Frameworks The RUAIH ↔ CHAI ↔ NIST Crosswalk The organizational AI policy
Crosswalk control

The organizational AI policy

The mapping

FrameworkWhere this control sits
Joint Commission RUAIHFocus area 1 — Governance
CHAI governance playbooksPlaybook 1 — Organizational AI policy
NIST AI RMFGOVERN

The artifact: Organizational AI policy

Who signs it: The policy committee that approves clinical and administrative policy

What an assessor actually asks for

The approved policy with a date inside the last twelve months, the approving body named, and the version history. A policy without a governing-body approval record is a draft with formatting.

Why the mapping is not obvious

CHAI’s policy playbook and RUAIH’s governance area both want a policy, but the September 2025 guidance is more specific than either: review, implementation, use, ethical standards, safety protocols, data use, privacy and equitable access. A policy that covers procurement and security but is silent on equitable access is incomplete against the guidance even though it reads complete.

The most common failure

A policy written for enterprise software with “AI” inserted. The test is whether it says anything that would not also be true of a new billing system. If not, it does not govern AI.

Where this sits in the whole map

This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Organizational AI policy.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.