Frameworks The RUAIH ↔ CHAI ↔ NIST Crosswalk Data governance and minimum necessary
Crosswalk control

Data governance and minimum necessary

The mapping

FrameworkWhere this control sits
Joint Commission RUAIHFocus area 2 — Effective data management
CHAI governance playbooksPlaybook 6 — Responsible data management and use
NIST AI RMFMAP

The artifact: Data use agreement and access policy

Who signs it: The privacy officer

What an assessor actually asks for

The data use agreement template and the executed agreement for every vendor in the register that touches PHI, with the five required clauses present.

Why the mapping is not obvious

The September 2025 guidance is unusually specific here and it is worth quoting into your own template: permitted uses, data minimisation, prohibition of re-identification, third-party obligations, and audit rights. Most standard vendor paper contains two of the five.

The most common failure

A BAA treated as sufficient. A BAA governs permitted use of PHI; it says nothing about re-identification, model training on your data, or your right to audit. Those are separate clauses and vendors do not volunteer them.

Where this sits in the whole map

This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Data use agreement and access policy.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.