Frameworks The RUAIH ↔ CHAI ↔ NIST Crosswalk
Framework

The RUAIH ↔ CHAI ↔ NIST Crosswalk

Three bodies now describe what responsible healthcare AI looks like, and none of them maps to the others.

The Joint Commission’s Responsible Use of AI in Healthcare certification, released on 1 June 2026, organises its standards around five focus areas. CHAI published eight governance playbooks on 28 May 2026. NIST’s AI Risk Management Framework organises everything around four functions. The two bodies most likely to be quoted at your next board meeting — the Joint Commission and CHAI — have no incentive to publish a map to each other, and so far neither has.

This is that map. Fifteen controls, each one showing where it sits in all four frameworks, what artifact satisfies it, who signs that artifact, and the failure we see most often.

Why a crosswalk rather than a checklist

Because the frameworks disagree about what is hard.

CHAI gives organizational resources an entire playbook of its own. RUAIH does not name resourcing as a focus area at all — it sits inside governance. That asymmetry is informative rather than contradictory: CHAI’s playbooks are drawn from operators, and operators know the programme fails on resourcing first.

It runs the other way too. RUAIH treats monitoring, evaluating and validating as a single named area, which correctly signals that these stand or fall together. Read only the five RUAIH areas and you will miss that the September 2025 guidance underneath them lists voluntary, blinded reporting of AI safety-related events as its own element. Organisations working from the five-area summary alone miss it almost every time.

The crosswalk exists because the differences between the frameworks are where the work actually is.

The five RUAIH focus areas

  1. Governance
  2. Effective data management
  3. Risk and bias reduction
  4. Monitoring, evaluating and validating safety performance, effectiveness and responsible use
  5. Transparency, education and training

The certification is voluntary. It certifies the organisation, not individual AI products — it does not evaluate or certify any particular tool or use case — and an organisation does not need to be Joint Commission-accredited to apply.

The eight CHAI playbooks

  1. Organizational AI policy
  2. Organizational structure
  3. Organizational resources
  4. Responsible AI lifecycle management
  5. Risk and impact assessments
  6. Responsible data management and use
  7. Third-party management
  8. Education, training and feedback

The fifteen controls

Each control below has its own page with the full mapping, the artifact, the signature, and the failure mode.

ControlRUAIHCHAINIST
The AI governance committee12GOVERN
The organizational AI policy11GOVERN
The AI inventory and product registry14MAP
Board and executive reporting13GOVERN
Resourcing the governance programme13GOVERN
Data governance and minimum necessary26MAP
Data security controls for AI systems26GOVERN
The risk-tiering method35MAP
Bias and equity assessment35MEASURE
Third-party and vendor due diligence37GOVERN
Local validation before deployment44MEASURE
Post-deployment monitoring44MEASURE
AI safety event reporting44MANAGE
Patient disclosure and consent58GOVERN
Role-specific workforce training58GOVERN

How to use it

If you are preparing for certification, work down the RUAIH column. Each control names the artifact an assessor asks for and who signs it. The gap is usually not the document — it is the record showing the document operated.

If you are building a programme from CHAI’s playbooks, work down the CHAI column and check the RUAIH column for what the playbook does not ask you to prove. CHAI describes the practice; RUAIH asks for the evidence.

If you already run a NIST-aligned risk programme, work down the NIST column. Most of your GOVERN function is already built; MEASURE is where healthcare-specific work concentrates, because local validation on your own population has no analogue in a general enterprise AI programme.

Start with the registry

If you do only one thing from this map, build the AI inventory. You cannot risk-tier, validate, monitor or train against an inventory you do not have, and every other control on this page assumes it exists.

Build it from your EHR vendor’s own feature list and two years of contracts rather than from what colleagues volunteer. The tool nobody remembers procuring is the one that arrived inside something else.

A note on what this is not

This is the Institute’s reading of published material as at July 2026. It is not the certification manual and it is not a substitute for it. Obtain the current standards directly from The Joint Commission before preparing a submission, and take your own professional advice.

The Healthcare AI Institute is not affiliated with, endorsed by, or working in cooperation with The Joint Commission, CHAI or NIST.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Authored control by control from the published RUAIH focus areas, the September 2025 Joint Commission and CHAI guidance, the CHAI governance playbooks released 28 May 2026, and NIST AI RMF 1.0. Reviewed on each framework revision; next scheduled review October 2026.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.