AI GOVERNANCE FORM v1.0 · VRC1 PLATFORM CONFIDENTIAL
AI Governance Intake & Scope Confirmation Form
Complete all required sections before engagement commences. Sections marked REQUIRED must be fully populated prior to engagement start.
SECTION 01ENGAGEMENT OVERVIEWREQUIRED
SECTION 02ORGANIZATION & COMPLIANCE CONTEXT
REGULATORY REQUIREMENTS (SELECT ALL THAT APPLY)
SECTION 03ENGAGEMENT OBJECTIVES
PRIMARY GOAL (SELECT ALL THAT APPLY)
SECTION 04AI SYSTEM INVENTORY● CRITICAL
SCOPE NOTE: Include ALL AI/ML tools regardless of deployment model — public LLMs, fine-tuned models, vendor-embedded AI, internal pipelines, and automation tools with AI components. VanRein assesses both external and internal surfaces.
PUBLIC / COMMERCIAL LLMS IN USE (SELECT ALL THAT APPLY) *
INTERNAL AI / ML MODELS OR PIPELINES
AI OUTPUTS USED FOR CONSEQUENTIAL DECISIONS? *
CUSTOMERS INFORMED AI IS IN USE? *
SECTION 05DATA HANDLING & ARCHITECTURE● CRITICAL
DATA CATEGORIES PROCESSED *
TRANSPORT & NETWORK CONTROLS IN USE *
DATA SENT TO THIRD-PARTY AI VENDORS? *
NETWORK DIAGRAM AVAILABLE?
DATA FLOW DIAGRAMS AVAILABLE?
SECTION 06RISK POSTURE & CURRENT GOVERNANCE
CURRENT AI GOVERNANCE MATURITY *KNOWN RISK CONCERNS (SELECT ALL THAT APPLY)
GOVERNANCE CONFIDENCE RATING (1 = NOT CONFIDENT, 5 = VERY CONFIDENT)
PRIMARY DRIVERS FOR PURSUING AI GOVERNANCE (SELECT ALL THAT APPLY)
SECTION 07PROGRAM SELECTION & PRICINGREQUIRED
★ PREFERRED CLIENT PRICING — 10% LOYALTY ADJUSTMENT APPLIEDAs a long-term client, we've applied preferred pricing to extend your compliance program into AI Governance without increasing complexity. Discounted rates are reflected below.
SELECT PROGRAM OPTION *PREFERRED PAYMENT STRUCTURE *
TIMELINE TO BEGIN ENGAGEMENT *
SECTION 08INCLUDED SERVICE COMPONENTS
VRC1 AI Governance Platform Solutions
VRC1 AI Governance Platform Solutions extends your existing HIPAA compliance foundation into the rapidly evolving AI landscape — ensuring that how AI is used across your organization is secure, controlled, and aligned with regulatory expectations. Rather than introducing a separate program, VRC1 integrates AI governance directly into your current compliance framework, providing visibility into AI usage, managing risk exposure, and establishing governance aligned with regulatory expectations.
01
AI Risk Assessment & Use Case InventoryIdentifies where AI is used across your organization and evaluates risk exposure (data input, output reliability, vendor risk). This is not a separate compliance program — it's an extension of your existing HIPAA foundation, designed to govern how AI interacts with sensitive data, workflows, and decision-making across your organization.
02
AI Governance Policies & Acceptable Use FrameworkDefines how AI can and cannot be used across teams, including PHI handling, prompt guidance, and data restrictions.
03
AI Risk Register & Ongoing Risk TrackingCentralized register of AI-related risks with scoring, ownership, and mitigation tracking inside VRC1.
04
AI Vendor Security ReviewDocumentation of third-party AI tools (e.g., ChatGPT, ambient scribes, automation tools) to ensure proper data handling and contractual safeguards aligned with HIPAA and AI governance requirements.
05
Workforce AI Training & CertificationPractical training for staff on safe AI usage, prompt hygiene, and compliance alignment — aligned with HIPAA and emerging AI regulations.
06
AI Output Validation & Human Oversight ControlsEstablishes guardrails to reduce hallucinations, ensure accuracy, and maintain human-in-the-loop review where required.
07
Incident Response & AI Misuse ProtocolsDefines procedures for AI-related incidents including data exposure, incorrect outputs, or unauthorized use.
08
AI Governance Meetings & AdvisoryOngoing guidance to adapt policies and controls as AI tools and regulations evolve.
09
Dedicated AI Compliance Support TeamDirect access to VanRein experts for real-time questions, tool reviews, and implementation support.
SECTION 09COMPLIANCE & CERTIFICATION TARGETS
CERTIFICATION / FRAMEWORK TARGETS *
SECTION 10REPORTING & DELIVERABLES
REPORTS REQUIRED
REMEDIATION TRACKING REQUIRED?
FRAMEWORK ALIGNMENT
SECTION 11POINT OF CONTACT & ESCALATIONREQUIRED
SECTION 12LEGAL & FINAL AUTHORIZATIONREQUIRED
LEGAL NOTE: Written authorization will be finalized prior to engagement start. All activities are governed by the VanRein Compliance Master Services Agreement and applicable confidentiality terms.