Acceptable use
Define approved, restricted and prohibited uses.
Practical, NIST-aware governance as an operating capability.
Define approved, restricted and prohibited uses.
Track tools, vendors, owners, data and purposes.
Scale controls to impact and context.
Match information and environments to the use.
Assess identity, integration, logging and incidents.
Consider creation, retention and disclosure.
Document and communicate use appropriately.
Assign meaningful review responsibility.
Evaluate suppliers, changes and portability.
Build inclusive access into services.
Keep proportionate records of decisions.
Reassess as tools, law and needs change.
Assess maturity, workflows, data, technology, workforce readiness, risk and high-value opportunities.
Establish ownership, acceptable use, risk tiers, privacy, security, records, accessibility and oversight.
Implement appropriate automation, assistants, document intelligence, integrations and service support.
Measure performance, adoption, quality, service impact, risk and the next opportunity.
CivicOrigin can map practices to the voluntary NIST AI Risk Management Framework. This does not imply certification or endorsement.