HITRUST Releases Industry's First AI Assurance Program
HITRUST released its AI Assurance Program, the industry's first certifiable approach to managing AI-related risks in regulated industries. Built on the HITRUST CSF (v11.2 at release) and aligned with ISO and NIST AI risk management guidance, the program allows organizations to integrate AI risk management dimensions into existing e1, i1, and r2 assurance reports, supports shared responsibility and inheritance models for AI service providers, and announced a forthcoming standalone AI security certification for deployed AI systems.
Key Analytics
Impact Analysis
Healthcare organizations and SaaS companies deploying AI/ML systems gained a path toward certifiable AI governance using a framework they already understood, extending existing HITRUST programs rather than building AI governance from scratch. The program has since matured into concrete offerings: the AI Risk Management Assessment (August 2024) provides 51 control requirements aligned to NIST and ISO/IEC standards, and the AI Security Assessment with Certification (November 2024) certifies deployed AI platforms against controls harmonized from NIST, ISO, and OWASP sources. CSF v11.4.0 (December 2024) further expanded AI coverage, including the OWASP ML Top 10. Organizations evaluating AI assurance should target these current offerings rather than the original program preview.
Recommended Actions
- Inventory all AI/ML systems and classify them by risk level per NIST AI RMF categories
- Assess current AI governance practices against the 51 controls in the HITRUST AI Risk Management Assessment
- Evaluate the HITRUST AI Security Assessment with Certification for deployed AI platforms, and designate an AI governance lead to scope the effort
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment of current AI governance against the 51 controls
- ›Risk classification of inventoried AI and ML systems per NIST AI RMF categories
- ›Certification path selection across the e1, i1, and r2 inheritance model
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 100 to 210 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.