moderate |
| 40 – 59 | Elevated |
| < 40 | High |
Two overrides sit on top of the arithmetic and are reported whenever applied: critical questions (marked ●) answered No or Unsure floor the tier at Elevated regardless of score; a use case identified as an Art. 5 prohibited practice sets the outcome to Blocked.