GOVERNANCE
Enterprise governance framework
Clinical AI governance, operational assurance, and enterprise risk governance for MedTalk AI deployments.
Enterprise governance overview
MedTalk operates under an enterprise governance framework spanning clinical safety, AI governance, information security, and operational assurance, designed for deployment into enterprise and public healthcare environments.
Governance principles
- Clinical safety first: AI capability is strictly bound by human-in-the-loop clinical review; no AI output reaches an electronic medical record without explicit clinician sign-off.
- Absolute data sovereignty: 100% of data capture, processing, inference, and storage remains within Australian AWS infrastructure.
- Zero trust security: explicit, identity-verified access control across every trust boundary, backed by continuous policy evaluation.
- No training on confidential patient data: full architectural and contractual enforcement guaranteeing confidential patient information and session history are never used, in identifiable form, to train or refine public or proprietary AI models. Only de-identified data, stripped of PHI, may be used under strict contractual safeguards to improve transcription accuracy.
- Transient media preservation: minimum necessary retention enforced via programmatic 24-hour destruction of transient audio streams.
- Proactive transparency and compliance: continuous alignment with applicable government and health sector standards, the Australian Privacy Act 1988, ISO/IEC 27001, and the ACSC Essential Eight.
Governance committees
Executive Steering Committee
Provides strategic direction, approves program baseline changes, evaluates SLA performance, and acts as the ultimate escalation authority for contractual and operational risks. Membership spans MedTalk executive leadership and the customer's executive sponsor. Meets monthly.
Clinical Governance Board
Oversees clinical safety, evaluates AI output accuracy metrics, reviews clinical hazard logs, and validates human-in-the-loop workflow adherence. Membership spans MedTalk's Clinical Safety Officer and Clinical Advisor and the customer's clinical safety leads. Meets fortnightly during mobilisation and monthly in business-as-usual operation.
Technology and Security Council
Monitors technical performance, security boundary integrity, vulnerability patching timelines, cloud posture auditing, and cyber incident readiness. Membership spans MedTalk's CISO and lead architect and the customer's technology and security representatives. Meets monthly.
Escalation approach
- Strategic:contract scope, commercial terms, and architectural shifts are decided by the Executive Steering Committee, escalating to both parties' executive leadership if unresolved.
- Clinical and safety: clinical guardrail updates and hazard mitigation are decided by the Clinical Governance Board, with any Severity 1 clinical safety event escalated within two business days.
- Technical and security: vulnerability exceptions and infrastructure changes are decided by the Technology and Security Council, with high or critical severity security matters escalated within 24 hours.
- Operational:day-to-day user provisioning and routine maintenance are managed by MedTalk's Operations Lead, with unresolved Severity 2 tickets escalated within four hours.
Security and vulnerability governance
MedTalk's information security management system is structured in accordance with ISO/IEC 27001 and the ACSC Essential Eight, with vulnerability patching governed by a fixed severity-based SLA.
| Severity | Patch SLA |
|---|---|
| Critical | 48 hours |
| High | 14 days |
| Medium | 60 days |
| Low | Routine release cycle |
Contact
Clinical Governance: legal@medtalk.co
Security & Compliance: support@medtalk.co