RUAIH focus area 3 — Risk and bias reduction
Area 3 is where governance meets the uncomfortable questions: how much harm could this thing do, is it fair here, and did the vendor answer in writing?
The three controls
Risk-tiering method. A written procedure that classifies AI at intake by potential patient harm — so a documentation assistant and an autonomous triage model get governance proportional to their stakes. Evidence: the intake and tiering procedure, applied to the inventory — and where the tier is genuinely contested, as it is for ambient documentation, the method is what gets sampled rather than the answer.
Bias assessment. Equity examined on your population. Vendor fairness numbers describe the vendor’s data; case mix, demographics and documentation habits shift performance across sites, so the assessment that counts is local. Evidence: the completed local assessment, subgroups named.
Vendor due diligence. AI-specific questions put to third parties, answered in writing: training data provenance, subgroup performance, update and retraining cadence, monitoring support. Evidence: the disclosure request and the completed questionnaire — kept, because the vendor’s answers become your baseline when their model changes under you.
The thread through all three
Each control converts something vague into something datable: “we considered risk” becomes a tier with a method behind it; “the vendor says it’s fair” becomes a local measurement; “we trust our vendors” becomes a questionnaire with a signature. Surveyors sample the datable kind. The readiness score will tell you which of the three is your gap.
Asked alongside this
Why does bias assessment have to be local?
Because performance travels badly. A model fair on the vendor's development population can be measurably unfair on yours — different case mix, demographics, equipment, documentation habits. Only local measurement answers the question a surveyor would actually ask.
What counts as vendor due diligence for AI?
Written answers to AI-specific questions: training data provenance, known subgroup performance, update cadence, monitoring support. The completed questionnaire is the evidence — a claim in a sales deck is not.
Does every AI system need the same scrutiny?
No — that is the point of risk tiering. An ambient scribe and a sepsis predictor do not deserve equal governance; the tiering method is how proportionality gets defended in writing.
← All RUAIH questions, areas and terms · The complete healthcare AI governance guide · Score your readiness