Govern
Cultivate a risk-management culture with clear accountability
Govern is the cross-cutting function that makes the other three work: policies, roles, and accountability for AI risk have to exist before anyone can map or measure anything. It calls for documented AI policies, defined risk tolerance, clear ownership, and processes that keep working as tools and staff change.
For data privacy, Govern means someone owns the question of which AI tools employees may use and with what data. An organization where 63% is the norm (IBM found in 2025 that 63% of organizations have no AI governance policy) fails this function on day one. A written acceptable-use policy, an approved-tools list, and a named owner are the minimum evidence.
Map
Establish context and identify where AI touches your data
Map asks the organization to inventory its AI systems and understand the context each one operates in: what data goes in, who is affected, what could go wrong. You cannot manage a risk you have not located.
The hard part of Map in practice is not the AI you bought, it is the AI employees adopted on their own. Prompts to consumer chatbots are AI data flows like any other, and LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage. Mapping means discovering actual usage across the organization, not just listing sanctioned vendors.
Measure
Assess, analyze, and track AI risks with evidence
Measure turns the Map inventory into tracked, quantified risk: test systems, monitor them in use, and measure whether controls work. It explicitly covers privacy risk alongside safety, security, and bias.
For privacy, Measure means being able to answer with evidence: how often does confidential or personal data leave in prompts, of what types, to which tools? An organization that cannot produce those numbers is not measuring. Point-of-entry monitoring of prompts is what makes the answer verifiable rather than a guess.
Manage
Act on mapped and measured risks with real controls
Manage is where risk treatment happens: prioritize the risks surfaced by Map and Measure, apply controls proportionate to them, respond to incidents, and feed lessons back into governance.
For data flowing into AI tools, Manage means technical controls at the point of entry, not just policy documents. IBM's 2025 breach study found only 17% of organizations have technical controls that redact or block sensitive data at the point of entry, and that shadow AI involvement added an average of $670K to breach costs. Policy without enforcement is a documented risk you chose not to treat.