Module v1.0 · Required
Govern and Map a Financial Services AI Use Case
A practical guide to defining purpose, roles, boundaries, data, affected people, and regulated decision limits.
Apply the Govern and Map functions to a bounded financial-services operations use case and identify where human authority, compliance review, and prohibited-use boundaries must remain explicit.
Purpose, authority, and accountable roles
Make the intended benefit, owner, reviewer, and decision boundary explicit.
Start with a specific operational purpose: drafting a service response, organizing a compliance case, identifying missing fields in a fictional intake form, or retrieving an approved internal policy excerpt. State what the system may assist with and what it may not decide. A useful governance record names the business owner, operational reviewer, compliance and risk partners, privacy and security partners, affected people, escalation owner, and the person who can pause or retire the use case.
NIST's Govern function is not a one-time approval. It creates the policies, roles, resources, and accountability that remain in place as the use case, vendor, data, or regulation changes.
- The purpose and expected benefit are written in plain language
- Prohibited uses and consequential decision boundaries are visible
- A named owner and accountable reviewer are assigned
- Compliance, risk, privacy, security, and business contacts are identified
- A pause, rollback, or retirement authority exists