Buyer Guides

Governance Documentation a Hospital Board Needs Before Approving Clinical AI

Boards are not evaluating the algorithm. They are evaluating whether the organization can demonstrate control over it. Those need different documents.

The short answer

A board approving clinical AI is not assessing model performance. It is assessing whether the organization can show it has control: a named accountable owner, an entry in the model inventory, a stated intended use, documented validation, a monitoring plan with thresholds, an escalation and withdrawal procedure, and a policy that covers how the next tool gets approved. Bring evidence of control, not evidence of accuracy.

Explained at three levels

1 Plain English

A board is asking one question in several forms: if this goes wrong, will we be able to show we were paying attention? That means they want to see who is responsible, how you will notice a problem, and what you will do about it. Accuracy numbers do not answer any of those.

2 Informed buyer

The documentation splits into two stacks. Tool-specific documents cover this deployment. Program-level documents cover how the organization governs algorithms generally. A board seeing only the first stack will approve one tool and then ask for the second, which is a second meeting. Bringing both is what turns an approval into a precedent.

3 Technical and professional detail

The item most often missing is a withdrawal procedure with a named trigger. A monitoring plan that produces a report but has no defined threshold and no stated action is a reporting exercise, not a control, and sophisticated board committees have learned to ask which it is.

Tool-specific documents

Intended use statement

One page. What the tool does, what clinical decision it touches, who acts on the output, what is explicitly out of scope, and what the workflow does when the tool is unavailable. Written by the organization, not copied from the vendor.

Validation summary

The population the model was developed and validated on, how that compares with the organization’s population, the reported performance and at what threshold, subgroup findings, and any local validation performed or planned.

Where local validation has not been done, say so and say why. A board can accept a stated gap. It cannot accept discovering one.

Risk assessment

What happens when the tool is wrong in each direction. A false negative on a triage tool and a false positive on the same tool cause different harms to different people, and the assessment should treat them separately. Include automation bias: what happens when clinicians start trusting it.

Monitoring plan

Metrics, cadence, who reviews, the threshold that triggers investigation, the named accountable owner, and the procedure for withdrawal. That last element is what makes it a control.

Accountable owner

A named individual, not a committee. Committees govern programs. Individuals own tools. A model without a named owner does not get monitored, and every organization that has built an inventory has discovered this the same way.

Model inventory entry

The tool’s record in the AI model inventory: purpose, deployment sites, owner, validation reference, monitoring reference, review date.

Vendor and contract summary

Data handling including whether organizational data trains anything, the model update and notification terms, the monitoring support included, security attestations, and exit terms. The board is not reading the contract. It is reading whether these questions were asked.

Program-level documents

AI governance policy

Scope, what counts as in-scope AI, the review process, approval thresholds, roles, and who decides. Note that scope is harder than it looks: algorithms arrive embedded inside purchased systems and medical devices, not only as standalone purchases.

Governance body charter

Composition, authority, meeting cadence, and what it can actually decide versus recommend. Common seats: clinical leadership, clinical informatics, nursing informatics, information security, privacy and compliance, legal, data science, quality and safety, and operations.

Inventory summary

Not the full inventory. A count, the categories, how many have named owners, how many have active monitoring, and where the gaps are. Boards respond better to an honest gap list than to a clean sheet they do not believe.

Escalation and incident procedure

How a suspected problem gets reported, who investigates, on what timeline, and who can suspend a tool while that happens.

The shape of the argument

A board approving a single tool is setting a precedent for every tool after it. That is the framing that tends to land: this approval is the first application of a process we intend to apply consistently, here is the process, and here is the evidence it was followed.

It is also why the program-level stack matters as much as the tool-specific one. Approving an algorithm without a policy is a decision. Approving one with a policy is a system.

Where this goes next

More in Buyer Guides