The problem
Healthcare AI is assessed by two groups who rarely share a vocabulary. Clinical safety wants to know how the system fails and who notices. Information governance wants to know where the data goes. An AI vendor arrives with a model card and a penetration test, and satisfies neither.
The result is procurement that stalls for months, not because anything is wrong but because nobody has produced the evidence in the form the reviewer needs.
What you get
- DTAC preparation across clinical safety, data protection, technical security, interoperability and usability
- Clinical risk management framed for DCB0129 and DCB0160, with hazard logs that read as clinical rather than technical documents
- An AI-specific view most assessments miss: training data provenance, drift, and what happens to a clinical decision when the model is wrong
- Data protection work that addresses the actual question, which is usually whether identifiable data leaves the organisation and on what basis
- Evidence packaged for the people who will read it, separately for clinical safety and information governance
Proof point
Grounded in building healthcare AI, not just reviewing it: Zeromed, commercialised in 2017 for radiology, pathology and back-office workflow, and OxRad, an on-premise AI radiology reporting platform designed to keep patient data on site. ISO 42001 Lead Auditor, and ISACA AAISM.