KPSGILL framework · 12 dimensions · a proposal, not a standard in force

KPSGILL AI Governance Readiness Framework

Governance readiness, not deployment speed, is the honest measure of progress in clinical AI. This framework states the dimensions on which readiness can be assessed and, for each, the observable that distinguishes a governed deployment from a documented intention.

Why readiness rather than capability

The prevailing measure of AI progress in health care is deployment: how many systems are live, in how many sites, across how many workflows. That metric cannot distinguish a validated, monitored, auditable deployment from an unvalidated one, and it rewards the second because the second is faster.

Readiness inverts the measure. It asks what an institution could answer if asked — by a regulator, a board, a plaintiff, or a patient. Every dimension below is written so that the answer is either available or it is not; none of them can be satisfied by an intention.

The twelve dimensions

01 · Validation

Was the system evaluated on the population and for the use in which it is deployed, or on a development set from elsewhere? Local validation is the dimension most often skipped and most often decisive.

Observable: A hospital can state, for each deployed system, the population it was validated on and the clinical use validated.

02 · Data provenance

Where did the training and tuning data come from, under what authority, and can the institution answer that question without asking the vendor?

Observable: Provenance is documented at procurement, not reconstructed after an incident.

03 · Bias monitoring

Is performance monitored by subgroup after deployment, with a threshold that triggers action rather than a report?

Observable: Subgroup performance is reviewed on a stated interval and a named person can suspend the system.

04 · Accountability

When the system contributes to a harm, who is answerable — developer, deployer, or the clinician who accepted the output? An unallocated answer defaults to the clinician.

Observable: Allocation is written into the deployment agreement before go-live.

05 · Human oversight

Is override possible, is it recorded, and is overriding penalised in practice by productivity metrics or scheduling?

Observable: Overrides are logged and no adverse consequence attaches to a documented clinical override.

06 · Professional competence

Do the clinicians using the system understand what it does, what it cannot do, and how it fails? AI literacy is a competence question, not a training-completion question.

Observable: Competence is assessed for the specific system, not satisfied by a generic module.

07 · Patient transparency

Does the patient learn that a system participated in their care, and at what granularity — the encounter, the note, the decision?

Observable: A stated disclosure rule exists and is applied consistently.

08 · Incident reporting

Is there a route by which a clinician reports a suspected AI-related error, and does anything happen when they use it?

Observable: Reports reach a body with authority to change or withdraw the deployment.

09 · Model change management

A model updated by the vendor is a different instrument. Is the change notified, evaluated and version-recoverable from the record?

Observable: Version identity is recoverable for any past clinical output.

10 · Auditability

Can an adjudicator — a board, a court, a peer-review committee — reconstruct what the system produced and what the clinician did with it?

Observable: The record answers the question without vendor cooperation.

11 · Procurement

Are the preceding dimensions conditions of purchase, or aspirations addressed after deployment? Procurement is where governance is cheap and afterwards it is not.

Observable: Contract terms carry the duties.

12 · Equitable access

Does the deployment widen or narrow the gap between well-resourced and under-resourced settings? A tool that only functions with specialist support concentrates benefit.

Observable: Effect on under-resourced settings is assessed before scale.

The strongest argument against this framework

Twelve dimensions applied as gates would stop most clinical AI deployment in most institutions, including deployments that would have helped patients. A large academic centre can staff a governance committee; a five-physician practice and a critical-access hospital cannot, and a readiness standard they cannot meet becomes a reason they are excluded from tools their patients need. The framework would then widen exactly the gap its twelfth dimension is meant to protect.

The KPSGILL response. That objection is why the dimensions are stated as observables rather than as thresholds, and why no scoring is published. Readiness should be tiered to risk: an ambient documentation tool and an autonomous triage system do not warrant the same governance, and a framework that treats them alike will be ignored for both. The tiering work is not published on this site, so this page stops at the dimensions and does not pretend to be a compliance instrument.