Skip to main content

AI procurement assessment form

Extended risk assessment

  • What are the potential risks and negative impacts of implementing this AI system?
    • How will AI systems be used?
    • What is needed for accuracy?
    • How has the AI model been trained?
    • What data sources will be relied upon by an AI model to perform work?
  • How might it impact data privacy and security, especially with regard to sensitive information?
    • What data will be provided?
    • What sensitive data will be provided? (Note: Sensitive data includes but is not limited to: Personally Identifiable Information (PII) such as names, demographic data, geographic data, biological data, etc.; and intellectual property information)
    • How will the data that is provided be protected?
    • How will data that is provided be used?
    • What data will be produced?
    • How will data that is produced be used?
    • Are there any uses of our data by provider other than college use? For instance, will data be used for training an AI model in any way?
  • Vendor must contractually agree to handle all data in accordance with any applicable privacy laws and regulations
  • What are the implications of this system with respect to fairness, accountability and transparency?
    • How has vendor addressed bias in the use data or the creation of the output?
  • Vendor should warrant it has not infringed on third-party intellectual property rights in the AI system inputs or outputs
  • Does the system appear in the Augustana AI Systems Database with any flags or warnings?
    • If so, how will you address these warnings while using the system?
  • What concrete steps will be taken to mitigate identified risks?

Implementation considerations

  • Have Augustana's AI Professional Development Trainings been reviewed?
  • Consider transparency and whether the use of this system requires disclosure
  • What training will be required for safe & effective use? Does this training material already exist or will it need to be created?
  • How will the accuracy and fairness of outputs be verified?
  • What human oversight mechanisms need to be established to ensure safe and fair use?