Skip to main content
OpenIRB

Framework

A practical framework for Intelligent Review Boards.

OpenIRB provides a shared review model that institutions can adapt across AI governance, research ethics, medical technology, data stewardship, and human-impact decisions.

The seven-part model

From object of review to continuing review

  1. Object of review

    What is being reviewed: model, agent, protocol, data use, medical workflow, research plan, public-sector decision system, or other human-impact system.
  2. Review path

    What level of review is required: administrative screen, expedited review, full board review, emergency review, renewal, or incident review.
  3. Evidence packet

    What the submitter must provide: claims, evidence, intended use, affected groups, risks, controls, consent posture, authority, and monitoring.
  4. Deliberation protocol

    How reviewers assess evidence, ask questions, identify unresolved issues, manage conflicts, and reach decisions.
  5. Decision artifact

    The review outcome and conditions: approval, conditional approval, modifications required, denial, escalation, remediation, suspension, or closure.
  6. Receipt and registry

    The metadata and custody record that make the decision findable, versioned, auditable, and governed.
  7. Continuing review

    The monitoring and renewal process for drift, changes, incidents, adverse events, new evidence, complaints, and scope changes.

Risk classes

Proposed review classes

Proposed operating classes for early OpenIRB implementations. Risk classes are not communicated by color alone.

A risk matrix mapping human impact against autonomy and scale, from O-0 to O-4 with an O-X emergency path.
Review should be proportional to autonomy, scale, sensitivity, and human impact.
ClassNameDescriptionReview path
O-0Out of scopeNo meaningful human-impact intelligence or only trivial administrative useRecord only
O-1Low impactMinimal risk, no sensitive data, no material effect on rights/safety/welfareAdministrative screen
O-2Moderate impactSome human impact, sensitive context, or operational dependencyExpedited review
O-3High impactAffects health, safety, rights, access, opportunity, vulnerable groups, or regulated domainsFull board review
O-4Critical impactAutonomous action, clinical/high-risk deployment, public-scale systems, irreversible harmsFull board + independent review
O-XEmergency / exceptionTime-sensitive use requiring provisional decision with post-action reviewEmergency path + retrospective review

Decision types

What a review can conclude

  • Approved — acceptable under stated conditions.
  • Approved with conditions — acceptable only if specified controls are implemented.
  • Modifications required — insufficient as submitted; resubmission required.
  • Denied — unacceptable risk, insufficient evidence, or invalid consent/authority.
  • Escalated — requires specialized review, legal/regulatory analysis, or leadership decision.
  • Remediated — deficiencies corrected after review.
  • Suspended — approval paused due to incident, drift, scope change, or new evidence.
  • Closed — review lifecycle ended, with final record preserved.

Implementation principles

How OpenIRB stays accountable

  1. Human accountability remains central

    AI may assist review, but it does not replace accountable human decision-making.
  2. Review artifacts must be versioned

    Evidence, decisions, and conditions must be traceable over time.
  3. Consent and authority must be explicit

    Review should not rely on implied permission where humans or sensitive data are affected.
  4. Privacy by design

    Sensitive evidence should not be made public by default.
  5. Continuing review is mandatory for adaptive systems

    Drift, scope change, incidents, and new evidence must have review pathways.
  6. Fail-closed where uncertainty is material

    If authority, consent, evidence, or safety controls are indeterminate in a high-impact case, the system should not proceed without remediation or escalation.