RUAIH RUAIH focus area 3 — Risk and bias reduction
RUAIH focus areas

RUAIH focus area 3 — Risk and bias reduction

The short answer. Area 3 holds three controls: a risk-tiering method that classifies every AI system by potential patient harm at intake, local bias assessment that examines equity on your population rather than the vendor's, and vendor due diligence that converts marketing claims into written, keepable answers.

Area 3 is where governance meets the uncomfortable questions: how much harm could this thing do, is it fair here, and did the vendor answer in writing?

The three controls

Risk-tiering method. A written procedure that classifies AI at intake by potential patient harm — so a documentation assistant and an autonomous triage model get governance proportional to their stakes. Evidence: the intake and tiering procedure, applied to the inventory — and where the tier is genuinely contested, as it is for ambient documentation, the method is what gets sampled rather than the answer.

Bias assessment. Equity examined on your population. Vendor fairness numbers describe the vendor’s data; case mix, demographics and documentation habits shift performance across sites, so the assessment that counts is local. Evidence: the completed local assessment, subgroups named.

Vendor due diligence. AI-specific questions put to third parties, answered in writing: training data provenance, subgroup performance, update and retraining cadence, monitoring support. Evidence: the disclosure request and the completed questionnaire — kept, because the vendor’s answers become your baseline when their model changes under you.

The thread through all three

Each control converts something vague into something datable: “we considered risk” becomes a tier with a method behind it; “the vendor says it’s fair” becomes a local measurement; “we trust our vendors” becomes a questionnaire with a signature. Surveyors sample the datable kind. The readiness score will tell you which of the three is your gap.

Asked alongside this

Why does bias assessment have to be local?

Because performance travels badly. A model fair on the vendor's development population can be measurably unfair on yours — different case mix, demographics, equipment, documentation habits. Only local measurement answers the question a surveyor would actually ask.

What counts as vendor due diligence for AI?

Written answers to AI-specific questions: training data provenance, known subgroup performance, update cadence, monitoring support. The completed questionnaire is the evidence — a claim in a sales deck is not.

Does every AI system need the same scrutiny?

No — that is the point of risk tiering. An ambient scribe and a sepsis predictor do not deserve equal governance; the tiering method is how proportionality gets defended in writing.

Where do you actually stand? The free RUAIH readiness score maps your organisation against the five focus areas in about eight minutes, and the published crosswalk shows how each control lands across RUAIH, CHAI and the NIST AI RMF.

← All RUAIH questions, areas and terms · The complete healthcare AI governance guide · Score your readiness