Every hospital now runs algorithms it did not build, bought from vendors it cannot fully audit, making recommendations no single clinician can second-guess in the moment. A governance committee is the body that decides which of those tools go live, on what evidence, and under what watch. This page is a build sequence for standing one up — charter, membership, intake, tiered review, a local-validation gate, monitoring, and board reporting — with each step cross-walked to a published framework rather than invented. It is orientation and general guidance; because governance decisions carry compliance and liability weight, confirm your committee's mandate and any binding obligations with your legal and compliance functions before you rely on this outline. As of July 2026.
Why a committee, and why now
The question shifted in 2025 from whether to govern AI to how. On 17 September 2025 the Joint Commission — the largest US healthcare accreditor — and the Coalition for Health AI released the first governance framework from a US accrediting body, and it opens by making the structure non-optional in spirit: "Healthcare organizations should establish policies and procedures for implementing and using AI and a governance structure to manage the responsible use of health AI in their organization, including a mechanism to keep the hospital's governing body updated on uses, outcomes, and potential adverse events" 1. The guidance is careful to add that the structure "does not need to be its own standalone team" — an existing body can carry the remit — but the accountability and the board reporting are expected either way 1.
The mandate is echoed upstream. The World Health Organization's 2024 guidance on large multi-modal models issued more than forty recommendations for governments, developers, and providers, treating governance as a precondition for safe deployment rather than an afterthought 7. And the reason all of this exists is concrete: a 2019 study of a care-management algorithm used on millions of patients found that "Black patients are considerably sicker than White patients" at any given risk score, because the model optimized on cost as a proxy for need 8. A governance committee's bias review exists to catch exactly that class of failure before it reaches patients.
The remit: seven elements to own
Before building the body, fix its scope. The Joint Commission and CHAI define seven elements of responsible AI use, and together they form a serviceable charter outline — the committee owns all seven.
| # | Element | What the committee owns | Source |
|---|---|---|---|
| 1 | AI policies and governance structures | The charter, the risk-tiering rules, the accountability lines | 1 |
| 2 | Patient privacy and transparency | Disclosure to patients and staff; consent where relevant | 1 |
| 3 | Data security and data-use protections | Business associate agreements, minimum-necessary use, re-identification limits | 1 |
| 4 | Ongoing quality monitoring | Post-deployment performance surveillance and dashboards | 1 |
| 5 | Voluntary, blinded reporting of safety events | A route for AI-related incidents into existing safety systems | 1 |
| 6 | Risk and bias assessment | Pre- and post-deployment equity and risk review | 1 |
| 7 | Education and training | Role-specific training and AI-literacy for staff | 1 |
The build, step by step
Six steps stand up a working committee. Each is anchored to the framework that grounds it, and the frameworks agree with one another more than they differ.
| # | Step | Anchoring framework |
|---|---|---|
| 1 | Write the charter around values and pillars | NAM code; Reddy governance model 52 |
| 2 | Compose cross-functional membership | Joint Commission / CHAI 1 |
| 3 | Stand up intake and an AI inventory | Health AI Partnership 4 |
| 4 | Tier every tool by clinical risk | Joint Commission / CHAI; Duke ABCDS 13 |
| 5 | Gate deployment on local validation | Health AI Partnership; Duke ABCDS 43 |
| 6 | Run monitoring, escalation, and board reporting | Duke ABCDS; Joint Commission / CHAI 31 |
1. Write the charter around values and pillars
A charter needs a spine of principles, and two peer-reviewed sources supply one. The Reddy governance model organizes AI oversight around four components — "fairness, transparency, trustworthiness and accountability" — and recommends both a data-governance panel and a clinical governance committee spanning clinicians, managers, patient representatives, and technical and ethics experts 2. For a higher-order values layer, the NAM AI Code of Conduct — a framework from one of the US National Academies — "presents six commitments and 10 principles," among them commitments to ensure equity and to monitor performance 5. Adopt the four pillars as the charter's evaluation lens and the code's commitments as its stated values.
2. Compose cross-functional membership
The most common failure mode is a committee of IT and clinicians with no compliance, no patient voice, and no one who owns safety reporting. The Joint Commission and CHAI name the span directly: a team that "could include individuals with the following expertise as appropriate: executive leadership, regulatory/ethical compliance, information technology (IT), safety/incident reporting, relevant clinical/operational expertise, cybersecurity and data privacy needs, and stakeholders reflecting the needs of impacted populations" 1. A designated individual with technology expertise, ideally in AI, should lead 1.
| Seat | Why it is on the committee |
|---|---|
| Executive sponsor | Authority to restrict or retire a tool; owns board reporting |
| Compliance / legal / ethics | Regulatory fit, consent, liability |
| Clinical leads (by service) | Workflow reality and clinical risk judgement |
| IT / informatics | Integration, data pipelines, technical validation |
| Safety / incident reporting | Wires AI events into existing safety systems |
| Cybersecurity / privacy | Data-use agreements, PHI protection |
| Patient / population representative | The voice of those the tool affects |
3. Stand up intake and an AI inventory
A committee that only meets about the tools someone happens to escalate governs nothing. Build a single intake front door and an inventory of every AI tool in use or under consideration. The Health AI Partnership's eight key decision points give the intake its questions, running from "identify and prioritize a problem" and "define AI product scope and intended use" through to "generate evidence of safety, efficacy and equity" — the sequence a submission should have to answer before it reaches review 4. Require every new clinical decision support system and every AI-enabled tool to enter through this door.
4. Tier every tool by clinical risk
Uniform scrutiny wastes the committee's time on schedulers and under-examines diagnostics. Tier by proximity to clinical decisions. The Joint Commission and CHAI set the rule of thumb — tools that inform or drive clinical decisions get more scrutiny; administrative tools get less 1 — and Duke's ABCDS oversight framework operationalizes tiering through an "executive-level committee that provides institution-wide oversight and governance" and four lifecycle phases separated by decision gates 3. Assign each intake a tier, and let the tier set the depth of review and the monitoring cadence.
5. Gate deployment on local validation
The single most important gate is that a tool proves itself on local data before it touches local patients. The Health AI Partnership makes "generate evidence of safety, efficacy and equity" a discrete decision point, and pairs it with a decision on whether to integrate or abandon the product 4. This is where external validation evidence and a local performance check are demanded and read; the questions to ask of that evidence are in our guide on how to read an AI validation study, and the disclosures a vendor must supply are covered in our transparency and labeling requirements guide. A tool that cannot show it holds up locally does not pass the gate.
6. Run monitoring, escalation, and board reporting
Approval is the start of the committee's duty, not the end. Duke's framework requires that "monitoring plans are established" precisely because models drift after deployment 3, and the Joint Commission and CHAI make ongoing quality monitoring one of the seven elements 1. Wire three things: continuous post-deployment monitoring — the subject of our algorithmovigilance program guide, which watches discrimination, calibration, subgroup performance, and model drift; a defined escalation path from a monitoring signal to restriction or retirement; and regular reporting to the board, since the guidance holds that "the fiduciary board of the healthcare organization should be regularly updated on AI use and its outcomes" 1. The transparency the committee reviews at intake is itself now partly mandated: the HTI-1 rule requires certified predictive decision-support tools to expose source attributes so users can judge whether a tool is "fair, appropriate, valid, effective, and safe" 6.
How to read this playbook
Four cautions travel with the build.
First, structure follows accountability, not the org chart. The guidance allows an existing body to hold the remit 1; what matters is that one group owns the seven elements and the board hears from it. Do not create a committee that can review but cannot restrict or retire a tool.
Second, the frameworks are guidance, not statute — but the direction is one way. The Joint Commission and CHAI document is an initial, high-level guidance with governance playbooks and a voluntary certification program still to come 1. Build to the guidance now; expect the bar to rise.
Third, equity review is the load-bearing function rather than a checkbox. The bias case is the reminder that a model can hold its overall performance while failing a subgroup, so the committee's risk-and-bias review has to look at subgroup performance rather than aggregate accuracy alone 8. For the wider regulatory picture the committee operates inside, see our global AI in health regulation tracker.
Fourth, this is a US-anchored synthesis of voluntary frameworks. Obligations differ by jurisdiction and are hardening in several. Confirm the binding requirements for your setting — and the liability position of any specific governance decision — with your legal and compliance functions before you rely on this outline.
Sources and method
This playbook cross-walks published frameworks into one build sequence. The accreditor scope, membership, and board-reporting expectations come from the Joint Commission and CHAI's 2025 responsible-use guidance 1. The charter's pillars and two-body structure come from the peer-reviewed Reddy governance model 2; its values layer from the NAM AI Code of Conduct 5. The gated lifecycle and monitoring requirement come from Duke's published ABCDS oversight framework 3; the intake-to-retirement decision points from the Health AI Partnership 4. The concrete disclosures the intake reviews are grounded in the HTI-1 Final Rule 6, the global governance expectation in the WHO's 2024 guidance 7, and the equity mandate in the 2019 bias study 8. Every quotation is drawn from the source cited beside it. We revisit this page every ninety days and whenever a tracked framework changes — most urgently, when the Joint Commission and CHAI publish their promised governance playbooks. Statuses are current as of July 2026.