NIST AI RMF GOVERN 1
You have written, approved rules for how AI risk is handled, and people actually follow them.
What NIST says
Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.
Category statement quoted from NIST AI 100-1 (AI RMF 1.0). Function: GOVERN, a culture of risk management is cultivated and present.
Evidence that shows you're doing it
- AI policy approved by leadership, with a review date
- List of laws, regulations and contract terms that apply to your AI use
- Records showing the policy is applied (for example, completed AI risk assessments)
Rate yourself
- Not done
- Ad hoc
- Defined
- Operating
- Measured and improving
The AI Governance Toolkit (Professional, $599) has the NIST AI RMF mapping workbook: maturity scoring, evidence, owners and next steps for every category, plus the ISO/IEC 42001 crosswalk.
Other GOVERN categories
- GOVERN 2: Named people own AI risk decisions, know it, and are trained for it.
- GOVERN 3: Decisions about AI risk draw on a range of backgrounds, skills and viewpoints, including people affected by the system.
- GOVERN 4: Teams talk openly about AI risk, test critically, and share what they find.
- GOVERN 5: You collect and act on input from people outside the team: users, customers, affected groups and experts.
- GOVERN 6: AI you buy or build on (models, APIs, data, plugins) is covered by your policies and contracts.