AI governance: assign a decision-maker to each risk decision

Relevant ownership lies in the decision
The useful question is not who holds all the AI roles, but who is allowed to make or reverse a specific choice: may this workflow send customer data to this model, is human oversight needed, and when is the workflow switched off? NIST describes governance and oversight tasks as the work of actors with management, fiduciary, and legal authority and responsibility. This does not support a prescribed org chart, but it does support the principle that authority must be visible at the point of decision.
Use the four functions to organize, not as a checklist
The NIST AI RMF Playbook organizes suggestions under Govern, Map, Measure, and Manage. These suggestions are voluntary, and the Playbook explicitly is not a checklist that must be followed in full. Use the functions to examine a single workflow: determine the objective and stakeholders, describe the data flow and potential harm, test the output, and manage the outcome with a stop or escalation decision. The appropriate level of depth depends on the specific application and context.

A decision card for one AI workflow
For the next change, create a card with six fields: the decision, the decision-maker, the relevant workflow and data, the required evidence, the stop threshold, and the reassessment date. For example, before a model may draft customer emails, the product owner documents which evaluation examples were reviewed; security gets an explicit stop threshold in the event of an access incident; following a change to the model, prompt, or data source, a new assessment takes place. Use this as a working rule: "For each AI workflow, document: decision, authorized owner, data used, test evidence, stop threshold, and next reassessment." This turns an abstract owner into a verifiable action.
What a card does not solve
The card makes a decision traceable, but it does not provide authority, expertise, or time. "A decision card does not replace authority, expertise, or available time; rehearse the stop threshold and adjust the evidence burden to the potential harm." Therefore, for a meaningful workflow, schedule a short exercise: have the designated decision-maker assess an error signal, stop the workflow, and document what is required to restart it. For a simple internal application, the same card can remain brief; the source passages provide no universal thresholds, legal classifications, or guarantees about outcomes.




