What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Govern AI use as an ongoing company process, not a policy document that sits on a shelf. Assign an executive accountable for risk decisions, give legal, security, IT, privacy, procurement, HR, business and technical teams defined responsibilities, and require each AI use to be inventoried, assessed for its context and potential impacts, approved at the right level, monitored after launch and reviewed when it changes. NIST’s voluntary AI Risk Management Framework organizes this work into Govern, Map, Measure and Manage, with governance informing the other three functions.

Who should own AI governance?

One executive should be accountable for the company’s AI risk decisions, but no single department can govern every relevant risk alone. Legal and compliance can interpret obligations; privacy and security teams can assess data and technical safeguards; IT and technical teams can manage systems and integrations; procurement can examine suppliers; HR can address workforce uses; and business owners can explain the purpose, users and consequences of a particular deployment. The governing group should be able to escalate decisions to executives when a use exceeds the company’s risk tolerance.

For a smaller company, these responsibilities may be assigned to existing leaders rather than a new committee. A larger or more complex organization may need a standing cross-functional group. In either case, document who proposes a use, who assesses it, who approves it, who operates it, and who can pause or retire it. NIST’s AI RMF calls for documented roles, communication lines, executive accountability and resourcing for governance activities; its Govern function is intended to cut across the rest of the framework. NIST AI RMF Core

What should an AI policy cover?

A usable policy tells employees what they may do, what requires review, and what is not allowed. It should apply to AI features embedded in ordinary software as well as tools people access directly, and should cover both internally built systems and third-party services. Keep the rules specific enough to guide everyday decisions, with a route to ask questions before a use begins.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Purpose and boundaries: permitted business purposes, restricted or prohibited uses, and any required approval before a system is tested or deployed.
  • Data handling: what company, customer, employee or other sensitive information may be entered or processed, and which approved tools may handle it.
  • Human responsibility: when a qualified person must review an AI output or decision, and who remains accountable for the result.
  • Transparency and records: when users or affected people must be informed, and what decisions, evaluations or approvals must be documented.
  • Operations: how to report incidents, request exceptions, escalate concerns, and suspend or decommission a system.

Set the policy in light of applicable law, organizational values and the company’s tolerance for risk. The appropriate rule may differ by use: an internal drafting aid and a system that influences decisions affecting people do not necessarily warrant the same approval path. NIST recommends policies that address legal requirements, organizational values, risk tolerance and transparent risk processes. NIST AI RMF Core

How to put governance into operation

Use a lifecycle process that starts before deployment and continues while the system is in use. NIST describes risk management as continuous throughout an AI system’s lifecycle and uses four functions to organize it: Govern, Map, Measure and Manage. NIST AI RMF Core

  1. Set ownership and decision rights. Name the executive accountable for risk decisions and define the operating roles, approval authority and escalation route. Make clear who can approve, restrict, pause or reject a proposed use.
  2. Record the use in an inventory. Capture the system or supplier, model or tool where known, business owner, purpose, affected people, data, integrations, user groups, deployment status, risk tier, approvals and next review date. Include AI capabilities within purchased software, not only separately procured AI tools. Assign someone to keep each record current.
  3. Map context and potential impacts. Describe the intended purpose and foreseeable uses, who will use or be affected by the system, what data and dependencies it relies on, and the operating environment. Consider expected benefits, potential harms and important uncertainties. Use this picture to decide whether AI is appropriate at all and what additional evaluation or safeguards are needed.
  4. Choose checks and controls proportionate to the use. Before approval, define what acceptable performance means for this particular task. Depending on the context, that may involve task quality or accuracy, reliability, security, privacy, harmful-bias or fairness checks, robustness, human oversight and how failures will be handled. Set the required evidence and approval level according to potential impacts, organizational priorities and risk tolerance; no single checklist fits every use.
  5. Approve, document and prepare for operation. Record the decision, its conditions, the evidence reviewed, the accountable owner and any unresolved uncertainty. Give users role-appropriate training and explain when to question an output, escalate a problem or stop using the system.
  6. Monitor, review and retire. Track performance and incidents against the criteria set before deployment. Reassess after material changes to the model, tool, data, purpose or operating context, and review the governance process periodically. Keep human responsibilities clear and plan how to safely discontinue the system.

NIST’s Map function focuses on use context and potential impacts; its Measure and Manage functions support evaluating and addressing risks. The framework’s outcomes include inventory, training, ongoing monitoring, incident practices and decommissioning, with activity scaled to organizational priorities and risk tolerance. NIST AI RMF Core

How to make risk tiers useful

A company can use internal tiers to route work consistently, but should define them as a practical triage mechanism—not as legal categories or proof that a use is safe. Base the tier on context and plausible consequences, not just the model’s technical sophistication or the vendor’s description.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Lower-impact uses: routine assistance where a mistake is readily noticed and corrected and does not materially affect people or important business outcomes. A streamlined review may be proportionate.
  • Uses needing closer review: systems whose outputs influence consequential work, involve sensitive data, or are difficult for users to verify. Require a documented assessment and evidence for the relevant safeguards.
  • High-impact or uncertain uses: uses with potentially serious effects on people, substantial uncertainty, or limited ability to detect and remedy errors. Escalate to senior decision-makers; the company may require stronger independent review, restrict the use, or decline it.

These tiers are an example of an internal operating model, not a universal classification. The company should define its own triggers and approval requirements, then check applicable jurisdictional and sector-specific obligations separately.

How to govern vendors and third-party AI

Buying a tool does not transfer the company’s responsibility for deciding whether and how to use it. Before approval, examine the provider’s terms, data handling, security, model-change practices, incident notifications, support, subcontractors, intellectual-property considerations and service continuity. Establish how the company will be informed of changes that could affect an approved use.

For suppliers whose failure could materially disrupt a high-risk use, define contingency and exit plans: who decides to suspend use, what alternative process is available, and how data or records will be handled when the relationship ends. NIST’s Govern outcomes address third-party software and data risks, intellectual-property risks and contingency planning for high-risk supplier incidents. NIST AI RMF Core

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which frameworks can help?

Frameworks can structure governance work, but they do not replace legal analysis or make a company compliant by themselves. Select a reference based on whether the company needs a risk-management framework, governing-body guidance or a management-system approach, and consider its use cases, sectors, locations, expertise and assurance goals.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reference What it is useful for Important qualification
NIST AI Risk Management Framework A voluntary framework for incorporating trustworthiness and managing AI risks across design, development, use and evaluation. Its four functions are Govern, Map, Measure and Manage. NIST says the framework is voluntary. Its AI RMF 1.0 is described on the NIST page as under revision; check that page for current status before adopting a version-specific implementation.
NIST Generative AI Profile NIST-AI-600-1, released July 26, 2024, identifies risks particular to generative AI and proposes actions organizations can align with their goals and priorities. It supplements risk-management work; do not assume it is the latest or final generative-AI guidance without checking for subsequent releases.
ISO/IEC 38507:2022 Guidance for governing bodies and other stakeholders on enabling and governing organizational AI use. ISO lists it as applicable to organizations of any size and current and future AI uses. It is governance guidance, not proof that following it alone satisfies applicable law or produces a particular certification.
ISO/IEC 42001 A management-system reference to investigate when a company wants a formal AI management-system approach. NIST’s AI RMF resources page lists a crosswalk between it and the NIST framework. The cited resource does not establish certification requirements, costs or whether certification is suitable for a particular organization.

NIST released AI RMF 1.0 on January 26, 2023. ISO lists ISO/IEC 38507:2022 as its first edition, published in April 2022. Those are publication dates, not evidence of adoption rates or effectiveness. NIST AI RMF ISO/IEC 38507:2022

Keep governance distinct from legal compliance

The AI RMF and ISO/IEC 38507 are guidance, not universal legal clearance. A company’s binding requirements depend on where it operates, its sector, the use case, the data involved and the people affected. Review those facts with qualified legal and compliance advisers, and check current regulator guidance before approving a deployment. Contracts and internal obligations may also apply independently of a voluntary framework.

Adopting a framework can give teams a shared process and documented evidence, but does not eliminate risk or establish compliance by itself. Use it alongside—not instead of—specific legal, contractual and operational review.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.