AIFOD publishes in full the rubric every application is scored against, the points allocated to each pillar and sub-indicator, and the role and limits of AI in the assessment. The assessment process is itself designed to comply with the FAIR principles it certifies. You can also score your own organisation against this rubric before applying.
Framework FAIR v2.0 · Procedure v2.0 · published 24 Aug 2026
Assessment combines a structured documentation review, AI-assisted scoring against the rubric below, and a confirmatory interview conducted by human examiners.
AI-generated scores are advisory. They triage, structure and inform the examination. They set a provisional tier and nothing more. No application is finally declined, and no rating is finally awarded, without human review and sign-off. Every decline and every rating carries the signature of the responsible human reviewer or examiners.
To reduce variance, each application is scored in three independent runs and the median score per pillar is adopted. For each pillar the engine produces a score out of 25, sub-indicator scores, the specific evidence it relied upon with document references, the evidence gaps it identified, and a list of questions recommended for the examiner interview. The full output, including its reasoning, is retained in the case file and is auditable.
An examiner may adjust the provisional tier by one level in either direction, with written reasons. An adjustment of more than one level requires the countersignature of a second examiner not previously involved in the case. Where two examiners disagree, a senior examiner decides.
Every application is assessed against four pillars of equal weight. Each pillar carries a maximum of 0 points, for a total score of 100.
| c1-1 | Purpose of the product or solution | 0 |
| c1-2 | The problem it is designed to address | 0 |
| c1-3 | Its primary users or beneficiaries | 0 |
| c1-4 | The countries or markets where it is used | 0 |
| c1-5 | The main AI-enabled functions | 0 |
| c1-6 | Whether AI models are developed internally or provided by third parties | 0 |
| c1-7 | Whether the product makes or supports decisions that may affect individuals | 0 |
| c2-1 | Where data originates | 0 |
| c2-2 | What types of data are processed | 0 |
| c2-3 | Which systems process the data | 0 |
| c2-4 | Which AI models or APIs receive data | 0 |
| c2-5 | Where data is stored, and relevant cloud/hosting regions | 0 |
| c2-6 | Who can access the data | 0 |
| c2-7 | Whether data is transferred across national borders | 0 |
| c2-8 | Major external system integrations | 0 |
| c3-1 | What personal or organizational data is collected, and why | 0 |
| c3-2 | The legal or consent basis for collection | 0 |
| c3-3 | Who can access the data, and where it is stored/processed | 0 |
| c3-4 | How long the data is retained | 0 |
| c3-5 | How users can request correction or deletion | 0 |
| c3-6 | Whether data is transferred internationally | 0 |
| c3-7 | Whether user data is used for AI training, fine-tuning or model improvement | 0 |
| c4-1 | Who can access production systems, and how permissions are granted | 0 |
| c4-2 | How privileged access is controlled, and whether MFA is used | 0 |
| c4-3 | How access is removed when employees or contractors leave | 0 |
| c4-4 | How sensitive information is protected | 0 |
| c4-5 | How security incidents are identified and handled | 0 |
| c4-6 | Whether security testing is conducted | 0 |
| c5-1 | Major AI models, cloud services and third-party providers are named | 0 |
| c5-2 | What each dependency is used for, and what data it processes | 0 |
| c5-3 | Processing/hosting region for each major dependency | 0 |
| c5-4 | Whether each dependency is critical to the product's operation | 0 |
| c6-1 | Relevant stakeholders are identified | 0 |
| c6-2 | Intended users, local communities or affected groups were consulted | 0 |
| c6-3 | Local language, cultural or accessibility needs were considered | 0 |
| c6-4 | What feedback was received, and whether it changed the product | 0 |
| c6-5 | How users can continue to give feedback after deployment | 0 |
| c7-1 | How users can submit complaints, and who investigates them | 0 |
| c7-2 | Expected response times and escalation procedures | 0 |
| c7-3 | How AI-related incidents are recorded and addressed | 0 |
| c7-4 | Whether an affected person can challenge an AI-supported decision and get meaningful human review | 0 |
| c7-5 | How corrective action is taken | 0 |
| c8-1 | Benefits delivered to users or communities, and measurable outcomes | 0 |
| c8-2 | Local employment, training, or capacity building | 0 |
| c8-3 | Workforce displacement or employment impacts | 0 |
| c8-4 | Accessibility and inclusion | 0 |
| c8-5 | Environmental / computing footprint and steps to reduce negative impact | 0 |
A pillar score is the sum of its sub-indicator scores. The total score is the sum of the four pillar scores. Detailed level descriptors for each sub-indicator are provided to applicants in the Applicant Portal.
Ratings are awarded on total score and pillar floors. A weakness in any single pillar limits the overall rating — the weakest-pillar principle. Where the total meets a tier threshold but a pillar floor is not met, the rating is the highest tier whose floors are satisfied.
| Tier | Total score | Pillar floor |
|---|---|---|
| FAIR Certified | 0 – 100 | Every pillar at least 0 / 0 |
| Not certified | Below 0 | Or any pillar below 0 / 0 |
Applicants that are not certified may reapply after 0 months. The decision notice states the pillar-level reasons and the improvements required.
Core documentation is mandatory. Where the core documentation for a pillar is missing or materially incomplete, the score for that pillar is capped at 15 points regardless of the quality of other evidence, which in most cases precludes a Gold or Silver rating. Supplementary documents are optional, maximum two per pillar.
Accepted formats are PDF, DOC/DOCX and common image formats. Each file must not exceed 15 MB. Documents may be submitted in any official UN language; AIFOD may request certified translations where necessary.