ESOMAR’s AI Guidance: Setting Standards for Ethical Research
When ESOMAR published its 20 Questions to Help Buyers of AI-Based Services in March 2024, the framework addressed a problem that most procurement processes in market research were not equipped to handle: evaluating AI tool providers when the tools themselves were new, the terminology was unsettled, and the questions worth asking had not yet been standardized.
The document is a buyer’s checklist designed to facilitate structured conversations between research firms and AI service providers, covering credentials, methodology, ethics, human oversight, and data governance. For insights leaders who sign off on research vendor relationships, it functions as a due diligence framework that makes the implicit evaluation criteria explicit.
Overview of ESOMAR’s AI Checklist
The framework is more useful than it first appears because it is not primarily about AI. It is about accountability, and that scope extends further than most readers initially realise.
The 20 Questions Framework
ESOMAR launched the 20 Questions framework on March 12, 2024, developed by its Professional Standards Committee working with industry experts in artificial intelligence and AI governance. Ray Poynter, ESOMAR President and head of the organisation’s AI Task Force, described the document as central to ESOMAR’s commitment to supporting research professionals in harnessing AI responsibly.
The framework is divided into five sections: company profile, explainability and fit-for-purpose, trust and ethics and transparency, human oversight, and data governance protocols.
Three Core Themes: Trust the Company, the Process, and the Data
QuestionPro’s analysis of the ESOMAR framework identifies three underlying themes that the 20 questions are really asking buyers to evaluate, each framed around a different dimension of trust. The first is whether the buying organisation can trust the company supplying the AI service, covering track record, credentials, and institutional values.
The second is whether they can trust the process, meaning the sourcing methodology, the validation steps, and the bias controls. The third is whether they can trust the data, covering ownership, lineage, privacy protections, and quality assurance.
Key Guidance Areas
The five sections of the framework each reveal a different category of due diligence question, and they become more interesting as you move deeper into them.
Company Profile and Expertise
The first section of the ESOMAR 20 Questions asks buyers to assess the credentials and track record of the AI service provider before evaluating anything about the service itself. This is the same logical sequence that applies to any research vendor relationship: the quality of the service depends partly on the competence and stability of the organisation providing it, and an impressive product demo from a team without deep research methodology experience carries a different risk profile than the same capability delivered by a firm with demonstrable domain expertise. Some published ESOMAR 20 responses are considerably more concrete than others, which itself communicates something meaningful about the provider’s level of institutional rigour.
Explainability and Fit-for-Purpose
The second section asks whether the AI capability matches the buyer’s actual research objectives and whether the provider can explain how the system works in sufficient detail for a professional research buyer to evaluate it. Explainability is a higher bar than it sounds. A provider who can describe their model at the level of inputs, processing logic, and output validation has a fundamentally different accountability relationship with the buyer than one who can only describe the interface.
For insights leaders evaluating AI tools against specific study types, including VOC programmes, qualitative coding, market sizing, or competitive intelligence, the fit-for-purpose question requires matching the provider’s actual capability to the specific methodology the study demands.
Trust, Ethics and Transparency
Section three addresses the alignment between buyer and supplier on ethical principles, bias mitigation, data security, and the resilience of the AI system under edge cases. The 2025 ICC/ESOMAR International Code now includes specific guidance on AI and emerging technologies, reinforcing the 2024 checklist with regulatory weight: duty of care, data minimisation, transparency, and human oversight are explicitly embedded in the updated Code, which has been adopted across many associations and markets globally.
The bias question in the ESOMAR checklist, asking providers how they identify, measure, and handle skewed or unreliable outputs, is the same question a research director should be asking any data provider whose outputs will inform a recommendation that goes to a client.
Human Oversight
The fourth section asks buyers to understand how human involvement has been built into both the development and the ongoing operation of the AI service. Research World’s August 2025 analysis of the 2025 ESOMAR Code quotes ESOMAR council member Lucy Davison on why this matters: trust in the data collected, analysed, and presented as insight is paramount to the future of market research, and the Code provides the ethical guardrails to ensure that human researchers remain the accountable party regardless of what technology is used.
For AI tools used in qualitative coding, theme identification, or synthesis, the human oversight requirement translates into a documented review process where a trained researcher examines AI output before it enters the deliverable chain.
Data Governance Protocols
The fifth section covers data quality, lineage, sovereignty, ownership, and compliance. For buyers operating across multiple jurisdictions, the data governance section of the ESOMAR checklist becomes a legal compliance exercise as much as an ethics one: a provider whose data collection and processing practices are not documented against GDPR, UK GDPR, and equivalent frameworks in operating markets creates downstream liability for the research firm using their service.
Think of it the way a supply chain auditor approaches a new vendor in a regulated industry: the quality of the finished product is only as trustworthy as the governance of the materials that went into it, and the same logic applies to AI-generated research outputs.
Implications for Researchers and Buyers
The practical question for insights leaders is not whether to engage with the ESOMAR framework but how to operationalise it inside their own vendor evaluation processes.
Due Diligence Questions in Practice
ESOMAR’s 20 Questions are intentionally structured as a conversation framework rather than a pass-fail checklist, because the most important information is often revealed not by the answer but by how the provider responds to the question.
A provider who can explain their bias testing methodology in operational terms, who can describe their human review process with specific examples, and who can produce their data governance documentation on request is demonstrating a level of institutional maturity that affects the risk profile of every project that flows through their platform. Providers who respond to technical questions with marketing language are communicating something equally informative about how their accountability is structured.
Aligning With Client Values
For research firms presenting AI-assisted deliverables to clients, ESOMAR’s framework provides the vocabulary for a conversation that clients are increasingly asking to have. The same questions clients use to evaluate whether a research firm’s methodology is credible, covering transparency, human oversight, and data quality, now extend to the AI tools embedded in that methodology.
A firm that can demonstrate its AI vendor relationships are governed by the ESOMAR framework is making a claim about the integrity of its research process that clients in regulated industries, including financial services, healthcare, and consumer goods, will find relevant when they review methodology documentation.
Staying Informed on ESOMAR’s Evolving Standards
The 2024 AI buyer checklist and the 2025 ICC/ESOMAR Code update are part of an ongoing standard-setting process, and the direction of travel is clear: greater explainability requirements, more explicit human oversight obligations, and stronger data governance documentation standards across the board.
The updated Code is being adopted across markets through 2026, with MRSI implementing it in India from April 2026. For insights leaders whose vendor landscape is expanding to include AI-native tools alongside traditional panel providers, expert networks, and qualitative agencies, the practical answer to staying current is treating the ESOMAR frameworks as a living audit checklist rather than a one-time procurement document.
The Checklist Is the Starting Question, Not the Final Answer
ESOMAR’s 20 Questions framework does not tell buyers which AI tool to select. It tells them which questions to ask before they make that selection, and it structures those questions around the three things that determine whether any research service is trustworthy: the organisation behind it, the process it runs, and the data it produces.
The same architecture applies to every research service relationship, including expert networks whose sourcing methodology, credential verification process, and compliance documentation are exactly the categories the ESOMAR framework was designed to surface. Buyers who internalise this framework stop evaluating research vendors on capability demos and start evaluating them on the quality of the answers they give to the questions that reveal whether the capability is actually there.
Looking for a research partner whose sourcing and compliance hold up to the ESOMAR standard? Talk to Nexus Expert Research about how we vet, document, and deliver expert insight.