AI for Government
Capable · M29 · lesson 29 of 43 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
NIST AI RMF: The GOVERN Function
📖
now learning

NIST AI RMF: The GOVERN Function

15 min

Learning Objectives

After completing this lecture, you will be able to:

  • Understand the key concepts of nist ai rmf: the govern function in a government context
  • Participate in structured workshop activities with real-world scenarios
  • Connect nist ai rmf: the govern function to your agency's AI initiatives
  • Identify next steps for applying these concepts in your role

Key Topics Covered

-
Organizational policies, roles, responsibilities, culture

-
Building governance from the ground up

-
Government context for nist ai rmf: the govern function

-
Practical applications and next steps

Why This Matters for Government

Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing analysts, project leads, team supervisors with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.

As part of the L2 (AI Practitioner) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding nist ai rmf: the govern function is essential for responsible, effective government AI adoption.

======================================================================

TRANSCRIPT: NIST AI RMF: The GOVERN Function

======================================================================

Chapter: 3

What you will learn:

  • The NIST AI Risk Management Framework (AI RMF 1.0) and its four core functions
  • The GOVERN function in detail: structure, policies, and organizational design
  • How to establish roles and decision rights within governance
  • Building governance maturity in your agency
  • Connecting GOVERN to OMB requirements and executive order directives

Welcome to L2: AI Ready, Chapter 3--the heart of practical AI governance. Over the coming modules, you'll learn how to implement the NIST AI Risk Management Framework in real government agencies. This lecture focuses on the GOVERN function, which is where everything starts.

Think of GOVERN as the foundational layer of responsible AI. Before you can map AI systems, measure their performance, or manage their risks, you need to establish who decides what, how decisions get made, what standards apply, and how accountability works. That's what GOVERN does. It's not sexy--it's often invisible--but it's absolutely foundational.

Many government agencies are learning this the hard way. They've deployed AI systems quickly, thinking governance can be bolted on later. Then problems emerge, and no one knows who's responsible. Escalations go nowhere. Decisions conflict with each other. Different parts of the agency are using AI in completely different ways. The lack of governance becomes the bottleneck that prevents responsible deployment.

This lecture will show you how to establish governance structures that actually work--structures that provide clear decision rights, create accountability, and enable responsible innovation. You'll see how to scale governance across small and large agencies. You'll understand how GOVERN aligns with OMB M-24-10 and the Executive Order on Safe, Secure, and Trustworthy AI. By the end, you'll be able to design a governance structure for your agency or unit that's both compliant and practical.

WHY THIS MATTERS FOR GOVERNMENT

In the private sector, companies can sometimes afford to move fast and break things. If an AI system misbehaves or produces unexpected outputs, the response is often to quickly fix it and move on. There's no formal accountability mechanism beyond lawsuits and regulation.

In government, the dynamics are fundamentally different. Government agencies operate under statutory authority. They serve citizens who can't opt out. They're subject to multiple levels of oversight--GAO audits, IG reviews, Congressional inquiries, Freedom of Information Act requests. They have explicit obligations around equity, due process, and administrative procedure.

This means government AI governance isn't optional. It's the structural foundation that allows AI to be deployed lawfully and responsibly. Without clear governance, agencies face multiple risks: legal liability if systems violate rights; political liability if systems fail publicly; operational liability if systems cause internal chaos; and ethical liability if systems harm communities.

The stakes are high. Clear, well-designed governance isn't bureaucratic overhead--it's the infrastructure that makes responsible innovation possible.

THE NIST AI RISK MANAGEMENT FRAMEWORK OVERVIEW

The NIST AI Risk Management Framework (AI RMF 1.0) is the foundational governance architecture for U.S. federal AI adoption. Adopted across multiple executive branch agencies and recommended to state and local governments, it provides a systematic approach to managing AI risks across the full lifecycle of AI systems.

The framework has four core functions:

GOVERN: Establish the organizational structures, roles, policies, and accountability mechanisms for AI governance. Answer: "How will we make AI decisions? Who decides? What standards apply?"

MAP: Identify and inventory all AI systems in your organization. Document what they do, what risks they pose, and how they fit into your mission. Answer: "What AI systems do we have? What are the key characteristics and risks?"

MEASURE: Systematically assess AI system performance, fairness, security, and other critical attributes. Use measurement data to understand whether systems are working as intended. Answer: "How is this system actually performing? Is it fair? Is it accurate? Are there emerging risks?"

MANAGE: Implement controls, mitigations, and adjustments based on measurement findings. Establish processes to respond to identified risks, retire systems that are no longer appropriate, and continuously improve. Answer: "What do we do when we find a problem? How do we prevent it from happening again?"

These four functions are not sequential. You don't do GOVERN once and then move on. Instead, they're cyclical. As your governance matures, it enables better mapping. Better mapping enables more sophisticated measurement. Better measurement enables more effective management. And throughout, you're refining your governance based on what you learn. The cycle repeats continuously.

This lecture focuses on GOVERN, but understanding that it's part of a larger cycle is essential. The governance structure you design should be sophisticated enough to support sophisticated measurement and management, but simple enough that people actually use it.

THE FIVE PILLARS OF AI GOVERNANCE

Effective AI governance has five core components. These aren't sequential steps--they're interconnected pillars that together create a functioning governance system.

Pillar 1: Organizational Structure

First, you need to establish the governance structure--the committees, boards, and roles that will make AI decisions. Most mature AI governance structures include some combination of:

  • AI Steering Committee or Executive Steering Group: Senior leadership (CIO, Chief Data Officer, agency leadership, policy teams) who set AI strategy and make high-level policy decisions. This is where resource allocation and strategic direction are determined.
  • AI Review Board or Governance Board: Cross-functional representatives who evaluate specific AI systems for compliance, fairness, and risk. This is where day-to-day governance happens. This board reviews impact assessments, approves deployments, and makes go/no-go decisions on specific systems.
  • Technical AI Review Committee: Engineers, data scientists, and architects who evaluate the technical feasibility and robustness of proposed AI systems. They assess whether the technical approach is sound, what dependencies exist, and what technical risks need to be managed.
  • Fairness and Ethics Review Board: Subject matter experts focused specifically on equity, fairness, and civil rights implications. As AI systems touch more citizens and influence more decisions, dedicated focus on fairness becomes critical.
  • Data Governance Committee: If your organization has one, this group establishes standards for data quality, data provenance, retention, and access. For many agencies, data governance is the foundation of responsible AI governance.
  • Incident Response Team: When problems with AI systems emerge, you need a clear incident response process. Who escalates? Who investigates? Who decides on remediation? This is often a subcommittee formed ad hoc when needed, but knowing the structure in advance is critical.

The specific structure depends on your agency's size and maturity. A small agency might combine several of these roles into one committee with multiple subcommittees. A large agency might have all of them plus additional specialized boards.

What matters is clarity. Every person in the organization should be able to answer: Where does my question about an AI system go? Who makes decisions about this? What's the timeline? Who do I escalate to if I disagree?

Pillar 2: Policies and Standards

The governance structure makes decisions, but what decisions? That's where policy comes in. Well-designed AI governance includes clear policies about:

  • AI Use Cases: What types of AI uses are permitted? What requires approval before deployment? What's explicitly forbidden?
  • Data Standards: What quality standards must data meet before it can be used in AI systems? What documentation is required? How do you verify data provenance?
  • Fairness Requirements: What constitutes acceptable fairness? How do you measure whether a system is fair? What happens if a system shows disparate impact?
  • Transparency Requirements: How much transparency is required? Do citizens need to know when they're interacting with an AI system? Must decisions be explainable?
  • Risk Tolerance: What level of risk is acceptable for different types of decisions? A high-risk system (one that determines benefits eligibility) might require more rigorous measurement and oversight than a low-risk system (one that ranks internal emails by importance).
  • Testing Requirements: What kinds of testing are required before deployment? Should systems be tested for adversarial robustness? For performance across demographic groups?
  • Human Oversight Requirements: For which decisions must humans remain in the loop? Which decisions can be fully automated? What override mechanisms exist?
  • Monitoring and Reporting: How often must systems be checked for degradation? What metrics are monitored? What triggers escalation?

These policies should be documented. They should be accessible to stakeholders. They should evolve based on learning. And critically, they should be designed to be actually implementable, not beautiful-in-theory but impossible-in-practice.

Pillar 3: Roles and Responsibilities

Clarity about roles is essential. Too often, governance fails because it's unclear who's actually responsible for what. "Someone should check this," but everyone thinks someone else is checking it. Robust governance is explicit about roles.

Key roles include:

  • Chief AI Officer or similar executive: Accountable for the organization's overall AI governance approach. Sets strategy, represents AI in leadership, advocates for governance investments.
  • AI Governance Officer: Manages day-to-day governance operations, scheduling reviews, collecting documentation, tracking decisions, ensuring follow-through.
  • Data Owner: For each dataset used in AI, someone is responsible for data quality, provenance, and appropriate use.
  • Model Owner: For each AI model in production, someone is responsible for its performance, monitoring, and maintenance.
  • Domain Expert: For each AI system, domain experts validate whether outputs make sense in context, whether the system captures the complexity of the decision, and whether there are known edge cases.
  • Fairness Lead: Someone responsible for evaluating fairness implications, commissioning fairness audits, and ensuring fairness concerns are addressed.
  • Security Lead: Someone responsible for evaluating cybersecurity and adversarial robustness.

For each role, you should document: What are they responsible for? What authority do they have? Who do they report to? What support do they need? What happens when they identify a problem?

Pillar 4: Decision Rights and Escalation Processes

Governance is most effective when decisions are made at the lowest possible level, but escalation is clear when a decision exceeds someone's authority or there's disagreement.

A robust decision rights framework answers:

  • What decisions can be made at the staff/team level? For example, refining a prompt or adjusting parameters within approved bounds might be a team-level decision.
  • What decisions require unit/department approval? Deploying a new AI system, changing a fairness threshold, or conducting an audit might require department-level approval.
  • What decisions require governance board approval? High-risk systems, systems that affect new populations, systems with new fairness implications might require board approval.
  • What decisions require executive approval? Setting AI strategy, allocating budget, committing to new policy directions--these likely require executive sign-off.
  • What's the escalation path when there's disagreement? If a team thinks a system is ready but a fairness reviewer disagrees, where does that go? Who has final authority?

Clear decision rights prevent gridlock (where everything requires consensus and nothing gets decided) and prevent rogue decisions (where individuals make major decisions without oversight).

Pillar 5: Accountability and Culture

Finally, governance only works if people are actually accountable. This means:

  • Decisions are documented. Who decided what, when, and based on what information. This creates a record and allows later review.
  • Accountability is assigned. Someone's responsible for each AI system. If it fails, they're responsible for understanding why. They're responsible for escalating and fixing.
  • There are consequences for cutting corners. If someone deploys an AI system without required reviews, there should be consequences. Not draconian ones, but real ones. Otherwise, governance becomes theater.
  • There are rewards for responsible practice. When people escalate concerns, when they slow down to do things right, when they design careful governance--those actions should be recognized and rewarded.
  • Culture supports governance. Leaders should communicate that governance is important, not something to minimize. Responsible practice should be valued. People should feel safe raising concerns.

This is often the hardest pillar to build, because it requires cultural change. But without it, even perfectly designed governance structures become bureaucratic obstacles that people work around.

GOVERNANCE MATURITY MODELS

Not all governance is created equal. Organizations progress through levels of governance maturity. Understanding these levels helps you assess where your agency is and where you want to go.

Level 1: Ad Hoc

  • No formal governance structure
  • AI decisions are made informally
  • There's no central awareness of what AI systems exist
  • Responsibility for ensuring responsible use is unclear
  • Policies are absent or purely aspirational
  • Risk management is reactive (problems emerge in production and are handled then)

Level 2: Initial

  • Basic governance structure in place (maybe one oversight committee)
  • Some AI systems are documented, but not all
  • Policies exist but are incomplete or not consistently applied
  • Some oversight process exists but is not fully staffed
  • Responsibility is beginning to be clarified
  • Risk management is emerging but still largely reactive

Level 3: Defined

  • Formal governance structure in place with clear roles
  • Governance processes are documented and communicated
  • Most AI systems are known and documented
  • Policies are clear and consistently applied
  • Impact assessments are required before deployment
  • Monitoring processes are established
  • Risk management is increasingly proactive

Level 4: Optimized

  • Mature governance structure with clear escalation and decision rights
  • All AI systems are tracked, monitored, and regularly reviewed
  • Policies are comprehensive and regularly updated
  • Fairness and equity are systematically assessed
  • Continuous improvement processes are in place
  • Risk management is predictive and data-driven
  • Governance integrates with broader enterprise risk management

Most U.S. federal agencies are currently at Level 2 or early Level 3. Many state and local governments are at Level 1 or 2. The most mature organizations (some large tech companies, some forward-thinking government agencies) are approaching Level 4.

Your agency doesn't need to jump directly to Level 4. Instead, the goal is to move progressively from your current state toward greater maturity. Each level builds on the previous. And there are real benefits at each stage: Level 2 governance is dramatically better than ad hoc. Level 3 is dramatically better than Level 2.

ALIGNING GOVERNANCE WITH OMB M-24-10

The Office of Management and Budget's memorandum on "Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence" (OMB M-24-10) sets specific requirements for federal AI governance. These aren't suggestions--they're compliance obligations.

Key OMB requirements include:

Chief AI Officer or Equivalent: Every agency must have someone in a senior role responsible for AI governance. This person should have decision-making authority and direct access to leadership.

AI Governance Structure: Agencies must establish a governance structure that includes cross-functional representation. The structure must make decisions about which AI systems are appropriate for deployment and how they're monitored.

Impact Assessments: Before deploying significant AI systems, agencies must conduct impact assessments addressing:

  • Intended and actual outcomes of the AI system
  • Potential impacts on civil rights and liberties
  • Potential impacts on the protected classes
  • Data quality and availability
  • Necessary and sufficient resources for successful implementation

AI Inventory: Agencies must maintain an inventory of all AI systems in use or in development. The inventory must include information about the system's purpose, scope, data sources, and known risks.

Minimum Practices: Agencies must implement minimum practices for responsible AI, including:

  • Governance structures and accountability
  • Documentation and transparency
  • Testing for bias and performance
  • Human oversight and review processes
  • Ongoing monitoring

Incident Reporting: If an AI system causes significant harm or is found to violate civil rights, agencies must report it through specified channels.

OMB M-24-10 isn't bureaucratic busywork--it's a floor, not a ceiling. It establishes minimum requirements. Agencies committed to truly responsible AI will exceed these minimums.

DESIGNING GOVERNANCE FOR YOUR AGENCY

Overview

How do you take these concepts and actually build governance in your agency? Here's a pragmatic approach:

Step 1: Assess Current State

Before building governance, understand where you are. Questions to answer:

  • What AI systems currently exist in your agency?
  • Who's responsible for each one?
  • Are decisions about AI made formally or informally?
  • Is there any documentation of AI systems or decisions?
  • Who cares most about responsible AI within leadership?
  • What barriers exist to establishing governance?

This assessment typically takes 2-4 weeks and involves interviews with technical staff, program managers, and leadership.

Step 2: Define Governance Structure

Based on your assessment and your agency's size, design the governance structure. At minimum, you need:

  • A single accountable person (Chief AI Officer or equivalent) responsible for governance
  • A governance board or committee that makes decisions about AI systems
  • Clear roles for key positions (data owner, model owner, fairness lead)
  • Defined escalation paths

For a small agency (fewer than 500 people), this might be one part-time committee. For a large agency, it might be multiple committees with full-time staff. The structure should be right-sized for your organization.

Step 3: Establish Policies

Work with governance leadership to develop the core policies. Start with essentials:

  • What AI systems require governance board approval before deployment?
  • What data standards must be met?
  • What fairness assessment is required?
  • How are decisions documented?
  • What's the escalation process for concerns?

Don't try to build perfect policies. Build practical policies that address the most important decisions and can be refined later.

Step 4: Communicate and Train

Once governance structure and policies are established, communicate them broadly. Conduct training on the governance process. Help people understand why governance exists, how it works, and how to use it.

Step 5: Pilot and Refine

Run your governance through a few decisions. What works? What's burdensome? What's missing? Refine based on experience.

Step 6: Scale and Mature

As people get comfortable with governance, gradually increase sophistication. Add fairness assessment. Add monitoring processes. Increase oversight of high-risk systems. The governance matures over time.

ANTI-PATTERNS AND MISUSE RISKS

Risk 1: Governance as Bottleneck

The Risk: Well-intentioned governance becomes so complex and time-consuming that it actively prevents innovation. Teams start avoiding the governance process because it's faster to ask forgiveness than permission.

Why it happens: Sometimes governance committees are too large, or the approval process requires too many sign-offs, or policies are too stringent, or decision-making is too slow. The friction exceeds the benefit.

What goes wrong: You end up with two governance systems: the formal one (which people work around) and the informal one (which actually happens). Ironically, the informal system is less accountable and less responsible than if there were no governance.

How to avoid it: Design governance to be lean. Make the approval process fast (decision in 1-2 weeks, not months). Have governance committees meet regularly so you're not waiting for a rare meeting. Push decision-making to the lowest level that can appropriately make the decision. If governance is slowing things down excessively, that's a sign it needs redesign, not that people should work around it.

Risk 2: Governance Without Compliance

The Risk: Your agency establishes governance structure and policies that look good on paper, but no one actually follows them. Systems are deployed without going through the approval process. Decisions are made without documentation. The governance structure exists but has no teeth.

Why it happens: Governance is hard to enforce, especially if leadership doesn't actively support it. People get busy. Timelines pressure shortcuts. If there are no real consequences for bypassing governance, people will.

What goes wrong: You get the worst of both worlds: the bureaucratic burden of governance without the actual benefits. Systems get deployed irresponsibly, and then people blame "governance" as the problem.

How to avoid it: Leadership must visibly support governance. When someone tries to bypass the process, they should encounter push-back. When governance is followed properly, it should be recognized. And importantly, make governance easy enough that it's not a burden. People comply with processes that make sense and aren't too hard.

Risk 3: Governance Capture

The Risk: Governance structures are established, but they're dominated by a single perspective (technical, legal, business) and neglect others. For example, fairness concerns are systematically subordinated to speed-to-deployment concerns.

Why it happens: Whoever holds the most power on the governance committee shapes its decisions. If technical staff dominate, governance becomes overly technical. If lawyers dominate, governance becomes overly risk-averse. If business concerns dominate, responsible practices get neglected.

What goes wrong: You get governance that's technically sophisticated but ignores fairness. Or governance that's very careful about risk but prevents any innovation. The purpose of governance--balancing multiple values--is undermined.

How to avoid it: Explicitly ensure representation on governance structures. Include domain experts, fairness specialists, legal perspectives, technical perspectives, and business perspectives. When there's disagreement, create space for that disagreement. Make sure perspectives that lose a particular decision still feel heard.

Risk 4: Governance Fatigue

The Risk: After establishing governance, people get tired of it. Meetings feel repetitive. Policies feel like busywork. Interest in governance wanes. Decision-making becomes perfunctory.

Why it happens: Governance is work. If you're not seeing direct benefits, it's easy to become cynical about it.

What goes wrong: Governance becomes theater. Committees meet but don't decide. Policies exist but don't influence decisions. You retain the burden without the benefits.

How to avoid it: Demonstrate the value of governance. When governance prevents a problem, talk about it. When governance catches an issue early, share it. When responsible practices deliver results, celebrate them. Connect governance to outcomes, not just process. Also, make governance efficient. Don't have extra meetings. Don't create unnecessary documentation. Don't require approval for trivial decisions. Keep governance lean and focused.

PRACTICE AND REFLECTION PROMPTS

Prompt 1: Map Your Current Governance

Take 30 minutes and document your agency's current AI governance (or lack thereof). What governance structures exist? Who makes decisions about AI systems? Are decisions documented? Who's accountable for each system? Be honest about gaps.

Prompt 2: Design Governance for Your Unit

Pick a specific unit or program in your agency. Design a governance structure that would work for that unit. What's the minimum governance required? What committees or roles are needed? How often would they meet? Be practical about what can actually be implemented.

Prompt 3: Identify Governance Obstacles

What's preventing better AI governance in your agency? Is it leadership support? Capacity? Clarity about responsibilities? Conflicting priorities? Identify the top three obstacles. For each one, sketch a possible solution.

Prompt 4: Research Peer Agency Governance

Look at how other agencies similar to yours have structured AI governance. What can you learn from their approach? What would work in your context? What wouldn't? (Many agencies have published their governance frameworks publicly or shared them through OMB networks.)

Prompt 5: Evaluate Governance Maturity

Using the maturity model described in Core Concept 3, where would you place your agency? What would it take to advance one level? What would be the benefits? What would be the costs? What's the priority for investment?

KEY TAKEAWAYS

  • GOVERN is foundational. Before you can map, measure, or manage AI risks effectively, you need clear governance structures that establish how decisions are made and who's accountable.
  • Governance has five pillars: Organizational structure, policies and standards, roles and responsibilities, decision rights and escalation, and accountability/culture. All five are necessary for functioning governance.
  • Maturity is progressive. Most agencies start with ad hoc or initial governance and move toward more defined and optimized levels. Progress is valuable at each stage.
  • OMB M-24-10 sets compliance floors. Federal agencies have specific governance requirements around Chief AI Officers, governance structures, impact assessments, AI inventory, and minimum practices. These are not optional.
  • Governance must balance multiple values. Governance should enable responsible innovation, not prevent it. The goal is finding the right balance between moving quickly and acting carefully.
  • Governance only works if people use it. Perfectly designed governance structures that people work around are worse than no governance at all. Governance must be practical, valuable, and actively supported by leadership.
  • Governance enables better Map, Measure, and Manage. Well-designed governance creates clarity about what systems exist and who's responsible for them, which enables better measurement and management downstream.

GLOSSARY

Chief AI Officer -- A senior-level position responsible for establishing and overseeing an organization's AI governance framework, strategy, and compliance with AI governance requirements.

Governance Structure -- The organizational arrangements, committees, and decision-making processes through which an organization makes decisions about AI systems and assigns responsibility for implementation.

Impact Assessment -- A systematic evaluation of the intended and potential unintended consequences of an AI system across multiple dimensions including fairness, civil rights, performance, and resource requirements.

Model Owner -- The person designated as responsible for a specific AI model's performance, maintenance, monitoring, and compliance with governance requirements.

Data Owner -- The person designated as responsible for the quality, provenance, appropriate use, and governance of a specific dataset.

Decision Rights -- The explicit allocation of authority specifying who can make what types of decisions about AI systems, and under what conditions decisions must be escalated to higher authority.

Escalation Process -- The formal procedure for raising concerns, conflicts, or decisions above the authority level of the person or group currently responsible.

Governance is often the unsexy part of AI adoption. It doesn't produce models or deploy systems or solve business problems. What it does is create the conditions under which everything else can happen responsibly. It's the scaffolding that makes innovation possible without chaos.

Think about what we've covered: organizational structure that makes clear who decides what. Policies that reflect institutional values. Roles that create accountability. Decision rights that enable speed while preventing rogue decisions. Culture that makes people actually care about doing things right.

These elements together create something powerful: an organization that can innovate with AI while maintaining institutional integrity. An organization where problems get escalated, not hidden. Where decisions are documented. Where learning gets captured and shared. Where fairness and security aren't afterthoughts but built into how decisions are made.

As you move into the MAP, MEASURE, and MANAGE functions in subsequent lectures, you'll see how they all depend on the governance foundation. Clear governance makes it easy to identify what AI systems need mapping. It makes measurement systematic rather than random. It provides the accountability structure for managing risks.

NIST AI RMF isn't a constraint on innovation--it's actually the framework that makes sustained, responsible innovation possible. And it all starts with governance.

Take three minutes for this reflection. Think about the governance structures in your organization. Start with whatever currently exists, even if it's minimal.

What decisions are being made about AI systems? Who's making them? Are they documented? Is it clear who has authority?

If you had to describe your current governance in one sentence, what would it be? Is that the governance you want? What would need to change?

Who in your organization cares most about responsible AI governance? These are the people you'll want to partner with as you work to improve governance maturity.

This lecture has provided a deep dive into the GOVERN function--the foundational piece of the NIST AI Risk Management Framework. You've learned about governance structures, policies, roles, decision rights, and the progression of governance maturity.

In the next lecture (2.3.2), we'll dive into the MAP function, which builds on this governance foundation. We'll explore how to identify and inventory AI systems, understand their risk profiles, and create the organizational awareness that effective governance requires.

The governance concepts you've learned here are universal--they apply whether you're a small team establishing governance for the first time, or a large agency trying to scale governance across hundreds of AI systems. The principles remain constant. The scale and complexity adjust.

End of Transcript

Source: GOVT.CLUB

Visit: https://govt.club/learn/lectures/l2/231-nist-ai-rmf-the-govern-function.html

Government AI CLUB Certification Program

Level 2: AI Ready | NIST AI RMF: The GOVERN Function | Lecture 2.3.1

A GOVT.CLUB initiative

<- 2.2.10 Capstone Lab: End-to-End AI Integration Project
2.3.2 NIST AI RMF: MAP, MEASURE, MANAGE ->

Start Your CLUB Certification

This lecture is part of L2: AI Practitioner -- 40 hours of comprehensive government AI training.

Explore CLUB Certification

L2
2.3.2 -- NIST AI RMF: MAP, MEASURE, MANAGE
60 min - Video + Workshop

L2
2.3.3 -- Your Agency's AI Governance Structure
60 min - Reading + Discussion

L2
2.3.4 -- AI Use Case Inventory and Documentation (OMB M-24-10)
60 min - Workshop + Template