NIST AI RMF GOVERN 4
Teams talk openly about AI risk, test critically, and share what they find.
What NIST says
Organizational teams are committed to a culture that considers and communicates AI risk.
Category statement quoted from NIST AI 100-1 (AI RMF 1.0). Function: GOVERN, a culture of risk management is cultivated and present.
Evidence that shows you're doing it
- Documented review or red-team steps before release
- Incident and near-miss reporting that covers AI
- Internal guidance on raising AI concerns
Rate yourself
- Not done
- Ad hoc
- Defined
- Operating
- Measured and improving
The AI Governance Toolkit (Professional, $599) has the NIST AI RMF mapping workbook: maturity scoring, evidence, owners and next steps for every category, plus the ISO/IEC 42001 crosswalk.
Other GOVERN categories
- GOVERN 1: You have written, approved rules for how AI risk is handled, and people actually follow them.
- GOVERN 2: Named people own AI risk decisions, know it, and are trained for it.
- GOVERN 3: Decisions about AI risk draw on a range of backgrounds, skills and viewpoints, including people affected by the system.
- GOVERN 5: You collect and act on input from people outside the team: users, customers, affected groups and experts.
- GOVERN 6: AI you buy or build on (models, APIs, data, plugins) is covered by your policies and contracts.