A market has formed around measuring what Medical Affairs delivers. That is a good thing, and it has produced the usual consequence: a set of demonstrations that all look similar, use overlapping vocabulary, and are difficult to tell apart in a sixty-minute call.
The questions below are the ones worth asking in that call. They are written to be useful in any medical affairs software evaluation, including one that does not involve us. Two of them we answer badly, and those are addressed honestly at the end — a checklist the author passes eleven times out of eleven is a brochure, and everyone recognises one.
For each, there is a note on what a weak answer sounds like. Weak answers are rarely evasive. They are usually confident, fluent, and about something adjacent to what you asked.
On the measure itself
1. Does the score measure the conversation, or the person running it?
This determines whether your field team will use the system honestly or defensively. A measure that functions as a performance rating changes the behaviour of the people producing its inputs, and the data degrades from that point on.
Weak answer: a description of dashboards showing MSL rankings, offered as a feature.
2. Where does the measure come from?
Ask what the score is calculated against. If the benchmark is derived from your own approved scientific content, the target is defensible. If it is a fixed rubric the vendor brought with them, or worse, tied to prescribing movement, you are measuring something other than science.
Weak answer: “our proprietary model,” with no account of what the model is scoring against.
3. What happens when the HCP declines recording?
A meaningful proportion of scientific interactions will never be recorded — preference, setting, local rules. If the system only produces intelligence when a recording exists, you have bought a measure of consent rates.
Weak answer: consent rates are high, so this rarely comes up.
4. Who signed off the clinical logic?
Somewhere in the product, a judgement has been made about what constitutes a good scientific discussion in your therapeutic area. Ask who made it. A named clinician with relevant experience is a different proposition from a data science team and a well-written prompt.
Weak answer: a reference to medical advisors, without a role or a name.
On the data
5. What is retained, for how long, and can it be deleted?
Get specific periods for audio, transcripts, derived insights and any voice data, and get them in writing. “Configurable” is not an answer — ask what the default is, because the default is what will apply.
Weak answer: enterprise-grade retention policies.
6. Which sub-processors see the content?
Ask for the list by name, and ask where it is published. Any third party that processes your scientific conversations is in scope, including transcription and model providers. Then ask how you are notified when the list changes.
Weak answer: the data is encrypted. That answers a different question.
7. Certified today, or in progress?
SOC 2, ISO 27001, HIPAA, 21 CFR Part 11. For each, the answer is held, in progress with a date, or not held. Vendors describing themselves as built to a standard are usually not certified against it, and there is nothing wrong with that as long as it is stated plainly rather than implied.
Weak answer: the word “compliant,” unqualified.
8. What happens to your data if you leave?
Ask for the export format, the timescale, and what is deleted afterwards. An HCP knowledge model that compounds over three years is valuable precisely because it cannot be quickly rebuilt — which makes it leverage unless the exit terms are clear at the start.
Weak answer: a reassurance that customers do not leave.
On the fit
9. Does it write back to your system of record, or sit alongside it?
If insights, questions and follow-up actions live only in the new platform, your team is now maintaining two records of the same interaction. That is a workload increase presented as a productivity gain.
Weak answer: an integrations page with logos, and no statement of what is actually written back.
10. What does it do on interaction one?
Every platform in this category is more valuable at interaction ten than interaction one, because history is the point. Ask what it does before any history exists. If the answer is thin, the pilot will be thin, and the pilot is what your evaluation is based on.
Weak answer: a description of what the system produces once it has been running for a year.
11. Who on the vendor's team has actually done this job?
Someone in the building should have carried a bag, run a field team, or sat inside a medical affairs function. Products built entirely from the outside get the workflow subtly wrong in ways that only surface after rollout.
Weak answer: advisory board members listed without roles.
Two of these we answer badly
Question 7. RocketMSL is not SOC 2 certified. The platform is built to SOC 2 controls and certification work is underway, but as of today the honest answer is “in progress,” not “held.” ISO 27001 is not held. Full 21 CFR Part 11 validation is not complete. If certification is a hard gate in your procurement process, that is a real constraint and it is better raised now than in month four. What we do hold is set out here.
Question 10. RocketMSL is more useful at interaction ten than at interaction one, and we would rather say so than pretend otherwise. On the first interaction with a new clinician there is no history to draw on, so preparation is generated from your approved content and the clinician's professional profile rather than from prior conversations. That is genuinely useful, and it is not what the platform is for. The compounding knowledge model is the reason to buy it, and compounding takes interactions.
Both of those are answerable. Neither is comfortable. The reason to publish them is that the other nine questions are only worth asking if the person handing you the list is willing to fail two of them.
If you want to work through the eleven against your own situation, talk it through with us.


