The NIST AI RMF Govern function is the part of the AI Risk Management Framework that decides whether the rest of it works. You can map AI use cases, measure model behavior and manage risks, but if nobody owns the policies, nobody is accountable and nobody is trained, those activities fade within a quarter. Govern is the function that keeps them alive.
This guide explains the six GOVERN categories, the 19 subcategories they contain, who should own each one and what evidence an auditor, customer or regulator will expect. It is written for compliance leads and AI program owners who need a practical plan, not a theory lecture. NIST has said that AI RMF 1.0 is being revised, so check the current text before you finalize your mapping.
Free gap assessment
How much of ISO 42001 could you evidence today?
Score every clause and Annex A control of the AI management standard, free, and see where the programme really sits.
Run the free ISO 42001 gap assessment → or View premium report sample
What the NIST AI RMF Govern function covers
The AI RMF, released by NIST on 26 January 2023, organizes AI risk management into four functions: Govern, Map, Measure and Manage. Govern is different from the other three because it is cross-cutting. It applies to all stages of the AI lifecycle and supplies the culture, policies and accountability that the other functions rely on.
In the framework text, Govern has six categories, GOVERN 1 through GOVERN 6, and 19 subcategories in total. The outcomes describe things the organization should have in place, such as policies for mapping, measuring and managing AI risk, defined accountability, workforce practices, a risk-aware culture, engagement with relevant AI actors and controls over third-party software and data. The Govern function does not tell you which tools to use; it tells you which outcomes to achieve.
For a wider view of how all four functions fit, read our overview of the NIST AI RMF and the NIST AI RMF Playbook.
GOVERN 1: policies, processes and practices
GOVERN 1 is the largest category, with seven subcategories. It expects your organization to have legal and regulatory requirements identified, trustworthy AI characteristics built into policies, a way to decide how much risk is acceptable and a process for reviewing and decommissioning systems. It also covers how often you review the program itself.
Practically, this means a written AI risk management policy, a risk tolerance statement approved by leadership, an AI system inventory and a lifecycle procedure that includes retirement. The trustworthy AI characteristics are the vocabulary your policy should use. The inventory feeds the AI risk register, which shows where risk sits.
Free AI risk assessment
Which of your AI systems could harm people, or you?
List your AI systems, models and data, pick from 38 AI risk scenarios, rate them for the people affected and for you, and plan treatment with ISO 42001 Annex A controls. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free AI risk assessment → or View premium report sample
A common gap here is the inventory. If you do not know which AI systems are in use, including embedded vendor features and employee use of public tools, every other control has holes.
GOVERN 2 and 3: accountability and workforce
GOVERN 2 asks that roles, responsibilities and lines of communication for AI risk are documented and that people are trained for them. The test is simple: can you name the person accountable for each AI system and show that they know it? Keep a role matrix, a charter for the governing committee and training records.
GOVERN 3 addresses workforce diversity, equity, inclusion and accessibility in AI risk decisions, including human oversight roles. Organizations interpret this differently, and the framework is under revision, so document what your organization actually does: how reviewers are chosen, how different perspectives are obtained and how oversight responsibilities are defined. Do not claim practices you cannot evidence.
| Category | Focus | Typical owner | Example evidence |
|---|---|---|---|
| GOVERN 1 | Policies, processes and practices | Risk or compliance lead | AI risk policy, risk tolerance statement |
| GOVERN 2 | Accountability structures | Executive sponsor | Roles, charter, training records |
| GOVERN 3 | Workforce diversity and accessibility in risk decisions | HR and AI lead | Team composition practices, review records |
| GOVERN 4 | Risk-aware culture | AI lead | Communication plans, feedback channels |
| GOVERN 5 | Engagement with relevant AI actors | Product owner | Stakeholder feedback log, consultation notes |
| GOVERN 6 | Third-party software and data risks | Procurement | Vendor assessments, contract clauses |
GOVERN 4 and 5: culture and engagement
GOVERN 4 concerns a culture that considers and communicates AI risk. Evidence includes policies that encourage raising concerns, documented challenge sessions, incident and near-miss reporting channels and records of decisions where risk changed the outcome. A culture claim without a record of someone saying no is hard to believe.
GOVERN 5 covers engagement with relevant AI actors, including affected communities, users and other stakeholders. Set up a feedback mechanism, log what you receive and show how it changed a design or a decision. For customer-facing AI, this may be a simple channel for reporting harmful outputs with a named owner and a response time.
GOVERN 6: third-party software and data
Most organizations use more AI than they build. GOVERN 6 requires policies and procedures for the risks that come from third-party software and data, including supply chain and intellectual property issues. Build this into procurement: due diligence questions, contract clauses, ongoing monitoring and exit plans.
Questions worth adding to every AI vendor review: what data trained the model, where is our data processed and retained, can our data be used for training, how are incidents communicated and what happens if the vendor is acquired or withdraws the service? For generative AI, pair this category with the generative AI profile.
How to implement the NIST AI RMF Govern function in 90 days
A workable first pass needs a small cross-functional group and a clear order of work. The steps below are a typical plan, not a guarantee; larger organizations take longer.
- Weeks 1 to 2: name an executive sponsor and form the governing group
- Weeks 2 to 4: inventory AI systems, including vendor and shadow AI
- Weeks 3 to 6: approve the AI risk policy and risk tolerance statement
- Weeks 5 to 8: define roles, training and escalation paths
- Weeks 6 to 10: add AI questions to procurement and vendor reviews
- Weeks 9 to 12: run a management review and record gaps and actions
Using templates for the NIST AI RMF Govern function
Governance produces documents: a policy, a charter, a role matrix, an inventory, a risk register, training material and vendor questionnaires. The NIST AI RMF Toolkit includes editable templates for these, so the team spends its time on decisions rather than formatting. See also our list of NIST AI RMF templates for what a complete set contains.
The framework is voluntary and there is no certification. If you want a certifiable management system, compare it with ISO 42001 vs NIST AI RMF. For regulatory context, see NIST AI RMF vs the EU AI Act. Always confirm the current version on the NIST AI Risk Management Framework page.
Evidence an assessor will ask for on the NIST AI RMF Govern function
Customers and auditors rarely ask whether you read the framework. They ask for proof that decisions were made and followed. Prepare a short evidence set: the approved AI risk policy with version history, the risk tolerance statement and the date leadership signed it, the current AI system inventory with an owner for every entry, the governing group charter and meeting minutes, training attendance and the vendor assessments for your most important AI suppliers.
Add examples of governance working in practice. One useful example is a proposed AI use case that was delayed, changed or rejected because of a risk review, together with the record of who decided and why. Another is an incident or complaint about AI output, how it was triaged and what changed afterward. Dated examples like these show that the policies are operating, which is what separates a living program from a binder on a shelf. Keep the evidence in one controlled location and refresh it on a fixed schedule, for instance every quarter, so you are never assembling it in a hurry when a customer questionnaire arrives.
Scaling governance to your organization size
A ten-person startup and a global bank will implement the same outcomes very differently. A small company may combine roles: one person acts as sponsor and risk owner, the inventory lives in a spreadsheet and the review happens monthly in a short meeting. A large company needs a committee, tiered approvals, automated inventory feeds and formal reporting to the board. Both can meet the outcomes if the roles are documented and the records exist. Choose the lightest structure that you can actually sustain, because a heavy process that nobody follows is worse than a light one that everybody does.
Common mistakes with the NIST AI RMF Govern function
The first mistake is writing a policy and calling it governance. Policies without owners, training and monitoring do not change behavior. The second is ignoring shadow AI: staff will use public tools unless you give them approved options and clear rules. The third is treating Govern as a one-time project. It needs a review cycle, and your risk tolerance should change as your use of AI changes.
A fourth is disconnecting Govern from measurement. If your policy sets a tolerance for bias or error but the Measure function never tests against it, the tolerance is decoration. Finally, avoid copying another organization’s statements. Regulators and customers ask for evidence, and only your own records will answer.
NIST AI RMF Govern Function FAQ
What is the NIST AI RMF Govern function?
It is the cross-cutting function of the AI RMF that establishes the policies, accountability, culture, engagement and third-party controls needed to manage AI risk across the lifecycle.
How many categories does Govern have?
AI RMF 1.0 lists six categories, GOVERN 1 to GOVERN 6, with 19 subcategories in total.
Is the Govern function mandatory?
No. The AI RMF is voluntary. Some organizations adopt it because customers, contracts or sector regulators reference it.
Who should own AI governance?
An executive sponsor should own it, with a cross-functional group covering legal, security, privacy, engineering and procurement, and named owners for each system.
Is the AI RMF being updated?
NIST states that AI RMF 1.0 is being revised under the White House AI Action Plan. Check the NIST page for the current version before you finalize your mapping.