RISK-BASED GOVERNANCE AND AUDIT FRAMEWORK FOR ARTIFICIAL INTELLIGENCE IN KENYA'S HEALTHCARE SECTOR

Authors

  • Dr. James Odhiambo Oringo Author

Keywords:

Risk-Based Governance; Audit Framework; Artificial Intelligence; Healthcare Sector

Abstract

This capstone study was undertaken at the end of a fellowship on AI Ethics and Governance in Africa Organized by the Policy Innovation Centre and African Hub for Innovation and Development, in Nigeria. Artificial Intelligence (AI) is increasingly becoming part of healthcare transformation in Kenya, with applications spanning diagnostic support, disease surveillance, telemedicine, health information management, predictive analytics and administrative decision support. The study responds to a governance gap: Kenya has developed an important legal and policy foundation for digital health and AI, but the existing arrangements do not yet constitute a single, operational, risk-based healthcare AI governance and audit system. The capstone adopted a desk-based qualitative design supported by systematic literature review and document analysis. Evidence was drawn from peer-reviewed literature, Kenyan legislation and policy documents, international standards, AI governance frameworks and reports from authoritative organizations. Priority was given to literature published between 2020 and 2026, while seminal sources were retained where they provided foundational theoretical or conceptual value. The findings show that AI adoption is progressing, but institutional readiness is uneven. National referral hospitals, research institutions, private facilities and donor-supported programmes are relatively more active, while county and primary healthcare settings face greater infrastructure, skills, financial, data, interoperability and governance constraints. The study further found that Kenya’s Kenya National Artificial Intelligence Strategy 2025–2030, Digital Health Act 2023 and Data Protection Act 2019 provide an important foundation, but significant AI-specific gaps remain around risk classification, algorithmic accountability, explainability, independent auditing, post-deployment monitoring, lifecycle governance and liability. Five interrelated categories of risk were identified: governance, ethical, technical, operational and regulatory. The study found that these risks interact and cannot be managed effectively through isolated controls. International frameworks reviewed, WHO, OECD, the EU AI Act, NIST AI RMF and ISO/IEC 42001, offer complementary strengths, but none can be transferred to Kenya unchanged. The principal deliverable is therefore a context-specific Risk-Based Governance and Audit Framework. The framework combines governance leadership, legal and ethical compliance, risk assessment and classification, lifecycle governance, human and clinical oversight, continuous monitoring, independent AI auditing and continuous learning. It adopts a proportional approach in which higher-risk healthcare AI receives more rigorous validation, monitoring and independent assurance. The report concludes that responsible AI adoption in Kenya requires a shift from principle-based statements alone towards operational governance. The proposed framework provides a practical reference for policymakers, regulators, healthcare institutions, professionals, AI developers, auditors, researchers and other stakeholders seeking to promote safe, ethical, transparent, accountable and trustworthy AI in healthcare.

Downloads

Download data is not yet available.

References

African Union. (2024). Continental Artificial Intelligence Strategy. African Union Commission.

Al Kuwaiti, A., Nazer, K., Al-Reedy, A., Al-Shehri, S., Al-Muhanna, A., Subbarayalu, A. V., Al-Muhanna, A., & Ali, A. (2023). A review of the role of artificial intelligence in healthcare. Healthcare, 11(6), 951.

Aven, T., & Renn, O. (2018). Improving government policy on risk: Eight key principles. Reliability Engineering & System Safety, 176, 230–241.

Bouderhem, R. (2024). Shaping the future of AI in healthcare through ethics and governance. Humanities and Social Sciences Communications, 11, Article 416.

Chaffin, B. C., Gosnell, H., & Cosens, B. A. (2014). A decade of adaptive governance scholarship: Synthesis and future directions. Ecology and Society, 19(3), Article 56.

Davenport, T. H., & Kalakota, R. (2019). The potential for artificial intelligence in healthcare. Future Healthcare Journal, 6(2), 94–98.

Davidson, S., Karlen, W., & Wiens, J. (2024). Governing artificial intelligence in healthcare: Institutional challenges and opportunities. Frontiers in Artificial Intelligence, 7, Article 1362108.

Ebers, M. (2024). The European Union Artificial Intelligence Act: A risk-based regulation for trustworthy artificial intelligence. Computer Law & Security Review, 53, 106018.

Floridi, L., Cowls, J., King, T. C., & Taddeo, M. (2022). How to design AI for social good: Seven essential factors. Science and Engineering Ethics, 28(3), 1–19.

Hashiguchi, T. C. O., Slawomirski, L., & Oderkirk, J. (2021). Laying the foundations for artificial intelligence in health. OECD Health Working Paper No. 128. OECD Publishing.

Hassan, M., Borycki, E. M., & Kushniruk, A. W. (2025). Artificial intelligence governance framework for healthcare. Healthcare Management Forum, 38(2), 90–97.

Hussein, R., Zink, A., Ramadan, B., Howard, F. M., Hightower, M., Shah, S., et al. (2026). Advancing healthcare AI governance through a comprehensive maturity model based on systematic review. npj Digital Medicine, 9, Article 236.

International Organization for Standardization. (2023). ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. ISO.

Makori, A., Nyongesa, H., & Mugo, P. (2023). Data governance and digital health regulation in Kenya: Implications for artificial intelligence adoption. BMC Medical Informatics and Decision Making, 23, Article 312.

Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2(3), 603–609.

Manya, A., Ochieng, J., & Omolo, B. (2024). Digital health transformation and artificial intelligence adoption in Kenya: Opportunities and implementation challenges. Frontiers in Digital Health, 6, Article 1362841.

Mennella, C., Maniscalco, U., De Pietro, G., & Esposito, M. (2024). Ethical and regulatory challenges of AI technologies in healthcare: A narrative review. Heliyon, 10(4), e26297.

Mittelstadt, B. D. (2023). Principles alone cannot guarantee ethical AI. Nature Machine Intelligence, 5(1), 8–10.

Mökander, J., Morley, J., Taddeo, M., & Floridi, L. (2023). Ethics-based auditing of automated decision-making systems: Nature, scope and limitations. AI and Ethics, 3(2), 405–417.

Morley, J., Floridi, L., Kinsey, L., & Elhalal, A. (2024). From principles to practice: Operationalising trustworthy artificial intelligence in healthcare. npj Digital Medicine, 7(1).

Ministry of Information, Communications and the Digital Economy. (2025). Kenya Artificial Intelligence Strategy 2025–2030. Government of Kenya.

Mugambi, M., Wanyama, P., & Njoroge, E. (2023). Artificial intelligence governance in Kenya's healthcare system: Challenges and future directions. Frontiers in Artificial Intelligence, 6.

Muthee, V., Mugo, D., & Kariuki, S. (2024). Readiness for artificial intelligence implementation in healthcare systems in low- and middle-income countries: Evidence from Kenya. BMC Health Services Research, 24, Article 412.

Muthoni, P., Kiplagat, J., & Mwangi, P. (2024). Artificial intelligence and digital innovation in Kenya's healthcare ecosystem. PLOS Digital Health, 3(2), e0000418.

Mwai, P., Ochieng, J., & Wambua, S. (2025). Artificial intelligence governance and digital health transformation in Kenya: Opportunities, challenges and future directions. African Journal of Health Informatics, 12(1), 45–61.

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce.

Okech, T. C., Nyaboga, Y., & Kiruja, J. (2023). Digital transformation and artificial intelligence in healthcare delivery in Kenya. BMC Medical Informatics and Decision Making, 23, Article 287.

Organisation for Economic Co-operation and Development. (2024). OECD framework for the classification of AI systems: A tool for effective AI policies.

Owoyemi, A., Owoyemi, J., Osiyemi, A., & Boyd, A. (2024). Artificial intelligence for healthcare in Africa: Opportunities, challenges and governance considerations. Frontiers in Digital Health, 6, Article 1365220.

Raji, I. D., Smart, A., White, R. N., et al. (2020). Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing. Proceedings of the 2020 Conference on Fairness, Accountability and Transparency, 33–44.

Republic of Kenya. (2019). Data Protection Act, 2019. Government Printer.

Republic of Kenya. (2023). Digital Health Act, 2023. Government Printer.

Republic of Kenya. (2025). Kenya National Artificial Intelligence Strategy 2025–2030. Ministry of Information, Communications and the Digital Economy.

Renn, O. (2021). The IRGC risk governance framework: Revisiting emerging risk governance. Journal of Risk Research, 24(9), 1081–1098.

Shneiderman, B. (2022). Human-centered AI: A framework for reliable, safe and trustworthy systems. International Journal of Human–Computer Interaction, 38(6), 495–504.

Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339.

Templin, T., Fort, S., Padmanabham, P., et al. (2025). Framework for bias evaluation in large language models in healthcare settings. npj Digital Medicine, 8, Article 414.

The Lancet Digital Health Commission. (2024). Governing health futures in the age of artificial intelligence. The Lancet Digital Health, 6(4).

Topol, E. (2019). Deep medicine: How artificial intelligence can make healthcare human again. Basic Books.

Veale, M., & Borgesius, F. Z. (2021). Demystifying the draft EU Artificial Intelligence Act. Computer Law Review International, 22(4), 97–112.

Waiganjo, P., Wambua, S., & Kibet, R. (2024). Digital health policy and artificial intelligence readiness in Kenya. BMJ Health & Care Informatics, 31(1), e100921.

Wang, A., Freeman, S., & Magrabi, F. (2026). Governance for safe and responsible AI in healthcare organisations: A scoping review of frameworks. npj Digital Medicine, 9, Article 516.

World Health Organization. (2021). Ethics and governance of artificial intelligence for health. World Health Organization.

Downloads

Published

2026-09-09