Healthcare AI governance and implementation consulting
AI that delivers — and stands up to scrutiny.
AI is entering healthcare faster than the rules around it. That's exciting, and it's exactly where things go wrong.
In most industries you can "move fast and break things". In healthcare you can't — the thing you break is someone's care, and the scrutiny that follows is unforgiving. So the question isn't whether to use AI. It's how to put it to work in a way that's safe, compliant and trusted from day one.
That's the work I do: helping you choose the right AI, implement it properly, and govern it so it holds up when a regulator, a payer or a clinician asks the hard question.
This is one of three ways I work with healthcare founders — alongside strategic and digital marketing — so your AI is held to the same evidence discipline as everything else you put in front of the system.
Why this matters now
The EU AI Act is the first comprehensive AI law, and it reaches well beyond the EU — if your AI touches EU patients or markets, it applies to you. It classifies AI by risk, and most healthcare AI workflows fall into Annex III as high-risk. That means real obligations: risk management, data governance, human oversight, documentation and conformity assessment before you can put a system on the market.
ISO/IEC 42001:2023 is the international standard for AI management systems — the AI equivalent of ISO/IEC 27001 for information security. It's expected to be designated as a harmonised standard under the EU AI Act, which would make certification against it the primary conformity route for most Annex III high-risk systems. In other words, the standard the market is converging on is the one built to prove your AI is governed.
Get it right now and you're ready when it's mandatory, not scrambling later. Building the management system while your AI programme is still young is far cheaper — and far more credible — than retrofitting governance onto a system that's already live.
How I help
AI use-case selection and implementation
Not every problem needs AI, and the ones that do rarely need the AI everyone's talking about. I help you choose high-value use cases — where AI genuinely reduces burden, improves outcomes or unlocks capacity — and rule out the ones that add risk without return.
Then we implement AI that actually delivers. For large-scale, secure engineering I work in partnership with USM Systems, so you get healthcare-grade strategy and enterprise-grade build in one team.
AI management system build — ISO/IEC 42001
Good AI without governance is a liability waiting to surface. I build the management system, documentation and controls that prove your AI is governed — the evidence a regulator, auditor or partner will actually ask to see.
That means the practical scaffolding: AI policies, risk assessment, impact assessment, roles and accountability, and ongoing monitoring — mapped to ISO/IEC 42001 so it's recognisable and defensible.
Audit-readiness and ongoing assurance
Governance isn't a document you write once. I prepare you for certification and conformity assessment, and get the organisation to the point where an external audit is a formality, not a fire drill.
Then I help you keep the system alive as regulation and models evolve — because both will. What's compliant today needs to stay compliant as your AI, your data and the rules around them all move.
Why work with me
I'm a GAICC Certified Professional in AI Governance, and I'm currently completing the GAICC ISO/IEC 42001 Senior Lead Implementer and Senior Lead Auditor certifications — so the management system I build for you is the same one I'm trained to implement and audit against.
That governance depth sits on top of real healthcare and scientific rigour. I hold a PhD in Neurogenomics, and my track record spans the World Health Organisation, NHS England, AstraZeneca and PwC — payers, providers, industry and advisory. I understand how "the system" actually makes decisions, which is exactly where healthcare AI governance succeeds or fails.
Strategy meets execution
World-class governance still needs world-class engineering behind it. When a project calls for large-scale, secure AI implementation, I partner with USM Systems as my key AI implementation partner.
That keeps me your strategic lead — the one bringing healthcare depth, governance and accountability — while USM brings the secure AI engineering and IT muscle to build it at scale. Strategy and execution, in one team, so nothing falls through the gap between the two.
Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international standard for AI management systems — the AI equivalent of ISO/IEC 27001 for information security. It sets out how an organisation should govern its AI: policies, risk and impact assessment, human oversight, and continual monitoring. Certifying against it demonstrates that your AI is managed responsibly and consistently, not case by case.
Does the EU AI Act apply to healthcare AI?
Yes — most healthcare AI falls under the EU AI Act, and typically as high-risk. The Act reaches beyond the EU: if your system touches EU patients or markets, it applies regardless of where you're based. Healthcare use cases usually sit in Annex III, which carries the strictest obligations around risk management, data governance, documentation and human oversight.
What counts as a high-risk AI system?
Under the EU AI Act, a high-risk AI system is one used in a context where it could materially affect people's safety or fundamental rights — and Annex III lists these explicitly. Most healthcare AI qualifies, because decisions about diagnosis, triage, access to care or clinical workflow directly affect patients. High-risk systems must meet conformity requirements before they can be placed on the market.
Do I need AI governance certification now, or can I wait?
You can wait, but it's the expensive option — and the risky one. ISO/IEC 42001 is expected to become the primary conformity route under the EU AI Act, so building your management system now means you're ready when it's mandatory rather than retrofitting governance onto live systems under deadline. Early governance is also more credible to payers, partners and investors doing due diligence today.
What's the difference between AI implementation and AI governance?
Implementation is building AI that works; governance is proving it works safely and stays that way. Implementation is the model, the data pipeline and the workflow it plugs into. Governance is the policies, risk and impact assessments, oversight and monitoring that keep it safe, compliant and auditable over time. In healthcare you need both — one without the other is either a liability or a missed opportunity.