Skip to main content

AI Gateway Service — Service Risk Register

Status: populated Owner: TBD Last updated: 2026-04-18 Companion: Service Template · FAILURE_MODES · SECURITY_MODEL

1. Risk register

IDRiskLikelihoodImpactSeverityOwnerMitigationResidual
RISK-AIGW-01AI-assisted clinical content accepted into chart without AIProvenance tagLowCriticalCRITICALTech LeadINV-01 enforced in domain; AcceptAIChunk rejects without provenanceId; mandatory integration testVery low
RISK-AIGW-02Provider API key leakage from consumer serviceMediumCriticalCRITICALSecurity LeadPhase 1 migration revokes all consumer keys; vault-only storage; CI secret scanLow
RISK-AIGW-03Prompt injection attack via malicious patient-supplied textMediumHighHIGHAI Safety LeadPre-moderation classifier; input length caps; injection pattern regex; adversarial test suiteMedium
RISK-AIGW-04PHI leakage into external provider logsMediumCriticalCRITICALCompliance OfficerPHI minimisation pre-processing; DPIA required before PHI route goes live; prompt stored hashedLow after DPIA
RISK-AIGW-05HITL reviewer queue backlog causes clinical workflow delayMediumHighHIGHClinical InformaticsAuto-reject timeout per feature; reviewer workload alerting; surge escalation runbookMedium
RISK-AIGW-06Moderation false positives block legitimate clinical contentLow–MediumMediumMEDIUMAI Safety LeadThreshold tuning; logged override workflow; audit trail of all blocksLow
RISK-AIGW-07Provider outage causes cascading failures across AI featuresMediumHighHIGHSRECircuit breaker per provider; fallback routing; graceful 503 with user messageLow
RISK-AIGW-08Tenant quota misconfiguration permits runaway spendLowHighHIGHPlatform EngRedis hard cap; spend alerts at 80 % and 100 % window; admin quota dashboardLow
RISK-AIGW-09AIProvenance row tampered or deleted post-writeVery LowCriticalCRITICALDBADB role UPDATE/DELETE revoked; append-only enforced at DB engine; monthly chain-hash verificationVery low
RISK-AIGW-10Cross-tenant data leakage via prompt payloadLowCriticalCRITICALSecurity LeadRLS on all tables; tenant extracted from JWT only; cross-tenant ref returns CROSS_TENANT errorVery low
RISK-AIGW-11Model version change breaks prompt template compatibilityMediumMediumMEDIUMPlatform EngPromptTemplate semver-versioned; routing rule pins model version; bumps require template reviewLow
RISK-AIGW-12Clinical AI feature accepted autonomously without HITLLowHighHIGHClinical InformaticsHITLPolicy defaults required_for_phi; explicit none requires CMO sign-off in Readiness Gate 6Low
RISK-AIGW-13On-prem model unavailable at offline clinicMediumLowLOWSREAssist returns graceful unavailable; UX falls back to manual entryVery low
RISK-AIGW-14Uncontrolled prompt template proliferationLowMediumMEDIUMPlatform EngTemplate registry with review workflow; tenants cannot publish without platform approvalLow

2. Clinical safety risks (AI-specific)

IDScenarioControl
CS-01Clinician accepts hallucinated diagnosis without reviewHITL required for differential-diagnosis feature; reviewer must explicitly accept
CS-02Radiology pre-read suggestion treated as final readFeature key radiology.preread.* always HITLPolicy=required; output watermarked "AI DRAFT — NOT FOR CLINICAL USE UNTIL REVIEWED"
CS-03Drug interaction narrative contains incorrect informationmedication.interaction_narrative has HITL + pharmacist reviewer; source cited in provenance
CS-04Triage suggestion under-triages high-acuity patientportal.triage severity bounded to recommendation; human escalation mandatory for severity ≥ 3

3. Compliance risks

IDRiskRegulationMitigation
CR-01AI-generated content in chart creates liability without clear authorshipHIPAA analogue / MoPHAIProvenance links to clinician acceptor; immutable
CR-02Data sent to foreign AI provider without DPIAGDPR / MoPH data-residencyProvider routing blocked for PHI features until DPIA signed per provider
CR-03Audit trail insufficient for regulator inquiry on AI decisionsMoPH audit mandateAll ai.* events stored in audit-service; AIProvenance queryable for 7 years

4. Risk review cadence

ActivityFrequencyOwner
Full register reviewQuarterlyTech Lead + Compliance Officer
CRITICAL/HIGH risk status updateMonthlyService Owner
Post-incident risk additionWithin 5 days of incidentOn-call SRE + Tech Lead
AI safety risk reviewBefore each new feature key activationClinical Informatics + AI Safety Lead