Skip to module content
Module 09 · ~8 min

Governance That Enables Instead of Strangles

NIST AI RMF — four functions you can scale down to a one-page register without losing the logic.

Reading progress
0/7 · 0%

The big idea

💡Key idea
The NIST AI Risk Management Framework gives you four functions — Govern, Map, Measure, Manage — that map directly onto a simple one-page risk register. You're not building something new; you're arranging what you already deliver into a structure that carries a federal standard's credibility. For a solo consultant, that borrowed institutional weight is exactly what procurement teams and legal counsel are looking for.
Quick check
1 question · instant feedback
0/1
  1. NIST AI RMF's four functions:

Deep dive

2/2 open

Agents introduce two governance upgrades that didn't matter as much with simple prompt-and-response tools.

First, speed and scale break human-paced oversight. A traditional workflow assumes a human can review each step — but an agent can execute thousands of actions per minute across many concurrent instances. Governance now has to include automated monitoring with guardrails, designed intervention points, and full traceability built into the architecture from the start. Audit-ability isn't a compliance checkbox you add later; it's a structural property of how the system is built. That's why the tool-surface permissions and trace capture from Volume 1 are governance controls, not just engineering hygiene.

Second, governance becomes cross-functional in a way IT alone can't handle. Deciding what an agent is allowed to decide autonomously — and what requires human sign-off — is a business question, an HR question, a finance question. The agentic-enterprise study found 58% of leading organizations expect governance and decision-rights changes within three years. That number is the mandate for bringing multiple functions to the table early.

Rebuild your risk-register one-pager on the four NIST functions — Govern, Map, Measure, Manage — so every engagement produces a consistent, citable artifact.

Pair it with the shadow-AI finding (roughly 90% of employees already using personal AI tools) to reframe governance in client conversations: the goal isn't to restrict what employees can do, it's to safely channel what they're already doing. Governance as acceleration, not as a brake — that framing lands very differently with leadership than a slide full of prohibitions.

Quick check
1 question · instant feedback
0/1
  1. In an LLM system, the Measure function is best implemented by:

How to run it

  1. Govern
    The cross-cutting function: policies, accountability, roles, risk tolerance, culture. Who owns AI risk, and what's the appetite? Everything else hangs off this.
  2. Map
    Establish context per system: intended purpose, users, data, and the specific harms possible in this deployment (wrong ad-spend decision, leaked client data, discriminatory output) — not AI risk in the abstract.
  3. Measure
    Assess and track the mapped risks with defined metrics and testing. For an LLM system, this function IS Volume 1's eval-and-tracing stack: golden sets, judges, drift probes, trace audits.
  4. Manage
    Act on what's measured: prioritize, mitigate, monitor, respond, and decide (including deciding not to deploy). Review gates, incident paths, rollback plans.
Quick check
1 question · instant feedback
0/1
  1. Blanket-prohibition governance fails because:

In the field

🔬Worked example
Mid-market translation of NIST AI RMF: Govern = a one-page policy naming an accountable owner and the red lines. Map = your risk-triage sheet per workflow (PII/PHI/financial/IP flags → residency, retention, access, audit). Measure = the eval harness and traces from Volume 1. Manage = the human-in-the-loop gates and an incident path. Lead with 'aligned to the NIST AI Risk Management Framework' in regulated-prospect conversations — procurement and counsel recognize the phrase.
🚫When not to reach for it
Governance as blanket prohibition is a documented failure — the shadow-AI data (90% personal use) shows suppression simply routes usage around the controls, ungoverned. Policy theater — a 40-page responsible-AI policy without mapped risks per system, measurement, or management — passes procurement and fails production.
Quick check
1 question · instant feedback
0/1
  1. Right posture for regulated-prospect conversations:

Pitfalls & takeaways

Failure modes

  • Policy theater. 40 pages of responsible-AI policy, no mapped risks per system, no measurement. Govern without Map/Measure/Manage.
  • Blanket prohibition. Governance as a no-machine — routes usage around the controls, ungoverned.
  • IT-only ownership. The function that can't see business consequences owns the decisions about them.
  • Untraceable agents. Autonomy granted before audit-ability exists; the first incident is unexplainable by construction.

Durable takeaways

  • Four functions: Govern, Map, Measure, Manage.
  • Your eval harness + traces IS the Measure function.
  • Audit-ability is an architectural property, not a policy line.
  • Cross-functional decision rights — not IT alone.

Do the work

📦Artifact to produce
NIST-aligned one-page risk register per engagement.

Sources

  • · NIST AI Risk Management Framework 1.0 (2023) + Generative AI Profile (2024)
  • · MIT SMR × BCG Responsible AI panel (50+ experts, 1,221-executive survey)