From principles to practice: an actionable framework for AI governance in healthcare organisations
Sam Freeman, Amy Wang, Sudeep Saraf, Erica Potts, Amy Mckimm, Enrico Coiera, Farah MagrabiObjective
Artificial intelligence (AI) technologies are being rapidly adopted in healthcare, yet organisational governance often lacks the processes needed to oversee their safe and responsible use. Previous AI governance frameworks largely focus on high-level AI ethics principles, leaving healthcare organisations struggling to translate these principles into practice, assess risk and embed AI oversight into existing processes. This study aimed to develop and validate a practice-oriented AI governance framework for healthcare organisations.
Methods and analysis
We developed an AI governance framework using an exploratory multimethod design that drew on a scoping review, document analysis and semistructured interviews. The framework was validated through stakeholder workshops and application to three case studies of AI systems to identify patients for home-based care, radiology decision support and infection surveillance within a large tertiary healthcare organisation. The case studies represented real-world governance decisions faced by healthcare organisations and reflected the major pathways for acquiring AI capabilities: in-house development, commercial procurement and codevelopment with external partners.
Results
The framework unifies ethics and governance principles, incorporates tiered oversight aligned with organisational digital maturity and includes a structured review checklist to support consistent decision-making about the implementation and operation of AI systems across clinical and operational contexts. Stakeholders found the framework relevant, usable and feasible to implement. Across the diverse AI use cases, the review checklist identified governance, safety and implementation risks and supported structured assessment and decision-making. The framework also enabled AI oversight to be integrated into existing organisational governance processes while supporting a proportionate approach to risk management across the AI life cycle.
Conclusion
This study addresses an important gap between high-level AI governance principles and organisational implementation. The framework provides healthcare organisations with a structured approach to assessing, governing and monitoring AI systems throughout their life cycle and may support the safe and responsible adoption of AI in practice. Further research is needed to evaluate the framework across diverse healthcare settings and emerging AI technologies, including generative and agentic AI.