Selected as Best Overall Capstone

Harvard Medical School Executive Education, "AI in Healthcare," February 2026

As featured in USA Today, Business Insider, Newsbreak

HCP-as-Pilot™ v4.0 — Operational AI Governance for AI-enabled healthcare
Read the Paper → 🇫🇷 En Français →
AI Act Audit Readiness

Deploy Healthcare AI with Confidence.

Prepare your AI systems for trusted deployment through practical governance aligned with the EU AI Act, ISO/IEC 42001 and ISO/IEC 23894.

AI Act Audit Readiness Sprint™ — a two-week operational governance assessment for regulated AI workflows.

Built for AI healthcare startups, SaMD and digital therapeutics companies, clinical AI vendors, insurers and care providers deploying AI. The Sprint answers the question buyers and boards keep asking: are you investor-ready, procurement-ready, and AI Act ready?

In two weeks you walk away with a board-ready evidence pack — your AI Act position, prioritised gaps, and a 90-day action plan for one AI workflow.

AI Act Audit Readiness Sprint — Before and After comparison for AI healthcare startups with medical devices: from uncertain and exposed (unclear classification, gap blind spots, no audit trail) to confident and ready (clear position, risk and gap map, audit-ready dossier). Two-week operational governance assessment. EU AI Act compliant.
From compliance uncertainty to competitive advantage — the AI Act Audit Readiness Sprint™ for AI healthcare startups with medical devices, in two weeks.

PRACTITIONER CREDENTIALS

Why trust us with your AI governance?

AI governance for healthcare is a new discipline. We invest in formal certification alongside real-world deployment experience to ensure our assessments meet the standard regulators expect.

EXIN Artificial Intelligence Compliance Professional (AICP) Certificate — Andrew Squire, July 2026. Certified by EXIN, organised by Advised Skills Ltd.

EXIN Artificial Intelligence Compliance Professional (AICP) · Certificate No. 12602/2026 · July 2026

Governance Framework Alignment

Aligned to the standards regulators recognise.

Our assessments are informed by recognised international governance, risk and lifecycle frameworks — so findings map cleanly to the expectations of auditors, procurement teams, and clinical governance boards.

AI Governance

ISO/IEC 42001

AI Risk Management

ISO/IEC 23894

AI Lifecycle

ISO/IEC 5338

Enterprise AI Risk

NIST AI RMF

Data Quality

CEN/CLC/TR 18115:2024

Ethics & Human Rights

ISO/IEC TR 24368

Regulatory Alignment

EU AI Act

Healthcare AI

MDR / IVDR / GMLP

Framework alignment supports a structured, defensible assessment. Framework alignment is used for assessment mapping only; it does not imply certification, accreditation, or formal conformity with any standard. CEN/CLC/TR 18115:2024 (European AI data-governance and quality) aligns with the international ISO/IEC 5259 series.

EU AI Act Compliance Checker — Free self-assessment tool to determine your AI system's risk classification and compliance obligations

FREE SELF-ASSESSMENT

EU AI Act Compliance Checker

Not sure where your AI system may fall under the EU AI Act? Start with the public EU AI Act compliance checker to understand possible risk classification, obligations, and next questions — in under 5 minutes.

Start Free Compliance Check →

This is a self-assessment starting point, not legal advice or a substitute for formal regulatory review.

EXPLAINER VIDEO SERIES

Can Your Healthcare AI Pass an EU AI Act Audit?

Operational Governance Readiness for Healthcare AI

Video 1 of 7

The Urgent Problem — Why Good Intentions Don’t Pass an Audit

Why healthcare AI systems need operational governance infrastructure — not just good intentions — to satisfy EU AI Act expectations on human oversight, logging, transparency, and vulnerable-user safeguards.

More coming soon
Series in production

A 7-part series on EU AI Act audit readiness for healthcare AI — covering human oversight, evidence, runtime governance and what auditors look for.

Why Most AI Audits Fail

Documentation is necessary. Operational governance is what ultimately matters.

Most AI audits focus on documentation. They review policies, procedures and controls. However, regulators increasingly expect organisations to demonstrate more than paperwork.

Human oversight Accountability Risk management Traceability Governance evidence
Documentation is necessary. Operational governance is what ultimately matters.

Our approach combines regulatory analysis, governance frameworks and practical implementation guidance to help healthcare AI organisations move from compliance theory toward demonstrable governance capability.

How We Assess AI Governance

A structured decision process — the way regulators and auditors think.

Every assessment follows the same defensible logic, applied to one named workflow or deployment context.

Step 1

Classification

Classify the AI system — its purpose, risk tier, and exposure under the EU AI Act.

Step 2

Actor

Identify the responsible actor — provider, deployer, or both — and where accountability sits.

Step 3

Obligation

Determine the applicable obligations that follow from the classification and actor role.

Step 4

Evidence

Assess governance evidence — whether the organisation can actually demonstrate each obligation.

Classification → Actor → Obligation → Evidence. This mirrors how regulators and auditors reason about AI systems — and where most organisations have gaps.

The Problem

Most AI audits stop before runtime.

Document reviews, model evaluations, and pre-deployment checklists are necessary — but they describe intent, not behaviour. They do not tell you what your AI will actually do in production, on the day it acts.

01

Policy ≠ enforcement

A policy that is not technically enforceable at runtime is a statement of intent. It does not stop an AI from acting beyond its authority.

02

Logging ≠ governance

Logs describe what happened. They do not constrain what is allowed to happen, who must approve it, or when an action must halt.

03

Monitoring ≠ operational control

Dashboards observe systems after the fact. Operational control means decisions can be bounded, escalated, and reversed in real time.

Regulators increasingly care about what happens while AI is acting — not only what was documented before deployment.

Policies define intent. Runtime governance provides the evidence auditors, clinical boards, and procurement teams increasingly expect.

Runtime governance Human oversight Escalation Traceability Bounded autonomy

EU AI Act Alignment

What the Readiness Sprint maps against.

The Readiness Sprint is not legal advice or a formal conformity assessment. It helps your team understand whether one AI workflow has the operational controls and evidence expected in regulated deployment contexts.

Art. 14

Human Oversight

Can human authority be exercised at the moment of decision, with clear approval, override, and escalation pathways?

Art. 12

Logging & Record-Keeping

Can the organisation reconstruct what happened, when it happened, who reviewed it, and what action was taken?

Art. 9

Risk Management

Are workflow-level risks identified, classified, monitored, and controlled across the AI lifecycle?

Art. 50

Transparency

Are users clearly informed when they are interacting with AI, especially in patient-facing, caregiver-facing, or senior-facing workflows?

Art. 5

Vulnerable Population Safeguards

Are controls in place to prevent manipulation, dependency creation, or exploitation of age, disability, cognitive vulnerability, loneliness, or social isolation?

Operational Governance Readiness

What the Readiness Sprint actually assesses.

A nine-domain operational maturity matrix — not a document review. We compare your current state with what regulated agentic AI demands at runtime, in plain commercial language.

Governance Area Typical Organisation State What We Assess
AI Inventory Partial register, scattered across teams. Whether every agentic workflow is identified, owned, and classified by risk and authority.
Workflow Risk Classification Treated as model-level risk, not workflow-level. Risk tiering of each workflow against EU AI Act exposure, clinical impact, and reversibility.
Human Oversight Human-in-the-loop on paper; review after the fact. Whether oversight exists at the moment of decision, not as retrospective review.
Runtime Controls Guardrails defined, rarely enforceable in production. Whether technical controls can bound, halt, or correct an AI action while it is happening.
Escalation Pathways Implicit, undocumented, person-dependent. Deterministic escalation logic — who is paged, when, and with what authority to override.
Auditability Logs exist; reconstruction of decisions is hard. Whether any past AI decision can be replayed end-to-end with the evidence regulators expect.
Consent Governance Consent captured upstream, not enforced downstream. Whether consent is bound to data, agents, and actions at runtime — not stored as a checkbox.
Operational Authority Boundaries Unclear what an AI is allowed to decide vs. recommend. Risk-tiered AI authority: where autonomy ends and human approval is mandatory.
Regulatory Evidence Readiness Scattered artefacts, no single defensible package. Whether the organisation can produce regulator-ready evidence on demand for a named workflow.
Vulnerable User & Transparency Safeguards AI is friendly and helpful, but transparency, non-manipulation, and dependency safeguards are implicit. Whether patient-facing or senior-facing AI workflows clearly disclose AI interaction, avoid persuasive exploitation, maintain non-medical boundaries where required, and escalate appropriately.

This is operational governance readiness — not a document review. It produces specific, prioritised actions tied to one named workflow or deployment context.

What You Receive

AI Act Audit Readiness Sprint™ — your deliverables.

Designed for organisations evaluating regulated AI deployment, governance maturity, or EU AI Act preparedness. Every engagement produces a board-ready package your regulatory, clinical and executive teams can act on immediately.

Tier 1 — Fixed-scope diagnostic
CHF 1,600 startup / single workflow CHF 2,200 regulated healthcare or multi-stakeholder workflow
2-week sprint · one workflow

A focused, executive-grade diagnostic — not a large consulting engagement.

We assess one specific workflow or deployment context against runtime governance requirements, then deliver a board-ready package your regulatory, clinical, and executive teams can act on immediately.

Fixed scope. Fixed price. Fixed two-week delivery.

1

Regulatory Positioning Memo

Likely AI classification, EU AI Act exposure, and operational governance implications — translated into commercial and clinical decisions. Includes review of transparency duties and vulnerable-user safeguards where the workflow interacts with patients, caregivers, seniors, or other protected groups.

2

Runtime Governance Gap Assessment

Identifies where current workflows lack enforceable runtime controls — not where documentation is missing.

4

Human-Agent Oversight Blueprint

Preliminary HAT operational model: escalation pathways, authority boundaries, and where human approval is non-negotiable.

5

Prioritised 90-Day Governance Action Plan

What to fix first, what to fix next, and how to evidence each control to regulators, clinical boards, and procurement.

6

Vulnerable User & Transparency Safeguards Review

Assessment of whether the workflow includes adequate transparency, non-manipulation, escalation, and boundary controls for patient-facing, caregiver-facing, or senior-facing AI use cases.

7

Provider / Deployer Assessment

Clarifies your role under the EU AI Act — provider, deployer, or both — and the obligations that follow for the assessed workflow.

8

Framework Alignment Assessment

Maps the workflow against recognised frameworks — ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 5338, CEN/CLC/TR 18115:2024 and NIST AI RMF — to surface where governance evidence is strong and where it is thin.

9

Healthcare Regulatory Interaction Review

Reviews how EU AI Act obligations interact with healthcare-specific regimes (MDR / IVDR / GMLP) for the assessed workflow, so duplicate or conflicting requirements are visible early.

Risk map preview

Workflow
Risk Tier
Allowed Autonomy
Required Oversight
Triage assistant for clinical intake
High
Recommend only — no clinical commitment.
Clinician approval at the moment of decision.
Care coordination scheduling agent
Medium
Bounded autonomy within consented scope.
Deterministic escalation on out-of-bounds events.
Internal knowledge retrieval & summarisation
Low
Autonomous within audit-logged guardrails.
Periodic sampling and drift monitoring.
Delivered as a single board-ready PDF dossier.

See It Before You Buy

Sample deliverable excerpts.

A look at the format and decision-grade clarity each engagement produces — so you can picture exactly what lands in your two-week dossier.

Regulatory Positioning Memo

WorkflowPatient triage assistant Likely AI Act classificationHigh-risk Primary actorProvider Key obligationsArticles 9–15 Priority gapHuman oversight at decision point

AI Workflow Risk Map

WorkflowCare-coordination scheduling agent Risk tierMedium Allowed autonomyBounded, within consented scope Required oversightDeterministic escalation on out-of-bounds events

90-Day Governance Action Plan

First 30 daysBuild AI inventory & risk classification By 60 daysDefine human oversight roles & authority boundaries By 90 daysImplement escalation pathways & evidence capture

Illustrative examples only — representative of format and depth, not drawn from any specific client engagement. Classifications and obligations are determined per workflow during the Sprint.

How It Works

Two weeks. One workflow. One executive readout.

A focused engagement built for clarity and decision-pressure — not open-ended consulting.

Week 0

Discovery & Workflow Selection

Structured 60-minute deep-dive. We agree on the single workflow or deployment context to assess and the decisions the diagnostic must inform.

Weeks 1–2

Governance Audit Sprint

Runtime governance assessment, oversight architecture review, targeted stakeholder interviews. Mid-sprint direction-check with your team.

End of Week 2

Executive Readout & Blueprint

Two-hour executive readout. Final memo, AI Workflow Risk Map, oversight blueprint, and 90-day action plan delivered as one PDF dossier.

Focused engagement. One workflow or deployment context. Not unlimited consulting scope.

AI Governance Maturity

Governance is a journey — the Sprint shows you where you stand.

Most organisations are further down this path than they realise — and the gap to audit readiness is usually operational, not documentary.

Level 1

AI Experimentation

AI is used in pockets. Tools are adopted ahead of governance, with little central visibility or risk classification.

Level 2

Policies & Controls

Policies, procedures and controls exist on paper. Governance is documented, but not yet demonstrably enforced in practice.

Level 3

Audit Readiness

The organisation can evidence governance for named workflows on demand — classification, oversight, and accountability are demonstrable.

Level 4

Operational Governance

Governance is embedded in day-to-day operations. Oversight, escalation and evidence capture run as routine practice, not exception.

Level 5

Runtime Governance

Governance is enforced at the moment AI acts — bounded autonomy, real-time oversight, and replayable evidence built into the system.

Safety OS™ is designed to support progression toward Level 5 — Runtime Governance Infrastructure for healthcare AI. The Readiness Sprint shows where you stand today and what it takes to advance.

Designed For

Built for organisations deploying AI under scrutiny.

The Sprint is scoped for healthcare and regulated environments where AI decisions carry real-world consequences.

Hospitals
Care Homes
Health Insurers
Pharmaceutical Companies
Digital Health Startups
Medical Device Developers
Public Sector Organisations
Regulated Enterprises Deploying AI

Typical buyers

RoleWhy they engage
CEOInvestor and procurement readiness — remove AI as a deal-stage risk.
FounderResolve EU AI Act uncertainty before it blocks customers or funding.
Head of QualityGenerate defensible governance evidence for audits and clients.
Compliance LeadA structured gap assessment against recognised frameworks.
Chief Medical OfficerA credible human-oversight model for patient-facing AI.
Product LeadConfirm high-risk classification and the obligations that follow.

Honest Scope

A focused diagnostic — not everything.

Clarity on what this Sprint is, and what it deliberately is not, so the engagement is the right fit before we start.

This Sprint is a strong fit if you…

  • Are deploying or piloting AI in a regulated or healthcare context.
  • Need to understand your EU AI Act exposure for a specific workflow.
  • Want board-ready governance evidence within two weeks.
  • Face investor, procurement or customer questions about AI governance.

This Sprint is probably not for you if you want…

  • Legal advice or a formal legal opinion.
  • MDR / IVDR certification support.
  • A notified-body conformity assessment.
  • A generic AI strategy or ideation workshop.
Limited capacity. To preserve founder-led delivery depth, only a small number of Sprint engagements are accepted each month. Early enquiry secures a kickoff slot.

Beyond Readiness

When Tier 1 surfaces real exposure, the next layers build the infrastructure.

Tier 2 and Tier 3 are enterprise engagements designed for organisations operationalising runtime governance for regulated agentic systems.

Tier 2 — Pricing on request

Runtime Governance Blueprint

Detailed oversight architecture for one or more priority workflows.

  • Detailed oversight architecture across the priority portfolio.
  • Authority stratification — risk-tiered AI authority, by role and decision.
  • Deterministic escalation logic, halt conditions, and override pathways.
  • Runtime governance design that is technically enforceable, not aspirational.
  • Governance evidence mapping aligned with EU AI Act, MDR, and FDA expectations.
Discuss Tier 2 →

Tier 3 — Pricing on request

Safety OS / RGI Implementation

Operational deployment of Runtime Governance Infrastructure.

  • Governance control layer integration with your AI and clinical systems.
  • Runtime enforcement architecture — bounded autonomy at production scale.
  • Audit infrastructure: replayable decisions, evidence on demand.
  • Operational governance deployment with Human-Agent Team patterns.
  • Implementation support through pilot and into supervised production.
Discuss Tier 3 →

What Success Looks Like

In two weeks, you move from uncertainty to evidence you can act on.

This is what founders and governance leads actually buy — not a report, but a defensible position and a decision.

Your EU AI Act position clarified — risk classification and provider/deployer status for one workflow.
Governance gaps prioritised — what to fix first, and why it matters to an auditor.
An investor-ready evidence pack — governance maturity you can show in due diligence.
A procurement-ready governance narrative — answers for hospital, insurer and enterprise buyers.
A prioritised 90-day action roadmap — concrete next steps, not theory.
A clear decision — proceed, remediate, or redesign — backed by evidence.

The Sprint is a readiness assessment, not legal advice, MDR certification, or a notified-body assessment. It tells you where you stand and what to do next.

Andy (Andrew) Squire

Founder, PatientCentricCare.AI
Architect, Physician-as-Pilot™ & Safety OS™
Basel, Switzerland

Book Readiness Sprint →

Frequently asked questions

Common questions about the AI Act Audit Readiness Sprint™.

How is this different from a generic AI audit?

Most AI readiness audits assess documents and models. We assess whether your organisation is operationally ready to safely govern AI systems at runtime. Policy is not enforcement, logging is not governance, and monitoring is not operational control.

What does the Readiness Sprint actually assess?

Nine assessment domains for one named workflow: AI inventory, workflow risk classification, human oversight, runtime controls, escalation pathways, auditability, consent governance, operational authority boundaries, and regulatory evidence readiness — including vulnerable-user and transparency safeguards where the workflow is patient-, caregiver- or senior-facing. These map directly to the nine deliverables listed in “What You Receive”.

How much does Tier 1 cost?

CHF 1,600 for a startup or single workflow; CHF 2,200 for a regulated healthcare organisation or multi-stakeholder workflow. Fixed scope, delivered over two weeks against one workflow or deployment context. Each Sprint is delivered directly by Andy Squire, and capacity is intentionally limited to ensure depth and defensibility.

What do I receive at the end?

A board-ready PDF dossier containing nine deliverables: the Regulatory Positioning Memo, Runtime Governance Gap Assessment, AI Workflow Risk Map, Human-Agent Oversight Blueprint, Prioritised 90-Day Governance Action Plan, Vulnerable User & Transparency Safeguards Review, Provider / Deployer Assessment, Framework Alignment Assessment, and Healthcare Regulatory Interaction Review.

What is Tier 2 and Tier 3?

Tier 2 — Runtime Governance Blueprint translates the Tier 1 diagnostic into an enforceable oversight architecture, authority stratification, and escalation logic. Tier 3 — Safety OS / RGI Implementation deploys the runtime governance control layer, audit infrastructure, and operational governance with implementation support. Both are priced upon request.

Why does the EU AI Act make this urgent?

EU AI Act high-risk obligations become enforceable on 2 August 2026. If your AI lands in a high-risk category, operational, transparency, and human-oversight requirements apply by default. Teams retrofitting under deadline pressure are visible to procurement and regulators as exactly that.

Who delivers the Sprint?

Andy Squire, Founder of PatientCentricCare.AI and Architect of the Physician-as-Pilot Safety OS. 20+ years inside regulated pharma (Roche, Novartis, Takeda) and four AI healthcare programmes (Harvard Medical School, Oxford Saïd, Microsoft/INSEAD, Cambridge).

Is this a legal compliance audit?

No. The Readiness Sprint is an operational governance readiness assessment. It does not replace legal advice, formal conformity assessment, notified body review, or regulatory certification. It helps organisations identify practical governance gaps, evidence gaps, and runtime control requirements before procurement, clinical governance, or regulatory scrutiny.

Why does vulnerable-user protection matter?

Some AI workflows interact with people who may be vulnerable because of age, disability, illness, cognitive change, loneliness, or dependency. The Readiness Sprint reviews whether the workflow includes transparency, non-manipulation, escalation, and authority-boundary controls so the system supports users without exploiting vulnerability.

Does Safety OS guarantee EU AI Act compliance?

No. Safety OS and the Readiness Sprint help organisations operationalise and evidence governance controls aligned with regulatory expectations. Compliance depends on the specific AI system, use case, legal role, risk classification, deployment context, and applicable sector regulations.

AI capability is accelerating. Governance infrastructure is not.

PatientCentricCare.AI helps organisations operationalise human authority, bounded autonomy, and runtime governance — before regulatory pressure forces retrofits.

Book Readiness Sprint → View Safety OS
One workflow. Fixed scope. Board-ready evidence pack within two weeks.
Book Readiness Sprint →

PatientCentricCare.AI aligns its governance approach with the principles of the EU AI Act and recognised AI governance frameworks including ISO/IEC 42001 and ISO/IEC 23894. Our objective is not simply compliance, but helping organisations deploy AI safely through trusted continuity, transparency and meaningful human authority.