A rule you can't prove is a rule you don't have. This is where you find out which ones you can prove.

ARC · The diagnostic AI Governance Diagnostic For healthcare organizations running AI in decisions that matter

Grade the proof.
Not the promise.

Somewhere in your organization, software is deciding what a person used to judge — scoring, flagging, sorting, approving, releasing. This diagnostic checks how well that's governed, and grades every answer on how well you could show it to a reviewer tomorrow. It's a governance-readiness readout, not a compliance certification. Free to start. About 20 minutes.

Required of youHIPAAYour setting's own rulebook
The frameworks you may chooseNIST's AI frameworkISO's AI standardEU AI Act
ARC · Our Read · Saguaro Health Sample — fictional data
AreaWho owns the decision — and who can stop it
Claim"Any result our AI flags can be halted before release."
Receipt"The system will allow supervisors to pause auto-release once the new middleware is configured."Your account · Section 2 · line 14
VerdictAspirationalWords alone
To verifyThe halt performed live, by the role that owns it, on a result in today's queue.
ARC Governance Diagnostic · Free self-checkUnverified — self-reported
Why this exists

A score nobody checked still travels to your board.

Here's how AI governance gets measured today: you answer a quiz about yourself, and you get back a confident score. Nobody checked a document. Nobody watched anything run. Then that score travels — to your board, your health-system partners, your inspectors — carrying a confidence it never earned.

We built this diagnostic on one rule: it grades your description of your governance, never your organization — and it tells you, line by line, where the description is solid, where it's thin, and where it's a plan wearing the present tense. The gap between what you can say and what you can show is the most useful number in AI governance.

The questions

Nine questions about your AI. Could you answer them tomorrow?

01
Who owns each AI-touched decision — and who can stop it?
02
Was the tool proven to work for your patients, your data, your volumes?
03
What runs on its own, what waits for a person — and who decided?Make-or-break
04
When the software changes quietly, who notices?
05
What do you actually know about the AI you bought — and the AI that came hidden inside the systems you already run?Make-or-break
06
Is human review real at your busiest hour, or a checkbox?Make-or-break
07
When someone challenges an AI-touched result, what happens next?
08
What is each AI supposed to be worth — and what would make you switch it off?
09
If an inspector asked tomorrow, could you show how one result was governed?Make-or-break
Each question, checked four ways 1Is it designed? 2Does it actually run? 3Can you prove it? 4Does it get better?

Four of the nine are make-or-break — the four where a single uncontrolled failure can put a patient decision at risk. If one of them fails, it caps your entire picture — no strength elsewhere buys it back. We name them up front, not at the reveal.

A rule that's written but not running is a diagram.

A rule that runs but can't be proven is a rumor.

The proof ladder

Every answer is graded on the proof behind it not the words in front of it.

"Told us" isn't "showed us." "Showed us" isn't "proved it live." You can describe strong governance in twenty minutes — plenty of organizations can. That's exactly why description alone can't reach the top of our scale. That's the product working.

Your self-check ceilingWords alone · capped early
12345

A perfect description, by itself, stops here.

L4

You demonstrated it live.

We watched it happen. The only level that can reach the top of the scale.

Top of the scale
L3

You showed us.

A real document, actually inspected. Strong — as long as what's missing doesn't matter.

Reaches high
L2

You named a document.

Better than words alone. Still unchecked.

Capped midway
L1

You told us.

Words alone. However good they sound, the score stops early here.

Capped early
Three ways to run it

Start with words. End with proof.

Self-Check
What you told us
Free · about 20 minutes
What happens
About 20 minutes of questions, in your organization's own language.
What you get
Where your account is solid, thin, missing, or contradicts itself — with your own words quoted back as the evidence.
Can you share it?
It's yours — marked "self-reported, unverified."
Unverified — self-reported
Document Review
What your documents show
On-screen, for your team
What happens
You fill in structured worksheets on how your governance actually works; our system — not a person — reads them and shows its reasoning, line by line.
What you get
A gap list per area: what's covered, what's missing, and exactly what a reviewer would ask to see.
Can you share it?
No — on-screen only, deliberately.
On-screen only
Live Verification
What you demonstrated
The paid engagement
What happens
A human reviewer inspects your real documents and watches four things demonstrated live.
What you get
The gap between what you said and what we found — and a signed, shareable verified profile.
Can you share it?
Yes. That's the point.
Independently verified

Why the middle level stays on-screen: an unverified score pasted into a board deck becomes "our official grade" the moment it leaves the room. The verified level exists because a human checked it, a human signed it, and you can hand it to whoever's asking.

What live verification looks like: your reviewer inspects roughly ten documents and watches four demonstrations — who can stop an AI-touched result, a change record pulled live, a model version retrieved on request, and your working list of the AI that came built into systems you already bought. It runs under a signed confidentiality agreement — and a BAA where patient information could be in view. It's built to respect the time of a team that still has a day job.

What the verified profile is for: your board, your partners, your payers, your procurement conversations — anyone currently taking your word for it. It states exactly what was demonstrated and at what level of proof. It doesn't claim to be a certification, and it doesn't replace anyone's own diligence. That restraint is why it's worth showing.

What a finding looks like

Verdicts with receipts.

ARC · Our Read · Change, monitoring & revalidation Sample — fictional data
Claim"Every software change is reviewed before it touches a reported result."
Receipt"Changes are reviewed per SOP QP-114, Software Change Control."Your account · Section 4 · line 3
Asked forThe last completed review. There isn't one.
VerdictPolicy, not yet practice
The findingThe policy is real. The practice isn't there yet. That gap is the finding — and it's the kind of gap an inspector is trained to look for.
One of nine areas · four checks eachUnverified — self-reported

You don't get a number to argue with. You get your own words, held against what a reviewer would need to see — and within a page, you'll know which conversation to have next, and with whom.

Your rulebooks

Your required rulebooks and your chosen ones.

Every healthcare organization answers to HIPAA. What sits beside it depends on where you work: a hospital answers to the CMS Conditions of Participation, a clinical lab to CLIA and CAP, a pharmacy to USP standards and its state board. That part isn't optional, and we treat it that way — you pick your setting at the start, and the required rulebook comes with it.

Beyond those sit the frameworks you may choose, or be asked about — NIST's AI framework, ISO's AI management standard, the EU AI Act. We keep the two groups apart, because the people doing the work know the difference even when vendors don't. A US organization does not answer to the EU AI Act; it may still be asked how it measures up. We show how your account holds up against what each one expects a governance program to have.

Notice the words: held against. We will never tell you you're compliant. No questionnaire can honestly tell you that — and you should question any that does.

Required — everyone

The one no healthcare organization gets to opt out of.

HIPAA
Required — your setting

Whichever one applies to you. One of these, not all of them.

Hospitals — CMS Conditions of Participation Clinical labs — CLIA/CAP Pharmacies — USP standards & state boards PBMs — CMS Part D & state licensure Blood centers — FDA manufacturing rules & AABB EMS — state protocols & CMS ambulance rules Payers — CMS rules & state insurance regulators
Chosen — the frameworks you may pick up

Useful to measure against. None of them is a rulebook you answer to.

NIST's AI frameworkISO's AI standardEU AI Act
Where this runs

Built for the settings that make healthcare run.

One diagnostic, set up for the place you work. Same nine questions, same standard of proof — asked in your language, and held against the rulebook your setting actually answers to.

Hospitals & health systemsHeld against the CMS Conditions of Participation and Joint Commission expectations.
Clinical labs & diagnosticsHeld against CLIA and CAP.
Specialty pharmaciesHeld against USP standards, accreditation bodies, and your state board.
Pharmacy benefit managersHeld against CMS Part D rules and state licensure.
Hub services providersHeld against program-integrity rules and the manufacturer agreements behind them.
Blood centersHeld against FDA manufacturing rules and AABB standards.
EMS organizationsHeld against your state protocols, medical direction, and CMS ambulance rules.
PayersHeld against CMS rules and your state insurance regulator's expectations.
Healthcare AI vendorsHeld against what your hospital customers ask before they sign.

Everyone answers to HIPAA. What sits beside it depends on where you work — so the questions, the language, and the rulebook change with your setting, and the standard of proof never does.

Words you will not find in our reports.

Certified. Compliant. Not at any level, not in any export. And we'll never claim to have "validated" your governance either — in your world, validation means something specific and earned, and we respect the word too much to borrow it. Only one phrase in this product carries weight outside your walls — independently verified — and it appears only on the profile a human reviewer signed after watching your governance work in person. An assessment that hands out bigger words than its evidence supports isn't rigorous. It's merchandise.

Who's behind this.

ARC comes out of Artha Consulting Lab — built by Ankur Jain, Esq. after fifteen years inside biopharma, pharma, and health-system work, and after watching too many confident scores travel further than the evidence behind them. The free self-check is the first rung of the same diagnostic we run in paid engagements. It isn't a quiz built to capture your email.

What this is not.

It's not a certification, and it doesn't pretend to be one. It's not a legal or compliance opinion. It's not a substitute for your inspectors, your accreditors, or your own diligence. It's a governance-readiness readout, not a compliance certification — a disciplined answer to one question: how much of your AI governance can you actually prove? — asked before someone with authority asks it for you.

Questions leaders ask

Before you start.

If software scores, flags, sorts, or auto-releases results a person would otherwise judge, you have AI in the sense that matters — and much of it arrived inside systems you already bought without ever being called AI. Question five exists for exactly that.

Whoever's closest to the answer — often a quality lead, an operations lead, or a clinical or medical director. It's one respondent. If two of your leaders would answer differently, that's worth knowing: the deeper diagnostic asks some questions of more than one role on purpose, and when their answers disagree, that disagreement becomes a finding.

No. A certification attests you met a standard. This measures how much of your governance you can prove, and says so with receipts. The verified profile tells the reader exactly how much weight it can bear.

Your answers produce your read, and they stay yours — nothing is published, benchmarked, or shared. No patient data is involved in the self-check; the questions are about your governance, not your patients. Document review and verification run under a signed confidentiality agreement, with a BAA where patient information could be in view. The verified profile is yours to distribute — that's what it's for.

Because an unverified document that looks official becomes "our score from the assessment" the moment it hits a slide. Keeping it on-screen is the same honesty that makes the verified profile worth paying for.

Twenty minutes. Your own words, held to the proof.

Built for healthcare, and honest about what words alone can show. Measure the gap between what you'd say and what you could prove — before someone with authority measures it for you.

Not running AI in decisions that matter yet? Start with the ARC Readiness Assessment →