RUAIH Risk tiering — proportionate governance
RUAIH glossary

Risk tiering — proportionate governance

The short answer. Risk tiering classifies each AI system by potential for patient harm — typically weighing autonomy, clinical consequence, and reversibility — so that governance effort scales with stakes. An ambient scribe and a sepsis predictor should not get identical oversight; the tier is the written, defensible reason they don't.

Governing everything maximally is a way of governing nothing well. Risk tiering is the escape: classify at intake, then let the tier drive how much validation, monitoring, and committee attention each system earns.

The classic factors: autonomy (does it inform a human or act directly?), consequence (what happens if it is wrong?), and reversibility (would the error be caught and undone?). A documentation assistant scores low on all three; an autonomous triage model does not — and note that an oversight claim only lowers the tier if the human in the loop is real. The low score is arguable rather than obvious, which is why ambient documentation is the worked example most organisations reach for first.

The evidence artifact is the written method plus its application: the intake and tiering procedure, and the inventory showing every system’s assigned tier. A tier assigned by no stated method is an opinion; a surveyor samples for the method.

Where do you actually stand? The free RUAIH readiness score maps your organisation against the five focus areas in about eight minutes, and the published crosswalk shows how each control lands across RUAIH, CHAI and the NIST AI RMF.

← All RUAIH questions, areas and terms · The complete healthcare AI governance guide · Score your readiness