The artifacts, one page each
An assessor does not ask whether you have a policy. They ask for the policy, the date it was approved, and the record showing it ran. These are the fifteen artifacts that answer.
1. Governance
AI governance committee charter
The charter, the membership roster against it, and minutes for the last three meetings.
Signed by the chief executive, or the board committee that delegates the authority
AI use case registry
The register, and the method by which it was compiled. The second question is harder and more revealing.
Signed by the accountable executive for ai, usually the cmio or chief digital officer
Board reporting pack
At least one board or board-committee paper in the last twelve months reporting AI use and outcomes.
Signed by the accountable executive, to the board quality or audit committee
Organizational AI policy
The approved policy dated within twelve months, the approving body named, and version history.
Signed by the policy committee that approves clinical and administrative policy
Programme resourcing plan
Named individuals with allocated time, not a roster of people doing this on top of existing roles.
Signed by the chief financial officer, on the accountable executive's request
2. Effective data management
Data use agreement
The template, and the executed agreement for every vendor in the register that touches PHI.
Signed by the privacy officer, counter-signed by the contracting owner
AI security control record
Encryption, access controls, evidence of log review with a named reviewer, security assessments, and an exercised incident response plan.
Signed by the chief information security officer
3. Risk and bias reduction
Local bias assessment
Performance broken out by the subgroups you actually serve, on your own population, with a date.
Signed by the quality or equity officer, jointly with the ai committee
Intake and risk-tiering procedure
The written rule, and the tier assigned to every entry in the register.
Signed by the ai governance committee chair
Vendor AI disclosure request
A standard question set, answered in writing, retained with the contract. Blanks are a finding.
Signed by supply chain, counter-signed by the ai committee
4. Monitoring, evaluating and validating
Local validation memo
A written protocol and a result, on your data, for every tool in the top risk tier.
Signed by the clinical sponsor and the ai committee jointly
Post-deployment monitoring plan
Metrics, thresholds, an owner and a review frequency tiered by risk — and evidence a review happened.
Signed by the operational owner of the workflow the tool sits in
AI safety event reporting route
The internal route a clinician uses, plus a decision on external voluntary reporting with the mechanism named.
Signed by the patient safety officer
5. Transparency, education and training
Patient disclosure standard
A written rule for when patients are told, what they are told, and the actual wording used.
Signed by the chief medical officer, with privacy and legal
Training curriculum and attestation
Completion records by role for every tool in the register, and evidence training preceded go-live.
Signed by the chief learning officer, or nursing and medical education