1EdTech TrustEd Apps Rubric for AI: A Governance Guide
A standards-based evaluation framework for assessing vendor disclosures on privacy, security, transparency, and efficacy during edtech procurement, and a clear view of where that baseline ends.
What the rubric establishes as a baseline
Before diving into procurement workflow design, it helps to name the dimensions the rubric is built to surface. These are disclosure categories, not runtime guarantees.
Data privacy
Vendor disclosures on data collection, use, and student data handling.
Security
Documented security practices and safeguards for institutional data.
Transparency
Disclosure of how AI features function and what data informs them.
Efficacy signals
Vendor-provided context on intended use and expected outcomes.
What the TrustEd Apps Rubric for AI evaluates
1EdTech Consortium, formerly IMS Global Learning Consortium, is a nonprofit standards organization that publishes interoperability and trust frameworks for education technology. Its TrustEd Apps program is a rubric-based evaluation model that asks vendors to document baseline privacy and security practices, giving institutions a standardized way to compare vendor disclosures during procurement rather than negotiating ad hoc questionnaires with every vendor.
1EdTech has publicly signaled that it is extending this rubric framework to address AI-specific considerations in edtech, which would introduce evaluation dimensions not present in traditional software checklists, such as how training data is sourced and used, how model outputs are validated, and how vendors handle data collected for model improvement. Publicly available documentation does not specify the exact wording or scoring structure of the AI-specific criteria, or how each item differs from the original rubric line by line.
Institutions reviewing a vendor's rubric response should request the specific rubric version used and confirm that it corresponds to the current AI capabilities of the product being purchased, rather than an earlier non-AI version of the same tool.
How the rubric should function in AI procurement
Rubric evaluation frameworks of this type rely on vendor-submitted responses, which means the quality of the evaluation depends heavily on the reviewing institution's own verification process rather than independent audit by the standards body. A completed rubric response should be treated as structured documentation, not as certification of vendor practice.
In a procurement workflow, the rubric fits earliest, typically at the pre-RFP or shortlist stage, where it helps compare vendor claims against a consistent baseline before formal legal and security review begins. Because the rubric is designed to evaluate software generally, institutions applying it to AI tools need supplementary questions covering training data provenance, visibility into any third-party foundation model the vendor relies on, and how frequently the underlying model changes after initial evaluation.
Rubric outcomes carry no enforcement mechanism on their own, so results should be paired with binding contractual terms covering data use, breach notification, and audit rights before a vendor relationship is finalized.
| Topic | What the rubric provides | What the institution still owns |
|---|---|---|
| Evidence type | Vendor-submitted, structured disclosures | Verification against docs, demos, and contracts |
| Timing | Pre-RFP or shortlist comparison baseline | Legal, security, and policy review before award |
| AI change risk | Point-in-time product representation | Re-evaluation triggers when models or features change |
| Enforcement | No standalone enforcement mechanism | Contract terms, audit rights, operational controls |
Where static evaluation ends and runtime governance begins
A rubric evaluation captures a point-in-time snapshot of documented vendor practices. It does not, by design, provide visibility into how an AI application behaves in production, how often a vendor updates its underlying model, or whether real-world data handling matches what was disclosed during evaluation. This is a structural characteristic of rubric-based programs generally, not a specific shortcoming of TrustEd Apps.
Institutions that treat a passing rubric score as ongoing assurance are extending a static evaluation beyond what it is built to support. Once an AI tool is deployed, governance responsibility shifts from documentation review to operational oversight: tracking what data the tool accesses, what actions it can take within institutional systems, and whether its behavior remains consistent with what was represented during procurement.
This is the layer where runtime governance and policy enforcement become relevant, applying controls such as agent identity, least-privilege permissions, tool approval workflows, and audit logging to AI tools after they are approved. Trussed AI provides this category of runtime governance and monitoring for AI agents in production, functioning as a complement to procurement-stage frameworks like TrustEd Apps rather than a substitute for them.
Practical boundary
Use the rubric to standardize what vendors claim before purchase. Use runtime governance to observe and constrain what approved AI tools actually do after deployment.
Implementation considerations for technology directors
- Define where the rubric fits in the lifecycle: Decide whether rubric review functions as a pre-RFP screen or a final gate, and document that decision in procurement policy.
- Validate rather than accept self-attestation: Build a process to check vendor rubric responses against actual documentation rather than treating them as verified fact.
- Pair rubric outcomes with contract terms: Link rubric results to enforceable contractual language on data use, breach notification, and audit rights.
- Train staff to interpret scores in context: Ensure procurement staff understand that a passing rubric result is one input, not a complete risk assessment.
- Set a re-evaluation cadence: Trigger re-review when a vendor changes its underlying model, adds AI features, or updates its data practices.
Questions to ask before accepting a vendor's rubric response
These checks keep rubric intake tied to the product version you are buying and to the controls that continue after approval.
- Does the rubric submission reflect the current version of the AI product being purchased, or an earlier iteration?
- What specific AI-related criteria, such as training data use and model update practices, are included, and how were they verified?
- How does the rubric evaluation integrate with our institution's existing vendor risk assessment and contract review process?
- What is the process and cadence for re-evaluating the vendor if the AI model or underlying provider changes after approval?
- What monitoring, incident response, or audit mechanisms exist beyond the rubric to detect issues after deployment?
Frequently asked questions
Is the TrustEd Apps Rubric for AI a certification?
Based on available information, TrustEd Apps functions as a structured evaluation and documentation framework rather than a formal certification with independent audit. Institutions should confirm current program terminology directly with 1EdTech before treating a rubric result as certification.
Does a passing rubric score satisfy student data privacy compliance?
No. The rubric is an input to institutional compliance review, not a replacement for it. Institutions remain responsible for meeting applicable student data privacy obligations regardless of a vendor's rubric status.
How often should AI vendors be re-evaluated after initial approval?
Because AI systems can change through model updates or new features, governance programs should define specific triggers for re-review, such as vendor model changes, rather than relying on a single initial evaluation.
Extend procurement evaluation into runtime oversight
A rubric evaluation establishes a baseline before deployment. Runtime governance addresses what happens after an AI tool is approved and put into use.
Explore Runtime Governance