Platform · The Reference Core

The CHAR Operating Model

CHAR is the Clinical Health AI reference governance model at the heart of FORGE™, one reference core spoked out to five governance clusters, each binding its policies, processes, SOPs, and crosswalked controls into a single accountable system.

CHAR
Operating Model
Definition

What is the CHAR Operating Model?

CHAR is Asher's reference governance model for clinical health AI, a versioned blueprint that organizes every governance policy domain, process area, SOP, and control into five accountable clusters. FORGE™ configures CHAR to your institution, turning the reference core into a working AI Management System where each run emits auditable records and telemetric signals. CHAR is what makes governance executable, repeatable, and inspection-ready.

A reference core, not a template
A single, versioned source of truth for how governance should run, spoked out, configured, and kept current as standards evolve.
Policy → process → SOP fabric
Every policy domain binds the process domains that carry it out, and every process hands off to the next, one connected fabric.
Crosswalked by construction
Every control maps to ISO 42001, the CHAI framework, and NIST AI RMF, so a single configuration satisfies many obligations.
The Framework

One reference core, five governance clusters

Each cluster is a capability domain: clinical AI governed as a leadership-owned capability, risk managed systematically, lifecycle taken from concept to validated use, operations measurably improved, and the external ecosystem safely engaged.

CHAR
Operating Model
01Strategy & Leadership
Clinical AI governed as a leadership-owned capability.
Policies · 3
SAPScope & Applicability
AGPAI Governance
SEPStakeholder Engagement
Processes & SOPs · 2
OVROversight & Steering
● 3 SOPs
ORGOrganization & Strategy
● 4 SOPs
9controls
02Risk, Ethics & Compliance
Systematically manage AI risk to patients & clinicians.
Policies · 3
RMPRisk Management
EFPEthics & Fairness
HOPHuman Oversight
Processes & SOPs · 3
RMRisk Management
● 3 SOPs
EFEthics & Fairness
● 4 SOPs
HOHuman Oversight
● 4 SOPs
13controls
03Data, Model & System Lifecycle
Take data & AI from concept to validated clinical use.
Policies · 3
DGPData Governance
LTPLifecycle Traceability
VALValidation
Processes & SOPs · 3
TRTransparency
● 3 SOPs
PVProblem & Value
● 4 SOPs
SASolution Architecture
● 4 SOPs
11controls
04Operations & Workflow Integration
AI measurably improves day-to-day care & operations.
Policies · 2
MMPModel Monitoring
CMPChange Management
Processes & SOPs · 3
MONMonitoring
● 3 SOPs
ITIT Systems & Data
● 4 SOPs
UGUsage Governance
● 3 SOPs
5controls
05Vendor, Partners & Ecosystem
Safely engage external AI products, vendors & partners.
Policies · 1
TPPThird-Party AI Management
Processes & SOPs · 2
SASolution Architecture
↗ shared
RMRisk Management
↗ shared
2controls
Policy governance policy domainProcess CMMI-style process areaSOP standard operating procedureControl crosswalked to ISO 42001, CHAI & NIST AI RMF
5
Governance Clusters
12
Policy Domains
12
Process Domains
39
SOPs
40+
Controls
CHAR as a connected graph

Not a binder of clusters: one connected fabric

Every policy domain binds the process domains that carry it out, and processes hand off to one another across cluster lines. The whole policy → process → SOP fabric lives in one view, 78 domain links reaching across the five clusters.

CHAR
Operating
Model
SAP
AGP
SEP
RMP
EFP
HOP
DGP
LTP
VAL
MMP
CMP
TPP
OVR3
ORG4
SE
RM3
EF4
HO4
TR3
PV4
SA4
MON3
IT4
UG3
How to read
Policy domain  governs intent
Process domain  does the work
SOP  standard procedure
Controls sit under each SOP — crosswalked to ISO 42001, NIST AI RMF & CHAI, then configured to your needs as the management system is built. Hover a process or SOP to reveal them.
Configures  policy → process
Feeds into  process → process
Gold links cross cluster lines — that reach is the connectedness CHAR designs in.
Governance clusters (Capability Domains)
01Strategy & Leadership3 policy · 3 process
02Risk, Ethics & Compliance3 policy · 3 process
03Data & System Lifecycle3 policy · 3 process
04Operations & Workflow2 policy · 3 process
05Vendor & Ecosystem1 policy · 0 process
Hover any domain to trace its links · hover a process to bloom its controls · click to pin
12
Policy domains
12
Process domains
39
SOPs
78
Domain links
A connected graph, not a static checklist — this one is live. Hover any domain to trace its links, hover a process to reveal its controls, click to pin.
Configures
Policy → Process
A policy domain sets intent; the process domains it configures do the work, with SOPs underneath each one.
Feeds into
Process → Process
Processes hand off to one another, including gold links that cross cluster lines, which is the connectedness CHAR designs in.
Crosswalked
Control → Framework
Controls sit under each SOP and map to ISO 42001, NIST AI RMF & CHAI, then configure to your needs as the management system is built.
The architecture beneath FORGE™

One connected graph: concept · organization · governance

The Asher Knowledge Graph binds three namespaces into one fabric: what the AI is (ash), who runs it and where (forge), and how it is governed (CHAR).

Three namespaces, one fabric

Each layer is a first-class namespace with its own vocabulary — yet every node can link across layers. A clinical concept connects to the organization that deploys it, which connects to the governance that covers it.

ash:
domain · what the AI is
AI modelImaging modalityClinical specialtySite of careRegulatory status
classified by · operated by
forge:
organization · who & where
OrganizationFacility / site of careAI governance authorityClinical roleMarket segment
governed by · scoped to
CHAR
governance · cai: operating model
Policy domainProcess domainSOPControlRegulatory crosswalk
concept (ash)
agent / place (forge)
policy domain
process domain
SOP
cross-layer link
SKOS bridges outward to external vocabularies
MIDRC MetricTreeSNOMED CTRadLexvia skos:closeMatch · skos:relatedMatch

Inside the ontology: standards · namespaces · vocabularies

FORGE’s graph isn’t bespoke plumbing. Every Asher namespace inherits from open W3C & community standards — that parentage is what makes it interoperable, reasoned, and tool-agnostic (Protégé, triplestores, SPARQL, OWL reasoners).

Built onOWL 2RDFSSKOSPROV-Op-plan
ash:domain · concepts
Product · AImodel · AIapplicationOWL class
ValidationScenario · AgenticCapabilityProfileOWL class
ClinicalPurpose · AIParadigm · WorkflowPosition + 11 more14 skos:Scheme
RobustnessFactor · FairnessFactor · ActionableFinding v0.7skos:Scheme
closeMatch MIDRC · SNOMED CT · RadLexskos:bridge
forge:organization
Organization · Role · Authorityprov:Agent
Facility ▸ ash:SiteOfCarebridge
policyAppliesToOrg ▸ cai:bridge
MarketSegment · GovMaturityskos:ConceptScheme
cai: / CHARgovernance
AIManagementSystemprov:Bundle
PolicyDomain · ProcessDomainp-plan:Plan
BasePractice · SOPTemplatep-plan:Step
WorkProduct · PolicyDocumentprov:Entity
ExemplarControl · RegRequirementskos:Concept
SKOS → vocabularies14 concept schemes — clinical purpose, AI paradigm, agentic behavior, multimodal I/O, validation, robustness & fairness — plus external bridges to MIDRC, SNOMED CT & RadLex.
PROV-O → provenanceWho decided, on what evidence — the backbone of AI-governance audit.
p-plan → executablePolicy becomes process, SOP & work product — not just a document.
One graph → leverageQuery, reason & extend without rewiring. This is the Asher Knowledge Graph.

Concepts at work: one governed path

Follow a single clinical-AI deployment as it crosses all three layers — from what it is, to who runs it and where, to exactly how it is governed and which regulations that satisfies.

ash · concept

Stroke-triage AI

Detection model on CT angiography; FDA-cleared, Class II.

forge · org & site

Radiology group

Off-campus imaging site (POS 19), provider-based to the hospital.

forge · authority

Governance authority

Medical Director holds AI policy ownership (inherited by the site).

CHAR · policy

AI governance (AGP)

Policy domain configures the oversight process for this tool.

CHAR · process → SOP

Oversight → charter

OVR process domain · SOP “governance structure” · work product “charter”.

Controls crosswalk to:NIST AI RMFISO 42001ACR ARCH-AIONC HTI-1URAC HAIJoint Commission
Why it matters the same path runs for any segment — a solo practice or a national health system — because every node reuses the canonical types.

The knowledge graph grows

Asher’s graph is not static. Content we scrape and the work we do with customers continually mint new, curated terms into the ash: base namespace — which immediately enriches every connected layer.

1 · Sources

cms.gov enrollment & taxonomycensus.gov market dataliterature & regulatory textMIDRC MetricTree curatedAI-Assess evaluation vocabulary legacy→promotedFDA-MIT evaluation terms curatedcustomer onboarding & FORGE usage

2 · Candidate & curation

Term candidates are extracted or mapped from curated external vocabularies, de-duplicated against the graph, then human-in-the-loop curated for label, definition, semantic type & relationships.

No orphan terms — each is typed and linked before it lands. External terms enter as SKOS bridges, not copies.

3 · Minted into the base

ash:NewTerm

Added to the base namespace with a semantic type & crosswalk hooks — instantly available to forge and CHAR.

Ripple effect:  a new ash: term  →  new forge: scoping (orgs / sites it applies to)  →  new CHAR policy & control coverage, with regulatory crosswalks attached.
3
Connected namespaces
12
Policy domains
12
Process domains
39
SOPs
35+
Exemplar controls
6
Reg frameworks
14
SKOS concept schemes
The Asher Knowledge Graph, live: concept, organization and governance in one connected ontology beneath FORGE™. The scenes advance on their own — click a numbered tab to explore.
ash:
domain · what the AI is
AI modelImaging modalityClinical specialtySite of careRegulatory status
classified by · operated by ↓
forge:
organization · who & where
OrganizationFacility / site of careAI governance authorityClinical roleMarket segment
governed by · scoped to ↓
CHAR:
governance · the operating model
Policy domainProcess domainSOPControlRegulatory crosswalk

See CHAR configured to your institution

FORGE™ takes the CHAR reference core and stands up your operational AI Management System, in days, not months.