In a five-person behavioral-health practice there is rarely a dedicated compliance officer or a standing AI governance committee. Decisions still have to be made, and those decisions still need to be explainable months later. The tool that made this possible for us was not sophisticated software. It was a one-page decision record that forced every AI-related choice into a short, consistent format.
This article shares the exact structure we used, why each section exists, and how the record functions as both a decision tool and a future audit trail. The goal is not perfection. The goal is a document that a busy practice can actually complete and later defend.
Why a One-Page Format Matters
Long policy templates look responsible until no one fills them out. In a small clinic the people who would write a ten-page risk assessment are the same people who answer the phones and cover lunch. A one-page record respects that reality. It is short enough to complete in a single meeting yet complete enough to answer the questions that surface later: Why did we approve this? What did we know at the time? Who owned the review steps?
The record sits in a shared folder and is updated whenever a pilot starts, changes, or stops. It is not a substitute for legal advice or a Business Associate Agreement. It is the practice’s own memory of its own reasoning.

The Five Sections of the Record
Our template contains five numbered sections. Each one is limited to a few lines of plain language.
1. Scope and Boundaries
State the exact workflow that is in scope and the items that are explicitly out of scope. Example: “In scope: generating a non-clinical internal checklist from three structured intake fields. Out of scope: any free-text clinical notes, patient-facing messages, or diagnostic language.”
Clarity here prevents quiet expansion. When someone later suggests “just adding one more field,” the written boundary is already visible.
2. Data That Will and Will Not Leave the Practice
List the specific data elements that will be processed by any external tool and the elements that will never leave the internal systems. This section forces the conversation about minimization before any login is created.
3. Human Review Points and Owners
Name the exact points at which a person must review the output and the role responsible for that review. Avoid vague language such as “staff will review.” Use role titles and specific actions: “Operations lead reviews the AI checklist for completeness before any patient message is drafted.”
4. Exception and Near-Miss Logging
Describe the single form or log that will capture problems, near-misses, and “we got lucky” moments. Include who is responsible for making the entry and how often the log is reviewed.
5. Stop Conditions and Authority
State who has authority to pause or end the workflow and under what conditions that authority will be exercised. This section turns an abstract governance principle into an operational fact.
How the Record Functions in Practice
We complete the record before any pilot begins. The completed page is stored with a clear file name that includes the date and the workflow name. When the pilot ends or changes, a short update is added at the bottom rather than creating a new document. The history remains visible on one sheet.
During staff training the record is the primary reference. New team members read the one page rather than a longer policy that may not match current practice. When a clinician who was not involved in the original decision asks why a particular tool is in use, the record supplies the answer without requiring a meeting.
The format also surfaces gaps early. If any of the five sections cannot be completed in clear language, the pilot does not start. That simple rule has prevented more problems than any sophisticated scoring system we considered.

Limits of the One-Page Approach
The record does not replace contracts, security questionnaires, or professional judgment. It does not make a practice compliant by itself. Clinical decisions and patient-facing documentation remain under appropriate review. The page is only as useful as the honesty with which it is completed. A record that papers over uncertainty is worse than no record at all.
We also learned that the physical or digital location of the document matters. If it lives in a folder that only one person can access, it fails its purpose. Shared access and a simple naming convention keep it usable when the original author is out of the office.
That’s a judgment call, not a tool question. The one-page AI decision record does not guarantee good outcomes. It does guarantee that the reasoning behind a decision remains visible long after the meeting ends. For a five-person practice, that visibility is the foundation of notes you can defend.
Slow is not the same as behind. Taking the time to fill out one clear page before testing begins has proven more valuable than rushing into a pilot with incomplete documentation.