LARRI and governance
Governments and institutions describe the same missing record.
Journalists, senators, clinicians, federal auditors, Canadian public-service faculty, and academic researchers have each examined automated decision-making in healthcare and arrived at a problem that sits at the integrity layer. LARRI is designed to address that layer. Hear from officials and researchers, in their own words, about the problems LARRI is built to answer.
Committee on Financefinance.senate.gov
Health, Education, Labor & Pensionshelp.senate.gov
Permanent Subcommittee on Investigationshsgac.senate.gov
Office of Inspector Generaloig.hhs.gov
Government Accountability Officegao.gov
Public Broadcasting Servicepbs.org
University of California / UCTVuctv.tv Governance and automation
In the age of AI, records need better integrity. Each account explains why
Institutional accounts
Choose a government to see available videos.
Choose a government panel, then select an available video to load its account in the theatre.
How can LARRI help?
Automated processing, sampled medical oversight, and individual clinical review would remain clearly distinct. Only a patient-specific review record could support an “individually reviewed” assurance.
LARRI changes the process
LARRI preserves the speed of automated claims processing while making every decision independently accountable. Each claim receives a unique content-derived identity and receipt, allowing the system to process large batches without collapsing fifty separate determinations into one generalized approval.
An organizational key can attest to each automated determination. A medical director can sign a separate batch-oversight record identifying:
- the claims sampled;
- the sampling method;
- the evidence examined;
- the errors or exceptions found;
- the decision to release, hold, or expand review of the batch.
Claims requiring individual medical judgment would receive a separate case-specific review record. Missing evidence, an unsupported denial reason, or failure to obtain required review could cause the assurance to refuse and route the claim for examination before issuance.
The patient and provider would receive the original decision basis for appeal, including the exact policy and system state in force at the time. Later evidence, corrections, and reversals would be linked to that record without rewriting it.
LARRI makes batch automation honest, reviewable, and governable. It prevents sampled oversight from being represented as fifty individual medical reviews and gives release controls the evidence needed to stop or reroute questionable denials before they reach patients.
How can LARRI help?
An outside verifier could then confirm that the required evidence existed, matched the decision, and remained unchanged. Missing provenance, approvals, risk records, or other mandatory elements would prevent the selected assurance from passing and could block or escalate the decision before release.
LARRI changes the process
Without an event-level integrity mechanism, an organization may later assemble:
- the policy it says applied;
- the model documentation it believes was current;
- selected data-source records;
- approval and risk-management materials;
- an explanation reconstructed for the audit.
With LARRI in place as a release condition, those relationships are fixed when the decision is made. The receipt identifies the exact evidence and contracts used, while protected materials can remain access-controlled and be represented through verifiable commitments rather than public disclosure.
The later reviewer no longer has to ask the institution to reconstruct its own conduct. The reviewer receives the original decision package and independently checks:
- which data and provenance records were declared;
- which policy and system version governed;
- which risk controls and approvals were required;
- which person or system took the action;
- which reason was recorded at the time;
- which evidence was absent or remained unverified.
LARRI therefore turns “show your work” into an operational requirement attached to each decision, rather than a documentation exercise triggered only when an auditor, regulator, or affected person demands answers.
How can LARRI help?
That record would let independent reviewers test outcomes against the precise deployment responsible for them. A model could not be silently updated, a policy substituted, or a fairness assessment applied to a different configuration; missing or outdated evidence could fail the required assurance and trigger review before further decisions were released.
LARRI changes the process
A fairness review often examines aggregate outcomes after a system has already affected patients. The investigation may then depend on the institution or vendor reconstructing:
- which model version was active;
- which proxy or objective it optimized;
- which threshold and configuration were used;
- which policy converted its output into action;
- which patient information was available;
- when a deployment or policy changed.
With LARRI imposed as a decision-release requirement, those elements are bound contemporaneously to each determination. Reviewers could group verified receipts by exact model, policy, threshold, location, and time period, then identify where disparities began and which deployment state produced them.
A healthcare governance profile could also require each operative model release to carry commitments to its intended use, data description, subgroup-performance results, fairness assessment, known limitations, and institutional approval. When those records were absent, expired, or associated with another version, the required assurance would refuse rather than allowing the organization to present the system as properly assessed.
How can LARRI help?
The insurer could not reduce the event to a later statement that a human made the final decision. The record would show what the reviewer received, which recommendation the system produced, which contrary clinical evidence was present, which policy governed the denial, and what action the reviewer took.
LARRI changes the process
Without a shared decision record, the dispute must be reconstructed from separate systems:
- the clinician holds the treatment recommendation;
- the insurer holds the predictive output and review workflow;
- the vendor controls the tool and its documentation;
- the patient receives the denial notice;
- the appeals unit later assembles its own version of the case.
A LARRI decision bundle would preserve those elements as distinct, identified objects linked to one determination. It could establish:
- the exact clinical material declared available;
- the model and configuration that produced the predicted stay;
- the coverage policy and criteria in force;
- the machine recommendation before human action;
- the reviewer’s acceptance, departure, or escalation;
- the reason recorded when coverage was ended;
- the notice delivered to the patient;
- any later appeal, additional evidence, or reversal.
Where the profile required patient-specific review, missing clinical evidence or an unsupported reviewer attestation could prevent the assurance from passing and route the case for further examination before coverage ended. A later appeal could add evidence and produce a new receipt without rewriting the original denial record.
Huberty’s call for patients to see the machine’s “moving parts” becomes an operational requirement: the patient, provider, auditor, or regulator can examine the exact relationship among the clinical judgment, automated prediction, governing rule, and final action without relying on the insurer’s later reconstruction.
How can LARRI help?
A denial based on a superseded rule, an unrecognized internal criterion, missing review evidence, or a reason contradicted by the committed record could fail the required assurance and be blocked or escalated before reaching the patient. Auditors would examine the original decision package rather than reconstructing the insurer’s process months or years later.
LARRI changes the process
OIG’s findings included decisions involving criteria outside Medicare rules, records treated as insufficient despite adequate documentation, material documents being overlooked, and systems that were incorrectly programmed or not updated. A governed LARRI profile could address each failure directly.
Every denial would preserve:
- the authorization request and supporting records;
- the exact Medicare coverage criterion cited;
- the plan’s utilization-management policy and version;
- the rules engine or workflow version applied;
- the automated recommendation;
- the evidence declared available to the reviewer;
- the reviewer’s action and attestation;
- the contemporaneous denial reason and notice;
- any later appeal, additional evidence, or reversal.
The profile could permit only recognized and current coverage-criterion identifiers. A denial invoking an obsolete policy, an unauthorized internal standard, or a rules-engine version that did not match the institution’s approved deployment would refuse verification.
Where the denial claimed insufficient documentation, the verifier could compare that reason with the closed evidence manifest. A required document shown as present in the signed package could not later be characterized as absent without leaving an explicit contradiction for review.
Once issued, the original decision would remain independently verifiable. An appeal or reversal would create a linked record rather than replacing the initial denial, allowing regulators to identify which policies, system versions, reviewers, reasons, or contractors repeatedly produced decisions that failed on reconsideration.
LARRI would turn the coverage rules OIG audits after harm occurs into verifiable release conditions applied before a denial becomes final.
How can LARRI help?
The documents needed to understand the decision would exist before an investigation began. A denial produced under an unauthorized policy, unsupported by patient-specific evidence, or approved without the required clinical review could fail the applicable assurance and be blocked or escalated before reaching the patient.
LARRI changes the process
The Senate investigation had to obtain and analyze internal documents after the decisions had already affected patients. Those materials connected automation, denial practices, appeal prediction, utilization policies, and financial savings, but they remained distributed across corporate systems and dependent on retrospective production.
With LARRI imposed as a release condition, each denial would create a contemporaneous decision package identifying:
- the exact clinical request and supporting records;
- the Medicare criterion and plan policy applied;
- the model, rules engine, configuration, and threshold in force;
- the automated recommendation before human action;
- whether the reviewer accepted, changed, or escalated that recommendation;
- the patient-specific reason for the final determination;
- the reviewer’s identity, role, and attestation;
- the notice delivered to the patient;
- any later appeal, reconsideration, or reversal.
A generic statement that “a clinician made the final decision” would no longer be enough. The receipt would show which evidence that clinician was given, which automated recommendation appeared, which rule governed the case, and what action the clinician actually recorded.
Across many decisions, verified receipts could reveal whether denial rates changed after a new model, policy, contractor, or workflow was introduced. Regulators could compare automated recommendations, human overrides, denial reasons, processing times, appeal rates, and reversals against exact deployment versions rather than relying on summary reports prepared by the insurer.
How can LARRI help?
A third party could independently verify that the required governance evidence existed, belonged to the deployed system, and remained unchanged. Missing approvals, mismatched versions, expired evaluations, or absent monitoring records could prevent the relevant assurance from passing and stop or escalate deployment.
LARRI changes the process
GAO’s framework asks institutions to demonstrate sound governance across four connected areas:
- governance and accountability;
- data quality and provenance;
- system performance;
- continuing monitoring.
Ordinarily, the institution itself inventories the system, maintains its documentation, reports its controls, and later assembles evidence for oversight. That process may leave reviewers dependent on the organization’s current databases, document repositories, and retrospective explanation.
With LARRI imposed as a release and decision-integrity requirement, the institution would produce exact artifacts as the system operates:
- a content-derived identity for each approved model or software release;
- commitments to the training, validation, and operational data declarations;
- the configuration, thresholds, prompts, and governing policies in force;
- the intended use and prohibited reliance;
- validation, risk, fairness, security, and human-factors evidence;
- approval by identified and authorized personnel;
- monitoring results tied to the deployed version;
- incidents, corrective actions, and subsequent changes;
- the human action associated with each consequential output.
External trust would be supplied independently of the artifact, allowing the verifier to determine which identified keys and institutional roles are accepted rather than trusting credentials embedded by the producer.
When a system changed, the new release would receive a new identity and a new evidence package. The institution could not apply an earlier validation report or approval silently to materially different code, data, configuration, or policy. Monitoring results could likewise be traced to the exact release that produced them.
LARRI turns lifecycle accountability into a continuous chain of independently verifiable releases, decisions, monitoring evidence, and responsible actions.
How can LARRI help?
The same record could therefore support different forms of justified reliance: a hospital could verify institutional approval, a regulator could inspect governance evidence, a clinician could confirm the decision context, and a patient or advocate could establish what was formally recorded when the action occurred.
LARRI changes the process
Healthcare institutions commonly ask several distinct questions under the single heading of whether a system is “trustworthy”:
- Is this the exact system release that was approved?
- Has the decision record changed?
- Did an accepted key sign it?
- Was that key authorized for this role?
- Which evidence and policy were associated with the decision?
- Which assurance checks passed?
- What remains unknown or unverified?
LARRI keeps those questions separate. Each artifact receives a content-derived identity. Signatures are checked against trust supplied independently by the receiver. Exact semantic contracts determine what the verification result means. Declared limitations remain part of the result rather than disappearing inside a general approval status.
For a consequential healthcare decision, the record could bind:
- the model or software release;
- the declared evidence;
- the governing policy;
- the machine output;
- the human response;
- the responsible attestation;
- the applicable governance approvals;
- the remaining limitations.
The hospital, regulator, patient representative, and independent auditor could verify the same artifact while applying the authority, role, and acceptance rules appropriate to each institution. The issuer’s live system would no longer control the only available account of the decision.
A changed model, substituted policy, altered evidence package, or revised explanation would produce a different identity or verification result. Later amendments could be linked without replacing the original state.
LARRI therefore gives practical form to the question at the centre of Sim and Han’s discussion: whose trust must be earned, what evidence earns it, and which exact assurance each community is entitled to rely upon.
How can LARRI help?
LARRI turns interoperable health information into a verifiable record of use. When records move between systems, LARRI binds the exact versions received and any transformations applied to the system, policy, recommendation, human action, reason, and attestation behind a consequential decision.
The patient, next provider, auditor, or regulator receives portable proof of the record state formally bound to that decision—across vendors and jurisdictions, without depending on the originating system to reconstruct what happened.
This is more accurate than saying LARRI merely “gives the information a verifiable identity.” Its distinct function begins after or during exchange:
- Interoperable health information
- Exact source versions and transformations
- System and policy applied
- Machine output and human response
- Signed, independently verifiable decision record
The Canadian institutional analysis identifies this precise gap: interoperability standards help information move, while LARRI’s additional value is binding the source state, system output, policy, human action, and monitoring context to the individual event.
How can LARRI help?
LARRI creates the evidence behind a significant automated outcome when the outcome is made. Each receipt binds the exact information sources, operative system and policy, principal factors, recommendation or decision, human review, contemporaneous reason, and responsible attestation, while sensitive records remain with their authorized custodian.
When a person requests an explanation or reconsideration, the organization can provide a plain-language account backed by the original, independently verifiable decision record. Corrections, representations, and appeals become linked records rather than later reconstructions that replace the initial event.
This is stronger than saying LARRI simply “produces the evidence for an explanation.” It addresses three specific evidentiary problems created by the bill:
- Source
- the receipt identifies the exact source records or versions formally associated with the decision.
- Reason
- the contemporaneous reason and principal-factor record are bound before a complaint arises.
- Review
- the automated outcome, the individual’s representations, the reviewer’s action, and any correction can remain separately identifiable in one linked history.
Strong combined formulation
Bill S‑5 is designed to make health information portable. Bill C‑36 is designed to make significant automated outcomes answerable. LARRI makes the relationship between the information, system, reason, human action, and final decision independently verifiable.
How can LARRI help?
LARRI turns those lifecycle duties into exact release and decision evidence. An EU healthcare profile can bind each deployed system version to its intended use, data and validation records, risk controls, configuration, responsible approvals and current monitoring state, then bind each consequential output to the exact source record, machine recommendation, human action, contemporaneous reason, attestation and limitations.
A changed model, threshold, policy, validation report or evidence package produces a different identity. An outside verifier can establish which materials belonged to the system and decision under review, whether the required evidence was present, and whether anything was substituted after the event.
That would give providers, deployers, auditors, notified bodies and market-surveillance authorities a stable evidentiary package for evaluating compliance. It would also support the Act’s human-oversight duties by preserving what the reviewer received, how the automated output entered the decision and what action the reviewer recorded. The Act expressly requires high-risk systems to support traceability, intelligible use and effective human oversight; for certain significant Annex III decisions, it also provides a right to a clear and meaningful explanation of the AI system’s role and the principal elements of the decision.
How can LARRI help?
EHDS makes health information portable and access events reviewable. LARRI preserves the exact consequential decision made from that information, binding the precise record versions and transformations selected to the system and configuration that acted, the policy in force, the machine output, the human response, the reason, the responsible attestation and the limitations that remained.
The patient, next provider, auditor or regulator receives a decision package that remains independently verifiable across vendors, institutions and member states. It shows which exchanged information was formally used, how it was transformed, what recommendation was produced and who adopted or changed it.
EHDS logging identifies access to health information. A LARRI receipt can add the relationship among:
- the accessed source state;
- the subset selected for the decision;
- any normalization or feature transformation;
- the model and configuration;
- the governing policy;
- the recommendation;
- the human action;
- the final record.
That distinction matters because an access log can establish that a professional viewed categories of health data without itself preserving the complete state formally associated with a particular automated or human determination. EHDS requires its EHR logging component to record the people involved, data categories, time and data origins; LARRI can use those standardized identities as inputs to a broader signed decision record.
LARRI should therefore integrate with the European electronic health-record exchange format and existing healthcare identifiers rather than create a competing clinical-data standard. Raw health information can remain with its authorized custodian while the receipt carries governed references, digests and attestations needed for verification. LARRI’s receipts and closed bundles are designed to bind exact assertions, commitments, artifacts, signatures and limitations while verification uses independently supplied trust.
Strong combined formulation
The AI Act makes high-risk AI accountable. The European Health Data Space makes health information portable and traceable. LARRI binds the exact data, system, policy, automated output, human action and final decision into one independently verifiable event record.
Choose a government
United States7 videos
Canada3 videos
European Union2 videos

Where regulation is converging
Governments have already named the required qualities.
Regulators have stopped asking whether automated decisions need governing and started identifying what governance must produce. ONC’s HTI-1 rule demands source attributes and risk management for predictive interventions. CMS demands specific denial reasons, standardized prior-authorization exchange, published metrics, and coverage criteria consistent with Medicare rules. NIST and GAO supply the lifecycle accountability frameworks around them. Every one of these instruments describes a decision an institution must be able to account for after the fact, and none of them specifies the record that would make the accounting possible.
Nine standards, one artifact
How LARRI meets the standards
Institutions are converging on the standards LARRI is built to uphold: every consequential automated decision should carry exact, reviewable evidence of its system, sources, purpose, risks, reasons, monitoring, human responsibility, and governing authority.
LARRI turns institutional governance into one independently verifiable decision artifact, binding every consequential outcome to its exact system, sources, intended use, risk controls, reasons, exchange context, audit history, responsible human action, and governing authority.
LARRI binds each decision to the declared system, policy, configuration, profiles, and verification contracts in force at that moment. The resulting record makes the operative decision context visible without requiring disclosure of proprietary internal logic.
LARRI can commit to source records, datasets, model documentation, evaluation reports, and performance evidence by exact digest and artifact identity. A verifier can confirm that the cited material is the same material originally bound to the decision.
Verification targets, selected profiles, permitted claims, and residual limitations are explicit parts of the public result. Every PASS remains confined to the exact assurance that was selected and verified.
A LARRI profile can require identified risk assessments, controls, evaluations, and approval records as decision evidence. The receipt preserves which risk-management materials governed the event and whether the required public checks passed.
A domain profile can require every adverse decision to carry a structured reason, governing rule, evidence references, and responsible attestation. Those elements become part of the signed decision record rather than a later narrative reconstruction.
LARRI uses exact schemas, canonical encodings, registered identifiers, content-derived identities, and deterministic normalized results. Independent systems can exchange the same artifact and reproduce the same public verification outcome from the same inputs.
Each receipt provides a portable, independently verifiable record of what was declared, committed, signed, and checked. Collections of receipts can support oversight across systems, vendors, policies, and decision classes while preserving the identity of each individual event.
A human action, reviewer role, signer declaration, and attestation can be bound to the exact decision package. Responsibility is therefore attached to a specific record state rather than inferred from a generic workflow log.
LARRI makes governing contracts, trust inputs, profiles, limitations, and conformance evidence explicit and independently inspectable. Institutions can demonstrate which rules governed a decision and outside reviewers can verify that those rules were applied to the declared record.
Normative foundation
Read how the receipt and bundle model works.
The protocol binds assertions, commitments, contracts, signer declarations, exact file bytes, and stated limitations for independent verification.