Frameworks The RUAIH ↔ CHAI ↔ NIST Crosswalk Third-party and vendor due diligence
Crosswalk control

Third-party and vendor due diligence

The mapping

FrameworkWhere this control sits
Joint Commission RUAIHFocus area 3 — Risk and bias reduction
CHAI governance playbooksPlaybook 7 — Third-party management
NIST AI RMFGOVERN
HTI-1HTI-1 source attributes are the disclosure a vendor should already be able to produce

The artifact: Vendor AI disclosure request and completed questionnaire

Who signs it: Supply chain, counter-signed by the AI committee

What an assessor actually asks for

A standard question set, answered in writing by the vendor, retained with the contract. Blank sections are themselves a finding.

Why the mapping is not obvious

CHAI gives third-party management its own playbook, which is a stronger signal than RUAIH’s structure suggests — vendor-supplied AI is most of the AI in a health system, so this control carries more weight than its single mapping implies. If HTI-1 applies to the tool, the source attributes are a disclosure the vendor should already be able to hand over; an inability to do so is diagnostic.

The most common failure

Sending the questionnaire after selection. Its value is as a discriminator between finalists, and a vendor who cannot answer it is telling you something you needed to know before the contract, not after.

Where this sits in the whole map

This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Vendor AI disclosure request and completed questionnaire.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.