Risk tiering — proportionate governance
Governing everything maximally is a way of governing nothing well. Risk tiering is the escape: classify at intake, then let the tier drive how much validation, monitoring, and committee attention each system earns.
The classic factors: autonomy (does it inform a human or act directly?), consequence (what happens if it is wrong?), and reversibility (would the error be caught and undone?). A documentation assistant scores low on all three; an autonomous triage model does not — and note that an oversight claim only lowers the tier if the human in the loop is real. The low score is arguable rather than obvious, which is why ambient documentation is the worked example most organisations reach for first.
The evidence artifact is the written method plus its application: the intake and tiering procedure, and the inventory showing every system’s assigned tier. A tier assigned by no stated method is an opinion; a surveyor samples for the method.
← All RUAIH questions, areas and terms · The complete healthcare AI governance guide · Score your readiness