
In 2024, ESOMAR published its 20 questions for buyers of AI-based market research services. We welcome the initiative. A framework that asks every AI vendor the same questions — about their models, their validation processes, their data practices, and their human oversight — gives buyers a kind of clarity that no vendor’s marketing can provide. It puts transparency ahead of positioning.
This article gives you our headline answers by section, in plain language. The full detailed document will be available to download shortly.
For each of the five sections, we explain what ESOMAR is asking for, then give CodexMR’s answer in plain language.
If you’re still deciding which questions to ask before you shortlist, the first article in this series covers that: Before the Demo: The Questions That Separate AI Market Research Vendors.
Keep reading.
Section A: Company Profile — What ESOMAR Asks, and Who We Are
ESOMAR’s opening section asks buyers to verify three things: that the vendor has real research expertise alongside their AI capability, that they have deployed at a meaningful scale, and that they can talk honestly about what has gone wrong.
The last point is the most useful. A vendor with no honest answer here has either not deployed at real scale or is not being straight with you.
CodexMR’s answer: CodexMR is built from the combined practice of Bright MR and Kalever in Sofia, Bulgaria. Within our operations, there are people building complex survey code and database structures in real development languages for more than 15 years — and who know quantitative market research in the same depth. The same person writes the code and understands what the research requires of it.
Getting AI to 70% accuracy is the easy part. The last 30% is where human expertise takes over — the judgment calls, the market knowledge, the client-specific standards that no general model carries by default. That is not a gap you automate. It is where your team’s experience matters most.
Section B: Explainability — What ESOMAR Asks, and How Our Platform Works
Section B asks vendors to explain their AI in plain language. Which models are used? Was the system built in-house or does it rely on third parties? How is client data handled? These questions catch vendors who are vague for a reason.
CodexMR’s answer: CodexMR uses a hybrid architecture. Google Gemini is the primary foundation model in current production workflows. The Platform also integrates Anthropic Claude and OpenAI GPT for selected tasks and client-specific requirements.
Our proprietary value is not the underlying model. It is the survey intelligence built around it: workflow design, structured schemas, validation rules, routing logic, QA processes, and the human review layer.
Client data is not used to train a shared model or influence another client’s result. The Platform uses client material to deliver the agreed task. That is the boundary, and it is a clear one.
Section C: Trust and Validation — What ESOMAR Asks, and How We Validate Output
This is where the ESOMAR 20 questions market research framework gets most specific — and where most vendor answers are thinnest. ESOMAR asks how output is verified before it reaches the client, what the known limitations are, and how the service handles unreliable results.
CodexMR’s answer: Validation is built into the Platform workflow before programming begins, not added as a final check.
Research Ready — our questionnaire validation tool — checks a survey across seven areas before a single line of code gets written: design, logic, compliance, data quality, language, respondent experience, and statistics. Everything flagged is documented and ready to act on.
Once the survey is built, QAReady checks it against the source and flags every mismatch — question order, wording, logic, quotas, code. On trackers, it compares wave to wave.
Both tools run independently from the tools that generate output. That is what makes the review a genuine second opinion.
Section D: Human Oversight — What ESOMAR Asks, and Where the Human Sits
Section D asks vendors to be specific about how AI use is communicated to clients, what ethical principles govern the system, and how human oversight is built into delivery — not promised in a policy document but structured into actual workflow.
CodexMR’s answer: The Platform distinguishes AI-generated output from human decisions at every step — what was generated, what was reviewed, and what was approved is visible throughout. The human is not limited to a sign-off at the end. An integrated AI assistant allows teams to communicate, question, and adjust the output at any point in the process.
The three ways to use the Platform — DIY, DIT, and DIFM — are three distinct models of human oversight, not a pricing structure.
In DIY mode, the client’s quant ops team or senior programmers operate the Platform directly. Their expertise is the oversight layer. DIT (Do It Together) mode adds a CodexMR expert working alongside the client team at the stages where specialist judgment matters most — complex routing, multi-language QA, research validation, and data-processing decisions. DIFM (Do It For Me) takes it further: our delivery team manages the work end to end, with human expert oversight at every stage.
The mode changes where the review sits. The Platform and its controls stay the same across all three.
Section E: Data Governance — What ESOMAR Asks, and How We Handle Data
Section E covers the questions with the highest legal and commercial stakes: data quality, lineage, privacy compliance, security, and who owns the output. Eight questions in total — and the ones most buyers forget to ask until they matter.
CodexMR’s answer, in brief: CodexMR is an EU-grown company. GDPR-aware practice is built into how the Platform is designed and reviewed. Client data is used to deliver the requested service — not to train a shared model or affect another client’s result.
Client-specific research outputs belong to the client under the applicable agreement. CodexMR does not claim ownership of findings or use them as a shared training asset. The Platform can work within the client’s existing survey and data systems, preserving their operating environment and audit trail. We are currently obtaining ISO certification, expected within the next few months.
The full data governance answers — processing locations, sub-processor details, contractual terms, and security frameworks — are in the detailed document below.
These are our headline answers. The full response to all 20 ESOMAR questions — covering every section in detail, including the technically complex areas on data lineage, sovereignty, and security — is coming soon to download.



