US AI governance operations guide
AI governance starts with a reliable inventory and named decisions. A policy without systems, owners and evidence cannot control daily use.
Map the system and its context
Record the use case, people affected, model or service, data, output, human role, owner, supplier and deployment state. Keep unknown facts visible.
Connect governance to risk work
Use the inventory to decide which systems need testing, supplier review, monitoring, incident preparation or a deeper legal assessment.
- Govern
- Map
- Measure
- Manage
Keep accountable decisions
Record the decision, approver, evidence, conditions, monitoring trigger and next review. The record should show why the system remained allowed, restricted or stopped.
Material reviewed for this guide
- Artificial Intelligence Risk Management Framework 1.0National Institute of Standards and Technology
- AI Risk Management Framework PlaybookNational Institute of Standards and Technology
- Generative Artificial Intelligence ProfileNational Institute of Standards and Technology
- Keep your AI claims in checkFederal Trade Commission
This guide is general operational information, not legal advice. Check the official material and obtain appropriate advice for circumstances outside the stated scope.