AI Governance & Responsible AI Policy – Life Sciences
Enterprise policy for AI governance in genomic research and precision medicine, including use classification, human oversight, traceability and lifecycle management.
Regulatory and governance references
- Regulation (EU) 2024/1689 (AI Act), consolidated text in force
- Regulations (EU) 2017/745 and 2017/746 where applicable to intended purpose
- Regulation (EU) 2016/679, including data protection by design and automated decision-making
- MDCG 2019-11 rev.1 for medical-software qualification where relevant
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Purpose and Responsible-AI Principles
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. AI Inventory and Use Cases
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Each AI use case should be registered with owner, purpose, users, inputs, outputs, data, model, version, supplier and dependencies. No model should enter production or a research protocol without a minimum file that allows assessment, traceability and suspension.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. Intended Purpose and Risk Classification
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
The current intended purpose must be reflected in product materials, manuals and onboarding. Any change introducing a medical, diagnostic, prognostic, predictive or therapeutic purpose requires a new software qualification analysis and, where applicable, an MDR/IVDR pathway and reassessment under the AI Act.
AI classification depends on intended purpose, the parties’ roles and any link to regulated products rather than on the sector in the abstract. The internal inventory should distinguish UESE-developed systems, third-party AI and deterministic functions, with reassessment whenever purpose or integration changes.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. AI Act and Applicable Regulatory Framework
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
AI classification depends on intended purpose, the parties’ roles and any link to regulated products rather than on the sector in the abstract. The internal inventory should distinguish UESE-developed systems, third-party AI and deterministic functions, with reassessment whenever purpose or integration changes.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Separation Between RUO and Clinical Functions
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
The current intended purpose must be reflected in product materials, manuals and onboarding. Any change introducing a medical, diagnostic, prognostic, predictive or therapeutic purpose requires a new software qualification analysis and, where applicable, an MDR/IVDR pathway and reassessment under the AI Act.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. Model Governance and Accountability
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. Data Quality, Provenance and Representativeness
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Metadata, provenance, lineage and documented quality are essential to make datasets interpretable and auditable. Cataloguing errors can propagate into analyses; the platform supports traceability, while scientific quality of the source remains with the parties generating and validating the data.
Training and evaluation data must be relevant to the population and use case. Bias, drift, under-representation and annotation quality should be monitored; where evidence is insufficient the limitation must be disclosed and the model must not be extended beyond the validated scope.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. Technical Documentation and Model Records
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Documentation is version controlled and may be updated to reflect technical, scientific or regulatory change. Databases imported by the customer remain subject to the rights and restrictions applicable to their source; the existence of an import feature does not grant UESE rights over the content or guarantee that the source may lawfully be reused.
Every output should be traceable to the model version and configuration that produced it. The Model Registry records at least intended purpose, version, validation status and technical references; material change requires review, renewed testing and, where needed, suspension of prior assumptions.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. Human Oversight and Veto Authority
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
RUO outputs require review by qualified personnel before they are accepted for research activity. Review must be attributable, reasoned and traceable; human oversight is not a formal rubber stamp and must be able to suspend, challenge or reject the result.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. Accuracy, Robustness and Cybersecurity
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Public information is descriptive and may be updated where it does not alter existing contractual commitments. Guaranteed specifications, service levels and features must be found in executed documents; healthcare or regulatory decisions must not rely on promotional material.
Metrics must be chosen for the intended purpose rather than reduced to a single aggregate number. Robustness and cybersecurity include anomalous inputs, dependencies, availability, manipulation and failure behaviour; thresholds and fallback conditions should be defined before operational use.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. Bias, Performance and Monitoring
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Training and evaluation data must be relevant to the population and use case. Bias, drift, under-representation and annotation quality should be monitored; where evidence is insufficient the limitation must be disclosed and the model must not be extended beyond the validated scope.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Explainability and Communication of Limitations
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Users must receive enough information to understand purpose, inputs, nature of scores, material limitations and non-use conditions. The required level of explanation is proportionate to risk and user role; a numerical score without context is not treated as adequate explanation.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Change Management, Versions and Validation
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Validation must be proportionate to purpose: test data, acceptance criteria, software and dependency versions, reproducibility and change control should be documented. Platform validation does not replace validation of the analytical method, laboratory or scientific protocol.
Every output should be traceable to the model version and configuration that produced it. The Model Registry records at least intended purpose, version, validation status and technical references; material change requires review, renewed testing and, where needed, suspension of prior assumptions.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
14. AI Suppliers and Third-Party Models
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
15. Incidents, Escalation and Model Suspension
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Events are classified by severity and impact, contained and documented. Where UESE acts as processor it notifies the controller without undue delay after becoming aware of a personal data breach and provides available information for GDPR Articles 33 and 34 assessments; regulatory notifications remain with the competent party.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
16. AI Literacy, Periodic Review and Customer Responsibility
Artificial-intelligence functions must be governed throughout their lifecycle and linked to an intended purpose, accountable roles, identifiable data and versions, and documented validation criteria. At the effective date of this framework Regulation (EU) 2024/1689 applies according to the consolidated implementation timetable; concrete obligations must be assessed for the specific use case and reassessed when law or functionality changes.
Organisations must ensure appropriate competence for personnel using or supervising AI. Training, manuals, incidents, feedback and assurance results feed periodic review; access to a platform does not replace the customer’s responsibility to organise roles and competence.
Governance should include at least inventory, owner, change control, validation criteria, monitoring, incident management and escalation. A third-party model is not automatically compliant because it is commercially available or widely used.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.