AI model cards for hospitals: what one must contain
A model card is the one-document answer to "show me this model." The fields a governance-grade card needs, and why a vendor datasheet is not one.
When a surveyor, a board member, or a plaintiff’s attorney says “show me this model,” the model card is the document you hand over. It is the complete story of one AI system in one place: what it is for, what it was approved at, who owns it, and what has been checked since.
Most hospitals do not have one for any system they run. The information exists — scattered across the vendor contract, an IT ticket, a validation email, and someone’s memory. A model card is the discipline of assembling it before anyone asks, because assembling it during a survey window is the thing that fails.
The fields a governance-grade card needs
Identity and ownership. System name, vendor and version in production, deployment status and go-live date, risk tier, and two named owners: an executive owner and a clinical owner. Titles, not names — titles survive turnover.
Intended use. What the system is for, in two sentences, and what it is explicitly not for. The second half matters more; scope creep is how approved tools drift into unapproved uses.
Context. Care settings, patient population (including exclusions), and what data goes in and what comes back out.
Human oversight. Who reviews outputs, when, and what they can override. If the system acts autonomously anywhere — scheduling, routing, drafting that auto-files — say exactly where, because that is the line surveyors and agent privileging both care about.
Known limitations. Populations, settings, or input conditions where performance degrades. A card with no limitations listed reads as a card nobody thought hard about.
Local validation. What was tested on your data before go-live, by whom, with what result. A vendor’s published performance is their card, not yours; case mix, documentation habits, and equipment differ, and this is the field a surveyor will ask about first.
Monitoring. The metrics watched, the review cadence, the thresholds that trigger escalation, and who owns the dashboard — including performance across demographic subgroups, since the headline number can stay green while one group’s performance slides.
Equity assessment. Performance across groups, disparities found, and the mitigation in place. “Not yet assessed” is an honest entry; silence is not.
One card per system, including the AI you did not buy
The inventory rule that catches organizations out: AI increasingly arrives as a feature enabled inside a release you already pay for, disclosed to an application analyst in release notes. If it produces a score, a ranking, or drafted text, it gets a card.
How this differs from a vendor datasheet
A vendor datasheet (and the CHAI applied model card work, which is aimed at vendors) describes the product as shipped. A hospital’s model card describes the product as deployed here — your population, your validation, your monitoring results, your owners. You need the vendor’s document as an input; it does not substitute for yours.
Building yours
Start by scoring your wider readiness with the free readiness assessment. The RUAIH Governance Artifact Pack includes the model card template and now the interactive Evidence Builder, which completes a card per system in the browser and exports board-ready documents. The full sequencing lives in the complete governance guide.
Published under the Institute's editorial standard.
Author: Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed against the standard on 2026-08-31.
Field list derived from the five focus areas of the Joint Commission's RUAIH certification announcement, the CHAI applied model card work, and hospital operational practice. No standards text is reproduced. Reviewed quarterly.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.