1. Intended use boundary
Describe who uses the system, for which task, in what setting, on which population, and for what decision. List excluded uses with equal precision. Marketing language and technical capability must not silently expand the intended use.
2. Clinical consequence map
Identify credible failure modes, affected people, severity, time to harm, reversibility, and existing safeguards. Include omission, delay, hallucination, automation bias, subgroup performance, workflow disruption, and escalation failure.
3. Evidence record
Connect every material claim to a source, dataset, evaluation, reviewer, date, population, and limitation. Distinguish internal prototype testing from evidence suitable for a clinical or regulatory decision.
4. Human factors and workflow
Test whether users understand limitations, notice uncertainty, verify consequential outputs, resist automation bias, and can escalate safely. A technically accurate output can still be unsafe in a poorly designed workflow.
5. Operational controls
Define access, logging, privacy, monitoring, incident response, rollback, model and prompt change control, and evidence retention. Assign owners and response deadlines before release.
6. Qualified authorization
Prepare a handoff that states intended use, excluded use, evidence status, unresolved risks, mitigations, monitoring, and the decision required. Authorization must be named, bounded, dated, and revocable.