Skip to main content
6 categories, 19 subcategories

GOVERN: The people, policies and culture that make the other three functions possible.

The complete GOVERN function of the NIST AI Risk Management Framework, every category and subcategory, verified against NIST AI 100-1 on August 25, 2026.

GOVERN is the cross-cutting function: it runs through everything else in the framework and never ends. It covers the policies, the accountability structures, the workforce, the culture, the outside feedback, and the third-party risk that decide whether the other three functions actually happen or just get talked about.

NIST puts it first on purpose. An organization that maps, measures and manages AI risk without governance is doing risk theater: the work exists, but nobody owns it, nobody is trained for it, and nobody answers for it.

GOVERN

GOVERN 1: Policies, processes and practices for managing AI risk are in place, transparent, and working

  1. GOVERN 1.1

    Legal and regulatory requirements involving AI are understood, managed and documented.

  2. GOVERN 1.2

    The characteristics of trustworthy AI are built into the organization's policies, processes, procedures and practices.

  3. GOVERN 1.3

    Processes decide how much risk management a system needs, based on the organization's risk tolerance.

  4. GOVERN 1.4

    The risk management process and its outcomes are set through transparent policies and controls tied to organizational risk priorities.

  5. GOVERN 1.5

    Ongoing monitoring and periodic review of the risk process are planned, with clear roles and a defined review frequency.

  6. GOVERN 1.6

    An inventory of AI systems exists and is resourced according to organizational risk priorities.

  7. GOVERN 1.7

    Processes exist to retire AI systems safely, in a way that does not increase risk or reduce trustworthiness.

GOVERN

GOVERN 2: Accountability structures put empowered, responsible, trained people in charge of AI risk

  1. GOVERN 2.1

    Roles, responsibilities and lines of communication for mapping, measuring and managing AI risk are documented and clear to the teams that hold them.

  2. GOVERN 2.2

    Personnel and partners are trained in AI risk management to do the duties their roles assign them.

  3. GOVERN 2.3

    Executive leadership takes responsibility for decisions about AI system risk.

GOVERN

GOVERN 3: Workforce diversity, equity, inclusion and accessibility are prioritized across the lifecycle

  1. GOVERN 3.1

    Decisions about AI risk are informed by a diverse team: demographics, disciplines, experience, expertise and backgrounds.

  2. GOVERN 3.2

    Policies define and differentiate human roles in human-AI configurations and oversight of AI systems.

GOVERN

GOVERN 4: Teams are committed to a culture that considers and communicates AI risk

  1. GOVERN 4.1

    Policies and practices foster critical thinking and a safety-first mindset in the design, development, deployment and use of AI.

  2. GOVERN 4.2

    Teams document the risks and potential impacts of the AI they build or use, and communicate those impacts broadly.

  3. GOVERN 4.3

    Practices enable AI testing, incident identification and information sharing.

GOVERN

GOVERN 5: Processes exist for robust engagement with relevant AI actors

  1. GOVERN 5.1

    Feedback from outside the team that built the system, about individual and societal impacts, is collected, considered, prioritized and integrated.

  2. GOVERN 5.2

    Adjudicated feedback from relevant AI actors is regularly incorporated into system design and implementation.

GOVERN

GOVERN 6: Policies address AI risks and benefits from third-party software, data and supply chains

  1. GOVERN 6.1

    Policies address third-party AI risks, including infringement of a third party's intellectual property or other rights.

  2. GOVERN 6.2

    Contingency processes handle failures or incidents in third-party data or AI systems deemed high-risk.

The other functions

GOVERN is a skill before it is a checklist

Reading the categories tells you what good looks like. The AI Governance program drills the calls themselves, and the credential shows an employer you made them under assessment.

Category and subcategory identifiers follow NIST AI 100-1 exactly; the wording is our plain-English paraphrase. Read the authoritative text in NIST AI 100-1. Not affiliated with or endorsed by NIST. Last verified: August 25, 2026.