A rule you can't prove is a rule you don't have. This is where you find out which ones you can prove.
Somewhere in your organization, software is deciding what a person used to judge — scoring, flagging, sorting, approving, releasing. This diagnostic checks how well that's governed, and grades every answer on how well you could show it to a reviewer tomorrow. It's a governance-readiness readout, not a compliance certification. Free to start. About 20 minutes.
A score nobody checked still travels to your board.
Here's how AI governance gets measured today: you answer a quiz about yourself, and you get back a confident score. Nobody checked a document. Nobody watched anything run. Then that score travels — to your board, your health-system partners, your inspectors — carrying a confidence it never earned.
We built this diagnostic on one rule: it grades your description of your governance, never your organization — and it tells you, line by line, where the description is solid, where it's thin, and where it's a plan wearing the present tense. The gap between what you can say and what you can show is the most useful number in AI governance.
Four of the nine are make-or-break — the four where a single uncontrolled failure can put a patient decision at risk. If one of them fails, it caps your entire picture — no strength elsewhere buys it back. We name them up front, not at the reveal.
A rule that's written but not running is a diagram.
A rule that runs but can't be proven is a rumor.
"Told us" isn't "showed us." "Showed us" isn't "proved it live." You can describe strong governance in twenty minutes — plenty of organizations can. That's exactly why description alone can't reach the top of our scale. That's the product working.
A perfect description, by itself, stops here.
We watched it happen. The only level that can reach the top of the scale.
A real document, actually inspected. Strong — as long as what's missing doesn't matter.
Better than words alone. Still unchecked.
Words alone. However good they sound, the score stops early here.
Why the middle level stays on-screen: an unverified score pasted into a board deck becomes "our official grade" the moment it leaves the room. The verified level exists because a human checked it, a human signed it, and you can hand it to whoever's asking.
What live verification looks like: your reviewer inspects roughly ten documents and watches four demonstrations — who can stop an AI-touched result, a change record pulled live, a model version retrieved on request, and your working list of the AI that came built into systems you already bought. It runs under a signed confidentiality agreement — and a BAA where patient information could be in view. It's built to respect the time of a team that still has a day job.
What the verified profile is for: your board, your partners, your payers, your procurement conversations — anyone currently taking your word for it. It states exactly what was demonstrated and at what level of proof. It doesn't claim to be a certification, and it doesn't replace anyone's own diligence. That restraint is why it's worth showing.
You don't get a number to argue with. You get your own words, held against what a reviewer would need to see — and within a page, you'll know which conversation to have next, and with whom.
Your required rulebooks — and your chosen ones.
Every healthcare organization answers to HIPAA. What sits beside it depends on where you work: a hospital answers to the CMS Conditions of Participation, a clinical lab to CLIA and CAP, a pharmacy to USP standards and its state board. That part isn't optional, and we treat it that way — you pick your setting at the start, and the required rulebook comes with it.
Beyond those sit the frameworks you may choose, or be asked about — NIST's AI framework, ISO's AI management standard, the EU AI Act. We keep the two groups apart, because the people doing the work know the difference even when vendors don't. A US organization does not answer to the EU AI Act; it may still be asked how it measures up. We show how your account holds up against what each one expects a governance program to have.
Notice the words: held against. We will never tell you you're compliant. No questionnaire can honestly tell you that — and you should question any that does.
The one no healthcare organization gets to opt out of.
Whichever one applies to you. One of these, not all of them.
Useful to measure against. None of them is a rulebook you answer to.
One diagnostic, set up for the place you work. Same nine questions, same standard of proof — asked in your language, and held against the rulebook your setting actually answers to.
Everyone answers to HIPAA. What sits beside it depends on where you work — so the questions, the language, and the rulebook change with your setting, and the standard of proof never does.
Certified. Compliant. Not at any level, not in any export. And we'll never claim to have "validated" your governance either — in your world, validation means something specific and earned, and we respect the word too much to borrow it. Only one phrase in this product carries weight outside your walls — independently verified — and it appears only on the profile a human reviewer signed after watching your governance work in person. An assessment that hands out bigger words than its evidence supports isn't rigorous. It's merchandise.
ARC comes out of Artha Consulting Lab — built by Ankur Jain, Esq. after fifteen years inside biopharma, pharma, and health-system work, and after watching too many confident scores travel further than the evidence behind them. The free self-check is the first rung of the same diagnostic we run in paid engagements. It isn't a quiz built to capture your email.
It's not a certification, and it doesn't pretend to be one. It's not a legal or compliance opinion. It's not a substitute for your inspectors, your accreditors, or your own diligence. It's a governance-readiness readout, not a compliance certification — a disciplined answer to one question: how much of your AI governance can you actually prove? — asked before someone with authority asks it for you.
If software scores, flags, sorts, or auto-releases results a person would otherwise judge, you have AI in the sense that matters — and much of it arrived inside systems you already bought without ever being called AI. Question five exists for exactly that.
Whoever's closest to the answer — often a quality lead, an operations lead, or a clinical or medical director. It's one respondent. If two of your leaders would answer differently, that's worth knowing: the deeper diagnostic asks some questions of more than one role on purpose, and when their answers disagree, that disagreement becomes a finding.
No. A certification attests you met a standard. This measures how much of your governance you can prove, and says so with receipts. The verified profile tells the reader exactly how much weight it can bear.
Your answers produce your read, and they stay yours — nothing is published, benchmarked, or shared. No patient data is involved in the self-check; the questions are about your governance, not your patients. Document review and verification run under a signed confidentiality agreement, with a BAA where patient information could be in view. The verified profile is yours to distribute — that's what it's for.
Because an unverified document that looks official becomes "our score from the assessment" the moment it hits a slide. Keeping it on-screen is the same honesty that makes the verified profile worth paying for.
Built for healthcare, and honest about what words alone can show. Measure the gap between what you'd say and what you could prove — before someone with authority measures it for you.
Not running AI in decisions that matter yet? Start with the ARC Readiness Assessment →
Thirty minutes, on your calendar, no forms in between.
Prefer email? ankur.jain@arthaconsultinglab.com