Question 23
Domain 1 — AI Governance and Risk ManagementThe NIST AI Risk Management Framework (AI RMF) includes four core functions. Which function is considered foundational because it enables and underpins all the other three?
Correct answer: D
Explanation
"Govern" is foundational in the NIST AI RMF because it establishes the policies, processes, and oversight that guide AI risk management across the organization. NIST describes the Govern function as the basis that "enables and underpins" the other core functions—Map, Measure, and Manage—by setting accountability and direction.
Why each option is right or wrong
A. Identify
B. Measure
C. Manage
D. Govern
NIST AI RMF 1.0 (NIST AI 100-1, Jan. 2023) organizes the framework into four core functions: Govern, Map, Measure, and Manage. In the framework’s structure, Govern is identified as the cross-cutting function that establishes the organization’s risk management culture, policies, roles, and oversight, which is why it is described as enabling and underpinning the other three functions rather than operating as a standalone technical step.