Portfolio

Governance work that
goes into production.

Every Provenance engagement is built from scratch for the client's regulatory environment, risk profile, and values. Two engagements are represented here.

Healthcare AI · AI Governance Framework

Psychiatric AI Documentation Startup

A pre-launch psychiatric AI tool that transcribes clinician dictation, generates structured clinical notes, and evaluates those notes against insurance payer documents to support prior authorization—operating in one of the highest-stakes environments in clinical AI.

Sector Healthcare AI / Psychiatric Software
Engagement April 2026
Engagement Type AI Governance Framework
Stage Pre-production / Pre-pilot

The Challenge

A founding team preparing for clinical pilot needed an honest governance assessment before any real patient data was processed. The product handles PHI, interfaces with payer systems, and produces outputs that directly affect patient care decisions—with no governance framework in place.

A CompassAI diagnostic surfaced the pre-launch gaps. The engagement expanded into a full five-pillar AI Governance Framework built to carry the product into pilot.


Key Considerations

  • Psychiatric patients are among the most vulnerable in clinical care. Every governance decision carries heightened ethical and legal weight.
  • Three output sources—clinician dictation, model inference, payer policy evaluation—must be distinguishable at review, not collapsed into a unified output.
  • Mandatory affirmative approval engineered into the product. No note finalizes without deliberate clinician action.
  • Clinician attestation on every finalized note. Accountability explicit, traceable, and auditable.
  • Critical HIPAA gap: no signed BAA with Azure cloud provider. Identified as the highest-priority pre-launch action item.
  • Audit log architecture assessed for full note provenance: model output, auto-populated fields, and clinician changes—individually attributable.
  • Cyber insurance co-design: governance documentation and incident response protocols built to satisfy both regulatory and underwriter review simultaneously.

Governance Profile at a Glance

Transparency
Strong. Full AI disclosure in every output. Clinician-selected payer documents constrain model scope.
Fairness
Developing. No proprietary fine-tuning reduces bias risk. Formal equity assessment and adversarial testing planned pre-pilot expansion.
Privacy
Needs attention. Azure-contained pipeline. Critical gap: unsigned BAA with Microsoft—most urgent pre-launch item.
Explainability
Developing. Mandatory approval and attestation in place. Source distinction in the clinician interface to be implemented.
Robustness
Developing. Baseline monitoring in place. Incident response and change control protocols to be formalized before pilot expansion.

Deliverables

CompassAI Assessment

Five-pillar governance diagnostic surfacing pre-launch gaps and prioritized action items.

AI Governance Framework v2.0

Full five-pillar framework: current posture, identified gaps, planned actions, and recommended protocols.

Product Design Guidance

Source delineation architecture for the clinician UI; mandatory approval flow; attestation language.

Cyber Insurance Alignment

Governance deliverables mapped to cyber insurance requirements for coordinated pre-launch review.

"Working through the governance framework before we deployed gave us a level of confidence we would not have had otherwise. Responsible AI governance became integral to how we thought about what we were building, not just how we documented it."

Founder, Psychiatric AI Documentation Startup

Outcomes

Full governance framework in place before the first clinical pilot participant is enrolled—shaping product architecture, not documenting it retroactively.

Governance built into the product itself: mandatory approval step, source-distinguished review interface, and clinician attestation on every output.

BAA identified as top pre-launch action item, prioritized across both HIPAA compliance and cyber insurance underwriting simultaneously.

Arts Nonprofit · AI Fluency & Governance

Canadian Arts Nonprofit

An artist-run nonprofit operating a dance festival, artist residency, and youth intensive (ages 8–18) serving equity-seeking communities including Indigenous artists—funded across national, provincial, and municipal arts councils.

Sector Arts Nonprofit
Location Canada
Engagement March 2026
Engagement Type AI Fluency, Privacy Governance, Research Protocols

The Challenge

A lean, budget-constrained nonprofit with zero existing AI infrastructure held significant responsibility for youth participants, Indigenous artists, and donor data. AI tools that could reduce administrative burden were accessible—but the risk of privacy exposure and value misalignment was real.

The engagement had to be grounded in Canadian law, OCAP principles, and the organization's specific community commitments before a single tool was adopted.


Key Considerations

  • Youth (ages 8–18) and Indigenous artists carry heightened data protections under Canadian law. Governance set above the legal minimum from the outset.
  • OCAP principles (Ownership, Control, Access, Possession) applied to all frameworks touching Indigenous community data. Consent treated as relational, not transactional.
  • Five Canadian legal frameworks integrated: PIPEDA, Ontario Human Rights Code, OCAP, CASL, and the Child, Youth and Family Services Act.
  • Public AI tools classified as zero-confidentiality environments. The framework defines explicit data boundaries for what can and cannot enter any AI system.
  • Parental consent built at the program level—covering registration, photo/video releases, and AI-assisted workflows—not added as an afterthought.
  • Tool selection criteria: workflow relevance, nonprofit pricing, Canadian data residency compliance, and minimal technical overhead.

Deliverables

AI Fluency Reference

Staff-facing guide using the 4D Framework with organization-specific use cases: research, writing, data analysis, workflow automation.

Privacy & Data Governance Framework

Internal governance (legal requirements, consent standards, AI data rules, breach protocol) plus external commitments for participants, donors, and community members.

AI Tools Starter Stack

Six tools evaluated for a small Canadian arts nonprofit: Claude, Google for Nonprofits (incl. NotebookLM), Gamma, Canva AI, Otter.ai, and Zapier.

AI Research Protocols

Guidelines for AI-assisted grant research and funder landscape scanning, with verification requirements for time-sensitive or regulatory information.

Learning Path

Curated free training resources with onboarding timeline. ~3 hours total for all staff and new board members.

CompassAI Assessment

Governance diagnostic establishing the organization's AI posture as a baseline for the engagement and ongoing review.


Legal Frameworks Addressed

  • PIPEDA (Personal Information Protection and Electronic Documents Act)
  • OCAP Principles for Indigenous data sovereignty
  • Ontario Human Rights Code
  • CASL (Canada's Anti-Spam Legislation)
  • Child, Youth and Family Services Act

Outcomes

Privacy and governance framework in place before any AI adoption—grounded in Canadian law and the organization's specific community commitments.

Staff onboarding pathway built on free, sequenced training resources. ~3 hours total—achievable alongside a full program calendar.

Leadership equipped with a consistent tool evaluation framework and a vetted starter stack, ready to implement immediately.

Ready to build something responsibly?

Provenance works with organizations at any stage of AI adoption. Whether you are building a product or integrating tools into an existing workflow, we can help you do it right.

Get in Touch