Skip to main content
Category: Management System Governance

Govern Function

Also known as: GOVERN, GV Function, Govern (NIST CSF 2.0)
Simply put

The Govern Function is one of the functions in the NIST Cybersecurity Framework (CSF) 2.0, focused on establishing and maintaining the governance structures and processes an organization uses to manage cybersecurity risk. It addresses policy, oversight, and accountability at the program level, and helps inform and prioritize the outcomes of the framework's other functions. It was added in the 2.0 version of the framework to reflect the growing importance of risk management and governance for IT and security teams.

Formal definition

In the NIST Cybersecurity Framework (CSF) 2.0, published by NIST in February 2024, the GOVERN Function provides outcomes intended to inform and prioritize the outcomes of the framework's other functions. As commonly described, it concerns establishing and maintaining organizational governance structures and processes for managing cybersecurity risk, making cybersecurity accountability explicit at the program level across policy, oversight, and risk management. Note that as scoped here, the Govern Function is a component of a cybersecurity framework rather than an AI-specific governance instrument; the NIST CSF is issued as voluntary guidance rather than binding law, and the evidence provided addresses cybersecurity governance specifically and does not establish its application to AI model governance. Characterizations of its relative importance within the framework (for example, as the 'glue' holding the framework together) reflect practitioner opinion in the evidence rather than a definitional claim.

Why it matters

The Govern Function marks a structural shift in how the NIST Cybersecurity Framework treats governance. In CSF 2.0, published by NIST in February 2024, GOVERN was added to the framework's set of functions and is positioned to inform and prioritize the outcomes of the other functions. This reflects a recognition, as described in the evidence, that risk management and governance have become essential tasks for IT and security teams rather than peripheral concerns handled only after technical controls are in place.

For practitioners, the significance is that the Govern Function makes cybersecurity accountability explicit at the program level, covering policy, oversight, and risk management. Rather than leaving governance implicit across scattered activities, it provides a defined place in the framework for establishing who is accountable and how cybersecurity risk decisions are made and maintained. One practitioner cited in the evidence characterizes it as the 'glue that holds the entire framework together,' though this is an opinion about its relative importance rather than a definitional claim.

It is important to scope the Govern Function correctly. The NIST CSF is issued as voluntary guidance, not binding law, and the Govern Function is a component of a cybersecurity framework specifically. The evidence provided addresses cybersecurity governance and does not establish the function's application to AI model governance or model risk management. Readers should not assume that adopting the Govern Function satisfies AI-specific governance obligations, nor that it is interchangeable with instruments such as the NIST AI Risk Management Framework, ISO/IEC 42001, or model risk guidance such as SR 11-7.

Who it's relevant to

Cybersecurity and Information Security Leaders
Those responsible for setting cybersecurity policy and oversight can use the Govern Function to structure program-level accountability and to inform and prioritize the outcomes pursued across the framework's other functions.
Risk and Governance Practitioners
Professionals focused on risk management and governance may find the Govern Function relevant because its addition in CSF 2.0 reflects the rise of these activities as essential tasks for IT and security teams. Note, however, that the evidence here addresses cybersecurity governance and does not establish application to AI model governance.
Organizations Adopting NIST CSF 2.0
Teams implementing the NIST Cybersecurity Framework should understand that the Govern Function is one function among the framework's set and that the CSF is voluntary guidance rather than binding law. It supports, but does not by itself guarantee, effective governance of cybersecurity risk.

Inside Govern Function

Cross-cutting placement in the NIST AI RMF
In the NIST AI Risk Management Framework (issued by the U.S. National Institute of Standards and Technology, a voluntary framework), Govern is commonly described as a function that spans and informs the other functions (typically Map, Measure, and Manage) rather than operating as a discrete sequential stage. It is intended to cultivate a culture of risk management across the AI lifecycle.
Policies, processes, and procedures
Establishing organizational policies and documented procedures that define how AI risks are identified, assessed, and managed. This includes accountability structures and decision-making processes for AI systems, aligning the Govern function more with AI governance (organizational oversight and accountability) than with the quantitative measurement techniques of model risk management, though the two overlap in practice.
Accountability and roles
Defining clear lines of responsibility, authority, and accountability for AI outcomes across the organization. This typically includes designating who is responsible for oversight and who has decision rights, which relates to but should not be conflated with the first, second, and third lines of defense as framed in some risk management models.
Risk tolerance and prioritization
Articulating organizational risk tolerance and mechanisms for prioritizing AI risks. As commonly framed, this addresses how much risk an organization is willing to accept, informing subsequent risk mapping and management rather than eliminating risk.
Workforce, culture, and competency
Fostering a risk-aware culture and ensuring personnel have the training and diversity of perspectives to identify and manage AI risks. Governance measures of this kind are intended to reduce and manage risk, not to guarantee its elimination.
Third-party and supply chain considerations
Addressing risks arising from third-party data, models, and services used in AI systems. In many frameworks this includes processes for oversight of externally sourced components, though the specific expectations vary by organization and sector.

Common questions

Answers to the questions practitioners most commonly ask about Govern Function.

Is the Govern function the same as model risk management?
No, though they overlap. The Govern function, as described in the NIST AI Risk Management Framework (a voluntary framework issued by the U.S. National Institute of Standards and Technology), addresses the organizational structures, policies, accountability, and culture that cultivate risk management across an AI system's lifecycle. Model risk management, historically framed by guidance such as SR 11-7 / OCC 2011-12, focuses more narrowly on identifying, measuring, monitoring, and controlling risks arising from model use. Govern is broader in scope and typically provides the accountability and policy environment within which model risk management activities operate; the two are complementary rather than interchangeable.
Does implementing the Govern function make an organization compliant with the EU AI Act or other regulations?
Not on its own. The Govern function is a component of the NIST AI RMF, which is a voluntary framework rather than binding law. Adopting it does not by itself establish compliance with distinct instruments such as the EU AI Act, which is issued by separate authorities and carries its own scope and obligations. Governance practices may support broader compliance efforts, but each regulatory regime should be assessed on its own terms and jurisdiction. Governance also reduces and helps manage risk; it does not eliminate it.
How does the Govern function relate to the other functions in the NIST AI RMF?
In the NIST AI RMF as commonly described, Govern is treated as a cross-cutting function that informs and is present throughout the other functions (typically Map, Measure, and Manage). Rather than being a discrete stage, it establishes the policies, roles, accountability, and culture that enable those functions to be carried out consistently. Practically, this means governance responsibilities are integrated into activities across the AI lifecycle rather than confined to a single point in time.
Who is typically responsible for the Govern function within an organization?
Responsibility is usually distributed rather than assigned to a single role. Senior leadership and boards commonly hold ultimate accountability for the risk culture and policy environment, while day-to-day governance activities may involve compliance, legal, risk management, and technical teams. In organizations that use a lines-of-defense model, governance responsibilities can be mapped across the first, second, and third lines, though the specific allocation varies by organization and sector. The framework itself does not prescribe a single organizational structure.
What documentation or artifacts support the Govern function?
Common artifacts include AI policies and standards, defined roles and accountability structures, risk tolerance statements, inventories of AI systems, and records of oversight and decision-making. The specific documentation appropriate for an organization typically depends on its size, sector, and risk profile. The framework describes outcomes to be achieved rather than mandating a fixed set of documents, so organizations generally tailor artifacts to their context.
How can an organization assess the maturity of its Govern function?
Assessment approaches vary and are not standardized across all contexts. Organizations often evaluate whether policies exist and are followed, whether accountability is clearly assigned, whether risk tolerances are defined and communicated, and whether governance practices are consistently applied across the AI lifecycle. Because the NIST AI RMF is a voluntary framework describing outcomes rather than a certification scheme, maturity assessment is typically an internal or advisory exercise tailored to the organization rather than a pass/fail regulatory determination.

Common misconceptions

The Govern function is a one-time setup step completed before the other functions begin.
As commonly described in the NIST AI RMF, Govern is a continuous, cross-cutting function that informs and is informed by the other functions throughout the AI lifecycle, rather than a discrete stage completed once at the outset.
Implementing the Govern function is equivalent to complying with binding regulatory requirements such as the EU AI Act or SR 11-7.
The NIST AI RMF is a voluntary framework issued by NIST and is distinct from binding law like the EU AI Act (adopted in the EU) and from supervisory guidance such as SR 11-7 (associated with U.S. banking supervisors and focused on model risk management). Adopting the Govern function does not by itself establish compliance with any of these instruments, and they are not interchangeable.
Strong governance structures eliminate AI risk.
Governance measures are intended to identify, reduce, and manage risk and to support accountability. They do not eliminate risk; residual risk typically remains even where governance controls are in place.

Best practices

Treat Govern as a continuous, cross-cutting function that connects to mapping, measuring, and managing activities, rather than a one-time exercise completed before technical work begins.
Document policies, procedures, and decision rights explicitly, and assign clear accountability for AI outcomes so that oversight responsibilities are traceable.
Articulate organizational risk tolerance up front so that later risk prioritization and management decisions have a defined reference point.
Distinguish organizational AI governance activities from quantitative model risk management practices, and identify where the two overlap so responsibilities are not left ambiguous.
Establish processes for evaluating and overseeing third-party data, models, and services, recognizing that externally sourced components carry risks the organization still bears.
Invest in workforce competency and a risk-aware culture, and communicate that governance controls reduce and manage risk rather than eliminate it.