Eventually the system needs named people who own the yes-or-no decisions around it. NIST AI RMF organizes that work through Govern, Map, Measure and Manage, and the Generative AI Profile applies the framework to generative AI. These are voluntary risk-management resources, not a certificate that a system is safe. [1–2]
For Northstar, ownership should be explicit before rollout. HR owns policy interpretation. Security owns the relevant security review. The platform team operates the service. A named business owner accepts remaining risk within organizational authority. The model owns none of those decisions.
Govern. Record permitted uses, prohibited actions, responsible owners and escalation routes. Define who may approve changes to the tool set or data scope. Make it possible to suspend the service when controls fail.
Map. Describe the users, affected people, data sources and consequences of error. An employee assistant that drafts a policy explanation has a different impact from one that recommends denying leave or ranks employees. Identify where users might mistake generated text for an authoritative decision.
Measure. Test the relevant outcomes and harms. Alongside correctness, inspect privacy exposure, unsupported claims, uneven performance across relevant groups and dependence on unreliable sources. Choose evaluation populations that reflect the actual use, rather than only the easiest cases.
Manage. Decide what to fix, limit, monitor or stop. Record why remaining risk is accepted and when the decision must be revisited. Connect monitoring to an operational response, rather than collecting scores with no action attached.
HR decisions need more than accurate extraction
An approved assistant can help HR find policy clauses and draft a response. Once the same tool starts inferring health, ranking candidates or recommending discipline, the purpose and potential harm have changed. Reassess the data, criteria, review path and the ability of affected people to challenge an error before treating that use as acceptable.
Ask whether the data is necessary, whether the decision criteria are defensible and how affected people can correct errors or seek review. Keep confidential information out of general-purpose traces. When the assistant cannot resolve a case, staff need a reliable route to a person. Chapter 4 covers the overreliance side of the same problem.
The references identify the exact NIST, OWASP and MCP editions used for this guide. That matters because overview pages can remain online after newer publications or protocol versions appear.