Calculators RUAIH readiness score
Free · takes about eight minutes

RUAIH readiness score

Twenty questions an assessor can ask, scored out of 60. Each one names the artifact you would have to hand over and the evidence test that separates a real control from a document nobody has run.

Score honestly. A policy nobody has run is a 2. A committee that meets but keeps no minutes is a 1. The point of the exercise is to find the gaps while they are still cheap to close.

1. Governance

1.1  AI governance committee charter

Named chair and members covering all seven expertise areas; a decision right that is actually exclusive; a stated cadence; minutes for the last three meetings.

1.2  Organizational AI policy

Approved and dated within twelve months. Covers review, implementation, use, ethical standards, safety protocols, data use, privacy and equitable access.

1.3  Board reporting record

At least one board or board-committee paper in the last twelve months reporting AI use and outcomes — not a technology update, an outcomes update.

1.4  Accountable executive, in writing

One named individual with appropriate technology expertise, with the accountability stated in a job description or charter — not an implied owner.

2. Effective data management

2.1  AI product registry

Every AI tool in the organisation, including those embedded in the EHR and those a department bought without telling anyone. Each entry names data touched, owner, risk tier and go-live date.

2.2  Data use agreement template and executed set

The template carries permitted uses, data minimisation, prohibition of re-identification, third-party obligations and audit rights. Executed for every vendor touching PHI.

2.3  Access control and audit log review record

Dated evidence that access logs for AI systems were actually reviewed, with the reviewer named and exceptions dispositioned.

2.4  Incident response plan covering AI failure

The plan names AI-specific failure modes — degraded output, an unavailable inference service, a silent vendor model update — and has been exercised.

3. Risk and bias reduction

3.1  Risk-tiering method, written

A rule that sorts tools by proximity to a clinical decision and consequence of error, applied to every entry in the registry — not to the two tools somebody worried about.

3.2  Model card or AI fact sheet per deployed tool

Intended use, training population, known limitations and reported performance by subgroup. Obtained from the vendor where one exists; written by you where it does not.

3.3  Local bias assessment on your own population

Performance broken out by the subgroups you actually serve, where lawful and available. Vendor-reported fairness on someone else’s population is not this.

3.4  Vendor due-diligence questionnaire, completed

A standard question set, answered in writing by the vendor, retained with the contract. Blank sections are themselves a finding.

4. Monitoring, evaluating and validating

4.1  Local validation study, pre-deployment

A written protocol and a result, on your data, for every tool in the top risk tier. A vendor’s published accuracy is an input, not a substitute.

4.2  Post-deployment monitoring plan with a named cadence

Metrics, thresholds, owner and review frequency, tiered by risk. A plan that says “monitored regularly” fails this row.

4.3  AI performance dashboard, in use

Someone looks at it on a schedule, and you can show what changed as a result at least once. A dashboard nobody reads is a 1.

4.4  AI safety event reporting route

A defined path for staff to report an AI-related safety event, wired into your existing incident system, plus a decision on external voluntary reporting with the route named.

5. Transparency, education and training

5.1  Patient disclosure standard

A written rule for when patients are told AI is involved in their care, what they are told, and how consent is handled where relevant — with the actual wording used.

5.2  Role-specific training, delivered

Completion records by role for every tool in the registry. Training that covers limitations and failure modes, not only how to click.

5.3  AI literacy programme and common terminology

A defined curriculum beyond tool training, and a published glossary so that “model”, “agent” and “automation” mean the same thing in every committee.

5.4  Training timed before go-live

Dated evidence that training preceded deployment for the last tool you implemented. Training delivered in week three is a finding.

Where should the gap report go?

We send the report and the weekly brief. One email, no sequence you cannot leave.

Independent: the Institute is not affiliated with or endorsed by The Joint Commission or CHAI.