Govern, Map, Measure, and Manage AI Risk
Govern, Map, Measure, and Manage AI Risk
Key jargon
| Term | Plain-language meaning |
|---|---|
| Govern | Establish accountable policies, roles, culture, and oversight for AI risk. |
| Map | Understand context, intended use, affected parties, dependencies, and risk. |
| Measure | Assess and track trustworthy characteristics and risk using evidence. |
| Manage | Prioritize, treat, monitor, communicate, and respond to identified risk. |
Key concepts
- The NIST AI RMF functions reinforce one another and operate throughout the lifecycle.
- Governance becomes operational when risks have owners, evidence, treatment decisions, deadlines, and review triggers.
Concept map
flowchart LR
A["Govern roles and policy"] --> B["Map context and impacts"]
B --> C["Measure with evidence"]
C --> D["Manage treatment and monitoring"]| Function | Practical questions |
|---|---|
| Govern | Who owns policy, accountability, skills, documentation, and oversight? |
| Map | What context, users, impacts, data, dependencies, and risks define the system? |
| Measure | How are quality, trustworthiness, safety, privacy, and uncertainty evaluated? |
| Manage | Which risks are accepted, mitigated, transferred, monitored, or cause retirement? |
Governance is not a one-time committee approval. It connects requirements, evaluation evidence, deployment decisions, incidents, and change management.
Exercise
Create a one-page AI system card with purpose, owner, users, data, model, tools, impacts, measurements, controls, residual risks, and review date.