Third-party and vendor due diligence
The mapping
| Framework | Where this control sits |
|---|---|
| Joint Commission RUAIH | Focus area 3 — Risk and bias reduction |
| CHAI governance playbooks | Playbook 7 — Third-party management |
| NIST AI RMF | GOVERN |
| HTI-1 | HTI-1 source attributes are the disclosure a vendor should already be able to produce |
The artifact: Vendor AI disclosure request and completed questionnaire
Who signs it: Supply chain, counter-signed by the AI committee
What an assessor actually asks for
A standard question set, answered in writing by the vendor, retained with the contract. Blank sections are themselves a finding.
Why the mapping is not obvious
CHAI gives third-party management its own playbook, which is a stronger signal than RUAIH’s structure suggests — vendor-supplied AI is most of the AI in a health system, so this control carries more weight than its single mapping implies. If HTI-1 applies to the tool, the source attributes are a disclosure the vendor should already be able to hand over; an inability to do so is diagnostic.
The most common failure
Sending the questionnaire after selection. Its value is as a discriminator between finalists, and a vendor who cannot answer it is telling you something you needed to know before the contract, not after.
Where this sits in the whole map
This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Vendor AI disclosure request and completed questionnaire.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.