DNA Advisory · AI Governance Benchmark

Healthcare
AI Governance Readiness

Healthcare AI carries the highest consequence of any sector — an ungoverned AI system can misdiagnose a patient, delay critical treatment, or systematically disadvantage a demographic group in clinical care. This benchmark — measured against ISO 42001 — reveals where the healthcare sector stands and what gaps remain between clinical excellence and structured AI governance.

Read the Analysis ↓
0
Industry Average
0%
Small (<200)
0%
Medium
0%
Large (1000+)
00 — URGENCY
The Clock Is Ticking
Four major regulatory and patient safety drivers are converging on healthcare simultaneously — creating the most urgent AI governance window the sector has ever faced. Every day without a structured AI governance framework increases exposure to patient harm, regulatory action, and reputational risk.
Days Until EU AI Act
Health AI = high-risk · Aug 2, 2026
LIVE
Colorado AI Act
Health AI decisions · Feb 1, 2026
ACTIVE
FDA AI/ML SaMD
Continuous approvals through 2025
PUBLISHED
WHO AI Ethics
6 principles for AI in health
01 — EXECUTIVE SUMMARY
The Healthcare AI Governance Gap

Healthcare organisations are, on average, 43% ready for ISO 42001 certification. This places the sector in the middle of the pack — ahead of energy (40%) but behind financial services (46%) and technology (53%). Yet healthcare AI carries the highest consequence of any sector: the stakes are not financial or reputational — they are lives.

Healthcare AI governance is fractured across three separate disciplines that don't communicate: clinical governance (patient safety, clinical protocols), data governance (health information, privacy), and IT governance (technology operations, cybersecurity). No hospital would introduce a new drug without clinical trials, regulatory approval, ongoing monitoring, and adverse event reporting. Why should clinical AI be any different?

ISO 42001 provides the unifying framework that bridges these silos into a single AI management system — ensuring that clinical AI, operational AI, and research AI are all governed to a consistent standard. The clinical governance infrastructure — patient safety committees, clinical audit, incident reporting, evidence-based practice — provides a mature foundation that other sectors lack. The gap is extending this discipline to AI.

€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
SaMD Gap
Regulated vs. Unregulated
Most clinical AI falls outside SaMD
Health Equity
AI Bias = Patient Harm
Demographic disparities in clinical AI
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations. Understanding the full landscape is essential before choosing a path, and helps explain why ISO 42001 has emerged as the leading certifiable option for organizations serious about structured AI governance.
ApproachWhat It IsStrengthsLimitations
Internal AI PoliciesSelf-defined governance frameworks developed in-houseFlexible, quick to implement, tailored to organizationNo external validation, inconsistent across departments, not recognized by regulators as proof of governance
EU AI Act ComplianceMeeting requirements of Regulation 2024/1689Mandatory in EU, clear penalties, health AI classified as high-riskJurisdiction-specific, not certifiable, reactive, doesn't cover full management lifecycle
FDA SaMD FrameworkFDA regulation of AI/ML-enabled Software as a Medical Device
Source: FDA Total Product Lifecycle approach
Rigorous clinical validation, established regulatory pathway, patient safety focusCovers only SaMD-classified AI. Most clinical AI falls outside SaMD. Doesn't address bias, transparency, or lifecycle governance comprehensively.
WHO AI Ethics GuidanceSix principles for AI in health (2021, updated)
Source: WHO, ISBN 9789240029200
Global moral authority, consensus principles, health-specificPrinciples, not standards. Not certifiable. No enforcement mechanism.
ISO 13485 (Medical Devices QMS)Quality management system for medical device manufacturers
Source: ISO 13485:2016
Established QMS for SaMD, certifiable, regulatory requirementCovers device quality, not AI governance. Doesn't address bias, fairness, transparency, or AI lifecycle.
ISO/IEC 42001:2023International standard for AI Management Systems (AIMS)
Source: ISO/IEC 42001:2023, published December 2023
Certifiable by accredited bodies worldwide. Covers ALL AI — not just SaMD. Bridges clinical, data, and IT governance. Addresses bias, fairness, transparency, lifecycle. Compatible with ISO 13485.Relatively new (27 months old). Healthcare-specific implementation guidance still emerging.
03 — WHY ISO 42001
The Case for ISO 42001
ISO 42001 is not the only approach to AI governance — but for healthcare organizations seeking to bridge the SaMD/non-SaMD governance divide and unify clinical, data, and IT governance into a single auditable framework, it is the strongest available option.
Governs ALL AI — Not Just SaMD
FDA/EU MDR regulates SaMD. But most clinical AI — decision support, patient flow, revenue cycle, EHR-embedded AI — falls outside SaMD. ISO 42001 governs all AI within scope, closing the governance gap that regulatory frameworks leave open. One standard for clinical, operational, and research AI.
Source: ISO/IEC 42001:2023, Clause 1 — Scope covers all AI systems.
Bridges Clinical + Data + IT Governance
Healthcare AI governance is fragmented across clinical governance (CMO), data governance (CDO/CISO), and IT governance (CIO). ISO 42001 provides a single management system that unifies these domains — ensuring AI receives consistent governance regardless of which department owns it.
Source: ISO/IEC 42001:2023 follows Annex SL — integrates with ISO 27001, ISO 13485, ISO 9001.
Health Equity Through Governance
ISO 42001 Annex A controls A.7.1–A.7.4 mandate bias assessment, fairness by design, bias monitoring, and inclusive design. For healthcare, this translates to systematic demographic performance analysis — ensuring clinical AI doesn't systematically disadvantage patient groups. Governance is the mechanism for health equity in AI.
Source: ISO/IEC 42001:2023 Annex A, controls A.7.1–A.7.4.
Compatible with Existing Systems
Healthcare organisations with ISO 13485 (medical devices), ISO 27001 (information security), or JCI/ACHSI accreditation already have governance infrastructure. ISO 42001 extends this rather than replacing it. Clinical audit, incident reporting, and management review processes transfer directly.
Source: ISO Annex SL harmonized structure. ISO estimates 30–40% implementation reduction.
39 Controls Across the Full AI Lifecycle
Annex A provides 39 specific controls covering data governance (A.4), transparency (A.5), accountability (A.6), bias and fairness (A.7), reliability (A.8), security (A.9), privacy (A.10), human oversight (A.11), documentation (A.12), and third-party AI management (A.13).
Source: ISO/IEC 42001:2023, Annex A — Reference control objectives and controls.
What ISO 42001 Does Not Cover
Medical device regulatory approval. ISO 42001 governs AI management systems, not clinical efficacy. SaMD still requires FDA clearance, EU MDR conformity assessment, or equivalent national regulatory approval. ISO 42001 complements, not replaces, medical device regulation.
Clinical validation. The standard covers governance, not clinical science. Clinical validation studies demonstrating diagnostic accuracy, sensitivity, and specificity remain the domain of clinical research and regulatory submission.
Our position: For healthcare organizations, ISO 42001 certification is the bridge between clinical governance and AI governance. The clinical infrastructure — patient safety culture, incident reporting, evidence-based practice — provides the strongest governance foundation of any sector. The gap is extending this discipline to AI systems.
The Benchmark
Healthcare averages 43% readiness.
The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How healthcare organizations score across each of the 7 mandatory ISO 42001 management system clauses. Scores reflect alignment with each clause's specific requirements, adjusted for clinical governance maturity, regulatory infrastructure, and the SaMD/non-SaMD governance divide. Click any clause to see the detailed analysis, key gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and healthcare-specific compliance infrastructure patterns.
No hospital would introduce a new drug without clinical trials, regulatory approval, and monitoring. Why should clinical AI be any different?
05 — ANNEX A CONTROLS
Control Maturity by Domain
ISO 42001 Annex A defines 39 controls across 12 groups, organized into 5 operational domains. Each domain scored on a 1–5 maturity scale based on typical healthcare implementation patterns. Data & Privacy leads at 2.5/5.0 — reflecting strong health data protection (HIPAA, GDPR) — while Third-Party management at 1.5/5.0 reveals the critical EHR vendor AI governance vacuum.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and healthcare-specific control implementation analysis.
A diagnostic AI with lower sensitivity for one demographic group will miss diagnoses in that group. People will be harmed.
06 — CRITICAL GAPS
Top 5 Gaps in Healthcare
The most significant AI governance gaps in healthcare — ranked by severity, with ISO 42001 clause references and estimated remediation timelines.
Clinical governance is healthcare's greatest asset — the gap is extending that discipline to AI systems.
07 — REGULATORY LANDSCAPE
Healthcare AI Regulations
A comprehensive reference of every regulation affecting AI governance in healthcare — current status, enforcement dates, penalty structures, and the specific impact on healthcare operations.
RegulationJurisdictionStatusPenaltiesImpact on HealthcareISO 42001 Alignment
EU AI ActEU/EEAHigh-risk: Aug 2026€35M / 7%Health insurance AI = high-risk (Annex III §5c). Medical device AI via EU MDR. Chatbots (Art. 50).Cl.6 · Cl.8 · A.5 · A.7
EU MDREU/EEAIn forceDevice enforcementAI-based SaMD must comply. Classification by clinical purpose and risk.Cl.8 · A.3 · A.8
FDA AI/ML SaMDUSAEvolvingFDA enforcementTotal Product Lifecycle approach. Continuous approvals through 2025. GMLP principles.Cl.8 · A.3 · A.8 · A.12
HIPAAUSAIn force$1.5M/category/yearAI training on PHI requires authorisation. De-identification standards for AI datasets.A.4 · A.10
GDPR (Health)EU/EEAIn force€20M / 4%Health data = special category. Explicit consent for AI processing. DPIA mandatory.A.4 · A.10 · A.2
WHO AI EthicsGlobalPublishedSoft law6 principles: autonomy, well-being, transparency, responsibility, inclusiveness, responsiveness.Cl.5 · A.5 · A.7 · A.11
Colorado AI ActColorado, USAEffective Feb 2026AG enforcementHealth AI making "consequential decisions" = high-risk. Impact assessments, bias monitoring.A.2 · A.7 · A.5
KSA SFDASaudi ArabiaIn forceRegulatorySaudi FDA governs medical devices including AI-based SaMD.Cl.8 · A.3 · A.8
KSA PDPLSaudi ArabiaFull: Sep 2025SAR 5MHealth data processing. AI training on patient data subject to PDPL.A.4 · A.9 · A.10
The regulatory multiplier: Healthcare faces AI regulation from medical device regulators (FDA, EU MDR, SFDA), data protection authorities (HIPAA, GDPR, PDPL), AI-specific regulation (EU AI Act, Colorado AI Act), and international guidance (WHO). ISO 42001 provides a single governance framework that addresses the overlapping requirements of all these regimes.
08 — METHODOLOGY
How This Benchmark Was Built
Scores were derived by mapping each ISO 42001 clause against healthcare practices, regulatory maturity, and published research. Adjusted for clinical governance maturity, the SaMD/non-SaMD divide, and health data protection infrastructure.
Data Sources
  • FDA AI/ML-enabled medical device database (continuous 2025 approvals)
  • EU AI Act (Regulation 2024/1689) — Annex III §5c
  • WHO Ethics and governance of AI for health (2021)
  • Deloitte State of AI in the Enterprise 2026 (3,235 leaders)
  • Colorado AI Act (SB24-205, signed May 17, 2024)
  • ISO Survey of Management System Certifications (2019–2024)
Important Caveats
  • Healthcare is highly heterogeneous — digital health startup vs. 10,000-bed system
  • Clinical governance is a genuine advantage — strongest foundation of any sector
  • The SaMD divide is the critical structural insight — ISO 42001 bridges it
  • Health equity is the defining moral imperative for AI governance
  • Certification typically requires 70–75% readiness to engage and 80–85% to certify
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates

Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.

He is a transformation leader specializing in governance, large-scale change, and AI-driven operating models, with over 20 years of experience across North America, Europe, and the GCC.

He holds an AI Strategy and Leadership certification from MIT and is currently pursuing Applied Agentic AI for Organizational Transformation (MIT, expected May 2026). He is the founder of Digital North Associates, an AI governance and transformation firm focused on enabling organizations to operate at machine speed while maintaining control through policy-driven governance.

Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology
© 2026 Digital North Associates. All rights reserved.
Where does your organization stand? Take the free ISO 42001 assessment — 15 minutes, no commitment.
Take Free Assessment