Evidence
Evidence library

The artifacts, one page each

An assessor does not ask whether you have a policy. They ask for the policy, the date it was approved, and the record showing it ran. These are the fifteen artifacts that answer.

1. Governance

AI governance committee charter

The charter, the membership roster against it, and minutes for the last three meetings.

Signed by the chief executive, or the board committee that delegates the authority

AI use case registry

The register, and the method by which it was compiled. The second question is harder and more revealing.

Signed by the accountable executive for ai, usually the cmio or chief digital officer

Board reporting pack

At least one board or board-committee paper in the last twelve months reporting AI use and outcomes.

Signed by the accountable executive, to the board quality or audit committee

Organizational AI policy

The approved policy dated within twelve months, the approving body named, and version history.

Signed by the policy committee that approves clinical and administrative policy

Programme resourcing plan

Named individuals with allocated time, not a roster of people doing this on top of existing roles.

Signed by the chief financial officer, on the accountable executive's request

2. Effective data management

Data use agreement

The template, and the executed agreement for every vendor in the register that touches PHI.

Signed by the privacy officer, counter-signed by the contracting owner

AI security control record

Encryption, access controls, evidence of log review with a named reviewer, security assessments, and an exercised incident response plan.

Signed by the chief information security officer

3. Risk and bias reduction

Local bias assessment

Performance broken out by the subgroups you actually serve, on your own population, with a date.

Signed by the quality or equity officer, jointly with the ai committee

Intake and risk-tiering procedure

The written rule, and the tier assigned to every entry in the register.

Signed by the ai governance committee chair

Vendor AI disclosure request

A standard question set, answered in writing, retained with the contract. Blanks are a finding.

Signed by supply chain, counter-signed by the ai committee

4. Monitoring, evaluating and validating

Local validation memo

A written protocol and a result, on your data, for every tool in the top risk tier.

Signed by the clinical sponsor and the ai committee jointly

Post-deployment monitoring plan

Metrics, thresholds, an owner and a review frequency tiered by risk — and evidence a review happened.

Signed by the operational owner of the workflow the tool sits in

AI safety event reporting route

The internal route a clinician uses, plus a decision on external voluntary reporting with the mechanism named.

Signed by the patient safety officer

5. Transparency, education and training

Patient disclosure standard

A written rule for when patients are told, what they are told, and the actual wording used.

Signed by the chief medical officer, with privacy and legal

Training curriculum and attestation

Completion records by role for every tool in the register, and evidence training preceded go-live.

Signed by the chief learning officer, or nursing and medical education