Case Study · Enterprise AI governance program build

    Building an Audit-Ready AI Governance Program

    How a regional health system went from 40+ ungoverned AI tools to a fully inventoried, risk-tiered, board-ready AI program.

    Regional health system · 12 hospitalsNIST AI RMFISO/IEC 42001HIPAAONC HTI-1
    47
    AI tools inventoried & risk-tiered
    100%
    Unsanctioned tools remediated
    6 wks → 10 days
    Time to approve new AI use case
    Abstract visualization of an AI core surrounded by concentric governance audit rings, verification gates, and monitored data streams
    The Challenge

    The challenge: AI everywhere, governance nowhere

    Like most health systems, this organization did not decide to adopt AI — AI arrived. Clinical teams piloted ambient documentation and decision support. Operational teams bought scheduling, coding, and revenue-cycle tools with AI embedded. Vendors shipped AI features into products the system already owned. By the time leadership asked how many AI tools were in use, nobody could answer.

    The turning point was a vendor AI incident that reached the board. Directors asked three questions management could not answer: what AI are we running, who approved it, and what data is it touching? There was no inventory, no intake or approval process, no risk tiering, and no owner for AI governance as a function.

    The system needed more than a policy document. It needed an operating model — one that could discover what was already deployed, bring it under control, and give the board and auditors evidence that AI was being governed, not just used.

    What the board heard

    • 40+ AI tools in use across clinical and operational teams with no central inventory
    • No intake, risk-tiering, or approval workflow for new AI use cases
    • Shadow AI: teams adopting unsanctioned tools with patient data and no oversight
    • Vendor contracts silent on AI accountability, audit rights, and data use
    • Board-level concern after a vendor AI incident, with no evidence pack to present
    The Approach

    The approach: governance built into the operating model

    BCP ran the engagement through the same six-phase model we bring to every governance program — Discover, Assess, Design, Implement, Validate, Operate — so the result was a working operating model, not a shelf-ware framework.

    01

    Discover

    Full AI/ML inventory across models, vendors, and shadow usage. Architecture, database, and data-flow evaluation to see where PHI actually touched AI pipelines. Regulatory scope mapping across HIPAA, ONC HTI-1, and emerging state AI laws.

    02

    Assess

    Gap analysis against NIST AI RMF and ISO/IEC 42001. Security and compliance audit of pipelines, access controls, and endpoints. Every discovered tool risk-tiered, producing a prioritized remediation roadmap.

    03

    Design

    Governance operating model: roles, committees, intake and approval workflows. Control framework covering model auditability, drift monitoring, and incident response. A policy and contract clause library for vendor AI.

    04

    Implement

    Deployed the model registry, monitoring, and evidence collection. Data governance controls for lineage, quality, retention, and PHI/PII handling. Vendor contract remediation with AI accountability and audit-rights clauses.

    05

    Validate

    Control testing and a full mock audit. Model documentation and evaluation packs completed. A board-reporting dry run so leadership could present the program with confidence.

    06

    Operate

    Continuous monitoring with drift and incident review. Quarterly governance reviews and a regulatory change watch. Annual framework re-assessment to keep the program current as regulation evolves.

    Full AI inventory & shadow-AI discovery

    Every AI tool across the clinical and IT estates was discovered, catalogued, and risk-tiered — including tools teams had adopted without sanction. The inventory became the single source of truth for governance decisions.

    Governance operating model

    Intake, risk tiering, and approval workflows gave every new AI use case a defined path to production — with clear ownership, review gates proportional to risk, and an audit trail for every decision.

    Vendor contract remediation

    AI accountability and audit-rights clauses were negotiated into vendor agreements, so the system's governance standards extend into the products it buys — not just the models it builds.

    The Results

    The results: measurable, audit-ready, board-ready

    The program turned an unanswerable board question into a standing agenda item. The inventory that started at '40+' ended at 47 fully catalogued, risk-tiered AI tools — every one with an owner, a data-handling review, and a monitoring plan.

    Every unsanctioned tool discovered during shadow-AI discovery was remediated: either brought through the approval workflow, replaced with an approved alternative, or retired.

    The approval workflow itself became the proof that governance accelerates adoption rather than blocking it. A new AI use case that previously took six weeks of ad-hoc review — or slipped in with no review at all — now moves through a defined intake-to-approval path in ten days.

    NIST AI RMFAzure PurviewServiceNow GRCMicrosoft Responsible AI

    Trust assets delivered

    • Board governance report
      A standing, board-ready view of the AI estate: inventory, risk tiers, incidents, and approval pipeline.
    • Mock audit results
      Control testing evidence showing the program holds up under audit conditions before a real auditor asks.
    • AI policy library
      The complete policy and contract clause set governing AI use, procurement, and data handling.
    Lessons

    What made it audit-ready

    Inventory before policy

    Governance written without a real inventory governs an imaginary estate. Discovery came first, so every control maps to something actually deployed.

    Risk tiering keeps governance fast

    Not every tool needs the same scrutiny. Tiering let low-risk automation move quickly while clinical and PHI-touching AI got deep review — which is how approval time dropped instead of rising.

    Contracts are a control surface

    Most of the system's AI risk arrived through vendors. Audit rights, accountability, and data-use clauses made vendor AI governable — aligned to NIST AI RMF's Govern function and ISO/IEC 42001 supplier controls.

    Evidence is the product

    Model cards, evaluation packs, and mock audit results mean the next board question, auditor request, or regulator inquiry is answered from documentation that already exists.

    Build your audit-ready AI program

    Start with our interactive AI governance readiness assessment, explore the full service, or talk to us about your environment.