NIST AI RMF
APPLICATION
DATA
GOVERNANCE
INFRASTRUCTURE
Policies, processes, and practices
Description
AI policies, processes, procedures, and practices are in place across the organization to map, measure, manage, and govern AI risks.
Suggested Actions
1
Develop a comprehensive AI governance policy suite covering ethics, risk management, and compliance — this is not optional, it is the foundation everything else builds on2
Establish AI risk management processes integrated with the enterprise risk framework (ERM) — AI risk should not exist in a silo separate from operational, financial, and compliance risk3
Create operational procedures for every phase of the AI lifecycle: intake/approval, development, testing, deployment, monitoring, and decommissioning4
Document and communicate governance practices to all relevant personnel through mandatory training with role-specific content5
Implement a policy exception process with documented justification, risk acceptance, and compensating controls — policies without enforcement mechanisms are suggestions6
Review and update all AI policies at least annually, or triggered by significant incidents, regulatory changes, or material changes to AI system portfolio