HCIIF INFORMATION INTEGRITY

HUMAN-CENTRIC INFORMATION INTEGRITY FRAMEWORK

Information is everywhere.
Confidence needs
a foundation.

An Enterprise Information Integrity Management System for establishing trust and confidence in the information organisations rely upon.

Explore HCIIF

Available information.
Justified confidence.

Having information does not automatically mean it is appropriate to act on it.

Quality matters. So do provenance, context, sensitivity, accountability and human judgement. HCIIF brings these considerations into a coherent enterprise approach to information integrity.

It asks a practical question: is this information sufficiently trusted for its intended purpose, risk and consequence?

From data quality to
enterprise information integrity.

Data is the starting point. Trusted information is the outcome.

Organisations invest in data quality, data governance and AI governance. These disciplines are essential—but data is interpreted, combined, transformed, shared and relied upon in a wider organisational context.

HCIIF builds on those foundations and extends them into Enterprise Information Integrity: establishing whether information is sufficiently trusted for its intended purpose, risk and consequence.

01

Data quality

Is the data accurate, complete, consistent and timely?

02

Data governance

Is the data appropriately owned, controlled and managed?

03

Information integrity

What confidence is justified when data informs people, processes and AI?

04

Trusted outcomes

Is the resulting information sufficient for the intended decision or action?

Make the basis for trust explicit.

A human-centric, risk-based approach that connects evidence, assurance and accountable use across the information lifecycle.

01

Understand the information

Establish what information is being relied upon, where it comes from, its context and the consequences of using it.

02

Establish confidence

Assess the evidence, limitations and conditions that justify confidence. Communicate that basis through the Information Integrity Passport.

03

Govern reliance over time

Keep confidence under review as information, circumstances and intended uses change, with clear accountability and proportionate assurance.

“The objective is not perfect information.
It is sufficiently trusted information.”

A stronger foundation
for what comes next.

Confident decisions

Make the evidence and limitations behind information-led judgements visible.

Accountable governance

Connect information risk, ownership and assurance to the purpose of use.

Responsible AI adoption

Strengthen the information foundations on which AI-enabled processes and outcomes depend.

HCIIF gold shield with H monogram: Evidence, Confidence, Trusted Outcomes
ENTERPRISE EDITION

Human-Centric
Information Integrity
Framework

Deepak Sadasivan

Currently undergoing peer review

The Enterprise Edition.

The architecture, principles and operating model behind HCIIF.

Across 20 chapters, the Enterprise Edition explores how organisations can understand, assess, communicate and sustain confidence in enterprise information.

20
Chapters
229
Pages in the review edition

The publication edition will be made available here after peer review and final revisions.

Enquire about the framework

In development

The HCIIF™ Practitioner Guide.

A practical companion for organisations applying the Enterprise Edition.

The Practitioner Guide will translate the framework’s architecture and principles into implementation guidance for practitioners. It is intended to support proportionate application across different organisational contexts—not prescribe a single operating model.

01

Apply

Scoping, information-asset identification, confidence assessment and Information Integrity Passports.

02

Embed

Governance roles, lifecycle controls, assurance and integration with existing enterprise capabilities.

03

Sustain

Adoption, maturity, continual improvement and evidence-led measurement.

The guide is being developed alongside peer review and practical validation. Its scope and publication timing will be confirmed when that work is sufficiently mature.

Explore the 20 chapters.

From the information trust challenge to a sustained enterprise capability. Browse the chapter summaries to see how the framework fits together.

CHAPTERS 01–04 FoundationsThe challenge, the discipline and the management system.
01

The Confidence Challenge

Explores why access to information is not enough for confident action. Establishes the need to understand its origins, evidence, limitations and suitability for the decision at hand.

02

Enterprise Information Integrity

Defines information integrity in its enterprise context, bringing together meaning, provenance, quality, authority and purpose. Explains why technically accurate information can still be unsuitable for a particular use.

03

Introducing HCIIF™

Introduces HCIIF as a human-centric management system for establishing and sustaining justified confidence. Connects information integrity to organisational purpose, professional judgement, accountability and consequence.

04

Enterprise Information Integrity Management System (EIIMS)

Sets out how leadership, governance, planning, operation, assurance and improvement work together. Explains how to embed HCIIF proportionately within existing organisational structures and capabilities.

CHAPTERS 05–09 Assessment and lifecycleEstablishing, communicating and maintaining confidence.
05

Enterprise Confidence Assessment Methodology (ECAM)

Explains the evidence-led methodology for assessing confidence for a defined purpose. Makes strengths, limitations, contradictions and professional judgement visible through an explainable Confidence Basis.

06

Information Integrity Passport (IIP)

Introduces the governed, traceable representation of an information asset’s integrity context. Shows how purpose, provenance, confidence, rights, caveats and history remain available to authorised users.

07

Enterprise Confidence Management

Explains how confidence is monitored, challenged and maintained as information and circumstances change. Connects reassessment, emerging gaps, drift, intervention and escalation to proportionate organisational action.

08

Enterprise Information Assets

Identifies the information that warrants deliberate integrity management because of its value, sensitivity, dependencies or consequences. Helps organisations focus assessment and assurance where reliance matters most.

09

Confidence Lifecycle Management (CLM)

Follows confidence through information creation, use, transformation, transfer and retirement. Explains when scheduled reviews, events and exceptions should trigger reassessment or action.

CHAPTERS 10–13 Governance and enablementRights, assurance, technology and accountability.
10

Information Rights, Visibility, Caveats and Confidence Transfer

Distinguishes justified confidence from permission to access, use or share information. Examines how rights, restrictions and context accompany information, while recipients remain accountable for their own reliance.

11

Continual Assurance, Assurance Intelligence and Predictive Governance

Explains how ongoing assurance evidence becomes insight into patterns, trends and emerging weaknesses. Connects that intelligence to proportionate governance responses and earlier attention to material risks.

12

Enterprise Confidence Enablement Layer (CEL)

Describes the technology-neutral architecture that brings confidence context into existing systems, workflows and AI capabilities. Makes governance information available where people and technologies rely upon information.

13

Enterprise Confidence Operating Model

Sets out responsibilities for ownership, assessment, decisions, acceptance of uncertainty and escalation. Separates evidence-led confidence judgements from the authority to act, within a federated operating model.

CHAPTERS 14–17 Adoption and enterprise valueImplementation, measurement, decisions and change.
14

HCIIF™ Adoption, Maturity and Continual Improvement

Shows how to begin with a defined organisational need, assess existing capability and prioritise improvements. Treats maturity as demonstrated effectiveness and sustainable practice, supported by learning and proportionate adoption.

15

HCIIF™ Measurement, Performance and Enterprise Value

Explains how to measure changes in capability, reliance and organisational outcomes. Connects those changes to benefits and enterprise value while distinguishing HCIIF’s contribution from unsupported claims of causation.

16

HCIIF™ Information-Led Decision-Making and Organisational Direction

Explores how leaders use integrity evidence to govern consequential decisions, investment and organisational direction. Makes rights, caveats, confidence, consequences and decision authority explicit.

17

Transformation, Integrity Continuity and Confidence Recovery

Examines how to preserve integrity context through migrations, organisational change and disruption. Explains how to operate under degraded conditions and re-establish justified confidence during recovery.

CHAPTERS 18–20 AI and the connected enterpriseResponsible reliance across technologies and organisational boundaries.
18

HCIIF™ and Trusted AI Enablement

Applies HCIIF before, through and after AI reliance, including source information and derived outputs. Explains why confidence in inputs does not automatically establish confidence in AI-generated information.

19

Operating and Sustaining HCIIF™

Brings the capabilities together as a sustained enterprise management system. Distinguishes implementation, effectiveness and maturity, and examines what is needed to keep HCIIF operating within an agreed scope.

20

Trusted Information in the Connected Enterprise

Draws together the framework’s implications for information moving across organisations, suppliers, sectors and national boundaries. Returns to the central question: what confidence is justified, under what conditions, and for which intended use?

Summaries reflect the Enterprise Edition currently undergoing peer review.

FROM PRINCIPLES TO RELIANCE

HCIIF in practice.

Three illustrative scenarios show how information integrity affects decisions across commercial, international and healthcare settings.

ILLUSTRATIVE SCENARIO Supplier readinessCan we rely on this supplier-readiness report?

Illustrative scenario

Can we rely on this
supplier-readiness report?

A service launch. Three critical suppliers. One executive briefing that says everyone is ready.

The decision is real. Is the evidence sufficient?

An organisation is preparing to launch a new service. A consolidated report marks its critical suppliers as ready. An AI assistant summarises that report for the launch meeting: “All critical suppliers are ready for launch.”

But the consolidation has lost important qualifications. One supplier’s evidence relates to an earlier configuration. Another supplier’s readiness is conditional on an unresolved dependency. The executive summary presents a stronger conclusion than the evidence supports.

SUPPLIER A

Current evidence

Recent acceptance evidence covers the intended launch scope. Its source and accountable owner are identifiable.

SUPPLIER B

Changed configuration

The evidence predates a material configuration change. Applicability to the planned launch needs reassessment.

SUPPLIER C

Conditional readiness

The supplier’s report depends on an outstanding integration check. That condition is missing from the consolidated summary.

01

Define the information and intended reliance

The consolidated readiness report is identified as an Enterprise Information Asset, linked to its supporting supplier evidence. The intended use is the launch decision for a defined service scope and configuration. Required Confidence is established in that context, with attention to the consequences of disruption.

02

Assess what the evidence justifies

ECAM examines provenance, currency, scope, contradictions and limitations. The available evidence does not justify the blanket claim that all three suppliers are ready. This is a gap in the basis for reliance; it does not, by itself, prove that a supplier is unready.

03

Put the decision with the accountable authority

The leader considers whether to delay, narrow the launch or proceed with defined conditions. That judgement includes wider operational and risk evidence. Any permitted acceptance of reliance below Required Confidence is recorded within the relevant authority; it does not remove the Confidence Gap or override rights and restrictions.

04

Carry the context into AI summaries and later use

The briefing is corrected to retain the qualifications. Existing recipients are notified where their reliance may be affected. AI-generated summaries are assessed for their intended use; confidence in source material does not automatically transfer to a derived conclusion. New supplier evidence triggers review of the report, Passport and affected briefings.

What changes?

The launch discussion moves from an unexplained “ready” label to a visible basis for judgement: what is supported, what remains uncertain, what conditions apply and who can decide.

The intended benefit is earlier, better-informed action on uncertainty. No pilot results, measured savings or validated outcomes are claimed.

Explore the underlying chapters ↗
ILLUSTRATIVE SCENARIO Cross-border sharingTrusted by the sender. Suitable for the recipient?

Illustrative scenario

Trusted by the sender.
Suitable for the recipient?

The same assessment crosses a border. Its intended use changes. Does the original basis for reliance still apply?

From planning insight to operational action

An organisation shares a regional service-disruption assessment with an overseas partner to support contingency planning. It describes likely disruption over the coming month, with qualifications about incomplete source coverage and the period assessed.

The recipient later proposes using it to reroute a live service that day. A shortened internal briefing omits the source limitations and onward-sharing conditions. The original assessment remains unchanged, but the new decision needs more current and specific evidence.

ORIGINAL PURPOSE

Contingency planning

A regional assessment supports planning for possible disruption over a defined period. Its Confidence Basis is tied to that purpose and scope.

PROPOSED USE

A live operational decision

The recipient needs evidence about a specific service, location and time. That need is not automatically met by the broader assessment.

MISSING CONTEXT

Qualifications lost in summary

Incomplete source coverage, the assessment period and onward-sharing restrictions are absent from the briefing reaching the decision-maker.

01

Recover the source and sharing context

The recipient traces the briefing back to the original assessment and its supporting context. The information owner clarifies the purpose, assessment period, limitations and conditions of the original sharing. The shortened briefing is treated as a derived information product whose suitability also requires attention.

02

Separate permission from confidence

Authorised roles check whether the proposed use and any onward disclosure are permitted under the applicable agreements and requirements. Separately, the assessor considers whether the existing Confidence Basis applies to the operational decision and meets Required Confidence. Reliable information does not create permission, and permission does not establish sufficient confidence.

03

Choose a proportionate response

The recipient can seek current evidence, clarify sharing permissions, retain the assessment for its original planning purpose or escalate the operational decision. If action under uncertainty is permitted, the relevant authority records its rationale and conditions. Accepting uncertainty does not override a restriction on use or disclosure.

04

Maintain continuity across the boundary

The missing qualifications are restored to the internal briefing. If later evidence changes the assessment, material updates or recall notices reach authorised recipients and affected downstream users. Recipients review their reliance and derived products rather than assuming the previous position remains valid.

What changes?

The recipient can distinguish what the sender’s assessment supports, what the new decision requires and what use is permitted. Context becomes part of the exchange, not something left behind when the information moves.

This illustrative scenario demonstrates the intended use of HCIIF. It does not describe a real operation or claim validated outcomes.

Explore Chapters 9, 10, 16 and 20 ↗
ILLUSTRATIVE SCENARIO Healthcare information continuityIs the discharge information sufficient for safe onward care?

Illustrative scenario

A patient is ready to leave.
Is the information ready to travel?

Hospital, primary care and community services must rely on the same discharge information—but a late medication change has not reached every record.

The summary is complete. The position has changed.

A patient is being discharged from hospital with follow-up care provided by a GP and a community team. The electronic discharge summary contains the expected medication list, care instructions and follow-up arrangements.

Shortly before discharge, one medication is changed following a clinical review. The change appears in the prescribing system but not in the version of the discharge summary prepared for onward transfer. An AI-enabled summarisation tool reproduces the earlier list without identifying the difference between the source records.

DISCHARGE SUMMARY

Apparently complete

The document contains the expected fields and an identifiable author, but its medication content predates the final review.

PRESCRIBING RECORD

Later change recorded

A more recent entry records an amended medication decision, creating a material contradiction requiring resolution.

DERIVED SUMMARY

Context not carried forward

The generated summary repeats the earlier list without exposing its source version, timing or the conflicting record.

01

Define the intended reliance and consequence

The discharge information is identified as an Enterprise Information Asset supporting medication reconciliation, follow-up care and communication across organisational boundaries. Required Confidence reflects the potential consequence of relying on an incorrect or outdated medication position.

02

Establish what the evidence supports

ECAM examines provenance, timing, authority and consistency across the relevant records. The conflicting versions mean that the current discharge summary does not yet provide a sufficient basis for reliance on the medication list. This identifies a Confidence Gap for resolution by an appropriately authorised healthcare professional.

03

Resolve, communicate and govern the change

An authorised professional reconciles the records and confirms the current medication position. The discharge summary and its integrity context are updated, affected recipients are notified, and the correction is traceable to the source decision rather than silently overwriting the earlier version.

04

Assess every derived use

The AI-generated summary is treated as a separate information product. Its source, currency and intended use are assessed, and it is regenerated or corrected after reconciliation. Confidence in a source record is not assumed to transfer automatically to a derived output.

What changes?

Teams can distinguish a document that looks complete from information that is sufficiently current, consistent and authoritative for the intended care decision. The contradiction becomes visible early enough for accountable human resolution.

This illustrative scenario demonstrates the intended use of HCIIF. It does not provide clinical advice, describe a real patient or claim validated outcomes.

Explore Chapters 2, 6, 9, 10, 12 and 18 ↗

Deepak Sadasivan

Senior consultant. Strategic advisor.
Creator of HCIIF™.

Developed from more than 20 years of operational and consulting experience.

Deepak’s work spans enterprise data governance, international information sharing, risk, assurance and strategic transformation. Across operational environments and consulting engagements, one challenge has remained consistent: establishing sufficient trust and confidence in information to act upon it.

That experience led him to create HCIIF—bringing governance, evidence and human judgement together to strengthen enterprise information integrity.

START A CONVERSATION

What information does
your organisation rely on?

For enquiries about HCIIF, peer review, collaboration or potential pilots, please get in touch.

Contact