Framework
A practical framework for Intelligent Review Boards.
OpenIRB provides a shared review model that institutions can adapt across AI governance, research ethics, medical technology, data stewardship, and human-impact decisions.
The seven-part model
From object of review to continuing review
Object of review
What is being reviewed: model, agent, protocol, data use, medical workflow, research plan, public-sector decision system, or other human-impact system.Review path
What level of review is required: administrative screen, expedited review, full board review, emergency review, renewal, or incident review.Evidence packet
What the submitter must provide: claims, evidence, intended use, affected groups, risks, controls, consent posture, authority, and monitoring.Deliberation protocol
How reviewers assess evidence, ask questions, identify unresolved issues, manage conflicts, and reach decisions.Decision artifact
The review outcome and conditions: approval, conditional approval, modifications required, denial, escalation, remediation, suspension, or closure.Receipt and registry
The metadata and custody record that make the decision findable, versioned, auditable, and governed.Continuing review
The monitoring and renewal process for drift, changes, incidents, adverse events, new evidence, complaints, and scope changes.
Risk classes
Proposed review classes
Proposed operating classes for early OpenIRB implementations. Risk classes are not communicated by color alone.
A risk matrix mapping human impact against autonomy and scale, from O-0 to O-4 with an O-X emergency path.
| Class | Name | Description | Review path |
|---|---|---|---|
| O-0 | Out of scope | No meaningful human-impact intelligence or only trivial administrative use | Record only |
| O-1 | Low impact | Minimal risk, no sensitive data, no material effect on rights/safety/welfare | Administrative screen |
| O-2 | Moderate impact | Some human impact, sensitive context, or operational dependency | Expedited review |
| O-3 | High impact | Affects health, safety, rights, access, opportunity, vulnerable groups, or regulated domains | Full board review |
| O-4 | Critical impact | Autonomous action, clinical/high-risk deployment, public-scale systems, irreversible harms | Full board + independent review |
| O-X | Emergency / exception | Time-sensitive use requiring provisional decision with post-action review | Emergency path + retrospective review |
Decision types
What a review can conclude
- Approved — acceptable under stated conditions.
- Approved with conditions — acceptable only if specified controls are implemented.
- Modifications required — insufficient as submitted; resubmission required.
- Denied — unacceptable risk, insufficient evidence, or invalid consent/authority.
- Escalated — requires specialized review, legal/regulatory analysis, or leadership decision.
- Remediated — deficiencies corrected after review.
- Suspended — approval paused due to incident, drift, scope change, or new evidence.
- Closed — review lifecycle ended, with final record preserved.
Implementation principles
How OpenIRB stays accountable
Human accountability remains central
AI may assist review, but it does not replace accountable human decision-making.Review artifacts must be versioned
Evidence, decisions, and conditions must be traceable over time.Consent and authority must be explicit
Review should not rely on implied permission where humans or sensitive data are affected.Privacy by design
Sensitive evidence should not be made public by default.Continuing review is mandatory for adaptive systems
Drift, scope change, incidents, and new evidence must have review pathways.Fail-closed where uncertainty is material
If authority, consent, evidence, or safety controls are indeterminate in a high-impact case, the system should not proceed without remediation or escalation.