AI security control record
What it is
The AI security control record is the artifact that satisfies RUAIH focus area 2 — Effective data management — at the control level.
Who signs it
The chief information security officer.
A document without a signature is a draft. An assessor is checking that someone with authority put their name to it.
What an assessor asks for
Encryption, access controls, evidence of log review with a named reviewer, security assessments, and an exercised incident response plan.
What goes in it
- Encryption in transit and at rest, covering inference endpoints and prompt logs
- Access controls and the review cadence for them
- Audit log review record with named reviewer and dispositioned exceptions
- Security assessment schedule and most recent result
- Incident response plan naming AI-specific failure modes
- Evidence the plan has been exercised
The most common failure
AI systems assumed to be inside the existing security perimeter without anyone checking. Inference endpoints, prompt logs and vector stores frequently are not, and the SOC 2 report that covers the EHR says nothing about them.
Where this sits
See the RUAIH crosswalk for how this control maps across CHAI’s playbooks and the NIST AI RMF.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Specified from the published RUAIH focus areas and the September 2025 Joint Commission and CHAI guidance, plus the failure modes we see most often in practice.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.