The RUAIH ↔ CHAI ↔ NIST Crosswalk
Three bodies now describe what responsible healthcare AI looks like, and none of them maps to the others.
The Joint Commission’s Responsible Use of AI in Healthcare certification, released on 1 June 2026, organises its standards around five focus areas. CHAI published eight governance playbooks on 28 May 2026. NIST’s AI Risk Management Framework organises everything around four functions. The two bodies most likely to be quoted at your next board meeting — the Joint Commission and CHAI — have no incentive to publish a map to each other, and so far neither has.
This is that map. Fifteen controls, each one showing where it sits in all four frameworks, what artifact satisfies it, who signs that artifact, and the failure we see most often.
Why a crosswalk rather than a checklist
Because the frameworks disagree about what is hard.
CHAI gives organizational resources an entire playbook of its own. RUAIH does not name resourcing as a focus area at all — it sits inside governance. That asymmetry is informative rather than contradictory: CHAI’s playbooks are drawn from operators, and operators know the programme fails on resourcing first.
It runs the other way too. RUAIH treats monitoring, evaluating and validating as a single named area, which correctly signals that these stand or fall together. Read only the five RUAIH areas and you will miss that the September 2025 guidance underneath them lists voluntary, blinded reporting of AI safety-related events as its own element. Organisations working from the five-area summary alone miss it almost every time.
The crosswalk exists because the differences between the frameworks are where the work actually is.
The five RUAIH focus areas
- Governance
- Effective data management
- Risk and bias reduction
- Monitoring, evaluating and validating safety performance, effectiveness and responsible use
- Transparency, education and training
The certification is voluntary. It certifies the organisation, not individual AI products — it does not evaluate or certify any particular tool or use case — and an organisation does not need to be Joint Commission-accredited to apply.
The eight CHAI playbooks
- Organizational AI policy
- Organizational structure
- Organizational resources
- Responsible AI lifecycle management
- Risk and impact assessments
- Responsible data management and use
- Third-party management
- Education, training and feedback
The fifteen controls
Each control below has its own page with the full mapping, the artifact, the signature, and the failure mode.
| Control | RUAIH | CHAI | NIST |
|---|---|---|---|
| The AI governance committee | 1 | 2 | GOVERN |
| The organizational AI policy | 1 | 1 | GOVERN |
| The AI inventory and product registry | 1 | 4 | MAP |
| Board and executive reporting | 1 | 3 | GOVERN |
| Resourcing the governance programme | 1 | 3 | GOVERN |
| Data governance and minimum necessary | 2 | 6 | MAP |
| Data security controls for AI systems | 2 | 6 | GOVERN |
| The risk-tiering method | 3 | 5 | MAP |
| Bias and equity assessment | 3 | 5 | MEASURE |
| Third-party and vendor due diligence | 3 | 7 | GOVERN |
| Local validation before deployment | 4 | 4 | MEASURE |
| Post-deployment monitoring | 4 | 4 | MEASURE |
| AI safety event reporting | 4 | 4 | MANAGE |
| Patient disclosure and consent | 5 | 8 | GOVERN |
| Role-specific workforce training | 5 | 8 | GOVERN |
How to use it
If you are preparing for certification, work down the RUAIH column. Each control names the artifact an assessor asks for and who signs it. The gap is usually not the document — it is the record showing the document operated.
If you are building a programme from CHAI’s playbooks, work down the CHAI column and check the RUAIH column for what the playbook does not ask you to prove. CHAI describes the practice; RUAIH asks for the evidence.
If you already run a NIST-aligned risk programme, work down the NIST column. Most of your GOVERN function is already built; MEASURE is where healthcare-specific work concentrates, because local validation on your own population has no analogue in a general enterprise AI programme.
Start with the registry
If you do only one thing from this map, build the AI inventory. You cannot risk-tier, validate, monitor or train against an inventory you do not have, and every other control on this page assumes it exists.
Build it from your EHR vendor’s own feature list and two years of contracts rather than from what colleagues volunteer. The tool nobody remembers procuring is the one that arrived inside something else.
A note on what this is not
This is the Institute’s reading of published material as at July 2026. It is not the certification manual and it is not a substitute for it. Obtain the current standards directly from The Joint Commission before preparing a submission, and take your own professional advice.
The Healthcare AI Institute is not affiliated with, endorsed by, or working in cooperation with The Joint Commission, CHAI or NIST.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Authored control by control from the published RUAIH focus areas, the September 2025 Joint Commission and CHAI guidance, the CHAI governance playbooks released 28 May 2026, and NIST AI RMF 1.0. Reviewed on each framework revision; next scheduled review October 2026.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.