Coriqo
One control plane · two regulated verticals

Get through the hospital AI committee with a record they can check themselves.

Coriqo seals your clinical AI system's governance record — approvals, model and threshold changes, validation evidence, and how much scrutiny each human review actually got. The committee verifies it against a public key rather than taking your word for it. Coriqo seals the evidence and never makes the clinical decision.

Coriqo holds attestations about how your AI system was approved and reviewed. It is not a clinical data store and does not need patient records to produce the package.

Maps to Joint Commission RUAIHONC HTI-1 DSINIST AI RMF 1.0EU AI Act
Where clinical AI deals stall

The model passed. The governance review is what's holding the contract.

Three objections show up in nearly every health system's AI committee, and none of them are about accuracy.

Repeated work

Every health system asks differently

One committee wants your bias-management approach. The next wants demographic representativeness of the training data. The third wants your retirement policy. Same underlying evidence, reassembled by hand for every deal, by whoever has the deck open.

Self-reported numbers

Your override rate is your own number

You tell them clinicians override 12% of the time. Their counsel asks who computed that figure and whether anyone could have edited it afterward. Both answers are bad when the measured party also keeps the record.

The new objection

The question changed

Committees stopped asking whether the model is accurate. They now ask whether your tool turns their clinicians into rubber stamps — and a promise in a slide does not answer it.

One record, every framing

Pick the domain the committee is asking about. The same sealed record answers it.

Coriqo ships the Joint Commission's RUAIH certification domains as a deterministic checklist, cross-referenced to the ONC HTI-1 source attributes a developer has to publish per algorithm. Each requirement resolves to records already in your chain instead of a document you assemble again.

RUAIH domain
RUAIH certifies the health system's AI governance program, not your product. These are the checks your documentation has to satisfy for their certification to hold.
Governance2 checks
R-01Blocks sign-off if absent

Documentation must name the accountable owner and governance body responsible for the AI system’s oversight, and state how AI-related decisions are escalated and reviewed within that structure.

RUAIH · Governance
Answered by 4 sealed records · last change event #2,208
R-02Weakens the record if absent

Documentation must state the policies covering the AI system’s full lifecycle — intake and approval, deployment, change management, and retirement — not only its initial validation.

RUAIH · Governance
Answered by 6 sealed records · last change event #2,377

Requirement text is the shipped rulepack, sourced from the Joint Commission's RUAIH certification domains and the ONC HTI-1 predictive DSI source attributes. Evidence counts shown here use sample data.

Oversight Proof

A review-quality number the measured party cannot edit.

Logging timestamps is a weekend of work and any engineering team can ship it. What they cannot ship is a number about their own oversight that a hospital's counsel will believe. Coriqo records how long each review took, how often the reviewer agreed with the model, and across how many decisions — then seals it in the same chain as everything else.

Why it holds up

The referee is not the player

The measurement is written into an append-only chain your team cannot rewrite, and the committee checks it with a public key. It is the ordinary standard applied to any record the measured party keeps, pointed at the review itself rather than at the model.

Why it grows in value

Better models widen the gap

As accuracy rises, review gets more ceremonial and automation bias deepens. The distance between a signature and actual scrutiny is not inferable from model quality — it has to be measured at the human.

Where it's heading

Approval leverage, once agents act

When an agent acts instead of scoring, one approval of a mandate can authorize thousands of downstream actions. Coriqo records how much action volume a single signature covered, and whether the approver saw a representative sample.

coriqo.io / vendor_clinical_ai / oversight / sepsis-triage@v4Sealed
Human review record
Tier-1 diagnostic recommendation · 2026-02-01 → 2026-07-31 · sample data
Median time on decision
1.4s
Across 3,000 reviewed decisions
Concordance with model
100%
No reviewer departure recorded
Decisions in scope
3,000
4 reviewers · 6-month window
Threshold you set · finding opened

Concordance stayed above 95% for 90 days on Tier-1 decisions. Coriqo opened a tracked finding against the threshold your medical director configured. It reports the number; the judgment stays with your clinical governance body.

Owner · dr. c. mensah, medical director  ·  due 2026-09-15
Recorded as event #2,411 in an append-only chain
Merkle root 7a3f…c901 · Ed25519, coriqo-key-2026-01
Verifiable with the public key alone — no Coriqo server required
 What Coriqo does — a monitorWhat Coriqo will not do — a detector
Output"Dr. Park: 1.4s median, 100% concordance, 3,000 decisions.""This approval was not a genuine review."
The claimA fact about what happened.A verdict about a named clinician.
Who judgesYour medical director, the committee, a regulator.Us — which is not our place.
If it's wrongIt cannot be. It reports the record.Every false positive becomes your employment-law problem.
Also for payers

Every 2026 state statute says a licensed human, not the model, makes the denial. Most plans cannot show it happened.

The figure that defined this whole problem — roughly a second per claim — came from journalism and discovery, not from any system a plan could produce. A utilization-management team with its own sealed dwell-time and concordance record argues from evidence instead of assertion.

ArtifactThe same sealed governance package the vendor motion uses. Nothing separate to buy or configure.
RecordsWho reviewed the determination, how long they spent, whether they departed from the model, and what changed since.
AudienceState regulators, external review organizations, and your own appeals team — each checking the chain rather than trusting a report.
BoundaryCoriqo never decides a claim and never scores a reviewer. It records what the reviewer did and seals it.
Shared foundation

One verification core. A healthcare rulepack on top of it.

Tamper-evidence is not industry-specific, and Coriqo does not reimplement it per industry. The chain, the seal, and the public-key verification are one code path, already carrying regulated workloads under supervisory review. A health system's AI committee checks exactly what any other outside reviewer checks. Healthcare is a rulepack over that record — not a separate product with separate guarantees.

How verification works  ·  How it's built

Shared

Append-only event log. Every approval, change, and finding sealed with SHA-256. Alter a record after the fact and verification fails.

Shared

Merkle attestation. Inclusion proofs let a committee verify one event without holding the whole chain.

Shared

Time-boxed external portal. Read-only access for a reviewer outside your company, with every view logged.

Healthcare-specific

RUAIH and HTI-1 rulepack. Ten deterministic requirement checks, plus NIST AI RMF 1.0 as the framework substrate.

Healthcare-specific

Clinical decision classes. Diagnostic recommendation, treatment plan, and risk stratification, each governed on its own track.

We're looking for clinical AI vendors to shape this vertical.

Healthcare is new. Two rulepacks ship today and no vendor has run the full motion end to end yet, which is exactly why we want to build it with the first few. Tell us which committee question keeps stalling your deals.

Talk to us