THE SHORT ANSWER

AI governance is the set of roles, policies, decision rights, processes and evidence used to direct and control AI across its lifecycle. It connects business ownership, risk review, technical evaluation, human oversight, monitoring and incident response.

Governance joins people, process and evidence

A practical governance system
ElementPurpose
Decision rightsDefine who may propose, approve, pause and retire a use
Lifecycle processApply proportionate review from idea through monitoring
EvidenceRecord data, tests, limitations, approvals and incidents
AccountabilityName an owner for the business outcome and controls

Govern, map, measure and manage

NIST organizes AI risk work around GOVERN, MAP, MEASURE and MANAGE. Governance is cross-cutting: it establishes culture and accountability while the other functions understand context, assess risk and act on evidence.

Evidence & context: National Institute of Standards and Technology

Use stronger gates where harm is harder to reverse

A small internal experiment can use a lightweight record and human check. A customer-facing or high-impact system needs clearer authority, representative testing, documented recourse, monitoring and escalation. Proportionate does not mean optional.

Paper compliance is not operational control

  • A policy nobody can find
  • A committee with no decision rights
  • A risk register disconnected from deployment
  • A launch approval without monitoring
  • A vendor contract treated as proof of fitness

Build from an AI use inventory, then attach owners and decisions to real systems.

Evidence & context: International Organization for Standardization · National Institute of Standards and Technology

Sources & further reading

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0)

    National Institute of Standards and Technology. Voluntary, rights-preserving guidance organized around GOVERN, MAP, MEASURE and MANAGE. NIST was revising AI RMF 1.0 when checked on 28 September 2026, so organizations should verify the current version before formal adoption.

  2. ISO/IEC 42001 explained: What it is, why it matters, and how it works

    International Organization for Standardization. Official overview of the AI management-system standard and its continual-improvement approach. Certification scope and a management system do not by themselves prove that a specific AI use is safe, fair or legally compliant.

  3. NIST AI RMF Playbook

    National Institute of Standards and Technology. Suggested actions for using AI RMF 1.0. It is voluntary, not a checklist or certification, and NIST states that it will be updated after the framework revision.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗