Skip to main content

Assurance

Assurance beyond technical performance

AIHRI evaluates the organisational and service conditions under which artificial intelligence is deployed, governed and monitored in healthcare.

I. Central proposition

Healthcare AI cannot be assessed only as software

The safety and responsible use of AI in healthcare depend on governance, clinical integration, professional oversight, data controls, workforce competence and continuing monitoring.

AIHRI's assurance model addresses those conditions. Technical performance matters, but it is neither sufficient nor separable from the institutional environment in which an AI-enabled service operates.

II. Object of conformity assessment

What is assessed, and against what

Under an approved certification scheme, the potential object of assessment may be:

  • A defined healthcare service that incorporates AI.
  • An AI-enabled service model operated by the organisation.
  • A defined organisational process supported by AI.
  • An organisational scope in which AI is deployed and supervised.

Assurance is always scope-specific and based on defined requirements and objective evidence. AIHRI does not offer generic assurance detached from a stated scope.

III. Six assurance domains

Domain architecture

Six interdependent domains structure AIHRI's assessment perspective. They are an analytical framework, not a public AIHRI standard, and they do not reproduce proprietary requirements of any certification scheme.

Governance and leadership

Condition examined

Whether accountability, decision rights and oversight for AI-enabled services are defined, documented and exercised at the appropriate level of the organisation.

Why it matters

AI-enabled services introduce decisions that cross clinical, technical and administrative boundaries. Without explicit governance, responsibility becomes diffuse and oversight becomes reactive.

Typical categories of evidence

  • Terms of reference and minutes of oversight bodies
  • Delegated authority and decision-rights matrices
  • Policies covering approval, change and retirement of AI-enabled services
  • Board and executive reporting on AI-related risk

Boundary of AIHRI's judgement

AIHRI assesses the presence, operation and effectiveness of governance arrangements. It does not exercise governance on the organisation's behalf.

Clinical integration and human oversight

Condition examined

How AI outputs enter clinical workflows, how they are presented to professionals and how meaningful human review is maintained.

Why it matters

The clinical value and safety of an AI-enabled service depend on how it is used, not only on how it performs. Integration and oversight determine whether professional judgement remains effective.

Typical categories of evidence

  • Documented clinical workflows incorporating AI outputs
  • Standard operating procedures for review, override and escalation
  • Training records for clinical users
  • Human-factors and usability evaluations

Boundary of AIHRI's judgement

AIHRI assesses the conditions for oversight. It does not make clinical decisions or evaluate individual clinical judgements.

Data infrastructure and security

Condition examined

The provenance, quality, protection and lifecycle management of the data on which the AI-enabled service depends.

Why it matters

AI behaviour is a function of the data around it. Weak provenance, quality or protection undermines both clinical reliability and legal defensibility.

Typical categories of evidence

  • Data flow, provenance and lineage records
  • Data quality controls and monitoring outputs
  • Access control, encryption and information security policies
  • Records of data protection impact assessments and reviews

Boundary of AIHRI's judgement

AIHRI assesses institutional data controls. It does not audit individual patient records or act as an information security certification authority.

Regulatory and ethical alignment

Condition examined

Whether the organisation has identified and demonstrably aligns with the healthcare, data protection and AI-specific obligations that apply to the service.

Why it matters

Regulated healthcare environments carry distinct legal, professional and ethical duties. Alignment must be visible and evidenced, not assumed.

Typical categories of evidence

  • Legal and regulatory horizon-scanning records
  • Ethical review documentation for material changes
  • Policies mapping obligations to controls
  • Records of engagement with competent authorities where applicable

Boundary of AIHRI's judgement

AIHRI assesses evidence of alignment. It does not provide legal advice, certify statutory compliance or act on behalf of any regulator.

Workforce competence

Condition examined

The knowledge, training, role clarity and support of the professionals who deploy, supervise or rely on the AI-enabled service.

Why it matters

Assurance without competent users is fragile. Effective oversight requires practitioners who understand the tool, its limits and their own responsibilities.

Typical categories of evidence

  • Role descriptions referencing AI-related duties
  • Training curricula and completion records
  • Competence frameworks and periodic reviews
  • Feedback and incident learning fed back into training

Boundary of AIHRI's judgement

AIHRI assesses institutional workforce arrangements. It does not certify individual professionals or replace professional regulatory functions.

Monitoring and continual improvement

Condition examined

How the organisation monitors service performance, detects drift, learns from incidents and improves the AI-enabled service over time.

Why it matters

AI-enabled services change with their data, users and context. Assurance is credible only when it extends beyond the point of deployment.

Typical categories of evidence

  • Performance monitoring plans and outputs
  • Model and process change control records
  • Incident, near-miss and complaint analyses
  • Internal audit programmes and corrective action logs

Boundary of AIHRI's judgement

AIHRI assesses monitoring and improvement arrangements. It does not operate the service or perform continuous monitoring on the organisation's behalf.

IV. Service and organisational assurance

Assessing a service is not approving a product

A product approval evaluates a technology in isolation. An AI-enabled healthcare service assessment evaluates how the technology is embedded in an organisation, how its outputs meet clinical work and how the organisation maintains safe and responsible use over time.

At a general level, AI-enabled services may include clinical decision support, diagnostic workflow integration, laboratory interpretation support and AI-enabled remote services. These examples are illustrative. AIHRI does not endorse any product, vendor or clinical technology.

V. Risk proportionality

Assessment depth calibrated to context

Not every AI-enabled service requires the same depth of assessment. Effort is calibrated to defined factors. AIHRI does not publish a proprietary risk score or a fixed category system.

Intended use
The clinical purpose the AI-enabled service is designed to support.
Clinical influence
The extent to which AI outputs shape clinical decisions or actions.
Organisational impact
The scale of operational, professional and safety-critical change involved.
Deployment context
The setting, population and workflow in which the service operates.
Risk profile
The likelihood and severity of harm associated with misuse, error or drift.

VI. Evidence model

From inputs to traceable conclusions

Assessment draws on controlled documentation, structured interviews, workflow observation, governance outputs, technical controls, performance and incident records, and corrective actions. Conclusions must be traceable to objective evidence.

01

Inputs

What AIHRI draws on

  • Controlled documentation
  • Structured interviews
  • Workflow observation
  • Technical controls
  • Performance and incident records

02

Structured evidence

How inputs are organised

  • Mapped to domain criteria
  • Attributed to source and date
  • Reviewed for completeness
  • Assessed for consistency

03

Assessed conclusions

What is recorded

  • Findings against defined criteria
  • Non-conformities and observations
  • Corrective action requirements
  • Traceable rationale for each judgement
Every conclusion is traceable to structured evidence assessed against defined criteria.

VII. Boundaries of assurance

What AIHRI assurance is not

These boundaries are the honest limits of the Institute's remit. They protect both the organisations AIHRI assesses and the public interest.

  • Statutory regulatory approval.

  • Medical-device conformity assessment.

  • Product endorsement.

  • Clinical validation of an algorithm.

  • A guarantee of patient outcomes.

  • A substitute for legal, professional or organisational responsibility.

  • Consultancy designed to secure certification.

VIII. Human responsibility

Certification does not transfer clinical accountability

AI may support professional judgement. It does not replace it.

Independent assurance can help an organisation demonstrate that its AI-enabled services are governed and supervised with discipline. It does not transfer clinical accountability from licensed professionals or from the healthcare organisation responsible for the service.

Continue

Explore the assessment model

The assurance perspective on this page is operationalised through AIHRI's assessment model. For scope-specific enquiries, contact the Institute.