Cardinal AI Systems
CDEA v1.1 · Self-assessment

Score one decision type

Six questions about a specific past decision. Returns your tier today, your tier at the end of your liability horizon, and the ratio between them.

Before you start. Pick one decision type, not your whole estate. Then pick one completed decision from at least nine months ago — long enough for log expiries and model updates to have taken effect. Answer about that decision, not about your policy.

Nothing you enter is sent anywhere. This runs entirely in your browser.

The decision

The longest of the applicable limitation period, regulatory record-keeping requirement, contractual obligation or realistic complaint window. Regulatory floors below the limitation period do not set the horizon.

The six tests

Test 1 · Input capture

Are the exact inputs to the decision retained, or only the output?

Verbatim inputs as submitted, retrievable for this named decision, including all documents and data passed to the system. Fails where inputs are summarised rather than retained, recoverable only by re-querying a database that has since changed, or where the prompt was templated and only the variables were stored without the template version.

Test 2 · System state

Is the state of the system at the point of decision recorded?

Model identifier and version, material configuration parameters, the version of any prompt template or rules layer, the identity and version of any retrieval corpus, and the vendor and endpoint. Fails where the vendor is recorded but not the version.

Test 3 · Human intervention

Where a person accepted, modified or overrode the output, is that act recorded with its rationale?

Identity of the individual, the action taken, the output as it was presented to them, and their rationale in their own words. Fails where "reviewed by" is captured without content, or where the interface did not retain what the model actually produced.

Test 3 · Follow-up

Does the firm claim human oversight as a control for this decision type?

In a policy, a regulatory submission, a DPIA, an Article 14 statement, or to customers. This changes the classification: a firm claiming oversight it cannot evidence is in a worse position than one that never claimed it.

Test 4 · Temporal integrity

Can the decision be rebuilt as it stood on the decision date, rather than as the system stands today?

The record is immutable or version-controlled, and the rebuild does not depend on any component that has since changed without a snapshot. Fails where the rebuild requires querying current customer records, where policies were updated in place, or where the exercise produces today's answer to yesterday's question.

Test 6 · Third-party rebuild

Could a competent person outside the firm perform the rebuild from the record alone?

Someone with no institutional knowledge, working only from the retained record. Note the difference between not having tried and having tried and failed: the first blocks the top tier, the second demotes.

Test 5 · Retention horizon

Retention periods for each component of the decision record, in months. Use what your systems are actually configured to, not what your policy says. The shortest-lived component governs, because a record missing one element cannot be rebuilt.

If a component sits with a vendor on the vendor's schedule and is not exported, enter the vendor's period, not yours.

Result

Standard result string

Report it in this form so results can be compared and cited.

Discuss this result

The discuss link opens your own mail client with the result already in the message. Nothing is sent until you send it.

How each test scored

TestTodayAt the end of the horizon

What would move the tier

This is a self-scored result, and a self-scored result is not evidence.

It tells you what you need to know internally, and for many purposes that is enough. But a supervisor, an insurer or an acquirer asking whether you can reconstruct an AI-assisted decision will not accept your own assessment of yourself — which is the same objection Test 6 makes about a rebuild performed by the team that built the system.

Cardinal AI Systems applies this method independently to a single decision type: both tiers, the ratio with its governing component, and a gap register naming what would have to change. Fixed fee, from £2,500. ronke@ronkejegede.com

Read the full method