Headline: Protect Your Organisation from Unexamined AI Decisions in Healthcare and Beyond: A New Era of Accountability Arrives with PIPEDA Reform and Straven & Co
What is happening: The Canadian government has introduced the Personal Information Protection and Electronic Documents Act (PIPEDA) reform, which brings significant changes to how organisations manage customer data. Quebec Law 25 and Ontario’s Personal Health Information Protection Act (PHIPA) also present new challenges for healthcare providers and insurance companies in Canada and the UK. These laws require businesses to demonstrate greater transparency and accountability regarding their AI decision-making processes.
Why it demands action now: As these regulations take effect, organisations that purchase or deploy AI solutions must ensure that they can effectively govern and defend AI-driven decisions before regulatory bodies, courts, and boards of directors. Straven & Co’s assessment identifies the following risks for healthcare providers and insurance companies: capability risk (does the technology do what was claimed?), governance risk (can the decision be defended when regulators or boards ask), and liability risk (what is the organisation accountable for if AI errors occur).
The action: Prudent organisations take strategic steps to address these challenges, including:
1. Conducting thorough evaluations of vendor claims before making an AI purchase decision.
2. Reviewing existing governance structures to ensure they can accommodate AI-driven decisions.
Why organisations struggle with this process alone is the difficulty in independently verifying a vendor’s claims about their technology. This information asymmetry often leaves internal teams too close to the decision, and without an independent way to test the claim. Straven & Co helps bridge this gap by providing a detailed assessment of the proposed solution against the client’s real operations, people, governance obligations, and legal exposure.
How Straven helps: Our assessments deliver a plain verdict – proceed, proceed with conditions, or do not – based on our independent examination of the AI decision-making process. We identify capability risk through testing against the organisation’s operational requirements, governance risk by assessing the solution’s compliance with regulatory demands, and liability risk by evaluating accountability for potential errors.
Straven & Co examines AI decisions before they are acted on: stravenandco.com