5Q HEALTH
Governance as Infrastructure
Working tools · For organizations deploying AI

RUAIH Readiness Scorecard

A structured self-assessment of your organization's readiness for Joint Commission's Responsible Use of AI in Healthcare (RUAIH) certification — scored on evidence, not intention.

The moment

In mid-2026, the ground shifted. The Coalition for Health AI published consensus governance playbooks — four domains, thirty-six baseline controls, built by 150+ health AI leaders on the structure of ISO/IEC 42001. Days later, Joint Commission launched RUAIH certification on that foundation. The standard for responsible AI use in healthcare now exists, in writing, with a certification behind it.

Here is what most coverage missed: Joint Commission accreditation is not a prerequisite. Organizations compliant with applicable federal law — including CMS Conditions of Participation or Conditions for Coverage — may pursue it. That puts RUAIH within reach of community health centers, FQHCs, critical access hospitals, and rural systems. It also means the readiness gap between resourced and under-resourced organizations is now measurable. Measuring it is what this instrument does.

What the Scorecard measures

Thirty-four items across the five published RUAIH certification areas, each cross-referenced to the CHAI baseline controls and NIST AI RMF functions it exercises:

GovernancePolicy, oversight body, intake, escalation, shadow-AI posture
Effective Data ManagementData registers, AI-specific BAA/DUA provisions, de-identification, security frameworks
Risk & Bias ReductionRisk categorization, impact assessment, no-go conditions, subgroup performance
Monitoring & ValidationNamed owners, local validation, decision gates, vendor telemetry obligations
Transparency & TrainingRole-based training, NPP disclosure, patient transparency, incident reporting, whistleblower protections

How it scores

Every item is rated 0–3 on a maturity scale where the top score requires dated, producible evidence — because certification review rewards operational proof, not policy binders. Results roll into four bands:

Foundational governance is aspiration
Developing structures exist, evidence is thin
Defined targeted gaps, not structural ones
Certification-posture evidence-producing program
The dual-protection cap. Ten items are marked beneficiary-critical — patient transparency, incident reporting, escalation authority, whistleblower protections among them. A zero on any of them caps the overall band at Foundational, no matter the total. An organization is not "ready" for a responsible-use certification while a patient-facing safeguard is absent. That is the 5Q difference: every assessment protects the entity and the person the algorithm actually adjudicates.

Built for organizations the standards forgot to price for

What you receive

A facilitated administration of the Scorecard, a findings memo with per-area scores and band, a prioritized remediation map tied to specific controls, and a clear read on your distance from certification posture — delivered under 5Q's three-pass validation methodology with every finding confidence-rated.

Request a readiness assessment