GOVERN — Policies, Accountability & Culture
Description
The GOVERN function establishes and maintains the organizational structures, policies, processes, and culture necessary for responsible AI risk management. It is cross-cutting — unlike MAP, MEASURE, and MANAGE which apply to individual AI systems, GOVERN applies organization-wide and sets the foundation for all other functions. Without effective governance, the remaining functions cannot operate consistently or at scale.
Subcategories
| ID | Name | Description |
|---|---|---|
| GV-1 | Policies, processes, and practices | AI policies, processes, procedures, and practices are in place across the organization to map, measure, manage, and gove... |
| GV-2 | Accountability structures | Roles, responsibilities, and lines of communication related to AI risk management are established with clear accountabil... |
| GV-3 | Diversity, equity, inclusion, and accessibility | Organizational teams building, deploying, and using AI systems reflect diversity, and are proactive in addressing harmfu... |
| GV-4 | Organizational culture and commitment | Organizational culture and leadership foster responsible stewardship of trustworthy AI aligned with societal values. Cul... |
| GV-5 | Stakeholder engagement | Organizational practices are in place to enable AI deployment and ongoing use with input from affected communities and s... |
| GV-6 | Supply chain risk management | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. ... |
Implementation Guidance
Establishing AI Governance Infrastructure
GOVERN requires building governance from the top down. Start with executive sponsorship — without C-suite commitment, AI governance becomes a checkbox exercise. Designate an AI governance owner (often the CISO, CTO, or a dedicated Chief AI Officer) with authority to enforce policies across business units.
Building the Policy Framework
Develop a tiered policy structure:
- AI Governance Policy — Board-approved, defines risk appetite, ethical principles, and accountability
- AI Acceptable Use Policy — Defines permitted/prohibited AI uses, data handling, and approval workflows
- AI Risk Management Procedures — Operational procedures for risk assessment, treatment, and monitoring
- AI Development Standards — Technical standards for code review, testing, model validation, and deployment
Organizational Structure
Establish a cross-functional AI Governance Committee with representatives from engineering, legal, compliance, risk, HR, and business units. This committee reviews high-risk AI deployments, adjudicates policy exceptions, and tracks the organization's AI risk posture.
Accountability and RACI
Create a RACI matrix mapping every AI lifecycle activity to specific roles:
- AI System Owner — Business leader accountable for system outcomes and risk acceptance
- AI Developer — Responsible for building systems that meet governance standards
- AI Risk Manager — Consulted on risk assessments, informed of all deployments
- Data Steward — Responsible for data quality, privacy, and lineage
- Ethics Reviewer — Consulted on high-risk or sensitive AI applications
Culture and Incentives
Governance fails without cultural reinforcement. Include responsible AI practices in performance reviews, create safe channels for reporting concerns (whistleblower protections), and publicly recognize teams that identify and mitigate AI risks before deployment.
Evidence Requirements
- Board-approved AI Governance Policy with executive signatures and annual review dates
- AI Acceptable Use Policy published to all employees with acknowledgment tracking
- AI Governance Committee charter, membership roster, and meeting minutes
- RACI matrix for AI lifecycle activities covering all active AI systems
- AI risk appetite statement with quantitative thresholds (e.g., maximum acceptable bias metrics, data exposure tolerance)
- Training completion records showing >90% coverage for target audiences
- Third-party AI vendor risk assessment questionnaire and completed evaluations
- Supply chain inventory of all third-party AI components, APIs, and models with version tracking
- Annual governance effectiveness review report with identified gaps and remediation plans