The organizational AI policy
The mapping
| Framework | Where this control sits |
|---|---|
| Joint Commission RUAIH | Focus area 1 — Governance |
| CHAI governance playbooks | Playbook 1 — Organizational AI policy |
| NIST AI RMF | GOVERN |
The artifact: Organizational AI policy
Who signs it: The policy committee that approves clinical and administrative policy
What an assessor actually asks for
The approved policy with a date inside the last twelve months, the approving body named, and the version history. A policy without a governing-body approval record is a draft with formatting.
Why the mapping is not obvious
CHAI’s policy playbook and RUAIH’s governance area both want a policy, but the September 2025 guidance is more specific than either: review, implementation, use, ethical standards, safety protocols, data use, privacy and equitable access. A policy that covers procurement and security but is silent on equitable access is incomplete against the guidance even though it reads complete.
The most common failure
A policy written for enterprise software with “AI” inserted. The test is whether it says anything that would not also be true of a new billing system. If not, it does not govern AI.
Where this sits in the whole map
This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Organizational AI policy.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.