AI Governance

GOVERN (NIST AI RMF)

The cross-cutting function of the NIST AI RMF focused on establishing and maintaining the organizational policies, processes, procedures, and practices needed for AI risk management. Unlike Map, Measure, and Manage — which apply to individual AI systems — GOVERN applies across the entire organization.

Why It Matters

GOVERN is the foundation that makes the other three functions possible. Without organizational commitment, clear roles, and established policies, system-level risk management efforts have no structural support.

Example

Under the GOVERN function, a company establishes an AI risk tolerance statement approved by the board, defines roles for an AI governance committee, creates a third-party AI risk policy, and implements AI-specific training for all business units.

Think of it like...

GOVERN is like a city's zoning laws and building department — the individual buildings (AI systems) get their own inspections, but GOVERN sets the rules, staffs the department, and ensures the whole system works.

Related Terms