Security, Privacy and AI Governance Manual
Controls for protecting people, systems, data, and institutional trust.
1. Security Governance
Security is a shared responsibility with named executive, business, and technical owners. Controls must be proportionate to risk and reviewed whenever systems, vendors, regulations, or data uses materially change.
2. Access Control
- Use unique accounts, strong authentication, and least privilege.
- Review privileged access quarterly and promptly remove unnecessary access.
- Separate routine editorial access from system administration.
- Log material administrative, entitlement, and configuration changes.
3. Data Protection
Collect only data needed for a legitimate organizational purpose. Document retention, sharing, deletion, backup, and breach-response practices. Sensitive data must not appear in public pages, logs, prompts, or unsecured exports.
4. Vendor and Integration Risk
Vendors and integrations require documented purpose, data exchanged, authentication method, owner, failure impact, contract status, and offboarding procedure.
5. AI Classification
AI uses are classified as Assistive, Operational, or High Impact. Assistive uses help draft or organize. Operational uses automate bounded processes. High-impact uses may affect rights, access, clinical interpretation, finances, accreditation, governance, or reputation and require explicit human approval.
6. AI Controls
- Approved data sources and prohibited data uses
- Prompt and model version records where practical
- Quality, bias, accuracy, and safety evaluation
- Human-review boundaries and escalation paths
- Visible source attribution for factual outputs
- Logging, rollback, and incident response
7. Prohibited Autonomous Actions
AI may not independently make final clinical, legal, financial, disciplinary, credentialing, election, or governance decisions; disclose protected information; or publish unverified high-risk claims.
8. Incident Response
Potential compromise, data exposure, unauthorized access, harmful AI output, or material misinformation must be contained, preserved for investigation, escalated, corrected, documented, and reviewed for preventive action.
9. Training and Review
Administrators, editors, committee owners, and AI operators must receive role-appropriate training. This manual is reviewed at least annually and after major incidents or platform changes.

