The Rule Existed. The Institution Could Not Prove the Decision Followed It.
A rule can be legally binding, operationally relevant, and still fail to govern in a reconstructable way.
That is the continuity lesson in an August 2026 HHS Office of Inspector General audit of Arizona Medicaid managed-care organizations. Federal parity requirements govern how mental-health and substance-use-disorder services may be restricted relative to medical and surgical benefits. Yet two of three reviewed organizations did not perform the required annual analysis and could not demonstrate that their prior-authorization restrictions complied with those requirements. OIG also found Arizona's written compliance policies unclear and its oversight inadequate.
The important point is not simply that a compliance analysis was missing. The governing authority existed. Operational decisions continued. What was missing was the evidentiary path connecting the authority to those decisions.
Policy Is Not the Same as Governance
Organizations often treat publication of a rule as evidence that the rule governs. But governance is not established by the existence of policy alone. It is established when authority remains connected to evidence, context, decisions, actions, and records.
In the GovKM Continuity Topology, the relevant path is Authority → Evidence → Context → Decision → Action → Record. A parity requirement establishes authority. Comparative analyses provide evidence. The circumstances of the benefit and restriction supply context. Prior authorization is a decision process. Approval, denial, or additional requirements become actions. The institution then needs a record capable of showing that the governing rule actually traveled through the process.
When that evidence is absent, the organization may know what the rule says and know what decision was made while being unable to establish that the decision was governed by the rule.
Compliance Is a Relationship
This distinction matters well beyond Medicaid. Compliance is often discussed as a property of documents, systems, or organizations: compliant or noncompliant. Operationally, however, compliance is a relationship between authority and action, supported by evidence.
An institution needs to reconstruct which rule applied, which evidence was evaluated, which criteria were used, who or what exercised decision authority, what action resulted, and what record demonstrates the chain.
If any of those relationships disappear, a later auditor may find both the rule and the transaction but not the institutional proof connecting them.
Automation Does Not Repair a Missing Governance Path
This becomes especially consequential as organizations introduce AI into authorization, eligibility, claims, compliance, and case-management workflows.
An automated system can apply a rule rapidly and consistently. But if the institution has not defined the evidence required to demonstrate that the rule was properly applied, automation can accelerate an unreconstructable process. The organization may receive more decisions without gaining stronger governance.
AI therefore needs more than access to current policy. It needs governed relationships among policy authority, evidence, context, decision criteria, human or delegated authority, action, and record.
Authority Must Travel
The Arizona audit illustrates a foundational continuity principle: institutional authority is useful only when its application can be followed into operations.
A rule does not govern merely because it exists. It governs when the institution can reconstruct how that authority constrained a particular decision and action.
For organizations adopting AI, that is a practical architectural requirement. Before automating a governed decision, preserve the path that proves why the decision is institutionally legitimate.

