<
Regulatory posture
- Which data protection regimes have you built to, and can you evidence it?
- For US institutions: how do your terms handle FERPA, given that in higher education the rights holder is the student?
- What is your position on the EU AI Act, including any classification you have assigned to your system?
- What documentation do you provide to help us meet our own obligations as a deployer, including staff AI literacy?
- How do you handle jurisdictional divergence for a multi-campus institution?
Question 18 is increasingly load-bearing for European institutions, because the AI literacy duty in Article 4 of Regulation (EU) 2024/1689 falls on deployers rather than on suppliers. A vendor that supplies training materials mapped to that duty saves you building them; one that has not considered the question is telling you how mature its institutional practice is.
Academic integrity posture
- What does your product do to prevent it being used to substitute for a student’s own work?
- Does the product generate disclosable process evidence — version history, drafting records — that an institution could rely on?
- Do you sell, in any part of your portfolio, tools intended to disguise machine-generated text?
- What claims do you make about detection accuracy, and what independent evidence supports them?
- How do your outputs interact with our existing similarity screening contract?
Question 22 should be asked of every supplier and answered across the whole catalogue rather than the tendered product. It is not a rhetorical trap: portfolios in this market genuinely contain products pointing in opposite directions, as we document in our review of what changed in integrity platforms this year.
Integration and operations
- Which SSO protocols do you support, and which identity providers are in production with comparable institutions?
- Which VLE or LMS integrations are generally available today, at which versions? Distinguish available from roadmap.
- What is a realistic implementation effort in institutional staff days, not vendor days?
- How are licences allocated and reclaimed as students enrol and graduate?
- What administrative reporting is available, and can we export it?
- What is your release cadence, and how much notice do we get of changes that affect users?
Question 30 has a specific history in this sector. When AI detection was switched on across a major platform, institutions reported receiving less than 24 hours’ notice and having no option to disable it. Ask for a notice commitment for feature changes that affect assessment, and ask for it in the contract.
Accessibility and inclusion
- Provide your current accessibility conformance statement and its date.
- What are the known exceptions, and what is the remediation timetable?
- Which assistive technologies have you tested with, and when?
- What evidence do you have about performance for users writing in a second language?
Question 34 matters more than it looks. Where products make judgements about writing, differential performance by language background is a documented risk in adjacent tooling, and an institution with an equality duty needs to have asked.
Commercial, support and exit
- What is the licensing model — per seat, per department, per institution — and how does it behave if enrolment falls?
- What are the price protection terms at renewal?
- What support is included, with what response targets, and in which time zones?
- What training is included for staff, and is it repeatable each year for new starters?
- On termination, in what formats can we export institutional and user data, and over what window?
- What happens to student accounts and their content when a student graduates?
- If you discontinue this product, what notice and transition support do we receive?
Question 41 stopped being hypothetical this year. At least one product in the standard comparison set for this category was withdrawn on a stated end date, so a written continuity answer belongs in the file rather than in the risk register as an unquantified entry.
Scoring the answers
Weight the sections against the problem you wrote down, not evenly. An institution buying to relieve a writing centre bottleneck should weight support, training and accessibility heavily; one buying to strengthen integrity casework should weight process evidence and the integrity posture section.
Then apply one rule that keeps the exercise honest: score what is contractual, and record separately what was merely stated. When two vendors score closely, the difference is almost always that one made commitments and the other made claims.
We are happy to answer this question set in writing for Tesify for Institutions before any call, including the training, sub-processor and exit questions. Request an institutional evaluation.
Frequently asked questions
Should we send all of these to every vendor?
Send the ownership, data protection and exit sections to everyone. The remainder can be scaled to the size of the contract.
What if a vendor answers verbally?
Ask them to confirm in writing and file the written version. Verbal assurances are not usable in a committee paper.
Which single question matters most?
Whether submitted content trains models, and whether that answer is contractual.
How long should we allow for responses?
Two weeks. Treat the response time itself as a data point about support quality.
Do we need a full tender?
That depends on your thresholds and rules. The question set is useful either way — for a tender it becomes the specification, and below threshold it becomes the due diligence record.
Can we reuse our standard IT questionnaire?
Use it as the base and add the model training, integrity posture and AI literacy sections, which standard questionnaires predate.
Should the academic side or procurement own this?
An academic owner should own the problem and the weighting; procurement should own the process.
How do we handle roadmap promises?
Score only what ships today. If a roadmap item is decisive, make it a contractual milestone with a remedy.
What if the vendor will not name sub-processors?
That is usually a stopping point for a data protection review, since you cannot assess a chain you cannot see.
Should we ask for references?
Yes, and ask for one institution that has been a customer for more than two years and one that has been through a renewal.
How does this fit with a pilot?
Shortlist on the written answers first, then pilot the leading candidate with pre-agreed criteria — see our guide to running a departmental pilot.
]]>
