The risk-tiering method
The mapping
| Framework | Where this control sits |
|---|---|
| Joint Commission RUAIH | Focus area 3 — Risk and bias reduction |
| CHAI governance playbooks | Playbook 5 — Risk and impact assessments |
| NIST AI RMF | MAP |
The artifact: Intake and risk-tiering procedure
Who signs it: The AI governance committee chair
What an assessor actually asks for
The written rule, and the tier assigned to every entry in the register. A method applied to two tools and not the other forty is not a method.
Why the mapping is not obvious
RUAIH asks for a risk-based approach in two separate areas — risk and bias reduction, and monitoring cadence — which means the tiering method is load-bearing twice. Get it wrong and both areas fail together. Tier on two axes: proximity to a clinical decision, and consequence of error.
The most common failure
Tiering by vendor size or contract value rather than by clinical proximity. A cheap tool that touches triage outranks an expensive one that schedules rooms, and procurement instinct gets this exactly backwards.
Where this sits in the whole map
This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Intake and risk-tiering procedure.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.