Regulation

The hospital AI governance committee playbook

A build sequence for standing up a hospital AI governance committee — charter, membership, intake, tiered review, a local-validation gate, monitoring, and board reporting — with every step cross-walked to a published governance framework. As of July 2026.

By Jonas WeirReviewed by Jonas Weir · editorial reviewUpdated

The short version

  • A hospital AI governance committee is now an accreditor expectation: the Joint Commission and CHAI's September 2025 guidance makes AI policies and governance structures the first of seven elements of responsible AI use.
  • The committee's remit spans a documented set of duties — policy, privacy and transparency, data security, ongoing monitoring, safety-event reporting, bias assessment, and training.
  • Four published frameworks converge on the same build: charter, membership, intake and inventory, tiered risk review, a local-validation gate, monitoring and escalation, and regular reporting to the board.
  • Membership should span executive leadership, compliance, IT, safety and incident reporting, clinical and operational roles, cybersecurity and privacy, and representatives of the populations a tool affects.
  • The committee exists to catch harms before they reach patients — including equity failures like the care-management algorithm that under-served Black patients because it optimized on cost.

Every hospital now runs algorithms it did not build, bought from vendors it cannot fully audit, making recommendations no single clinician can second-guess in the moment. A governance committee is the body that decides which of those tools go live, on what evidence, and under what watch. This page is a build sequence for standing one up — charter, membership, intake, tiered review, a local-validation gate, monitoring, and board reporting — with each step cross-walked to a published framework rather than invented. It is orientation and general guidance; because governance decisions carry compliance and liability weight, confirm your committee's mandate and any binding obligations with your legal and compliance functions before you rely on this outline. As of July 2026.

Why a committee, and why now

The question shifted in 2025 from whether to govern AI to how. On 17 September 2025 the Joint Commission — the largest US healthcare accreditor — and the Coalition for Health AI released the first governance framework from a US accrediting body, and it opens by making the structure non-optional in spirit: "Healthcare organizations should establish policies and procedures for implementing and using AI and a governance structure to manage the responsible use of health AI in their organization, including a mechanism to keep the hospital's governing body updated on uses, outcomes, and potential adverse events" 1. The guidance is careful to add that the structure "does not need to be its own standalone team" — an existing body can carry the remit — but the accountability and the board reporting are expected either way 1.

The mandate is echoed upstream. The World Health Organization's 2024 guidance on large multi-modal models issued more than forty recommendations for governments, developers, and providers, treating governance as a precondition for safe deployment rather than an afterthought 7. And the reason all of this exists is concrete: a 2019 study of a care-management algorithm used on millions of patients found that "Black patients are considerably sicker than White patients" at any given risk score, because the model optimized on cost as a proxy for need 8. A governance committee's bias review exists to catch exactly that class of failure before it reaches patients.

The remit: seven elements to own

Before building the body, fix its scope. The Joint Commission and CHAI define seven elements of responsible AI use, and together they form a serviceable charter outline — the committee owns all seven.

#ElementWhat the committee ownsSource
1AI policies and governance structuresThe charter, the risk-tiering rules, the accountability lines1
2Patient privacy and transparencyDisclosure to patients and staff; consent where relevant1
3Data security and data-use protectionsBusiness associate agreements, minimum-necessary use, re-identification limits1
4Ongoing quality monitoringPost-deployment performance surveillance and dashboards1
5Voluntary, blinded reporting of safety eventsA route for AI-related incidents into existing safety systems1
6Risk and bias assessmentPre- and post-deployment equity and risk review1
7Education and trainingRole-specific training and AI-literacy for staff1

The build, step by step

Six steps stand up a working committee. Each is anchored to the framework that grounds it, and the frameworks agree with one another more than they differ.

#StepAnchoring framework
1Write the charter around values and pillarsNAM code; Reddy governance model 52
2Compose cross-functional membershipJoint Commission / CHAI 1
3Stand up intake and an AI inventoryHealth AI Partnership 4
4Tier every tool by clinical riskJoint Commission / CHAI; Duke ABCDS 13
5Gate deployment on local validationHealth AI Partnership; Duke ABCDS 43
6Run monitoring, escalation, and board reportingDuke ABCDS; Joint Commission / CHAI 31

1. Write the charter around values and pillars

A charter needs a spine of principles, and two peer-reviewed sources supply one. The Reddy governance model organizes AI oversight around four components — "fairness, transparency, trustworthiness and accountability" — and recommends both a data-governance panel and a clinical governance committee spanning clinicians, managers, patient representatives, and technical and ethics experts 2. For a higher-order values layer, the NAM AI Code of Conduct — a framework from one of the US National Academies — "presents six commitments and 10 principles," among them commitments to ensure equity and to monitor performance 5. Adopt the four pillars as the charter's evaluation lens and the code's commitments as its stated values.

2. Compose cross-functional membership

The most common failure mode is a committee of IT and clinicians with no compliance, no patient voice, and no one who owns safety reporting. The Joint Commission and CHAI name the span directly: a team that "could include individuals with the following expertise as appropriate: executive leadership, regulatory/ethical compliance, information technology (IT), safety/incident reporting, relevant clinical/operational expertise, cybersecurity and data privacy needs, and stakeholders reflecting the needs of impacted populations" 1. A designated individual with technology expertise, ideally in AI, should lead 1.

SeatWhy it is on the committee
Executive sponsorAuthority to restrict or retire a tool; owns board reporting
Compliance / legal / ethicsRegulatory fit, consent, liability
Clinical leads (by service)Workflow reality and clinical risk judgement
IT / informaticsIntegration, data pipelines, technical validation
Safety / incident reportingWires AI events into existing safety systems
Cybersecurity / privacyData-use agreements, PHI protection
Patient / population representativeThe voice of those the tool affects

3. Stand up intake and an AI inventory

A committee that only meets about the tools someone happens to escalate governs nothing. Build a single intake front door and an inventory of every AI tool in use or under consideration. The Health AI Partnership's eight key decision points give the intake its questions, running from "identify and prioritize a problem" and "define AI product scope and intended use" through to "generate evidence of safety, efficacy and equity" — the sequence a submission should have to answer before it reaches review 4. Require every new clinical decision support system and every AI-enabled tool to enter through this door.

4. Tier every tool by clinical risk

Uniform scrutiny wastes the committee's time on schedulers and under-examines diagnostics. Tier by proximity to clinical decisions. The Joint Commission and CHAI set the rule of thumb — tools that inform or drive clinical decisions get more scrutiny; administrative tools get less 1 — and Duke's ABCDS oversight framework operationalizes tiering through an "executive-level committee that provides institution-wide oversight and governance" and four lifecycle phases separated by decision gates 3. Assign each intake a tier, and let the tier set the depth of review and the monitoring cadence.

5. Gate deployment on local validation

The single most important gate is that a tool proves itself on local data before it touches local patients. The Health AI Partnership makes "generate evidence of safety, efficacy and equity" a discrete decision point, and pairs it with a decision on whether to integrate or abandon the product 4. This is where external validation evidence and a local performance check are demanded and read; the questions to ask of that evidence are in our guide on how to read an AI validation study, and the disclosures a vendor must supply are covered in our transparency and labeling requirements guide. A tool that cannot show it holds up locally does not pass the gate.

6. Run monitoring, escalation, and board reporting

Approval is the start of the committee's duty, not the end. Duke's framework requires that "monitoring plans are established" precisely because models drift after deployment 3, and the Joint Commission and CHAI make ongoing quality monitoring one of the seven elements 1. Wire three things: continuous post-deployment monitoring — the subject of our algorithmovigilance program guide, which watches discrimination, calibration, subgroup performance, and model drift; a defined escalation path from a monitoring signal to restriction or retirement; and regular reporting to the board, since the guidance holds that "the fiduciary board of the healthcare organization should be regularly updated on AI use and its outcomes" 1. The transparency the committee reviews at intake is itself now partly mandated: the HTI-1 rule requires certified predictive decision-support tools to expose source attributes so users can judge whether a tool is "fair, appropriate, valid, effective, and safe" 6.

How to read this playbook

Four cautions travel with the build.

First, structure follows accountability, not the org chart. The guidance allows an existing body to hold the remit 1; what matters is that one group owns the seven elements and the board hears from it. Do not create a committee that can review but cannot restrict or retire a tool.

Second, the frameworks are guidance, not statute — but the direction is one way. The Joint Commission and CHAI document is an initial, high-level guidance with governance playbooks and a voluntary certification program still to come 1. Build to the guidance now; expect the bar to rise.

Third, equity review is the load-bearing function rather than a checkbox. The bias case is the reminder that a model can hold its overall performance while failing a subgroup, so the committee's risk-and-bias review has to look at subgroup performance rather than aggregate accuracy alone 8. For the wider regulatory picture the committee operates inside, see our global AI in health regulation tracker.

Fourth, this is a US-anchored synthesis of voluntary frameworks. Obligations differ by jurisdiction and are hardening in several. Confirm the binding requirements for your setting — and the liability position of any specific governance decision — with your legal and compliance functions before you rely on this outline.

Sources and method

This playbook cross-walks published frameworks into one build sequence. The accreditor scope, membership, and board-reporting expectations come from the Joint Commission and CHAI's 2025 responsible-use guidance 1. The charter's pillars and two-body structure come from the peer-reviewed Reddy governance model 2; its values layer from the NAM AI Code of Conduct 5. The gated lifecycle and monitoring requirement come from Duke's published ABCDS oversight framework 3; the intake-to-retirement decision points from the Health AI Partnership 4. The concrete disclosures the intake reviews are grounded in the HTI-1 Final Rule 6, the global governance expectation in the WHO's 2024 guidance 7, and the equity mandate in the 2019 bias study 8. Every quotation is drawn from the source cited beside it. We revisit this page every ninety days and whenever a tracked framework changes — most urgently, when the Joint Commission and CHAI publish their promised governance playbooks. Statuses are current as of July 2026.

Questions & answers

  • Does a hospital need a dedicated AI governance committee?

    A governance structure is now an accreditor expectation. The Joint Commission and CHAI's 2025 guidance makes AI policies and governance structures the first of seven elements of responsible AI use, though it notes the structure need not be a standalone team — it can be a responsibility given to an existing body, as long as accountability is clear and the governing board is kept informed.

  • Who should sit on a hospital AI governance committee?

    The published guidance points to a cross-functional group: executive leadership, regulatory and ethical compliance, IT, safety and incident reporting, relevant clinical and operational roles, cybersecurity and data privacy, and stakeholders representing the staff, clinicians, and patients an AI tool affects. A designated individual with technology expertise — ideally in AI — should lead.

  • What does an AI governance committee actually do?

    It owns the lifecycle: setting policy, running an intake and inventory of AI tools, tiering them by risk, requiring local validation before clinical use, overseeing post-deployment monitoring, handling safety-event reporting and bias review, and reporting regularly to the board. Published frameworks from the Joint Commission and CHAI, Duke, and others converge on that sequence.

Sources

  1. The Joint Commission and Coalition for Health AI (CHAI). Guidance on the Responsible Use of AI in Healthcare (RUAIH). 17 September 2025. digitalassets.jointcommission.org/api/public/content/dcfcf4f1a0cc45cdb526b3cb034c68c2
  2. Reddy S, Allan S, Coghlan S, Cooper P. A governance model for the application of AI in health care. Journal of the American Medical Informatics Association. 2020;27(3):491-497. doi.org/10.1093/jamia/ocz192
  3. Bedoya AD, Economou-Zavlanos NJ, Goldstein BA, et al. A framework for the oversight and local deployment of safe and high-quality prediction models. Journal of the American Medical Informatics Association. 2022;29(9):1631-1636. doi.org/10.1093/jamia/ocac078
  4. Health AI Partnership (Duke Institute for Health Innovation). Key decisions in adopting an AI solution — eight key decision points. Accessed July 2026. healthaipartnership.org/key-decisions-in-adopting-an-ai-solution
  5. National Academy of Medicine. An Artificial Intelligence Code of Conduct for Health and Medicine: Essential Guidance for Aligned Action (six commitments and ten principles). 2025. www.nationalacademies.org/news/ai-code-of-conduct-for-health-and-medicine-presented-in-new-nam-special-publication
  6. Federal Register. Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1 Final Rule). 9 January 2024. www.federalregister.gov/documents/2024/01/09/2023-28857/health-data-technology-and-interoperability-certification-program-updates-algorithm-transparency
  7. World Health Organization. Ethics and governance of artificial intelligence for health: Guidance on large multi-modal models. 18 January 2024. www.who.int/publications/i/item/9789240084759
  8. Obermeyer Z, Powers B, Vogeli C, Mullainathan S. Dissecting racial bias in an algorithm used to manage the health of populations. Science. 2019;366(6464):447-453. doi.org/10.1126/science.aax2342