A reusable, fillable pre-deployment gate for any framework or app in the Clinical Epistemology portfolio. Completing it is the system's governance "birth certificate" — the record of the risk under which it earned the right to be deployed. Structured on the CHAI Risk Categorization Tool (v3).
Score each modifier honestly. "N/A" and "Need More Info" are valid, first-class answers — do not assign a Low a system has not earned.
How to complete (6 steps).
Align on the use case — fill the header from the CHAI Applied Model Card or equivalent (intended use, users, patient population, deployment scope).
Read all modifiers end-to-end before scoring, so inter-modifier dependencies are visible.
Score each modifier Low / Medium / High — or N/A / Need More Info — recording rationale and evidence.
Review as a set: did any score change once you saw the whole picture? Update and note why.
Name the mitigation: for every Medium/High, cite the CRRF gate (or organizational control) that addresses it, and record any residual gap.
Complete both domains. Any single High → conduct a rigorous risk assessment before deployment. If the solution is SaMD, FDA guidance governs.
Domain 1 · Life & Patient Safety
#
Risk modifier
Low / Medium / High (abbrev.)
Response
Rationale & evidence
CRRF gate
1
Distance From PatientHow close the AI is to the patient.
L: no direct impact / back-office. M: indirect (scheduling, non-clinical). H: semi-direct or direct in patient care.
Gate 7
2
Decision AutonomyHow much human judgment stands between output and action.
L: Assistive — human decides. M: Augmentative — human on the loop. H: Autonomous — AI decides.
Gate 7
3
Consequences of FailureWorst-case severity if the output is incorrect.
L: no meaningful harm. M: temporary/reversible harm. H: permanent harm, disability, or death.
Gates 4–5
4
Use Context & ComplexityCriticality of setting + complexity of population.
L: non-critical / outpatient, stable. M: inpatient/urgent, complex but stable. H: life-critical/emergency, complex or unstable.
Gate 1
5
Monitoring DifficultyHow hard/resource-intensive to monitor output.
L: embedded real-time monitoring. M: partial; periodic. H: must be developed / resource-intensive manual.
Gate 9
6
React TimeTime to react before serious consequences.
L: time for reaction/planning. M: limited time. H: very little / none.
Gate 8
7
Breadth of Potential HarmHow broadly harm could spread across patients/sites.
L: single / small number. M: moderate; multiple units/clinics. H: widespread; systems/populations.
Gate 6
8
Cross-System PropagationHow far an incorrect output could cascade.
L: isolated. M: integrated, limited connections. H: deeply embedded; single point of failure cascades.
Gate 3
9
Population Sensitivity / DisparityRisk of exacerbating disparities/bias.
L: minimal. M: some disparity risk. H: significant; could reinforce inequities for vulnerable groups.
Gates 6, 8
Domain 2 · Technology & Data
#
Risk modifier
Low / Medium / High (abbrev.)
Response
Rationale & evidence
CRRF gate
1
Use of Sensitive DataSynthetic vs. de-identified vs. PII/PHI.
L: automated, timely, integrated with incident mgmt. M: partial; manual review. H: minimal/absent; no AI-incident separation.
Gate 9
10
AI Detection & TraceabilityWhether AI influence is visible/auditable.
L: outputs labeled; full audit trails. M: partial labeling/auditability. H: AI influence invisible to users.
Gate 8
Licensing & scope. Structured on the CHAI Risk Categorization Tool (v3), published by the Coalition for Health AI under CC BY-NC-ND 4.0. This is an independent internal template that aligns to the CHAI Tool; consult the source document for authoritative modifier definitions. A governance aid, not clinical, legal, or regulatory advice. Fillable in-browser; no data is stored — use Print / Save as PDF to retain a completed copy.