Guides Can an AI vendor be RUAIH certified?
Guide

Can an AI vendor be RUAIH certified?

No. The Joint Commission certifies organisations, not products. What a vendor claiming certification is actually saying, and what to ask instead.

A sales deck arrives with a Joint Commission logo somewhere near the bottom and a line about being certified, or aligned, or ready. It is worth knowing exactly what that can and cannot mean, because the Joint Commission has been unusually direct about it and most of the confusion is downstream of people not having read the sentence.

The sentence, from the launch announcement of 1 June 2026: the certification “focuses on the safe, reliable, transparent, and ethical use of AI by healthcare organizations” and “does not validate or certify individual AI products or tools.”

So, no. No AI vendor can be RUAIH certified. There is no product-level version of the certification to hold.

What RUAIH certifies instead

The organisation. The Joint Commission describes RUAIH as a voluntary certification programme recognising organisations in the United States that demonstrate they have the governance, safeguards, monitoring processes and education in place to use AI responsibly in healthcare settings. The published eligibility criteria are written around the applying organisation and its governance structure, and the Joint Commission states that certification is awarded at the organisation level.

That framing has a consequence people miss. Buying well does not certify you, and buying badly does not disqualify you. What is assessed is how you decided, what you checked, what you wrote down, and whether the process operated. A health system running a mediocre tool with a full evidence trail is in a better position than one running an excellent tool it cannot account for.

The four claims you will actually see

None of these are defined terms in anything the Joint Commission has published. Reading them as though they were is the mistake.

“RUAIH certified.” This one is straightforwardly not available for a product. If you see it on a product page, it is either an error or a claim worth raising with the vendor in writing.

“RUAIH aligned” or “RUAIH ready.” Marketing language. It may reflect genuine work by the vendor, and it may reflect a slide. The way to tell is to ask what the product hands you, in file form, that goes into your evidence set.

“Supports your RUAIH certification.” Sometimes true and worth pursuing. Ask which of the five areas, and ask for the artifact rather than the assurance.

“Joint Commission compliant.” Products are not the subject of the certification, so this is a category error regardless of intent.

What follows is inference rather than published fact: the Joint Commission has not published a policy on how vendors may reference RUAIH in marketing, and its general position on use of its marks is that they are controlled. Treat vendor use of the name as a signal about the vendor’s diligence rather than as information about the product.

What to ask instead

The useful question is not whether a vendor is certified. It is what the vendor gives you that survives being asked about.

Ask for subpopulation performance, by which you mean how the model performs on the groups in your catchment rather than in the development set. Ask what happens to your data, specifically whether it trains the vendor’s model, what the retention terms are, and what deletion actually means on exit. Ask what monitoring output you receive, at what frequency, in what format, and whether you can see it without asking. Ask what happens when the model is updated, who tells you, and whether anything is revalidated. Ask what the contract says on the day the tool is wrong and somebody is harmed.

The full question set, and the artifacts each answer belongs in, is in the vendor AI disclosure request.

Log the refusals, not only the answers

This is the part almost nobody does, and it is the part that is most useful to you later.

Most organisations record the bias assessment they performed and the documentation they received. Very few keep a record of what they asked for and were refused. The second record is more valuable, both internally and to anybody assessing your process, because it demonstrates the diligence rather than the conclusion. A vendor who declined to provide subpopulation performance is a fact about your risk position, and it is a fact that disappears entirely if the only thing you file is what arrived.

Keep one row per question: the date, who was asked, what was requested, what came back, and whether what came back answered the question. Questions answered with a marketing document count as declined for this purpose. That log belongs in your risk and bias evidence, and it is the artifact that turns procurement into something you can account for.

The refusal log ships in the readiness starter pack alongside the question set it accompanies.

Where vendor evidence lands in your certification

Vendor material feeds your evidence set. It does not replace it. What the vendor supplies is an input to your risk and bias assessment, your data management position and your monitoring plan, all of which you own, sign and have to show operating.

How each of those controls maps across the Joint Commission’s five areas, the CHAI playbooks and the NIST AI Risk Management Framework is set out in the crosswalk. The five areas themselves, and the evidence each plausibly asks for, are in the certification requirements guide. The longer treatment of vendor diligence, including the chapter on what to do when the only vendor who will answer is not the one you want, is in the readiness guide.

What is not published

As at 7 August 2026 the element-level standards, the scoring method, the fee, the survey format and the recertification interval are not in the public record. Nothing on this page is derived from the standards manual, which is not available to us. Anybody presenting a vendor checklist as an extract from the standards is inferring it.

Disclosure

The Healthcare AI Institute is not affiliated with, endorsed by, or accredited by the Joint Commission or CHAI, and nothing here is official guidance from either body. The Institute takes no vendor sponsorship, holds no vendor equity and takes no referral fees. It has not tested, trialled, piloted or benchmarked any product, and no product is named or assessed on this page. This is not legal advice.

Questions people actually ask

Can an AI vendor be RUAIH certified?

No. The Joint Commission states that the certification focuses on the safe, reliable, transparent, and ethical use of AI by healthcare organizations, and that it does not validate or certify individual AI products or tools. There is no product-level version of RUAIH to hold.

What does RUAIH actually certify?

The organisation using AI, at the organisation level. The Joint Commission describes it as a voluntary certification recognising organisations that demonstrate they have the governance, safeguards, monitoring processes and education in place to use AI responsibly in healthcare settings.

A vendor told me their product is RUAIH aligned. Is that meaningful?

It is a marketing claim rather than a status, because no body confers it. Aligned, ready, compliant and supportive are not defined terms in anything the Joint Commission has published. Ask what specific evidence the product hands you for your own certification, and put the answer in writing.

Does buying a certified vendor help our own certification?

There is no certified vendor to buy, so the question does not arise in that form. What does help is a vendor who supplies subpopulation performance data, a clear contractual position on training data, and monitoring output you can actually read. Those feed your evidence, which is what is assessed.

Can a vendor get us certified?

No. Eligibility as published requires the organisation to have its own governance structure for AI oversight and established processes. A vendor can supply documentation that lands inside your evidence set, but the governance being assessed is yours and the signatures on it have to be yours.

Published under the Healthcare AI Institute editorial standard.

Written and reviewed against the standard by a physician-executive whose career spans three national healthcare systems. Last reviewed on 2026-08-07.

Written from the Joint Commission's launch announcement of 1 June 2026 and the published RUAIH certification page, both read in full on 7 August 2026. The Institute has not tested, trialled or benchmarked any product and names no vendor. Where the published material stops, the reasoning that follows is labelled as inference. Reviewed monthly until the standards manual is public.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.