Healthcare AI Governance

    How Do We Build an AI Governance Committee and What Roles Need to Be On It?

    A governance committee is the operational core of AI oversight in a health system. Here's who needs to be on it, how to structure it, and what the AMA and Joint Commission/CHAI guidance say the minimum viable version looks like.

    Last updated: · By Teresa Younkin & Jim Younkin, Mosaic Life Tech

    Key Takeaways

    • ·The AMA identifies a minimum viable committee requiring three roles: a clinical champion (typically the CMIO), a data scientist or statistician familiar with the AI tool, and an administrative leader accountable for quality of care.
    • ·The most durable governance architecture separates enterprise oversight from use-case-specific review, using a two-tier model: an institutional steering committee as the front door, with domain-specific subcommittees handling detailed validation and monitoring.
    • ·The University of Wisconsin pattern is the documented evolutionary model: ad hoc algorithm workgroups mature to algorithm committees to formal subcommittees under an institutional steering committee.
    • ·Chief AI Officer prevalence has grown from 11% of health systems in 2023 to 26% in 2025. This role convenes committees and establishes governance requirements binding on both IT and clinical operations.
    • ·A committee that advises but lacks a named accountable individual has a structural gap. If the answer to 'who explains what happened if this tool caused harm?' is 'the committee,' that's not accountability, it's diffusion.

    The short answer

    Start with the AMA's minimum: a clinical champion, a data scientist, and an administrative quality leader. Add roles based on what's in your AI portfolio. Use a two-tier structure — an institutional steering committee that serves as the front door for all AI deployment decisions, and use-case subcommittees that handle detailed clinical validity review for individual tools. Integrate into existing operational forums rather than building a separate bureaucracy. Most organizations already have the people. What's missing is the structure, the mandate, and the named individual who is accountable when something goes wrong.

    The First Decision: Standalone or Integrated?

    Before recruiting committee members, decide where this committee lives structurally. The AMA recommends a dedicated AI governance committee when "the existing technology governance structure does not have the right representation, expertise, and/or capacity to handle AI requests." For many health systems, that's most existing structures. But the AMA also acknowledges that for smaller organizations or those with limited AI portfolios, integration into an existing committee can be the right starting point.

    Integrate into an existing committee

    Assign AI governance to a body that already has the right representation — typically Clinical Quality, the IT Governance Committee, or a combined Quality and Patient Safety structure. Add AI as a standing agenda item and expand membership as needed. This is faster to stand up, leverages existing meeting cadences, and avoids committee fatigue. It works well for organizations with fewer than five to ten active AI tools and those beginning to build governance from scratch.

    Create a dedicated AI governance committee

    A standalone committee signals organizational seriousness, enables deeper focus on AI-specific issues, and is more visible to the board and surveyors. The Joint Commission and CHAI guidance describes a multidisciplinary oversight committee as a structural expectation for reasonable AI governance. This is the right choice for larger organizations, those with a significant AI portfolio, or those preparing for formal accreditation standards.

    The University of Wisconsin system is the most frequently cited example of the evolutionary path: beginning with ad hoc "algorithm workgroups" that defined priorities and developed initial policies, which matured into "algorithm committees," which eventually became formal "algorithm sub-committees" under an institutional-level steering committee. Most health systems follow a version of this trajectory whether or not it's deliberate. Making it deliberate speeds it up.

    The C-Suite Roles That Need to Be Involved

    The AMA identifies eight C-suite executive roles as responsible for AI governance in health systems. Not all of them need to be on the committee for every meeting, but all of them need a defined relationship to the governance process. The committee lacks authority if none of these roles is the executive sponsor.

    Chief Medical Officer (CMO)

    Most common primary sponsor; AI governance intersects most visibly with clinical decision-making

    Chief Nursing Officer (CNO)

    Frontline clinical AI impacts nursing workflows most directly

    Chief Quality Officer (CQO)

    Connects AI performance to quality infrastructure and board reporting

    Chief Operating Officer (COO)

    Operational AI tools and deployment decisions run through this office

    CIO or CTO

    Technical infrastructure, vendor relationships, and IT security review

    Chief Digital Officer (CDO)

    Relevant where a CDO role exists; owns digital transformation strategy

    General Counsel (GC)

    Vendor contract review, liability exposure, regulatory compliance

    Chief Medical Information Officer (CMIO)

    Clinical informatics bridge between IT and clinical operations; most common clinical champion

    Some larger systems are creating a Chief AI Officer, a dedicated executive who convenes governance committees and holds requirements binding on both IT and clinical operations. CAIO prevalence grew from 11% of health systems in 2023 to 26% in 2025. That role isn't necessary to start, but it reflects where the accountability expectations are heading. What matters now is that one named executive can halt a deployment and is accountable to the board for AI risk.

    Committee Composition: Who Needs to Be in the Room

    The AMA's minimum viable committee for ongoing AI oversight requires three roles. Every organization should have all three regardless of size or structure. These aren't aspirational roles — they're the minimum functional core that makes committee decisions credible.

    01

    Clinical champion

    Typically the CMIO or a senior physician leader. This person understands the clinical context of AI use, bridges the committee to frontline clinical staff, and is accountable for clinical outcomes from AI-influenced decisions. The clinical champion's credibility with medical staff is what gives committee decisions traction. Without this role, the governance committee is technically competent but clinically disconnected.

    02

    Data scientist or statistician

    Evaluates model performance, interprets validation data, and assesses vendor accuracy claims against the organization's own patient population. Monitors for model drift post-deployment. This role can be shared or contracted if not available in-house, but it must exist. Organizations that rely on vendor-provided performance data without independent statistical review are outsourcing one of the core governance functions.

    03

    Administrative leader for quality

    Connects AI governance to existing quality infrastructure, owns the escalation path to the board, and ensures AI-related findings surface in Leadership and Quality reporting. This role is the link between what the committee discovers and what the board sees. Without it, governance findings can be thorough and still have no organizational effect.

    For a full committee with broader oversight authority, the Joint Commission and CHAI guidance and the University of Wisconsin governance model both describe an expanded multidisciplinary structure. Additional disciplines that strengthen the committee beyond the AMA minimum:

    • ·Nursing leadership (CNO or designee)
    • ·Clinical operations representative
    • ·Information technology and security
    • ·Bioethics or legal counsel
    • ·Human factors or patient experience
    • ·Compliance and risk management
    • ·Frontline clinical staff representative
    • ·Finance or procurement for vendor review
    • ·Academic faculty (for systems with research affiliates)

    One role worth naming specifically: the clinician-data scientist, sometimes called the translator role. This is someone who understands both clinical workflow and model behavior well enough to communicate between the two. They're uncommon, but they're the most effective bridge between technical AI output and the clinical decisions that output influences. If your organization has someone in this profile, they belong on this committee.

    The Two-Tier Structure That Holds Up Over Time

    Mature AI governance in health systems uses a two-tier model: an institutional-level steering committee that provides the "front door" and oversight of all AI models, with use-case-specific subcommittees handling detailed governance for individual tools. This separation exists because the skills and time requirements for enterprise oversight differ fundamentally from those required for deep domain-specific clinical validity review.

    The University of Wisconsin institutional committee's advantages over its earlier ad hoc workgroups include a stronger ethics and equity perspective and clearer connections to organizational leadership. Those advantages come specifically from the institutional-level structure, not from the domain-specific work that subcommittees handle. Collapsing both functions into one body tends to produce either superficial enterprise review or inadequate domain-level scrutiny.

    Tier 1: Institutional Steering Committee

    The front door for all AI tools. Every new AI deployment request enters here for initial review. This committee sets policy, owns the intake process, approves or rejects deployments at the enterprise level, and reports AI risk to the board. Meets monthly or quarterly with broad multidisciplinary representation including the executive sponsor. Its job is to ensure the right questions get asked, not to answer all of them itself.

    Tier 2: Use-Case Subcommittees

    Formed for individual tools or clinical domains: radiology AI, sepsis prediction, prior authorization automation, generative AI in documentation. Handles detailed clinical validity review, local validation on your patient population, deployment monitoring, and performance reporting back to the steering committee. Can be convened as needed rather than on a fixed schedule. Requires domain-specific clinical and technical expertise that a general steering committee can't provide and shouldn't try to substitute for.

    The Accountability Gap That Committees Can't Fill

    Committees should advise, review, and recommend. But a named individual must be accountable for each AI-influenced decision. This is the structural gap that most committee-based governance programs leave open, and it's the gap that surfaces most clearly in litigation and regulatory enforcement.

    If the answer to "who explains what happened if this tool causes harm?" is "the committee," you have identified a governance problem, not a governance structure. The committee's role is to ensure that named individual has the information, the process, and the authority to make a defensible decision. The named individual's role is to actually own the accountability.

    This applies at every level: for each high-impact clinical AI tool, there should be a named clinical owner accountable for its deployment decisions; for the governance program as a whole, there should be a named executive accountable for the program's adequacy. Committees support those individuals. They don't replace them.

    Two Barriers That Consistently Slow Governance Builds

    • ·Resource constraints: the data scientist role in particular is hard to fill internally. Consider academic partnerships, contracted data science support, or shared governance arrangements with peer institutions. The structure doesn't require all expertise to be in-house — it requires the right expertise in the room when decisions are made.
    • ·No executive champion with real authority: governance research consistently shows this as the single most predictive variable for whether programs succeed or stall. A committee that can review but can't halt a deployment isn't governing. It's documenting.

    Frequently Asked Questions

    Common questions from healthcare executives building AI governance committees.

    What is the AMA's minimum viable AI governance committee?

    The AMA identifies three roles as the minimum for a functioning AI governance committee: a clinical champion (such as the CMIO) who understands the clinical context of use, a data scientist or statistician familiar with the specific AI tool, and an administrative leader accountable for quality of care who connects governance findings to board-level reporting. These three roles represent the minimum functional core that makes committee decisions both technically credible and organizationally connected. Organizations with more than a handful of AI tools in deployment will need a broader structure, but these three roles are the non-negotiable starting point.

    Can we use an existing committee instead of creating a new one?

    Yes, and for many organizations that's the right starting point. The AMA specifically recommends incorporating AI governance into existing structures when the existing technology governance body has the right representation, expertise, and capacity. Assigning AI governance to a Clinical Quality or IT Governance Committee is faster and less resource-intensive than standing up a new structure. The requirement is that the function is real: an intake process exists, tools are reviewed before deployment, someone is accountable for post-deployment monitoring, and findings surface in board-level reporting. The structure matters less than whether governance actually happens.

    How big should the AI governance committee be?

    Start with the AMA minimum of three and expand based on your AI portfolio. A committee of six to ten that meets consistently and reviews actual deployment decisions outperforms a committee of twenty with low participation and unclear authority. Add representation as specific domains require dedicated oversight. Radiology AI, for instance, warrants radiologist representation on the relevant subcommittee regardless of whether radiologists sit on the institutional steering committee.

    What's the difference between an AI governance committee and an IT security review?

    IT security review addresses data protection, access controls, and infrastructure risk. AI governance addresses clinical validity, accountability assignment, bias assessment, local validation, and ongoing performance monitoring. Both are necessary, but they answer different questions. A tool can pass IT security review and still perform poorly on your patient population, produce biased outputs across demographic groups, or lack a clear accountability owner when something goes wrong. AI governance is the process that catches those issues.

    How does the governance committee handle shadow AI?

    Shadow AI, meaning tools adopted by departments or individual clinicians outside of IT procurement, is common and represents a genuine governance gap. The intake process is your primary control: require that any AI tool influencing clinical or operational decisions passes through the committee before use. Governance committees that periodically audit tools in active use, not just tools in procurement, surface shadow AI more reliably. The audit function also catches situations where a tool was reviewed and approved but has since been modified or expanded beyond its original scope.

    How often should the governance committee meet?

    Monthly is a reasonable starting cadence for the institutional steering committee, with the understanding that some months will have more to review than others. Use-case subcommittees should convene as needed, when a new tool is under review or a post-deployment issue requires evaluation. The cadence matters less than having a clear escalation path for urgent issues, a reliable reporting line to the board, and a meeting structure that produces documented decisions rather than informal conversations.

    Sources

    • American Medical Association. AMA AI Governance Toolkit for Health Systems. Developed with Manatt Health. 2025.
    • Joint Commission and Coalition for Health AI (CHAI). Responsible Use of Artificial Intelligence in Healthcare (RUAIH) Framework, Version 2. 2024.
    • Sendak, M.P. et al. Governance of clinical AI applications at a learning health system. NEJM Catalyst. 2022. (University of Wisconsin model cited.)
    • AI Governance in Healthcare: Current State, Frameworks, Implementation Evidence, and Gaps. MLT Internal Research Summary. 2025.
    • MLT AI Decision Impact Classification Framework v1. Mosaic Life Tech. 2025.

    About the Authors

    Teresa Younkin

    Teresa Younkin, MSHI

    CEO & Co-Founder, Mosaic Life Tech

    20+ years leading AI, data governance, and interoperability initiatives across provider, payer, and federal health IT environments, including HL7 Da Vinci standards work and ONC programs.

    Jim Younkin

    Jim Younkin, MBA, FACHDM

    CTO & Co-Founder, Mosaic Life Tech

    30+ years across federal health IT programs, enterprise interoperability, and AI governance, including directing federal AI initiatives for ONC/ASTP and co-founding Pennsylvania's first regional HIE serving 4M+ patients.

    Mosaic Life Tech helps healthcare executives build board-visible AI governance posture aligned with Joint Commission and CHAI guidance. We don't sell AI tools or implementation services. Our work is advisory, and our interest is in helping organizations govern well before expectations harden into standards.

    Building your governance committee from scratch?

    We help healthcare executives design and operationalize AI governance committees aligned with AMA, Joint Commission, and CHAI expectations. Start with a conversation.

    Start a Conversation