Abstract
AI governance ensures responsible use of AI through rules, processes, and technological tools. Implementing AI governance in healthcare delivery organizations (HDOs) requires understanding necessary capabilities and assessing readiness. This study introduces the scalable People, Process, Technology, and Operations (PPTO) framework—adapted from the People, Process, Technology (PPT) model—to guide governance across key domains. The PPTO framework offers a systematic roadmap for safe, effective, and equitable AI adoption in HDOs.
Similar content being viewed by others
Data availability
No datasets were generated or analysed during the current study.
References
Bajwa, J., Munir, U., Nori, A. & Williams, B. Artificial intelligence in healthcare: transforming the practice of medicine. Future Healthc. J. 8, e188–e194 (2021).
Mäntymäki, M., Minkkinen, M., Birkstedt, T. & Viljanen, M. Defining organizational AI governance. AI Ethics 2, 603–609 (2022).
World Health Organization. Ethics and governance of artificial intelligence. https://www.who.int/publications/i/item/9789240029200 (2021).
World Health Organization. Regulatory considerations on artificial intelligence for health. https://www.who.int/publications/i/item/9789240078871 (2023).
The White House. AI Bill of Rights. https://bidenwhitehouse.archives.gov/ostp/ai-bill-of-rights/ (2023).
The White House. Fact Sheet: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence. https://bidenwhitehouse.archives.gov/briefing-room/statements-releases/2023/10/30/fact-sheet-president-biden-issues-executive-order-on-safe-secure-and-trustworthy-artificial-intelligence/ (2023).
European Parliament and Council. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), OJ 2016 L 119/(1). https://eur-lex.europa.eu/eli/reg/2016/679/oj (2016).
European Commission. Data Act: Commission proposes measures for a fair and innovative data economy. https://ec.europa.eu/commission/presscorner/detail/en/ip_22_1113 (2022).
European Commission. How does it all work in practice for providers of high-risk AI systems? https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#ecl-inpage-how-does-it-all-work-in-practice-for-providers-of-high-risk-ai-systems? (2025).
Reddy, S., Allan, S., Coghlan, S. & Cooper, P. A governance model for the application of AI in health care. J. Am. Med. Inform. Assoc. 27, 491–497 (2019).
Leavitt, H. J. Applied organizational change in industry: Structural, technological and humanistic approaches. In Handbook of Organizations (ed. March, J. G) 1144–1170 (Routledge, 2013).
Morgan, J. & Liker, J. K. The Toyota Product Development System: Integrating People, Process, and Technology (Productivity Press, 2020).
Morley, J., Murphy, L., Mishra, A., Joshi, I. & Karpathakis, K. Governing data and artificial intelligence for health care: Developing an international understanding. JMIR Form. Res. 6, e31623 (2022).
Sandhu, S. et al. Accelerating health system innovation: principles and practices from the Duke Institute for Health Innovation. Patterns 4, 100710 (2023).
Kim, J. Y. et al. Organizational governance of emerging technologies: AI adoption in healthcare. In Proc. 2023 ACM Conference on Fairness, Accountability, and Transparency, 1396–1417 (ACM, 2023).
Boag, W. et al. The algorithm journey map: a tangible approach to implementing AI solutions in healthcare. npj Digit. Med. 7, 87 (2024).
IMDRF SaMD Working Group. Software as a medical device: possible framework for risk categorization and corresponding considerations. Int. Med. Device Regul. Forum. https://www.imdrf.org/documents/software-medical-device-possible-framework-risk-categorization-and-corresponding-considerations (2014).
National Institute of Standards and Technology (NIST). AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework (2023).
ISACA. Leveraging COBIT for Effective AI System Governance. https://www.isaca.org/resources/white-papers/2025/leveraging-cobit-for-effective-ai-system-governance (2025).
Kim, J. Y. et al. Establishing organizational AI governance in healthcare: a case study in Canada. npj Digit. Med. 8, 522 (2025).
Acknowledgements
Not applicable.
Author information
Authors and Affiliations
Contributions
J.Y.K. conceptualized the framework, conducted the investigation, analyzed the gathered information, and played a major role in the writing and editing of the manuscript. A.H. managed the project and conducted the investigation. S.B. conceptualized the framework, conducted the investigation, and provided oversight. M.S. conducted the investigation, played a major role in the reviewing and editing of the manuscript, and provided oversight. All authors read and approved the final manuscript.
Corresponding author
Ethics declarations
Competing interests
S.B. is named co-inventor of products licensed by Duke University to CohereMed Inc., FullSteam Health Inc., and Clinetic Inc.; he holds equity in Clinetic Inc. M.P.S. is a co-inventor of intellectual property licensed by Duke University to Clinetic Inc., KelaHealth Inc., and Cohere-Med Inc.; he holds equity in Clinetic Inc.; and he has received speaking engagement honoraria from Roche and the American Medical Association. All other authors declare no financial or non-financial competing interests.
Additional information
Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Supplementary information
Rights and permissions
Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/.
About this article
Cite this article
Kim, J.Y., Hasan, A., Balu, S. et al. People process technology and operations framework for establishing AI governance in healthcare organizations. npj Digit. Med. (2026). https://doi.org/10.1038/s41746-026-02419-6
Received:
Accepted:
Published:
DOI: https://doi.org/10.1038/s41746-026-02419-6
