Evidence Organizational AI policy
Evidence library · RUAIH focus area 1

Organizational AI policy

What it is

The Organizational AI policy is the artifact that satisfies RUAIH focus area 1 — Governance — at the control level.

Who signs it

The policy committee that approves clinical and administrative policy.

A document without a signature is a draft. An assessor is checking that someone with authority put their name to it.

What an assessor asks for

The approved policy dated within twelve months, the approving body named, and version history.

What goes in it

  • Scope — what counts as AI for the purposes of this policy, stated so a reasonable person can classify a new tool
  • Review and approval pathway
  • Implementation and use standards
  • Ethical standards
  • Safety protocols
  • Data use and privacy
  • Equitable access
  • Roles and accountabilities
  • Review cycle and owner

The most common failure

A policy written for enterprise software with ‘AI’ inserted. The test: does it say anything that would not also be true of a new billing system? If not, it does not govern AI. The equitable-access section is the one most often missing entirely.

Where this sits

See the RUAIH crosswalk for how this control maps across CHAI’s playbooks and the NIST AI RMF.

The drafted version. This page specifies the artifact. The Governance Artifact Pack ships it already drafted, one per RUAIH focus area, with the source files so you can put your own name on it.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Specified from the published RUAIH focus areas and the September 2025 Joint Commission and CHAI guidance, plus the failure modes we see most often in practice.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.