Key Takeaways
- ·As of early 2026, The Joint Commission has not published formal AI survey standards. Surveyors are working AI governance questions into existing Leadership and Performance Improvement chapters.
- ·The JC/CHAI RUAIH guidance and independent legal analysis identify three core governance areas organizations need to be prepared to address: inventory (what AI tools you're using and who authorized them), validation (how you validated the tool on your patient population), and monitoring (how you know it's still performing well).
- ·Organizations that can't address these areas when they come up — from a board, during a survey, or in a litigation context — are already exposed. The governance gap matters now, before formal standards create formal consequences.
- ·The standard surveyors apply is not perfection. Organizations that demonstrate awareness, intentionality, and a credible monitoring posture are in a fundamentally different position than those that can't answer basic questions.
- ·If your CIO or CMO cannot answer the inventory, validation, and monitoring questions today, that is a gap worth addressing before your next survey.
The short answer
No formal Joint Commission AI survey standards exist as of early 2026. The JC/CHAI RUAIH guidance — released September 17, 2025 — establishes seven governance domains as the framework for what reasonable AI oversight looks like. The governance areas it emphasizes cluster around three themes: what AI tools your organization is using and whether leadership authorized them, how you validated those tools on your patient population, and how you know they're still performing well. Organizations that can't address these areas are exposed — to boards, to litigators, and to an accreditation trajectory that moves in one direction.
The Current State: Questions Without Formal Standards
As of early 2026, The Joint Commission has not published formal survey standards for AI governance. There are no checklist items, no scoring criteria, no defined deficiencies tied specifically to AI use. That hasn't stopped AI governance questions from surfacing during surveys.
The Joint Commission and CHAI released the RUAIH guidance in September 2025, establishing seven governance domains as the framework for what reasonable AI oversight looks like. The guidance is explicitly non-binding today. Multiple independent legal analyses — from Fenwick, Katten, and Health Law Diagnosis — confirm it's non-mandatory but consistently note that "alignment is likely to influence the industry" and that accreditation bodies "may expect alignment over time." The seven domains it covers — AI policy structures, transparency, equity, data security, quality monitoring, patient safety, and education and training — are the areas organizations need to be able to address clearly.
The practical implication is that preparation can't wait for formal standards. TJC and CHAI have outlined a three-stage roadmap from current advisory guidance to governance playbooks to a voluntary certification program. Organizations building governance posture now will be positioned ahead of that progression — not scrambling to respond when expectations harden into requirements.
The Three Question Categories
Inventory Questions
Questions to be prepared for:
- "What AI tools are you using?"
- "Which ones affect clinical decisions?"
- "Who authorized their deployment?"
- "Do you have a complete inventory?"
These questions assess whether leadership has visibility into the AI tools operating across the organization. The RUAIH guidance expects evidence that someone in a leadership role made a deliberate decision to deploy each tool — not just that IT or a clinical department implemented something that sounded useful. General awareness isn't sufficient. What the guidance describes is a formal inventory and a documented authorization process.
The inventory question is also harder to answer than most organizations expect. EHR-embedded AI features, AI capabilities added through vendor software updates, and tools deployed at the department level without central visibility are common gaps. Organizations that have only catalogued their explicitly-procured AI tools will likely give an incomplete answer.
Validation Questions
Questions to be prepared for:
- "How did you validate this tool on your patient population?"
- "What evidence do you have that it works as claimed?"
- "Did you rely solely on vendor data or conduct your own evaluation?"
Local validation is emphasized specifically because FDA clearance and vendor-supplied performance data are not sufficient on their own. An AI tool that performed well in the vendor's validation environment may not perform the same way in your clinical environment with your patient population. Surveyors want to understand whether the organization assessed that question, not just whether they reviewed the vendor's claims.
This is a harder question for most organizations, particularly for tools embedded in EHR systems where the deployment decision wasn't explicit. Answering it well requires documentation of your evaluation process, what evidence you reviewed, what limitations you identified, and how you decided to proceed.
Monitoring Questions
Questions to be prepared for:
- "How do you know this tool is still performing well?"
- "Who is responsible for tracking its accuracy?"
- "What would trigger a review or removal?"
These questions assess whether governance is ongoing, not a one-time deployment decision. The RUAIH guidance expects that someone has named responsibility for tracking tool performance and that there are defined triggers for escalation or removal. Absence of a documented monitoring process is one of the most common gaps surveyors identify, and it's one that creates compounding risk: if the tool's performance degrades and no one is watching, no one will catch it.
Surveyors also distinguish between tracking process metrics, such as how often an alert fires, and tracking clinical outcomes, such as whether patients flagged by the tool are actually developing the predicted condition. Outcome-based monitoring is more meaningful, and organizations that can demonstrate it are in a stronger position.
Beyond the Three Categories
Inventory, validation, and monitoring form the core. Surveyors also probe organizational structure more broadly, and the following areas have come up in simulation materials and field reports from more advanced surveys.
Bias assessment
Have you evaluated AI tools for disparate impact across patient populations? This is particularly relevant for tools that use demographic variables in their predictions or that were trained on populations that don't represent your patients.
Clinician training
Are staff trained on AI limitations, on when to question AI recommendations, and on how to report concerns? Surveyors may speak directly with clinicians, and clinical staff who have never been briefed on AI governance is itself a finding.
Incident reporting
Can staff report AI-related concerns through an established channel? Does that channel receive follow-up? The existence of a reporting mechanism, and evidence that it's used, is a meaningful differentiator.
Board visibility
Does the board receive AI governance reports? Does leadership have accountability for AI safety that reaches the governance level? The RUAIH guidance expects AI oversight to be embedded in organizational leadership structures, not delegated entirely to IT or a clinical committee.
Voluntary blinded safety reporting
The seventh JC/CHAI governance element calls for mechanisms to report AI safety events voluntarily and without attribution — modeled on aviation's safety reporting culture. This is an emerging expectation, not a current standard, but organizations building reporting channels now are ahead of where this is heading.
What Happens When You Can't Answer
When formal standards arrive, organizations with no documented governance posture will face a more difficult position than those who built structure early. But the risk isn't limited to future accreditation standards. A board that asks about AI governance today and receives no answer, or a plaintiff's attorney who establishes that an organization had no oversight process when an adverse event occurred, faces the same underlying gap. The absence of documentation is itself the problem.
The JC/CHAI guidance was released September 2025. Governance playbooks follow. A voluntary certification program follows that. At each stage, organizations that built posture early will be ahead — not explaining why they hadn't started yet.
The standard isn't perfection. Organizations that can demonstrate awareness of what they're running, intentionality about how they authorized and validated it, and a credible monitoring posture are in a fundamentally different position than those that can't answer basic questions. AI governance is still maturing. What boards, litigators, and accreditors are assessing is whether the organization is taking it seriously.
The Gap That Creates the Most Risk
Organizations that rely on vendor FDA clearance or vendor-supplied performance data as their complete validation answer are carrying a meaningful governance gap. FDA clearance establishes that a device is substantially equivalent to a predicate device. It doesn't establish that it performs well for your patients in your clinical environment. The RUAIH guidance expects local validation specifically because this distinction matters — and boards, litigators, and accreditors will ask whether the organization understood it.
Frequently Asked Questions
Common questions from healthcare executives preparing for Joint Commission surveys.
Are there official Joint Commission AI standards we need to comply with right now?
As of early 2026, The Joint Commission has not issued standalone AI-specific accreditation standards. There are no checklist items, no scoring criteria, and no deficiency categories tied specifically to AI. AI governance questions are surfacing under existing Leadership and Performance Improvement chapters. That will change. TJC has been developing AI-related guidance, and formal standards are expected in the coming years. Organizations building governance posture now will be better positioned when that happens than those waiting for formal standards before acting.
What is a 'notable deficiency' and how does it affect our accreditation?
A notable deficiency is a finding surveyors document when they observe a significant gap in an area not covered by a specific standard citation. It doesn't automatically trigger the same immediate consequences as a Requirements for Improvement finding, but it creates a record that follows the organization. If adverse events occur after a survey where an AI governance deficiency was documented, that record is relevant. It also flags the area for follow-up in subsequent surveys, meaning a gap that isn't addressed will be noted again.
What does 'local validation' mean when a surveyor asks about it?
Local validation means evidence that your organization assessed how an AI tool performs in your clinical environment, with your patient population, using your data. Vendor-supplied performance data and FDA clearance establish that a tool can work in some clinical settings. They don't establish that it works for your specific patient population. Surveyors are looking for documentation that your organization went beyond accepting vendor claims and conducted some form of independent evaluation, even if that evaluation was less formal than a full clinical trial.
What if we're using AI tools that our EHR vendor deployed without our explicit decision?
This is one of the harder questions organizations face. EHR-embedded AI tools, including predictive scores, documentation assistance, and clinical decision support alerts, may have been turned on by the vendor without a deliberate deployment decision on your side. Surveyors don't accept 'the EHR vendor did it' as a complete answer. Your organization is responsible for what's running in your clinical environment. Inventory those tools, understand what they're doing, and document any validation or monitoring you've conducted or are planning to conduct.
How should we prepare clinical staff for AI-related questions during a survey?
Staff should be able to describe the AI tools they use in their clinical workflows, explain generally how those tools inform rather than replace their clinical judgment, and know how to report concerns or anomalies. They don't need to be AI governance experts. But surveyors do speak directly with clinicians during surveys, and a clinical team that has never been briefed on the AI tools in their workflow is itself a governance gap that surveyors will note.
What documentation should we have ready before a Joint Commission survey?
A formal AI inventory listing tools in clinical use, their purpose, and who authorized deployment. Documentation of any validation work, including what evidence was reviewed, what limitations were identified, and how the deployment decision was reached. Evidence of ongoing monitoring, including who is responsible and what triggers a review or escalation. Records of governance committee meetings showing that AI oversight is active. Training records for clinical staff. The standard isn't a perfect governance program. It's evidence that governance is happening.
Sources
- Joint Commission / Coalition for Health AI (CHAI). Guidance on Responsible Use of AI in Healthcare (RUAIH). September 17, 2025.
- The Joint Commission. Leadership (LD) and Performance Improvement (PI) Accreditation Chapters.
- American Hospital Association. Joint Commission releases guidance for responsible use of AI in health care. September 2025.
- Katten Muchin Rosenman LLP. Analysis of JC/CHAI RUAIH Guidance. 2025.
- Fenwick & West LLP. Analysis of JC/CHAI RUAIH Guidance. 2025.
- Health Law Diagnosis. Joint Commission AI Guidance: What Health Systems Need to Know. 2025.
Related Questions
- ›What does Joint Commission AI guidance mean for my health system?
- ›How do we create and maintain an AI tool inventory?
- ›How should we document AI-assisted decisions in the medical record to protect against malpractice claims?
- ›How do we build an AI governance committee?
- ›What AI governance framework should a mid-size hospital adopt?

