SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
D2

Data and information

PUBLISHED

Sourcing, judging and governing the information AI systems consume and produce.

Statements
Version
v1.29
Last reviewed
30.08.2026
In scope
Fitness for purpose of a data source for a given task
Provenance, lineage and the ability to say where information came from
Personal and sensitive data in prompts, context and logs
Consent and lawful basis, described abstractly with jurisdictional specifics in the indicators
Retention, minimisation and deletion in AI workflows
Structured and unstructured sources, and their different failure modes
Grounding output in sources, and citation of them
Verification of AI-produced claims before reliance
Information hygiene in shared and persistent AI workspaces
Out of scope
ExcludedWhere it lives
Data engineering pipelines and warehouse architectureOut of framework
Database administrationOut of framework
Retrieval and grounding architecture in depthX-RAG
Boundary notes

Where this domain abuts another, and how the line is drawn

Against D8 Security

D2 covers judgement about data. D8 covers protecting it. Where a statement concerns an adversary, it is D8.

Against D6 Evaluation and Assurance

D2 covers whether a source is fit to use. D6 covers whether the resulting system is fit to rely on.

Statements by level

Every identifier is a permanent address. Indicators are normative; they state what would be observed in a person who meets the statement.

L1 Aware

4 statements
D2.L1.01Knowledge

State where the information an AI system uses comes from.

Indicators
Distinguishes what the system was trained on from what it was given
Identifies whether the system can retrieve anything at the time of use
Recognises that the person supplying material is part of the supply
D2.L1.02Judgement

Recognise that information entered into a system may travel beyond the immediate task.

Indicators
States that prompts and attachments may be retained or logged
Checks before entering material whose sensitivity is unclear
Applies the same caution to context and history as to the prompt
D2.L1.03Judgement

Identify information that requires a source before it is used.

Indicators
Distinguishes a figure, date or quotation from a paraphrase
Identifies claims that would cause harm if wrong
Seeks the source rather than the system’s restatement of it
D2.L1.04Knowledge

Describe why an AI system may present unsourced content as though it were sourced.

Indicators
States that citations may be generated rather than retrieved
Checks that a cited source exists and says what is claimed
Recognises a plausible reference as no evidence at all

L2 Applied

7 statements

Check a factual claim in AI output against an authoritative source.

Indicators
Identifies the authoritative source for the class of claim
Checks the claim, not merely the existence of the citation
Records what was checked and what was not

Cite the sources used in and produced by AI-assisted work.

Indicators
Cites the underlying source rather than the system
States where the system contributed and how
Applies the organisation’s citation convention consistently
D2.L2.03Practice

Apply classification rules to material before using it with an AI system.

Indicators
Classifies before entering rather than afterwards
Applies the rule to attachments, context and retrieved material
Refers material whose classification is unclear

Establish the licence and permitted use of material supplied to or produced by a system.

Indicators
Identifies the licence before use rather than after publication
States whether the intended use is permitted
Refers cases where the licence is silent or unclear

Prepare source material so that a system can use it reliably.

Indicators
Removes duplication, obsolete versions and contradictions
Preserves structure the task depends on
States what was excluded and why

Record the provenance of AI-assisted output, including the material supplied.

Indicators
Records which sources were supplied and which were retrieved
Records the date and version of each source
Retains the record where the output is used

Recognise output shaped by an unrepresentative or incomplete source set.

Indicators
Identifies material absent from the supply that the task required
Distinguishes an omission in the source from an error in the output
Reports the gap rather than compensating for it silently

L3 Proficient

8 statements

Design the information supply for an AI system, including sources, refresh and exclusions.

Indicators
States each source, its owner and its refresh interval
States what is deliberately excluded and why
Provides for a source becoming stale or unavailable
D2.L3.02Judgement

Assess whether a source set is fit for the questions it will be asked.

Indicators
Tests the set against the questions actually expected
Identifies question classes the set cannot answer
States the consequence rather than only the gap

Diagnose failures caused by source quality rather than by the model.

Indicators
Isolates the source contribution before changing the model or instruction
Traces an incorrect output to the material that produced it
Corrects the source rather than patching the output

Design retention, minimisation and deletion for AI workflows.

Indicators
States what is retained, where, and for how long
Minimises what is supplied to what the task requires
Provides a deletion path that reaches context, logs and derived copies
D2.L3.05Judgement

Assess bias arising from source composition and state its consequence.

Indicators
Identifies whose material is over- and under-represented
States the effect on specific decisions rather than in general terms
Distinguishes a source bias from a model bias

Establish provenance requirements for output that will be published or relied upon.

Indicators
States the evidence required before publication
Defines who verifies it and how the verification is recorded
Provides for output whose provenance cannot be established
D2.L3.07Judgement

Advise on the use of personal, confidential or licensed material with AI systems.

Indicators
States the basis on which the use is or is not permitted
Identifies where an alternative achieves the purpose with less exposure
Records the advice and its reasoning

Design how conflicting sources are resolved and how the resolution is recorded.

Indicators
States precedence between sources in advance
Surfaces unresolved conflict rather than selecting silently
Records which source was preferred and why

L4 Advanced

4 statements
D2.L4.01Practice

Establish the organisation’s standard for information used by AI systems.

Indicators
Defines minimum provenance, quality and licensing requirements
Sets requirements proportionate to consequence
Establishes how compliance is verified
D2.L4.02Practice

Define ownership and accountability for source sets and their maintenance.

Indicators
Assigns a named owner to each significant source set
States the maintenance obligation, not only the ownership
Provides for the owner’s departure
D2.L4.03Judgement

Set the organisation’s position on training, retention and reuse by third-party providers.

Indicators
States what may and may not be shared with a provider
Establishes how contractual terms are verified rather than assumed
Reviews the position when terms change
D2.L4.04Practice

Hold accountable those responsible for source quality where output has caused harm.

Indicators
Traces the harm to the source and the obligation that was not met
Treats absent provenance as a finding rather than a neutral state
Requires a change to the supply, not only to the output
Editorial notes

Known gaps, open questions and contested points

Published because the record is more useful than the appearance of completeness.

Verification of AI-produced claims is the single highest-value competence in this domain and is under-taught everywhere. It should carry statements at L2, L3 and L4.

This page displays version 1.29 · last reviewed 30.08.2026