Readiness diagnostic

Answer the core controls. No answer is stored server-side in this MVP.

The product scope includes software modules, AI, APIs, data and updates delivered to customers.
A risk file links foreseeable use, misuse, potential harm and mitigation measures.
Vulnerabilities, dependencies, security tests and patches are tracked with dated evidence.
AI components have documented datasets, evaluations, limits, monitoring and withdrawal procedures.
Instructions, usage limits, integration requirements and warnings are available to customers and distributors.
Each delivered version can be linked to requirements, changes, tests, incidents and dependencies.
A post-market process collects incidents, complaints, weak signals and corrective actions.
Manufacturer, importer, distributor and integrator roles are contractualized and verifiable.
A customer communication, deactivation, urgent patch or software recall procedure is tested.
Evidence is kept in an auditable space with owner, date and retention period.

After the score

Turn every negative answer into an action plan: owner, expected evidence, due date and commercial risk.