Deliverable 2: Board Findings Report
A plain-English leadership summary explaining what was found, why it matters, the top findings and what should happen next. Written for readers who do not work in AI governance or data protection every day.
Clinical AI Exposure Diagnostic™
Nine outputs. Three audiences. One evidence pack.
In four working days from the start of delivery you receive a board-ready evidence pack structured for three distinct audiences: the board and senior leadership, the DPO and clinical governance team, and the insurer, MDO or inspector who may ask what AI is in use and how it is controlled.
Each output is listed below with the audiences it is written for and its deliverable number, so it can be matched against the pack you receive.
A plain-English leadership summary explaining what was found, why it matters, the top findings and what should happen next. Written for readers who do not work in AI governance or data protection every day.
A one-page board-level view across thirteen governance dimensions, using Red, Amber, Green and TBC ratings.
Ratings identify evidence positions and priorities for action. A Red rating does not mean that a breach, illegality, regulatory failure or loss of indemnity support has been confirmed. A Green rating does not provide a clean bill of health.
Prioritised actions for the first 30 days, with named owners, target dates, dependencies and the closure evidence required for each.
The master register of declared and shadow AI tools identified during the engagement: owner, users, purpose, patient-data involvement, approval position, human review position and next action for each.
High-risk indicators, DPIA readiness position, records of processing and privacy notice gaps, retention and data-flow matters, structured for DPO review and decision.
The note identifies whether DPIA screening is needed or whether a DPIA is likely required or strongly indicated. The final determination remains with your DPO.
Per-tool evidence status against supplier assurance, data protection, patient transparency, clinical safety and human oversight expectations.
For a Standard Diagnostic, this is recorded as not applicable with the reason stated, because ambient scribes and consultation transcription tools require a separate assessment route. A pack that records what was considered and ruled out is stronger evidence than one that leaves it unmentioned.
Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the clinic is routed to the six-working-day Ambient Scribe Diagnostic and this sheet is completed in full.
A supplier-by-supplier tracker covering data processing agreements, data residency, sub-processors, retention and deletion, model training and data reuse statements, security assurance and international transfer indicators.
ELSA AI assesses the evidence available to the clinic. It does not rank, endorse or criticise suppliers.
The current evidence position, the disclosure-readiness gaps and the matters requiring clarification with the relevant medical defence organisation, insurer or private medical insurer.
ELSA AI does not determine coverage, underwriting, disclosure obligations or indemnity support.
Material findings and recommendations mapped to the relevant published source or governance-standard signal, with the status of each source stated.
Guidance and recognised frameworks are not presented as universal legal mandates.
9
deliverables
£5,500 + VAT. Four working days from the start of delivery. Founder-delivered by Faisal Ali, AAISM, CISM, CRISC. Includes a 60-minute remote readout.
Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the engagement routes to the six-working-day Ambient Scribe Diagnostic at £8,500 + VAT. View pricing details.