Skip to main content
Category: Management System Governance

Manage Function

Also known as: Management Function, Managing
Simply put

A management function refers to one of the core activities involved in running an organization or overseeing people and projects toward a shared goal. These activities are commonly grouped into functions such as planning, organizing, leading, and controlling, though some frameworks add categories like staffing, coordinating, directing, record keeping, and budgeting. The evidence provided describes management in general organizational terms and does not define this as a specialized AI governance or model risk term.

Formal definition

In general management theory, a management function denotes a distinct category of activity through which an organization directs its resources (people, finances, and materials) toward defined objectives. The most commonly cited framework identifies four core functions—planning, organizing, leading, and controlling—that together provide a structured approach to overseeing work; broader treatments extend the set to include staffing, coordinating, directing, record keeping, and budgeting. The evidence packet describes these functions at the level of general business and organizational management and does not establish a definition specific to AI governance frameworks or model risk management contexts; readers should not assume this general-management usage maps directly onto specialized regulatory terminology without corroborating sources.

Why it matters

The term "management function" as described in the evidence digest is a general business and organizational management concept, not a specialized term of art within AI governance or model risk management. This distinction matters because professionals in regulated environments frequently encounter the word "manage" in domain-specific frameworks—where it may carry a defined meaning tied to specific oversight activities—and may mistakenly assume that the general-management usage documented here maps directly onto that specialized terminology. The evidence provided supports only the broad organizational definition and does not establish a regulatory or model-risk-specific meaning.

Who it's relevant to

General managers and organizational leaders
The evidence frames management functions as the core activities of running an organization—planning, organizing, leading, and controlling resources toward shared objectives. Those responsible for overseeing people or projects use these categories as a structured way to organize their work.
Project managers
Several of the cited sources situate management functions within project and team contexts, describing management as overseeing people or projects and guiding them toward a common outcome. This makes the framework relevant to those coordinating defined initiatives.
AI governance and model risk professionals — with caution
Compliance officers, model risk managers, and governance specialists may encounter the word "manage" in specialized frameworks. However, the evidence digest supports only a general-management definition. These readers should not assume this usage corresponds to any specific regulatory or model-risk term without corroborating, domain-specific sources.

Inside Manage Function

Risk Prioritization and Response
The Manage function, as one of the core functions in the NIST AI Risk Management Framework (a voluntary framework issued by the U.S. National Institute of Standards and Technology), typically involves prioritizing identified AI risks and determining appropriate responses. As commonly described, this builds on risks surfaced through the framework's other functions rather than identifying them for the first time.
Risk Treatment Options
This component generally addresses how an organization allocates resources to respond to prioritized risks, which may include actions to mitigate, transfer, avoid, or accept a given risk. These are described as measures intended to reduce or manage risk, not to eliminate it.
Ongoing Monitoring and Response Planning
The Manage function is commonly associated with monitoring AI systems over time and maintaining plans to respond to changes, incidents, or newly emerging risks. This overlaps with, but should not be conflated with, model risk management activities that focus specifically on ongoing monitoring of model risk under guidance such as SR 11-7 / OCC 2011-12 in the U.S. banking context.
Documentation and Accountability
As typically framed, this function includes documenting decisions about risk responses and assigning responsibility for managing them. This element sits at the intersection of AI governance (organizational accountability and oversight) and risk management activities, without collapsing the two.

Common questions

Answers to the questions practitioners most commonly ask about Manage Function.

Is the Manage function the same as the risk mitigation step where risks are eliminated?
No. As commonly framed, the Manage function is about prioritizing, responding to, and monitoring risks on an ongoing basis, not about eliminating them. Governance and risk response measures are typically described as actions that reduce or control risk, not remove it entirely. Treating Manage as a one-time fix that produces zero residual risk misstates its purpose; residual risk generally remains and must continue to be tracked.
Does the Manage function replace or duplicate the risk identification and assessment work done earlier?
Not typically. The Manage function generally builds on prior identification and assessment activities rather than repeating them. In many framework structures, earlier functions establish what risks exist and how significant they may be, while Manage focuses on allocating resources, selecting responses, and sustaining oversight over time. Conflating Manage with assessment can lead teams to re-litigate risk analysis instead of acting on it and monitoring outcomes.
How should an organization prioritize which risks to address first under the Manage function?
Prioritization in the Manage function is commonly informed by the significance of each risk, drawing on prior assessment outputs such as likelihood, impact, and the gap between inherent and residual risk. Many organizations also weigh resource constraints and the availability of effective responses. The specific prioritization method is generally left to the organization and its risk tolerance, so approaches vary by context and are not fixed by a single authoritative rule.
What kinds of risk responses fall within the Manage function?
Risk responses in this context commonly include actions to reduce, transfer, avoid, or accept risk, along with documenting the rationale for the chosen response. The Manage function generally also covers planning for how responses will be implemented and by whom. It is worth noting that acceptance of a risk is itself a legitimate response, provided it is documented and consistent with the organization's stated risk tolerance.
How does ongoing monitoring fit into the Manage function?
Monitoring is generally treated as a core part of the Manage function because risks and system behavior can change over time. In many implementations this includes tracking whether responses remain effective, whether new risks emerge, and whether previously accepted risks still fall within tolerance. The scope, frequency, and metrics for monitoring typically depend on the organization and the context of the system involved.
Who is typically accountable for carrying out the Manage function within an organization?
Accountability for the Manage function is commonly distributed across organizational roles rather than assigned to a single owner. In organizations that use a lines-of-defense structure, responsibilities for risk response and monitoring are often allocated across those lines, though the specific allocation varies. The details of role assignment generally depend on an organization's governance structure and are not dictated by a single universal model.

Common misconceptions

The Manage function is where AI risks are first identified and measured.
In the NIST AI RMF as commonly described, the Manage function focuses on prioritizing and responding to risks that are typically surfaced through other functions of the framework. Identification and measurement are generally treated as distinct activities.
Applying the Manage function eliminates AI risk.
Risk responses under this function are measures intended to reduce or manage risk; they do not eliminate it. Residual risk typically remains after treatment and should be tracked separately from inherent risk.
The Manage function is a legally binding requirement.
The NIST AI Risk Management Framework is a voluntary framework issued by NIST, not binding law. It should not be treated as interchangeable with binding instruments such as the EU AI Act or with supervisory guidance such as SR 11-7, which have their own scopes and jurisdictions.

Best practices

Treat the Manage function as the response-and-prioritization stage, and keep it distinct from risk identification and measurement activities carried out under the framework's other functions.
Document the rationale for each risk response decision (mitigate, transfer, avoid, or accept) and assign clear ownership so accountability is traceable.
Distinguish inherent risk from residual risk when recording outcomes, and describe controls as measures that reduce or manage risk rather than eliminate it.
Establish ongoing monitoring so that responses can be revisited as AI systems, data, or operating conditions change over time.
Where your organization is also subject to model risk management guidance (such as SR 11-7 in the U.S. banking context), map overlapping monitoring and response activities without collapsing the distinction between AI governance and model risk management.
Use qualified, framework-appropriate language in internal documentation, noting that the NIST AI RMF is voluntary and should not be represented as a universal or binding requirement.