By Cheryl Howard, MSPH · PMP · PMI-CPMAI · Prosci ADKAR
Principal Consultant, Howard Consulting LLC
July 30, 2026
Prior to submitting your business case to the AI architectural review board, answer these key questions. What are the downstream consequences of using this technology? What if the AI tool provides incorrect data? What is the purpose of this AI technology?
Using an AI tool to prepare meeting minutes does not have the same risk level as using it for a clinical trial or a regulatory submission. However, many organizations apply the same governance rigor to both scenarios. This creates a needless hurdle to low-risk efforts and leaves a potential audit finding intact in high-risk work.
Pharmaceutical organizations already utilize a model to navigate this challenge. We assess computerized systems based on intended use and potential impact on patient safety, product quality, and data integrity. The ISPE GAMP 5 framework exhibits this principle by focusing governance and validation efforts toward the areas of greatest risk. AI governance should adopt the same discipline.
Where the Risk Actually Lives
In my experience, exposure should be assessed according to the process the AI tool enables, the data it generates, the outcome of an inaccurate output, level of human decision making required, and the potential impact on patients, products, or compliance burden. These factors should determine the required governance, validation, and monitoring.
Three Tier AI Assurance Model
This is the model I use with clients. It is patterned after the GxP playbook.
Tier 1: Strengthen Efficiency. This is the low-risk, standard assurance tier. It enables responsible experimentation by leveraging existing controls. It improves productivity without directly influencing a decision. Governance includes approved use, basic inventory, user training, and periodic review. Examples include preparing meeting minutes, running an internal AI knowledge agent, or using an administrative copilot.
Tier 2: Business Impact. This tier sits at moderate risk and requires increased assurance. It contributes to business impact and processes. Governance includes formal risk assessment, providing a named human owner, along with human review, testing, monitoring, and change control. The human owner and reviewer need to have expertise, authority, and time to identify when an output is incorrect. Examples include drafting SOPs, preparing an initial deviation narrative, and quality trend analysis.
Tier 3: Decision Support. The highest assurance tier earns a full lifecycle. These use cases can impact patient safety, product quality, clinical decisions, or regulatory GxP compliance. The comprehensive approach includes validation evidence, independent audit review with an audit trail, performance monitoring, and documented human approval and oversight. Examples include supporting GMP decisions, batch release recommendations, and clinical decision support.
The FDA’s Computer Software Assurance guidance reinforces this principle. Assurance activities should reflect the risk associated with the software’s intended use.
Governance is not a brake pedal to innovation.
It is the gas that earns trust & moves teams to 1st place.
A Tier Is Not Permanent
Where I Would Start
After reading the policy, can you answer these questions: Are we solving the right business problem? Do we understand the risks? Do we have governance to sustain these risks?
Your answers frame AI risk governance into a leadership capability that assists teams to become AI ready and adopt AI responsibly. Governance is a strategic enabler of trustworthy AI and a path to innovation.
References
1. International Society for Pharmaceutical Engineering (ISPE). GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems (2nd ed.), 2022. https://ispe.org/publications/guidance-documents/gamp-5-guide-2nd-edition
2. U.S. Food and Drug Administration. Computer Software Assurance for Production and Quality Management System Software: Guidance for Industry and FDA Staff.
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/computer-software-assurance-production-and-quality-management-system-software
3. National Institute of Standards and Technology (NIST). AI Risk Management Framework (AI RMF 1.0) — Section 5, AI RMF Core (Govern, Map, Measure, Manage).
https://airc.nist.gov/airmf-resources/airmf/5-sec-core/
Cheryl Howard, MSPH, PMP, PMI-CPMAI, is Principal Consultant of Howard Consulting LLC and author of the LinkedIn pharmaceutical, biotech, and healthcare organizations turn AI potential into governed, human-centered outcomes by ali is trusted, compliant, and sustainable. A Prosci-certified change practitioner and PMI Standards+ volunteer for 2026, he Kerzner’s Global Project Management Playbook (2026). She writes monthly for IIL on AI readiness, governance, and ch industries.
Connect on LinkedIn:
https://www.linkedin.com/in/cheryl-howard25/