Chapter 3 of 13
Govern: Building AI Risk Governance, Roles, and Policies
Policies and principles alone do not govern AI—people, processes, and evidence do. This module dives into the Govern function and shows how to stand up an AI risk governance structure that can actually steer decisions, not just decorate slide decks.
1. From Principles to Governance That Actually Bites
Zooming in on Govern
The NIST AI RMF has four functions: Govern, Map, Measure, Manage. This module zooms in on Govern, which is about how organizations actually steer AI risk, not just write principles.
What Makes Governance Real
Governance happens when people have clear roles and decision rights, there are documented processes for AI approvals and oversight, and the organization keeps evidence that those processes are followed.
Core Govern Themes
NIST Govern outcomes cluster around: 1) culture and leadership, 2) roles and accountability, 3) policies and risk appetite, 4) integration with enterprise risk and compliance, and 5) continuous improvement and documentation.
Regulatory Momentum
Since 2023, laws like the EU AI Act and the US AI Executive Order have made AI governance concrete: authorities now expect evidence of governance, especially for high-risk and foundation models.
Your Learning Goals
You will learn to map Govern outcomes to policies, charters, and role descriptions, and to sketch an AI governance structure with clear accountability and escalation paths.
2. Quick Map: NIST Govern Outcomes to Real Artifacts
Why Map Outcomes to Artifacts?
NIST Govern outcomes like GOV-1 and GOV-2 are abstract. To make them real, translate each into tangible artifacts: documents, records, or tools you could actually inspect in an organization.
GOV-1: Culture and Risk Frame
GOV-1 artifacts include: an AI & Data Ethics Principles document, a CEO- or board-signed AI risk statement, and training slides used in new-employee AI ethics onboarding.
GOV-2: Roles and Accountability
GOV-2 shows up as: an AI governance charter, updated job descriptions with AI risk duties, and a RACI matrix for decisions across the AI lifecycle.
GOV-3: Policies and Procedures
GOV-3 artifacts: an AI Use Policy, a Model Development Standard (documentation, testing, fairness checks), and a Third-Party AI Procurement Policy with due diligence.
GOV-4 & GOV-5: Integration and Improvement
GOV-4 and GOV-5 appear as AI entries in the risk register, an AI risk appetite statement, an AI incident log, periodic AI risk reports, and a model inventory with lifecycle status.
3. Micro-Exercise: Spot the Missing Artifact
Imagine a mid-size fintech company that heavily uses machine learning for credit scoring and is starting to roll out a GenAI assistant for customer support.
You are told they have:
- A glossy AI ethics principles page on their website
- A model inventory spreadsheet kept by the data science team
- A security policy that mentions "AI" once in a generic way
They do not have:
- Any AI-specific governance charter or committee
- Any AI risk appetite statement
- Any formal AI incident log
Your task (2–3 minutes):
- List two NIST Govern outcomes that are clearly underdeveloped here.
- For each, name one concrete artifact that would strengthen governance.
Use this structure in your notes:
- Underdeveloped outcome: ...
- Artifact to add: ...
When you are done, compare with this sample answer:
- Underdeveloped outcome: GOV-2 (roles, responsibilities, accountability)
- Artifact to add: An AI governance charter defining an AI Risk Committee, its decision rights, and membership.
- Underdeveloped outcome: GOV-5 (monitoring and improvement)
- Artifact to add: A central AI incident log where teams must record service outages, bias complaints, and unexpected model behavior.
4. Designing an AI Governance Structure: Committees and Lines
Three-Layer Governance Model
Most organizations use three layers: 1) Board/executives set AI strategy and risk appetite, 2) a central AI governance body makes cross-cutting risk decisions, and 3) product/engineering teams execute and manage models.
Board and Executives
The board or C-suite approves overall AI strategy and risk appetite, and receives AI risk and incident reports. They may have a dedicated Technology or AI Risk Committee.
Central AI Governance Body
An AI Risk Committee or Responsible AI Council is cross-functional. It approves high-risk AI use cases, sets policies and standards, and reviews AI incidents and escalations.
Distributed Team Roles
Product managers own user impact and business justification; ML engineers own technical testing and monitoring; domain owners (like Credit Risk Leads) own domain-specific risk judgments.
Using a RACI Matrix
A RACI matrix clarifies who is Responsible, Accountable, Consulted, and Informed for each AI decision, avoiding confusion and making escalation paths explicit.
5. Design-Your-Own: Sketch a Simple AI Governance Structure
Imagine you are advising a university hospital that wants to deploy AI for:
- Radiology image triage (high-risk clinical decision support)
- A GenAI chatbot for patient FAQs (medium risk)
They already have:
- A Clinical Governance Committee
- An Information Security team
- A Data Protection Officer (DPO) for privacy
Your task (3–4 minutes): Sketch a minimal AI governance setup using the three-layer model.
- Board / Executive layer
- Who at the hospital should be Accountable for AI risk overall (e.g., Chief Medical Officer, CIO)?
- Central AI Governance Body
- What should this body be called (e.g., "Clinical AI Oversight Committee")?
- Which existing groups or roles must be represented (e.g., radiology, IT, legal, DPO, patient safety)?
- Team level
- For the radiology AI, who is Responsible for:
- Model performance monitoring?
- Clinical validation and sign-off?
- For the GenAI chatbot, who is Responsible for:
- Reviewing training data and prompts for accuracy?
- Handling patient complaints and incidents?
Write your answers in a short outline like:
- Board layer: ...
- Central body: name, members, key decisions: ...
- Team level: radiology AI R/A, chatbot R/A: ...
If you are stuck, start by reusing existing committees instead of inventing new ones. For example, the Clinical Governance Committee could expand its charter to include AI.
6. Concrete Artifacts: Policy, Charter, and Role Snippets
AI Governance Charter Snippet
An AI Governance Committee charter defines purpose, scope, and responsibilities such as approving high-risk AI use cases, setting AI standards, reviewing incidents, and reporting to an Executive Risk Committee.
AI Use Policy Snippet
An AI Use Policy states acceptable uses of GenAI, bans high-risk uses without oversight, requires human review of outputs, and assigns duties like annual AI risk training and incident reporting.
Role Description Snippet
A Product Manager for AI features is tasked with AI risk assessments, complying with a Model Development Standard, presenting high-risk cases to the AI Governance Committee, and coordinating with Legal and Privacy.
Link Back to Govern Outcomes
These snippets operationalize Govern outcomes: GOV-2 (clear responsibilities), GOV-3 (policies and procedures), and GOV-4 (integration with enterprise risk reporting). Even simple one-page docs can be powerful.
7. Quick Check: Roles and Decision Rights
Test your understanding of AI governance roles and decision rights.
Which of the following best illustrates a **clear accountability structure** for high-risk AI systems, aligned with the NIST Govern function?
- Data scientists decide when to deploy models, and executives are only informed if something goes wrong.
- A cross-functional AI Governance Committee approves high-risk AI deployments, with a named executive accountable and product teams responsible for implementation.
- Each team creates its own informal AI rules; as long as there is a model inventory, no further structure is needed.
- The organization publishes AI ethics principles on its website but leaves all decisions to vendor default settings.
Show Answer
Answer: B) A cross-functional AI Governance Committee approves high-risk AI deployments, with a named executive accountable and product teams responsible for implementation.
Option B describes a cross-functional committee with defined approval authority and a named executive accountable, while product teams are responsible for implementation. This matches NIST Govern outcomes around roles, responsibilities, and decision rights. The other options lack clear accountability or rely only on principles.
8. Flashcards: Key Govern Terms
Flip the cards (mentally) to review core terms related to AI governance.
- AI Governance (in NIST AI RMF)
- The set of organizational structures, policies, processes, and practices that establish oversight of AI risk, define roles and responsibilities, and integrate AI risk into enterprise risk management.
- Govern Outcomes (e.g., GOV-1 to GOV-5)
- A group of outcomes in the NIST AI RMF describing what effective AI governance looks like, including culture, roles and accountability, policies and procedures, integration with ERM, and continuous improvement.
- AI Governance Charter
- A document that defines the purpose, scope, membership, and decision rights of a central AI governance body such as an AI Risk Committee or Responsible AI Council.
- Risk Appetite (for AI)
- The amount and types of AI-related risk (e.g., accuracy, bias, explainability, security) an organization is willing to accept in pursuit of its objectives, often documented and approved by senior leadership.
- RACI Matrix
- A tool that clarifies who is Responsible, Accountable, Consulted, and Informed for specific AI lifecycle decisions, helping to avoid confusion and define escalation paths.
- AI Incident Log
- A structured record of AI-related failures, complaints, or unexpected behaviors (e.g., harmful outputs, bias, outages), used for monitoring, remediation, and continuous improvement.
Key Terms
- EU AI Act
- A comprehensive European Union regulation on artificial intelligence, adopted in 2024, that imposes obligations on providers and deployers of AI systems, especially high-risk and foundation models, including governance and risk management requirements.
- NIST AI RMF
- The National Institute of Standards and Technology Artificial Intelligence Risk Management Framework, released in 2023, which provides a voluntary framework for managing AI risks across four functions: Govern, Map, Measure, Manage.
- Govern Function
- One of the four core functions in the NIST AI RMF, focused on establishing organizational structures, policies, and processes to oversee and manage AI risks.
- Model Inventory
- A maintained list or database of AI and machine learning systems in an organization, typically including purpose, owner, risk level, and lifecycle status.
- AI Governance Committee
- A cross-functional group (e.g., AI Risk Committee or Responsible AI Council) that oversees high-impact AI use cases, approves policies and standards, and reviews AI incidents.
- Risk Appetite Statement
- A formal document approved by senior leadership that describes the level and types of risk an organization is willing to accept, including specific considerations for AI systems.
- Enterprise Risk Management (ERM)
- An organization-wide approach to identifying, assessing, and managing risks across different domains (financial, operational, technology, compliance), into which AI risk should be integrated.