Assess whether the vendor can be used in a regulated process (686c01)
August 31, 2026
SITUATION After an internal audit finding that human review logs are empty, generative-AI acceptable-use policy draft is what exam-readiness coordinator can touch in a hospital deploying a sepsis-risk model. AI Governance will live with Policy or governance breach versus Model defect on this Policy and Oversight file.
DECISION Exam-readiness coordinator in a hospital deploying a sepsis-risk model must choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact using generative-AI acceptable-use policy draft after an internal audit finding that human review logs are empty.
HYPOTHESES TO TEST 1. The population in generative-AI acceptable-use policy draft is the one an internal audit finding that human review logs are empty named, so Policy or governance breach follows for this Policy and Oversight file. 2. The population in generative-AI acceptable-use policy draft is adjacent only to an internal audit finding that human review logs are empty; Model defect is the honest AI Governance call. 3. A hospital deploying a sepsis-risk model already contained an internal audit finding that human review logs are empty before generative-AI acceptable-use policy draft arrived; no new Policy and Oversight path. 4. Provenance on generative-AI acceptable-use policy draft after an internal audit finding that human review logs are empty is broken; do not pick Policy or governance breach or Model defect yet.
ANALYSIS REQUIRED 1. Map the approved-use case to the system the vendor can be would bind. 2. Check intended purpose and inventory status against EU AI Act / exam-readiness language after an internal audit finding that human review logs are empty. 3. Map the approved-use case to the system the vendor can be would bind. 4. For this AI Governance Policy and Oversight file, read generative-AI acceptable-use policy draft against an internal audit finding that human review logs are empty and write the one fact that would move the vendor can be for exam-readiness coordinator.
RECOMMENDATION Choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact on this AI Governance / Policy and Oversight packet (generative-AI acceptable-use policy draft after an internal audit finding that human review logs are empty). If generative-AI acceptable-use policy draft cannot force a AI Governance label under Policy and Oversight, stop. Do not invent missing evidence a hospital deploying a sepsis-risk model does not have.
COMMAND RETURNS - Bottom-line AI Governance option on the vendor can be, then the evidence in generative-AI acceptable-use policy draft, then the action for exam-readiness coordinator - Hypothesis scorecard against generative-AI acceptable-use policy draft: supported / rejected / untestable - Named option among Policy or governance breach, Model defect, Dual failure and the fact that kills the others - Owner and next date for exam-readiness coordinator in a hospital deploying a sepsis-risk model
Explore more
More AI Governance prompts
- Assess whether a shadow system must be decommissioned this quarter (d1fa49)
- Assess whether the inventory can be represented to an examiner as complete
- Assess whether the system is high-risk under the EU AI Act (e2db71)
- Assess whether a generative-AI incident is a policy breach or a model defect
- Assess whether the board has been accurately briefed (6e1c2e)
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

