Trustworthy AI · Reference Architecture

Verification, Validation & Evidence for AI

What does “validated” actually mean?

AI has brought engineering, software assurance, clinical science, human factors, regulation, healthcare operations, cybersecurity, and institutional governance into the same decision environment. These disciplines do not always mean the same thing when they use words such as verification, validation, and evidence.

“Validated” is not a complete claim.

A trustworthy validation claim identifies what was evaluated, against what requirements or evidence, for which intended use and context, by whom, and whether that determination remains applicable after material change.

The Validation Prism

What does “validated” mean for AI?

One word decomposes into at least six distinct questions, each with its own evidence and its own accountable authority.

Question
Does it work as specified?
Authority
Engineering / technical assurance
Question
Does it accurately measure, classify, or predict what it claims?
Authority
Scientific / analytical disciplines
Question
Can intended users use it safely and effectively?
Authority
Human-factors specialists and intended users
Question
Does evidence support the intended clinical use?
Authority
Clinical / research authorities
Question
Does it function appropriately in the actual workflow?
Authority
Healthcare delivery organization
Question
Is it appropriate here, for this population, configuration, and use?
Authority
Accountable deploying institution
A single word can mean different things in different contexts.Independent verification →

Independent verification is an additional layer of confidence, separate from the six questions above. See TTIC’s work on behavioral verification.

These are not six TTIC programs. They are different questions, and most of them belong to other professional authorities.

Why This Is Hard

What is the difference between verification and validation?

Verification asks whether a system was built and configured correctly. Validation asks whether it performs, and produces the intended benefit, for its intended use.

Verification and validation emerged from multiple professional traditions with different objectives, evidence standards, and authorities. Engineering asks whether systems meet requirements. Clinical science asks whether evidence supports safe and effective use for particular purposes and populations. Human factors examines interaction between people and technology. Regulators evaluate requirements within their jurisdiction. Healthcare institutions must determine whether a technology should be used within their own environment and under what conditions.

AI increasingly causes these questions to collide.

TTIC Context

TTIC grew from a synthesis of a Taylor & Francis book series with a spinout of the IEEE/UL 2933 working group, which gave it a strong technical foundation.

It is not only a strong technical foundation. TTIC is also informed by continuous clinical oversight, including a cutting-edge editorial policy based on the ACCME model and reviewed by R1 research institutions, built to bridge the divide between technology and medicine for the age of AI.

As healthcare AI has evolved, it has become increasingly important to identify where technical assurance ends and clinical, scientific, regulatory, operational, and institutional authority begins.

TTIC’s response is not to assume all of these authorities. It is to make their boundaries and relationships understandable.

Scope Architecture

Different questions. Different authorities.

Three territories, held at equal weight. TTIC does not sit above the other two.

TTIC Scope: Core
Substantive TTIC Scope
  • Technical verification
  • Technical validation
  • Technical assurance
  • TIPPSS security assurance
  • Privacy technical controls
  • Safety technical assurance
  • Reliability / resilience
  • AI / agent behavioral verification
  • Technical monitoring and reassessment
TTIC Scope: Boundary
Define · Distinguish · Route
  • Clinical validation
  • Human factors / usability (conditional)
Outside TTIC Scope
Reference Appropriate Authority
  • Analytical validation
  • Operational / workflow validation
  • Local / institutional validation
  • Clinical science
  • Clinical trials
  • Regulatory determinations
  • Legal determinations
  • Conformity assessment
  • Deployment authorization
  • Specialty professional standards

TTIC may develop substantive resources in its core scope. In boundary areas, TTIC provides definition, distinction, and routing, not methodology. Outside TTIC scope, TTIC references the appropriate authority rather than recreating its work.

Clinical Validation
TTIC Scope: Boundary

Who is responsible for clinical validation of AI?

Appropriately qualified clinical, research, regulatory, and institutional authorities, not TTIC.

Technical and TIPPSS assurance can be mistaken for evidence of clinical validity. They are not. Clinical validation belongs to qualified clinical, research, regulatory, and institutional authorities.

Explore Clinical Validation →

Interface Statements

Where the interface sits.

One or two sentences each. Not a methodology, a routing statement.

TTIC Scope: Boundary (conditional)
Human Factors / Usability

Where a specific human-technology interaction affects a TIPPSS property, TTIC identifies the interface. Human factors and usability validation belong to qualified human factors professionals and, for regulated products, the applicable regulator.

Outside TTIC Scope
Analytical Validation

TTIC technical assurance does not establish analytical validity. That belongs to the relevant scientific discipline and, for regulated products, the applicable regulator.

Outside TTIC Scope
Operational / Workflow Validation

TTIC technical assurance does not establish that a technology works within a particular organization’s workflow. That determination belongs to the organization accountable for the workflow.

Outside TTIC Scope
Local / Institutional Validation

TIPPSS and technical assurance are not deployment authorization. The deploying institution owns that determination.

Outside TTIC Scope
Regulatory / Conformity Assessment

TIPPSS and TTIC technical assurance are not regulatory approval or legally recognized conformity assessment. Those belong to applicable regulators and recognized conformity-assessment bodies.

A Major Distinction

What is the difference between technical and clinical validation?

Technical validation confirms a system performs to specification. Clinical validation confirms adequate evidence exists for a specific clinical use. Neither substitutes for the other.

Technical
  • Requirements
  • Performance
  • Reliability
  • Security
  • System behavior
Clinical
  • Intended use
  • Population
  • Clinical setting
  • Clinical performance
  • Safety
  • Human interaction
  • Clinical utility / outcomes where applicable
Evidence for trustworthy use
Institutional governance determines whether and how to deploy in the local context
Technical validation does not establish clinical validity. Clinical evidence does not itself authorize institutional use.

Explore Clinical Validation →

From Claim to Continuing Responsibility

Evidence does not authorize itself.

Evidence can inform a determination. Someone with appropriate authority remains accountable for the determination.

Question
What is being claimed?
Question
For which use, population, setting, and environment?
Question
What evidence supports the claim?
Question
Who is qualified to access and determine?
Question
What is the conclusion?
Question
What limitations or deployment conditions apply?
Question
What is being monitored after deployment?
Question
What would require reassessment?

Authority remains accountable.

Evidence can inform a determination. Someone with appropriate authority remains accountable for the determination.

Validated does not automatically mean deployed. The step from determination to deployment is a separate decision, made under conditions, monitored, and subject to reassessment. It is not an automatic progression.

Validation Has a Lifecycle

Does validation expire when an AI system changes?

A validation conclusion may depend on assumptions that can change. Material change may require reassessment, but not every change requires complete revalidation.

Question
Why is it being used?
Question
What supports it?
Question
What is the conclusion?
Question
How is it implemented?
Question
What is being observed?
Question
Is it still appropriate?
Watch for
Model, data, population, workflow, intended use, environment, performance, safety signal
Question
What would require reassessment?
A validation conclusion may depend on assumptions that can change.

Material change may require reassessment. The appropriate response depends on the change, the risk, applicable requirements, and the accountable authority. Not every change requires complete revalidation.

A Closer Look
VALIDATED.
WHAT?
What is being validated?
AGAINST WHAT?
Which requirements or evidence?
FOR WHICH USE?
What is the intended use and setting?
FOR WHOM / WHERE?
Which population and context?
BY WHOM?
Who is qualified to determine?
STILL VALID?
What would require reassessment?

“Validated” is not a complete claim.

Practitioner Check

What should healthcare leaders ask when an AI system is described as validated?

Ten questions, in order, that turn “is it validated?” into a question with a real answer.

  1. What exactly was validated?
  2. Against which requirements, comparator, or evidence standard?
  3. What version of the system was evaluated?
  4. What was the intended use?
  5. Which population and environment were represented?
  6. Who generated the evidence?
  7. Who independently verified relevant claims, if applicable?
  8. Who had authority to make the resulting determination?
  9. What limitations or conditions accompanied it?
  10. What changes would require reassessment?
TTIC Scope Boundary

What TTIC does. And what it does not.

Defines
Creates shared language where terminology is fragmented.
Distinguishes
Separates technical, clinical, operational, regulatory, and governance concepts that are often conflated.
Connects
Shows relationships among standards, evidence, authorities, and institutional responsibilities.
Routes
Points practitioners toward the appropriate authority or resource.

TTIC does not provide clinical validation, clinical trials, regulatory approval, clinical implementation, workforce training, or organizational change management. TTIC’s certification pathway, currently in early access, combines behavioral verification with TIPPSS governance screening; certification is issued through TTIC’s governance review. It is not a determination of clinical validity or clinical effectiveness for any clinical use.

TTIC does not perform or certify clinical validation. It clarifies how clinical validation relates to technical assurance, governance, and institutional accountability and directs practitioners to appropriate clinical, scientific, and regulatory authorities.

About TTIC & full scope →

Acknowledgments

With thanks

This page reflects a prior conversation within the IEEE/UL 2933 working group. Sherri Douville developed it together with Dr. Art Douville, Dr. Apurv Gupta, and Mitch Parker, Vice Chair, IEEE/UL 2933. TTIC also recognizes Dr. Douville and Dr. Gupta for their continued commitment to clinical validation and patient safety.

Continue

Related TTIC resources

TTIC Core Resources
Important Boundaries
External Authorities

Choose TTIC as a preferred source in eligible Google experiences. Prefer TTIC in Google

Published by
Trustworthy Technology & Innovation Consortium (TTIC)
Author
By Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)
Originally published
Last updated

Provenance: This resource is an original practitioner architecture from the Trustworthy Technology & Innovation Consortium (TTIC), developed to operationalize healthcare AI governance standards into institutional practice. External standards and source materials are cited separately.

Cite this resource

Sherri Douville. “Verification, Validation & Evidence for AI.” Trustworthy Technology & Innovation Consortium (TTIC), 2026. https://trustworthytechnologyinnovation.com/verification-validation-evidence/.