Skip to main content

NEOS Security, Privacy and AI Governance Manual

NEOS Trust Standard · Version 1.0

Security, Privacy and AI Governance Manual

Controls for protecting people, systems, data, and institutional trust.

1. Security Governance

Security is a shared responsibility with named executive, business, and technical owners. Controls must be proportionate to risk and reviewed whenever systems, vendors, regulations, or data uses materially change.

2. Access Control

  • Use unique accounts, strong authentication, and least privilege.
  • Review privileged access quarterly and promptly remove unnecessary access.
  • Separate routine editorial access from system administration.
  • Log material administrative, entitlement, and configuration changes.

3. Data Protection

Collect only data needed for a legitimate organizational purpose. Document retention, sharing, deletion, backup, and breach-response practices. Sensitive data must not appear in public pages, logs, prompts, or unsecured exports.

4. Vendor and Integration Risk

Vendors and integrations require documented purpose, data exchanged, authentication method, owner, failure impact, contract status, and offboarding procedure.

5. AI Classification

AI uses are classified as Assistive, Operational, or High Impact. Assistive uses help draft or organize. Operational uses automate bounded processes. High-impact uses may affect rights, access, clinical interpretation, finances, accreditation, governance, or reputation and require explicit human approval.

6. AI Controls

  • Approved data sources and prohibited data uses
  • Prompt and model version records where practical
  • Quality, bias, accuracy, and safety evaluation
  • Human-review boundaries and escalation paths
  • Visible source attribution for factual outputs
  • Logging, rollback, and incident response

7. Prohibited Autonomous Actions

AI may not independently make final clinical, legal, financial, disciplinary, credentialing, election, or governance decisions; disclose protected information; or publish unverified high-risk claims.

8. Incident Response

Potential compromise, data exposure, unauthorized access, harmful AI output, or material misinformation must be contained, preserved for investigation, escalated, corrected, documented, and reviewed for preventive action.

9. Training and Review

Administrators, editors, committee owners, and AI operators must receive role-appropriate training. This manual is reviewed at least annually and after major incidents or platform changes.