Many AI policies share a similar structure: a statement on responsible use, a list of prohibited activities, a requirement for human review of outputs, and a rule that employees must obtain approval before using AI tools with company data. These policies are defensible, but they often do not answer the question employees face in daily work: whether a specific task, with specific data, may be performed in a specific tool. When policy does not answer that question, use continues without oversight.

Effective AI governance for a regulated organization rests on three elements: an inventory of AI systems, a tiering rule that non-specialists can apply, and an approval path that is faster than working around it. The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) provides a structure for all three.1 NIST has announced that AI RMF 1.0 is under revision, so organizations should monitor the NIST AI RMF page for updates.2

Start with the inventory

AI enters most organizations through three channels, and only one typically passes through procurement:

  • Tools purchased as AI products, such as assistants, coding tools, and transcription services.
  • AI features enabled within existing software, such as CRM summarization or suggested helpdesk replies. These often arrive through product updates without a new contract or review.
  • Consumer tools used with business data, including free tiers, personal accounts, and browser extensions.

An inventory record needs a small number of fields: the system, its owner, the data it receives, whether its output affects a decision about a person, how the vendor handles inputs, and approval status. The AI RMF's Govern function includes mechanisms to inventory AI systems, and its Map function establishes the context and intended use for each.1

Tier by consequence, not by technology

A tiering rule should allow a line manager to classify a use case in under a minute. A three-tier model based on data and consequence works well:

  1. Low. No regulated or confidential data; output supports an individual's own work and is reviewed by that individual. Approved by default.
  2. Moderate. Confidential business data, or output used in customer-facing work. Requires an approved tool with contractual terms on training and retention, and a named owner.
  3. High. Regulated data, such as protected health information, controlled unclassified information, cardholder data, or nonpublic personal information, or output that materially affects a decision about a person's credit, employment, care, eligibility, or access. Requires formal review, documented testing, human decision authority, and a usage record.

This model keys on regulated data and consequential decisions, which are the same factors that examiners, auditors, and customers evaluate.

Apply the AI RMF functions

AI RMF 1.0 organizes risk management into four functions. Govern is cross-cutting and informs the other three; Map, Measure, and Manage apply to specific systems and lifecycle stages.1

  • Govern: decision authority, policy, exception handling, and periodic review.
  • Map: purpose, affected parties, data, and potential harms for each system.
  • Measure: performance on the organization's own use cases, error modes, bias where decisions affect people, and post-deployment monitoring.
  • Manage: prioritization, restriction, remediation, and response when a system does not perform as expected.

For generative AI, the Generative AI Profile (NIST AI 600-1, July 2024) identifies 12 risks, including confabulation, data privacy, information security, and value chain and component integration, with suggested actions mapped to the same four functions.3 Neither document is a certification. Their value is a defensible structure and a shared vocabulary with auditors and examiners.

Sector considerations

Healthcare organizations should confirm that any AI service receiving protected health information operates under a business associate agreement meeting the requirements of 45 CFR 164.504(e).4 AI features added to an existing platform may fall outside the scope of the agreement signed for that platform's original purpose.

Banking organizations should note that in April 2026 the federal banking agencies replaced SR 11-7 with revised model risk management guidance (SR 26-2). The revised guidance states that generative and agentic AI models are not within its scope, and the agencies have indicated they plan a separate request for information on AI use.56 Until further guidance is issued, institutions using generative AI need governance beyond their model risk management program, and the AI RMF offers a suitable framework.

Vendor review

Four questions determine most AI vendor decisions. Are the organization's inputs used to train the vendor's models, as stated in the contract rather than marketing materials? Where are data stored and for how long, including subprocessors? What are the known failure modes, and what is logged? Can the organization reconstruct what the system received and returned on a given date?

Practical takeaways

  • Build the AI system inventory before finalizing the policy.
  • Publish a consequence-based tiering rule that managers can apply without escalation.
  • Maintain a short list of pre-approved tools and a request process with a defined response time.
  • State which AI RMF version and profiles the program relies on, and monitor NIST for revisions.
  • Confirm contractual coverage, including business associate agreements, for every AI feature that receives regulated data.

References

  1. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," NIST AI 100-1, January 2023. nvlpubs.nist.gov
  2. National Institute of Standards and Technology, "AI Risk Management Framework." nist.gov/itl/ai-risk-management-framework
  3. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 2024. nvlpubs.nist.gov
  4. 45 CFR 164.504(e), Business associate contracts; and U.S. Department of Health and Human Services, "Business Associates." hhs.gov
  5. Board of Governors of the Federal Reserve System, "Revised Guidance on Model Risk Management," SR 26-2, April 2026. federalreserve.gov
  6. Office of the Comptroller of the Currency, "Model Risk Management: Revised Guidance," OCC Bulletin 2026-13. occ.gov
Discuss this topic

DefenseLogix supports regulated and trust-sensitive organizations with this work. To discuss your organization's situation, start a conversation or review the AI Risk Management service.