AIGO — AI Governance Operating Framework
Framework Principles
Version: 0.1Status: Draft
Working Name: AIGO
Full Name: AI Governance Operating Framework
1. Purpose of the Principles
The AIGO Framework Principles define the fundamental governance expectations that should guide the design, implementation, operation, monitoring, and continuous improvement of AI systems. The principles provide the foundation for the AIGO governance model and establish a common basis for organizational decision-making.2. Application of the Principles
Organizations should use the AIGO principles when establishing AI governance policies, procedures, controls, responsibilities, risk management activities, and operational practices. The principles should be considered throughout the AI system lifecycle. They may be applied to:- AI strategy;
- AI system design;
- AI development;
- AI procurement;
- AI deployment;
- AI operation;
- AI monitoring;
- AI change management;
- AI incident management; and
- AI system retirement.
3. Principle Structure
Each AIGO principle should define:- principle identifier;
- principle name;
- principle statement;
- purpose;
- governance expectations;
- implementation considerations;
- evidence considerations; and
- related AIGO domains or controls where applicable.
4. Core AIGO Principles
The AIGO framework establishes a core set of principles covering areas including:- accountability and responsibility;
- human oversight;
- risk-based governance;
- transparency;
- traceability;
- security;
- privacy;
- data governance;
- reliability and resilience;
- fairness and appropriate treatment;
- proportionality;
- lifecycle governance;
- continuous monitoring;
- continuous improvement;
- third-party governance;
- evidence-based assurance; and
- technology independence.
5. Principle Identification
Each AIGO principle should have a stable identifier. A conceptual identifier format is:AIGO-PRN-001
Additional principles may use:
AIGO-PRN-002
AIGO-PRN-003
AIGO-PRN-004
The final identifier convention should be defined consistently across the AIGO framework.
6. Relationship to Controls
AIGO principles establish high-level governance expectations. Controls should translate these expectations into specific organizational requirements. A conceptual relationship is: Principle → Governance Requirement → Control → Procedure → Evidence This relationship should allow organizations to trace operational activities back to the fundamental principles of the framework.7. Relationship to Risk
AIGO principles should be applied using a risk-based approach. Not every AI system presents the same level or type of risk. Organizations should consider the characteristics, purpose, impact, autonomy, data, users, deployment environment, and other relevant factors when determining how principles should be implemented.8. Relationship to Organizational Context
Organizations may adapt the implementation of AIGO principles according to:- organizational size;
- industry;
- jurisdiction;
- AI maturity;
- system complexity;
- risk exposure;
- business objectives;
- regulatory environment; and
- organizational policies.
9. Principle Governance
AIGO principles should be reviewed periodically to ensure that they remain relevant to:- emerging AI technologies;
- changing AI risks;
- organizational experience;
- external standards;
- regulatory developments;
- security developments; and
- evolving governance practices.
10. Accountability and Responsibility
Identifier:AIGO-PRN-001
10.1 Principle Statement
Organizations should establish clear accountability and responsibility for the governance, development, deployment, operation, monitoring, and retirement of AI systems. AI governance responsibilities should be assigned to identifiable roles, functions, or organizational authorities. Responsibility should not be assumed to belong exclusively to technical teams or AI developers.10.2 Purpose
The purpose of this principle is to ensure that AI-related decisions have clear ownership and that organizations can determine who is responsible for:- approving AI systems;
- managing AI risks;
- implementing controls;
- monitoring system performance;
- responding to incidents;
- maintaining evidence;
- reviewing changes; and
- making decisions throughout the AI lifecycle.
10.3 Governance Expectations
Organizations should:- define AI governance responsibilities;
- assign accountable owners for AI systems;
- define decision-making authority;
- establish escalation paths;
- document relevant responsibilities;
- separate responsibilities where appropriate;
- ensure appropriate management oversight; and
- periodically review assigned responsibilities.
10.4 AI System Ownership
Each AI system should have an identifiable owner or accountable organizational function. The AI System Owner should have sufficient authority and organizational support to coordinate governance activities relevant to the system.10.5 Responsibility Across the Lifecycle
Responsibilities should be considered throughout the AI system lifecycle. Relevant responsibilities may exist during:- conception;
- assessment;
- design;
- development;
- testing;
- approval;
- deployment;
- operation;
- monitoring;
- change;
- incident response; and
- retirement.
10.6 Shared Responsibility
AI governance may involve multiple organizational functions. Relevant responsibilities may be distributed across:- executive leadership;
- business owners;
- AI governance teams;
- risk and compliance;
- legal;
- privacy;
- information security;
- engineering;
- data teams;
- AI operations;
- procurement;
- internal audit; and
- end users.
10.7 Accountability Matrix
Organizations should establish an appropriate responsibility model for significant AI systems. This may include a responsibility matrix such as:- Responsible;
- Accountable;
- Consulted; and
- Informed.
10.8 Separation of Duties
Organizations should consider separation of duties where the level of risk or organizational context requires it. For example, where appropriate, the person responsible for implementing an AI system may not be the sole person responsible for approving its production deployment.10.9 Management Accountability
Organizational leadership should provide appropriate oversight of AI governance. Leadership responsibilities may include:- approving AI governance policies;
- establishing organizational expectations;
- allocating resources;
- reviewing significant AI risks;
- approving risk acceptance where appropriate; and
- ensuring governance responsibilities are effectively assigned.
10.10 Delegated Authority
Organizations may delegate AI governance responsibilities. Delegated responsibilities should be:- clearly defined;
- documented;
- appropriately authorized;
- supported by sufficient competence; and
- subject to appropriate oversight.
10.11 Competence and Authority
Individuals assigned AI governance responsibilities should have appropriate competence, resources, and authority to perform their responsibilities. Competence may include knowledge of:- AI technologies;
- organizational processes;
- risk management;
- security;
- privacy;
- data governance;
- applicable requirements; and
- relevant AIGO requirements.
10.12 Documentation
Organizations should maintain appropriate documentation of AI governance responsibilities. Documentation may include:- organizational policies;
- role descriptions;
- responsibility matrices;
- governance committee structures;
- approval records;
- system ownership records; and
- escalation procedures.
10.13 Accountability for Third-Party AI
Where an organization uses third-party AI systems or services, it should establish internal accountability for their use. Use of an external provider should not automatically eliminate the organization’s responsibility for appropriate governance of the AI capability within its environment.10.14 Accountability for Autonomous Systems
Where an AI system can independently perform actions, organizations should establish clear human and organizational accountability for the system’s authorized behavior. Autonomy should not be treated as a transfer of organizational responsibility to the AI system.10.15 Accountability for AI-Assisted Decisions
Where AI contributes materially to a decision affecting individuals, customers, employees, or other stakeholders, appropriate responsibility for the decision process should remain assigned to authorized human or organizational decision-makers.10.16 Escalation
Organizations should establish escalation mechanisms for significant:- AI incidents;
- governance failures;
- unexpected system behavior;
- security events;
- privacy events;
- material risk changes;
- control failures; and
- regulatory concerns.
10.17 Periodic Review
AI governance responsibilities should be reviewed periodically and whenever significant changes occur. Reviews may be triggered by:- organizational restructuring;
- changes in AI system ownership;
- major technology changes;
- changes in risk classification;
- new regulatory requirements;
- significant incidents; or
- changes to business processes.
10.18 Evidence
Evidence demonstrating implementation of this principle may include:- approved policies;
- responsibility matrices;
- role descriptions;
- governance committee records;
- system ownership records;
- approval records;
- escalation procedures;
- training records; and
- periodic governance reviews.
10.19 Principle Outcome
The intended outcome of this principle is that an organization can clearly identify:- who owns an AI system;
- who is responsible for its operation;
- who approves significant decisions;
- who manages relevant risks;
- who monitors the system;
- who responds to incidents; and
- who has authority to intervene or stop the system when necessary.
11. Human Oversight
Identifier:AIGO-PRN-002
11.1 Principle Statement
AI systems should operate with an appropriate level of human oversight proportionate to their purpose, autonomy, potential impact, and associated risks.11.2 Purpose
Human oversight is intended to ensure that organizations retain appropriate control over AI systems and can identify, review, challenge, intervene in, or stop AI-supported activities when necessary.11.3 Governance Expectations
Organizations should determine:- whether human oversight is required;
- the appropriate level of oversight;
- who performs the oversight;
- when intervention is required;
- what decisions require human approval; and
- how oversight activities are documented.
11.4 Proportional Oversight
The level of human oversight should be proportionate to factors such as:- potential harm;
- system autonomy;
- decision impact;
- uncertainty;
- affected stakeholders;
- operational environment; and
- ability to reverse an AI-generated action.
11.5 Human Intervention
Where appropriate, authorized individuals should have the ability to:- pause an AI process;
- reject an AI recommendation;
- override an AI decision;
- modify system behavior;
- disable an AI capability; or
- initiate emergency procedures.
11.6 Oversight Competence
Individuals responsible for human oversight should have sufficient knowledge and authority to understand the relevant AI system and appropriately evaluate its outputs or actions.11.7 Automation Boundaries
Organizations should define boundaries for what an AI system may perform autonomously and what activities require human authorization.11.8 Evidence
Evidence may include:- oversight procedures;
- approval records;
- intervention logs;
- escalation records;
- system configuration;
- access permissions;
- monitoring records; and
- training records.
11.9 Principle Outcome
The intended outcome is that AI autonomy remains appropriately controlled and that authorized humans retain meaningful oversight over AI systems where required by risk and context.12. Risk-Based Governance
Identifier:AIGO-PRN-003
12.1 Principle Statement
AI governance should be based on the risks, potential impacts, characteristics, and context of each AI system. Organizations should avoid applying identical governance requirements to every AI system regardless of risk.12.2 Purpose
The purpose of this principle is to ensure that governance resources and controls are proportionate to the potential risks associated with an AI system.12.3 Governance Expectations
Organizations should:- identify relevant AI risks;
- assess potential impacts;
- determine an appropriate risk level;
- establish controls proportionate to risk;
- document significant risk decisions;
- monitor changes in risk; and
- periodically reassess AI systems.
12.4 Risk Factors
Relevant risk factors may include:- intended purpose;
- affected individuals or groups;
- potential harm;
- level of autonomy;
- decision-making authority;
- sensitivity of data;
- system complexity;
- model capabilities;
- external dependencies;
- operational environment;
- reversibility of actions;
- scale of deployment; and
- likelihood and severity of potential impacts.
12.5 Risk Classification
Organizations should establish an appropriate method for classifying AI system risk. AIGO may support classifications such as:- low risk;
- moderate risk;
- high risk; and
- critical or restricted risk.
12.6 Proportionality
Governance requirements should be proportionate to the level of risk. Higher-risk systems may require additional:- assessments;
- approvals;
- testing;
- monitoring;
- human oversight;
- documentation;
- security controls;
- privacy controls;
- incident management; and
- assurance activities.
12.7 Risk Acceptance
Where residual AI risk remains after controls are implemented, organizations should establish an appropriate risk acceptance process. Risk acceptance should be performed by an authorized individual or organizational function with appropriate authority.12.8 Risk Escalation
AI risks should be escalated when they exceed established organizational thresholds or when new information materially changes the risk profile.12.9 Continuous Risk Assessment
AI risk should not be treated as a one-time assessment. Organizations should reassess risk when:- system functionality changes;
- models change;
- data sources change;
- deployment environments change;
- new use cases are introduced;
- incidents occur;
- new vulnerabilities are identified;
- external requirements change; or
- system behavior materially changes.
12.10 Evidence
Evidence may include:- AI risk assessments;
- risk classification records;
- risk registers;
- risk acceptance records;
- mitigation plans;
- review records;
- escalation records; and
- monitoring results.
12.11 Principle Outcome
The intended outcome is that AI governance is proportionate to risk and that significant AI risks are identified, assessed, managed, monitored, and appropriately accepted or escalated.13. Transparency and Explainability
Identifier:AIGO-PRN-004
13.1 Principle Statement
Organizations should provide an appropriate level of transparency regarding AI systems, their purpose, capabilities, limitations, governance, and relevant decisions.13.2 Purpose
Transparency enables relevant stakeholders to understand how an AI system is used, what role it performs, what limitations may exist, and where responsibility lies.13.3 Governance Expectations
Organizations should document appropriate information about AI systems, including where relevant:- system purpose;
- intended use;
- prohibited or restricted use;
- system owner;
- relevant data sources;
- model or service dependencies;
- significant limitations;
- known risks;
- human oversight;
- monitoring arrangements; and
- change history.
13.4 Stakeholder Transparency
The level and form of transparency should be appropriate to the stakeholder. Relevant stakeholders may include:- employees;
- customers;
- users;
- management;
- regulators;
- auditors;
- affected individuals;
- suppliers; and
- internal governance functions.
13.5 AI Interaction Disclosure
Where appropriate, organizations should inform users when they are interacting with an AI system rather than a human. The implementation of such disclosure should consider the applicable organizational, legal, regulatory, and contextual requirements.13.6 Explainability
Where AI outputs materially influence decisions or actions, organizations should consider whether an appropriate explanation of the relevant process or outcome is required. Explainability should be proportionate to:- system complexity;
- decision impact;
- risk;
- affected stakeholders; and
- applicable requirements.
13.7 Limitations
Organizations should communicate relevant limitations of AI systems where those limitations could materially affect the interpretation or use of outputs. Examples may include:- uncertainty;
- known failure conditions;
- data limitations;
- model limitations;
- unsupported use cases; and
- known accuracy limitations.
13.8 Documentation
Organizations should maintain appropriate documentation that enables authorized stakeholders to understand the AI system and its governance.13.9 Evidence
Evidence may include:- AI system documentation;
- user notices;
- system descriptions;
- model documentation;
- limitation statements;
- decision records;
- governance records; and
- communication materials.
13.10 Principle Outcome
The intended outcome is that relevant stakeholders have sufficient information to understand the role, purpose, limitations, and governance of an AI system.14. Traceability and Recordkeeping
Identifier:AIGO-PRN-005
14.1 Principle Statement
Organizations should maintain sufficient records and traceability to understand the lifecycle, configuration, decisions, changes, and significant events associated with AI systems.14.2 Purpose
Traceability supports accountability, investigation, monitoring, assurance, incident response, and continuous improvement.14.3 Governance Expectations
Organizations should establish appropriate mechanisms for recording:- AI system identity;
- ownership;
- approvals;
- risk assessments;
- relevant versions;
- significant configuration changes;
- data sources;
- model or provider changes;
- significant incidents;
- monitoring results;
- governance decisions; and
- retirement activities.
14.4 Lifecycle Traceability
Organizations should maintain sufficient information to establish the history of an AI system throughout its lifecycle. This may include traceability from: Idea → Assessment → Design → Development → Testing → Approval → Deployment → Operation → Change → Retirement14.5 Change Traceability
Material changes to AI systems should be documented. Changes may include:- model changes;
- prompt or instruction changes;
- data source changes;
- retrieval changes;
- system architecture changes;
- agent behavior changes;
- permission changes;
- vendor changes; and
- significant configuration changes.
14.6 Evidence Integrity
Records used as governance evidence should be maintained with appropriate controls to protect their integrity, availability, and accessibility.14.7 Retention
Organizations should establish appropriate retention requirements for AI governance records based on:- organizational policy;
- business requirements;
- risk;
- contractual obligations;
- applicable requirements; and
- the nature of the record.
14.8 Accessibility
Authorized personnel should be able to access relevant AI governance records when required for:- audits;
- investigations;
- incident response;
- risk assessments;
- management review; and
- regulatory or contractual activities.
14.9 Evidence
Evidence may include:- AI system inventories;
- version records;
- change logs;
- approval records;
- risk assessments;
- incident records;
- monitoring records;
- audit trails; and
- retirement records.
14.10 Principle Outcome
The intended outcome is that organizations can reconstruct relevant aspects of an AI system’s lifecycle and governance history when required.15. Security
Identifier:AIGO-PRN-006
15.1 Principle Statement
AI systems should be protected against security threats and unauthorized use throughout their lifecycle.15.2 Purpose
The purpose of this principle is to ensure that AI systems, their data, models, interfaces, infrastructure, and supporting services are subject to appropriate security governance.15.3 Governance Expectations
Organizations should consider security risks affecting:- AI models;
- applications;
- APIs;
- prompts and instructions;
- data;
- retrieval systems;
- agents;
- tools;
- integrations;
- infrastructure;
- identities;
- credentials; and
- third-party services.
15.4 Access Control
Access to AI systems and supporting resources should be controlled according to organizational security requirements and risk. Access should follow appropriate principles such as:- least privilege;
- need to know;
- role-based access; and
- appropriate authentication.
15.5 AI-Specific Threats
Organizations should consider threats relevant to AI systems, including where applicable:- prompt injection;
- malicious instructions;
- unauthorized model access;
- data leakage;
- sensitive information exposure;
- malicious or manipulated training data;
- retrieval manipulation;
- unauthorized tool execution;
- excessive agent permissions;
- model abuse; and
- supply-chain risks.
15.6 Security Testing
AI systems should undergo security testing proportionate to their risk and intended use. Testing may include:- vulnerability assessment;
- adversarial testing;
- access-control testing;
- prompt injection testing;
- data leakage testing;
- abuse testing; and
- security configuration review.
15.7 Security Monitoring
Organizations should monitor relevant security events and indicators associated with AI systems.15.8 Incident Response
AI-related security incidents should be incorporated into appropriate organizational incident response processes.15.9 Third-Party Security
Organizations should consider the security posture of third-party AI providers, models, APIs, tools, and services used within AI systems.15.10 Evidence
Evidence may include:- access-control records;
- security assessments;
- vulnerability reports;
- penetration testing results;
- monitoring records;
- incident records;
- security reviews; and
- third-party assessments.
15.11 Principle Outcome
The intended outcome is that AI systems are protected against reasonably foreseeable security threats throughout their lifecycle.16. Privacy and Data Protection
Identifier:AIGO-PRN-007
16.1 Principle Statement
Organizations should govern the collection, use, processing, storage, transmission, and disposal of personal data within AI systems in accordance with applicable requirements and organizational policies.16.2 Purpose
The purpose of this principle is to ensure that privacy and data protection considerations are integrated into AI governance rather than treated as an isolated activity.16.3 Governance Expectations
Organizations should consider:- whether personal data is processed;
- the purpose of processing;
- data minimization;
- appropriate access;
- retention;
- data sharing;
- third-party processing;
- security;
- privacy risks; and
- applicable data protection requirements.
16.4 Data Minimization
AI systems should use only the data reasonably necessary for their intended purpose, where applicable requirements and organizational policies require such limitation.16.5 Sensitive Data
Organizations should identify and appropriately govern sensitive or otherwise protected information processed by AI systems.16.6 Privacy Risk Assessment
Where appropriate, organizations should conduct privacy risk assessments before deploying or materially changing AI systems that process personal data.16.7 Third-Party Processing
Organizations should understand relevant privacy implications when personal data is transmitted to external AI providers or other third parties.16.8 Data Retention
Organizations should establish appropriate retention and deletion practices for personal data processed by AI systems.16.9 Evidence
Evidence may include:- privacy assessments;
- data inventories;
- data-flow documentation;
- processing records;
- retention policies;
- contractual records;
- access records; and
- privacy review decisions.
16.10 Principle Outcome
The intended outcome is that privacy and data protection risks associated with AI systems are identified, assessed, controlled, and monitored appropriately.17. Data Governance
Identifier:AIGO-PRN-008
17.1 Principle Statement
Data used by or produced by AI systems should be governed according to its purpose, quality, sensitivity, provenance, lifecycle, and associated risks.17.2 Purpose
The purpose of this principle is to establish confidence that data supporting AI systems is appropriately managed and fit for its intended use.17.3 Governance Expectations
Organizations should consider:- data provenance;
- data quality;
- data relevance;
- data integrity;
- data sensitivity;
- data ownership;
- access rights;
- retention;
- transformation;
- lineage; and
- intended use.
17.4 Data Quality
Organizations should establish appropriate data quality expectations for AI systems where data quality could materially affect system performance or risk.17.5 Data Provenance
Where practical, organizations should maintain information about the origin and relevant processing history of important data used by AI systems.17.6 Data Lineage
For higher-risk AI systems, organizations should consider maintaining sufficient lineage information to understand how important data moves through the AI system.17.7 Data Access
Access to AI-related data should be governed according to organizational security, privacy, and data governance requirements.17.8 Data Change
Material changes to important data sources should be evaluated for their potential effect on AI system behavior and risk.17.9 Evidence
Evidence may include:- data inventories;
- data dictionaries;
- lineage records;
- data quality assessments;
- data ownership records;
- access records;
- source documentation; and
- data review records.
17.10 Principle Outcome
The intended outcome is that organizations understand and appropriately govern the data that materially supports AI system behavior and outcomes.18. Reliability, Resilience, and Performance
Identifier:AIGO-PRN-009
18.1 Principle Statement
AI systems should be designed, deployed, and operated with appropriate levels of reliability, resilience, availability, and performance according to their intended purpose and risk.18.2 Purpose
The purpose of this principle is to reduce the likelihood and impact of AI system failures and ensure that organizations can respond appropriately when failures occur.18.3 Governance Expectations
Organizations should establish appropriate expectations for:- availability;
- reliability;
- performance;
- capacity;
- error handling;
- recovery;
- continuity; and
- operational resilience.
18.4 Failure Management
Organizations should consider foreseeable AI system failure conditions and define appropriate responses.18.5 Graceful Degradation
Where appropriate, AI systems should be capable of degrading safely when:- models are unavailable;
- external services fail;
- data sources become unavailable;
- confidence is insufficient;
- system limits are exceeded; or
- unexpected behavior is detected.
18.6 Business Continuity
AI systems supporting important business processes should be considered within relevant business continuity and disaster recovery planning.18.7 Performance Monitoring
Organizations should monitor relevant performance indicators according to the purpose and risk of the AI system.18.8 Evidence
Evidence may include:- performance metrics;
- service-level records;
- availability records;
- incident reports;
- recovery tests;
- continuity plans;
- capacity assessments; and
- monitoring records.
18.9 Principle Outcome
The intended outcome is that AI systems operate reliably within their intended context and that organizations can respond effectively to failures or disruptions.19. Fairness and Appropriate Treatment
Identifier:AIGO-PRN-010
19.1 Principle Statement
Organizations should consider whether AI systems may produce unjustified or inappropriate differences in outcomes or treatment and should manage relevant risks according to their context and applicable requirements.19.2 Purpose
The purpose of this principle is to encourage organizations to identify and manage risks associated with unfair or inappropriate AI outcomes.19.3 Governance Expectations
Organizations should consider:- affected populations;
- intended outcomes;
- relevant differences in treatment;
- data limitations;
- potential bias;
- system performance across relevant groups;
- applicable requirements; and
- appropriate mitigation measures.
19.4 Contextual Assessment
Fairness considerations should be assessed according to the intended purpose and context of the AI system. A single fairness metric or approach may not be appropriate for every AI use case.19.5 Testing
Where relevant, organizations should evaluate AI system behavior for potential unfair or inappropriate outcomes.19.6 Monitoring
For systems where fairness-related risks are material, organizations should monitor relevant indicators over time.19.7 Evidence
Evidence may include:- impact assessments;
- testing results;
- monitoring reports;
- risk assessments;
- mitigation decisions; and
- governance reviews.
19.8 Principle Outcome
The intended outcome is that relevant risks of unfair or inappropriate AI outcomes are identified, evaluated, and managed according to the system’s context and risk.20. Lifecycle Governance
Identifier:AIGO-PRN-011
20.1 Principle Statement
AI systems should be governed throughout their lifecycle rather than only at the point of deployment.20.2 Purpose
The purpose of this principle is to ensure that governance remains active from initial conception through retirement.20.3 Governance Expectations
Organizations should establish governance activities across relevant lifecycle stages, including:- initiation;
- assessment;
- design;
- development;
- testing;
- approval;
- deployment;
- operation;
- monitoring;
- change;
- review; and
- retirement.
20.4 Lifecycle Gates
Organizations may establish governance gates requiring specific approvals or evidence before an AI system progresses to the next lifecycle stage.20.5 Change Management
Material changes should trigger an appropriate review to determine whether:- risk has changed;
- controls remain appropriate;
- testing should be repeated;
- approval is still valid; or
- additional governance activities are required.
20.6 Retirement
Organizations should establish appropriate procedures for retiring AI systems. Retirement may include:- disabling services;
- removing access;
- handling retained data;
- preserving required records;
- terminating third-party services; and
- updating inventories.
20.7 Evidence
Evidence may include:- lifecycle records;
- approval gates;
- change requests;
- testing records;
- deployment approvals;
- monitoring records; and
- retirement records.
20.8 Principle Outcome
The intended outcome is that AI governance remains active and traceable throughout the complete lifecycle of an AI system.21. Continuous Monitoring
Identifier:AIGO-PRN-012
21.1 Principle Statement
AI systems should be monitored throughout their operational lifecycle to identify material changes, failures, unexpected behavior, emerging risks, and deviations from intended performance or governance requirements.21.2 Purpose
The purpose of this principle is to ensure that organizations do not rely solely on pre-deployment assessments and that relevant AI risks continue to be managed during operation.21.3 Governance Expectations
Organizations should establish monitoring appropriate to the AI system’s:- purpose;
- risk level;
- autonomy;
- operational environment;
- expected performance;
- data dependencies; and
- potential impact.
21.4 Monitoring Areas
Where relevant, monitoring may include:- system availability;
- performance;
- output quality;
- accuracy;
- errors;
- abnormal behavior;
- security events;
- privacy events;
- data changes;
- model changes;
- usage patterns;
- policy violations;
- incidents; and
- emerging risks.
21.5 Monitoring Thresholds
Organizations should establish appropriate thresholds or indicators for determining when investigation or escalation is required.21.6 Human Review
Monitoring results should be reviewed by appropriately authorized personnel when automated monitoring alone is insufficient.21.7 Monitoring Changes
Monitoring requirements should be reviewed when material changes are made to an AI system or its operating environment.21.8 Evidence
Evidence may include:- monitoring dashboards;
- performance reports;
- alerts;
- logs;
- review records;
- incident records;
- investigation records; and
- escalation records.
21.9 Principle Outcome
The intended outcome is that material changes, failures, and emerging risks are detected and addressed during the operational lifecycle of AI systems.22. Continuous Improvement
Identifier:AIGO-PRN-013
22.1 Principle Statement
AI governance should be continuously reviewed and improved based on operational experience, incidents, assessments, monitoring results, technological developments, organizational changes, and emerging risks.22.2 Purpose
The purpose of this principle is to ensure that AI governance does not become static as AI technologies, organizational practices, and risks evolve.22.3 Governance Expectations
Organizations should establish mechanisms to:- review governance performance;
- identify deficiencies;
- analyze incidents;
- evaluate lessons learned;
- update controls;
- improve procedures;
- address recurring issues; and
- monitor emerging AI risks.
22.4 Lessons Learned
Significant incidents, failures, investigations, assessments, and operational experiences should be used to identify opportunities for improvement.22.5 Corrective Actions
Where governance deficiencies are identified, organizations should establish appropriate corrective actions. Corrective actions should have:- an identified owner;
- appropriate priority;
- defined actions;
- appropriate target dates; and
- evidence of completion where required.
22.6 Framework Improvement
Organizations using AIGO should periodically review whether the framework remains appropriate for their organizational context. AIGO itself should also evolve through its framework governance and version-management processes.22.7 Evidence
Evidence may include:- management reviews;
- corrective action records;
- lessons-learned reports;
- improvement plans;
- updated procedures;
- revised controls; and
- governance review records.
22.8 Principle Outcome
The intended outcome is that AI governance continuously improves based on evidence, experience, changing risks, and organizational needs.23. Third-Party and Supply Chain Governance
Identifier:AIGO-PRN-014
23.1 Principle Statement
Organizations should appropriately govern third-party AI systems, models, services, tools, data sources, infrastructure, and other dependencies that materially contribute to an AI capability.23.2 Purpose
AI systems frequently depend on external providers and components. Third-party dependencies may introduce risks related to:- security;
- privacy;
- availability;
- reliability;
- data processing;
- intellectual property;
- contractual obligations;
- model behavior;
- service changes; and
- concentration or dependency.
23.3 Governance Expectations
Organizations should assess relevant third-party risks before adopting significant AI services and periodically thereafter.23.4 Third-Party Assessment
Depending on risk, assessment may consider:- provider identity;
- service purpose;
- security controls;
- privacy practices;
- data processing;
- service availability;
- model or service limitations;
- change management;
- incident management;
- contractual terms; and
- exit arrangements.
23.5 Contractual Requirements
Where appropriate, organizations should establish contractual requirements covering relevant AI governance expectations. These may include:- security;
- privacy;
- confidentiality;
- service availability;
- incident notification;
- data handling;
- audit or assurance;
- change notification; and
- termination requirements.
23.6 Dependency Management
Organizations should maintain sufficient visibility into significant third-party dependencies supporting AI systems.23.7 Provider Changes
Material changes by third-party providers should be evaluated where they may affect:- system behavior;
- risk;
- security;
- privacy;
- performance;
- availability; or
- governance requirements.
23.8 Exit Planning
For important AI services, organizations should consider appropriate exit, replacement, or contingency strategies.23.9 Evidence
Evidence may include:- supplier assessments;
- contracts;
- security assessments;
- privacy assessments;
- service-level agreements;
- provider documentation;
- dependency inventories;
- review records; and
- exit plans.
23.10 Principle Outcome
The intended outcome is that material third-party AI dependencies are identified, assessed, monitored, and governed according to their risk and organizational importance.24. Evidence-Based Assurance
Identifier:AIGO-PRN-015
24.1 Principle Statement
AI governance should be supported by sufficient objective evidence to demonstrate that defined requirements, controls, procedures, and decisions have been implemented and operated appropriately.24.2 Purpose
Evidence enables organizations to demonstrate governance activities and supports:- management oversight;
- internal assurance;
- audits;
- investigations;
- risk management;
- continuous improvement; and
- accountability.
24.3 Governance Expectations
Organizations should determine what evidence is required for important governance activities. Evidence requirements should be proportionate to:- risk;
- system importance;
- regulatory context;
- organizational requirements; and
- assurance needs.
24.4 Evidence Types
Evidence may include:- policies;
- procedures;
- assessments;
- approvals;
- test results;
- monitoring records;
- logs;
- training records;
- incident records;
- risk decisions;
- meeting records; and
- audit results.
24.5 Evidence Traceability
Where practical, evidence should be traceable to:- a governance requirement;
- a control;
- an AI system;
- an owner;
- a date or relevant period; and
- the activity being demonstrated.
24.6 Evidence Integrity
Organizations should protect important governance evidence from unauthorized alteration, deletion, or inappropriate access.24.7 Evidence Retention
Evidence should be retained according to applicable organizational, contractual, legal, regulatory, and risk requirements.24.8 Assurance Activities
Organizations may perform assurance activities such as:- internal reviews;
- control assessments;
- independent assessments;
- audits;
- testing;
- management reviews; and
- external assurance.
24.9 Evidence Gaps
Where required evidence is unavailable or incomplete, organizations should assess the resulting governance risk and determine appropriate corrective action.24.10 Principle Outcome
The intended outcome is that organizations can demonstrate, with appropriate evidence, how AI governance requirements are implemented and operated.25. Proportionality
Identifier:AIGO-PRN-016
25.1 Principle Statement
AI governance requirements should be proportionate to the characteristics, purpose, risk, impact, complexity, and organizational context of an AI system.25.2 Purpose
Proportionality prevents governance from becoming unnecessarily burdensome for low-risk systems while ensuring that higher-risk systems receive appropriate scrutiny.25.3 Governance Expectations
Organizations should consider the appropriate level of:- documentation;
- assessment;
- approval;
- testing;
- monitoring;
- human oversight;
- security;
- privacy review;
- assurance; and
- evidence.
25.4 Risk-Based Scaling
Higher-risk systems should generally receive more extensive governance activities than low-risk systems where appropriate.25.5 Small and Low-Risk Systems
Organizations should be able to implement simplified governance processes for AI systems where the associated risks are demonstrably limited. Simplification should not eliminate necessary safeguards.25.6 High-Risk Systems
Higher-risk AI systems may require enhanced:- management oversight;
- risk assessment;
- testing;
- human oversight;
- monitoring;
- documentation;
- security controls;
- incident management; and
- independent assurance.
25.7 Organizational Context
Proportionality should consider organizational circumstances, including:- size;
- resources;
- industry;
- AI maturity;
- regulatory environment;
- operational complexity; and
- risk appetite.
25.8 Evidence
Organizations should document significant decisions regarding the proportional application of governance requirements.25.9 Principle Outcome
The intended outcome is that AIGO governance remains practical, effective, and appropriate to the risks and circumstances of each organization and AI system.26. Technology Independence
Identifier:AIGO-PRN-017
26.1 Principle Statement
AIGO governance requirements should remain independent of specific AI technologies, programming languages, development frameworks, model providers, cloud platforms, and implementation architectures unless a specific technology dependency is necessary to address a defined risk.26.2 Purpose
Technology independence allows organizations to apply AIGO across evolving AI technologies without requiring fundamental changes to the governance framework whenever technology changes.26.3 Governance Expectations
AIGO requirements should primarily describe:- governance outcomes;
- responsibilities;
- risks;
- controls;
- evidence;
- decision-making; and
- assurance expectations.
26.4 Framework Independence
Organizations should be able to implement AIGO alongside technologies and frameworks such as:- Python;
- AI and machine learning frameworks;
- agent frameworks;
- RAG systems;
- chatbot platforms;
- workflow systems;
- cloud AI services;
- proprietary AI platforms; and
- open-source AI technologies.
26.5 Implementation Flexibility
Organizations may select appropriate technologies and implementation methods provided that the resulting implementation satisfies applicable governance requirements.26.6 Technology Evolution
AIGO should be reviewed periodically to ensure that its governance model remains applicable to emerging technologies and AI architectures.26.7 Technology-Neutral Controls
Where practical, AIGO controls should describe the governance objective rather than prescribe a specific technical mechanism.26.8 Exceptions
A specific technical requirement may be introduced where necessary to address a defined security, privacy, safety, reliability, or governance risk. Such requirements should be justified and documented.26.9 Evidence
Evidence may include:- architecture documentation;
- technology assessments;
- governance decisions;
- control implementation records;
- risk assessments; and
- technical assurance records.
26.10 Principle Outcome
The intended outcome is that AIGO remains applicable across different AI technologies and implementation approaches while maintaining consistent governance expectations.27. Responsible and Sustainable AI
Identifier:AIGO-PRN-018
27.1 Principle Statement
Organizations should consider the broader organizational, societal, environmental, and operational impacts of AI systems and should seek to use AI in a responsible and sustainable manner appropriate to their context.27.2 Purpose
AI systems may create benefits while also producing broader impacts beyond immediate technical or business objectives. Organizations should therefore consider relevant impacts throughout the AI lifecycle.27.3 Governance Expectations
Where relevant, organizations should consider:- resource consumption;
- environmental impact;
- social impact;
- workforce impact;
- accessibility;
- stakeholder impact;
- responsible use;
- misuse risks; and
- long-term operational sustainability.
27.4 Appropriate Use
Organizations should define appropriate uses for AI systems and establish restrictions where specific uses may create unacceptable or disproportionate risks.27.5 Sustainability Considerations
Where material to the organization’s objectives or risk profile, organizations may consider:- computational resource consumption;
- infrastructure efficiency;
- model selection;
- system utilization;
- data storage;
- service dependencies; and
- lifecycle efficiency.
27.6 Stakeholder Impact
Organizations should consider potentially affected stakeholders when introducing or materially changing AI systems.27.7 Workforce Considerations
Where AI materially affects employees or work processes, organizations should consider appropriate organizational change, communication, training, and oversight.27.8 Accessibility
Where AI systems are intended for use by diverse populations, organizations should consider relevant accessibility requirements and practical usability.27.9 Evidence
Evidence may include:- impact assessments;
- sustainability assessments;
- stakeholder reviews;
- organizational policies;
- usage restrictions;
- accessibility assessments; and
- management decisions.
27.10 Principle Outcome
The intended outcome is that AI systems are implemented and operated in a manner that considers relevant broader impacts and supports responsible and sustainable organizational use.28. Security and Safety by Design
Identifier:AIGO-PRN-019
28.1 Principle Statement
AI systems should incorporate appropriate security and safety considerations from the earliest stages of their lifecycle rather than relying solely on controls added after deployment.28.2 Purpose
The purpose of this principle is to encourage organizations to identify and address foreseeable AI security and safety risks during planning, design, development, procurement, and implementation.28.3 Governance Expectations
Organizations should consider relevant security and safety risks during:- system conception;
- requirements definition;
- architecture;
- development;
- testing;
- deployment;
- operation; and
- change management.
28.4 Preventive Controls
Where appropriate, organizations should prioritize preventive controls that reduce the likelihood of harmful or unauthorized behavior.28.5 Defense in Depth
Higher-risk AI systems should consider multiple layers of protection rather than relying on a single safeguard. Controls may include:- access controls;
- input validation;
- output validation;
- monitoring;
- human approval;
- rate limiting;
- isolation;
- fallback mechanisms; and
- emergency shutdown capabilities.
28.6 Safety Boundaries
Organizations should define appropriate boundaries for AI system behavior, particularly where systems have autonomous capabilities or can affect external systems.28.7 Testing Before Deployment
Appropriate security and safety testing should be performed before deployment according to the system’s risk.28.8 Evidence
Evidence may include:- architecture reviews;
- threat assessments;
- safety assessments;
- security testing;
- control testing;
- approval records; and
- deployment reviews.
28.9 Principle Outcome
The intended outcome is that relevant AI security and safety risks are considered and addressed throughout the system lifecycle rather than treated solely as post-deployment concerns.29. Human-Centered AI
Identifier:AIGO-PRN-020
29.1 Principle Statement
AI systems should be designed and operated with appropriate consideration for the people who use, depend upon, are affected by, or interact with them.29.2 Purpose
The purpose of this principle is to ensure that AI governance considers human needs, capabilities, limitations, expectations, and potential impacts.29.3 Governance Expectations
Organizations should consider:- user needs;
- user understanding;
- accessibility;
- usability;
- human oversight;
- potential user errors;
- reliance on AI outputs;
- stakeholder impact; and
- appropriate communication.
29.4 Human Decision-Making
Where AI supports human decision-making, organizations should ensure that users understand the appropriate role and limitations of the AI system.29.5 Automation Bias
Organizations should consider the risk that users may place excessive trust in AI outputs. Where appropriate, organizations should implement measures such as:- user guidance;
- warnings;
- review requirements;
- confidence indicators;
- verification procedures; and
- escalation mechanisms.
29.6 User Feedback
Where appropriate, organizations should provide mechanisms for users to report:- incorrect outputs;
- harmful behavior;
- unexpected behavior;
- usability problems;
- security concerns; and
- governance concerns.
29.7 Accessibility
AI systems should consider appropriate accessibility requirements for their intended users and affected stakeholders.29.8 Evidence
Evidence may include:- user research;
- usability assessments;
- accessibility assessments;
- training materials;
- user feedback;
- incident reports; and
- system improvement records.
29.9 Principle Outcome
The intended outcome is that AI systems support people appropriately and that human users and affected stakeholders are not exposed to unnecessary or avoidable risks caused by poor governance or system design.30. Controlled Autonomy
Identifier:AIGO-PRN-021
30.1 Principle Statement
AI systems capable of autonomous or semi-autonomous actions should operate within clearly defined authority, permissions, boundaries, and oversight mechanisms.30.2 Purpose
Autonomous AI systems can perform actions beyond generating information. Examples include systems that can:- execute software;
- access databases;
- call external APIs;
- send communications;
- modify records;
- create transactions;
- manage workflows;
- make operational decisions; or
- coordinate other AI agents.
30.3 Governance Expectations
Organizations should define:- authorized actions;
- prohibited actions;
- permission boundaries;
- approval requirements;
- escalation conditions;
- monitoring requirements;
- intervention mechanisms; and
- emergency controls.
30.4 Least Privilege
Autonomous AI systems should receive only the permissions necessary to perform their authorized functions.30.5 Action Authorization
Actions with material consequences should require an appropriate level of authorization according to risk.30.6 Tool Governance
Tools and external capabilities available to autonomous AI systems should be governed according to their potential impact.30.7 Agent-to-Agent Interaction
Where multiple AI agents interact, organizations should consider:- communication boundaries;
- delegated authority;
- shared resources;
- cascading failures;
- conflicting objectives;
- escalation; and
- accountability.
30.8 Autonomous Workflow Controls
Organizations should establish controls for autonomous workflows where an AI system can initiate or complete business activities without direct human interaction at every step.30.9 Emergency Intervention
Where appropriate, authorized personnel should have mechanisms to suspend, restrict, or terminate autonomous AI activity.30.10 Evidence
Evidence may include:- permission configurations;
- tool inventories;
- workflow definitions;
- authorization records;
- monitoring logs;
- intervention records;
- testing results; and
- incident records.
30.11 Principle Outcome
The intended outcome is that AI autonomy remains bounded, authorized, observable, and controllable according to the risks associated with the system.31. AI System and Model Integrity
Identifier:AIGO-PRN-022
31.1 Principle Statement
Organizations should maintain appropriate integrity and control over AI models, system configurations, instructions, components, and other artifacts that materially influence AI system behavior.31.2 Purpose
AI system behavior may depend on multiple components rather than a single model. Relevant components may include:- models;
- prompts;
- system instructions;
- retrieval sources;
- tools;
- workflows;
- policies;
- configuration;
- code;
- datasets; and
- external services.
31.3 Governance Expectations
Organizations should establish appropriate controls for identifying, managing, approving, and changing important AI system components.31.4 Version Management
Material AI components should be version-controlled where practical.31.5 Configuration Management
Important configurations should be documented and protected against unauthorized modification.31.6 Model Changes
Material model changes should be evaluated to determine whether additional:- testing;
- risk assessment;
- approval;
- monitoring; or
- documentation
31.7 Prompt and Instruction Management
Where prompts or system instructions materially influence system behavior, organizations should establish appropriate change and access controls.31.8 Retrieval and Knowledge Sources
Where RAG or similar architectures are used, organizations should appropriately govern important knowledge sources and retrieval configurations.31.9 Evidence
Evidence may include:- version records;
- configuration records;
- change approvals;
- model inventories;
- prompt repositories;
- data-source inventories;
- deployment records; and
- testing results.
31.10 Principle Outcome
The intended outcome is that important components influencing AI behavior remain identifiable, controlled, and traceable.32. AI Literacy and Organizational Competence
Identifier:AIGO-PRN-023
32.1 Principle Statement
Organizations should ensure that individuals involved in the governance, development, deployment, operation, oversight, or use of AI systems have appropriate knowledge and competence for their responsibilities.32.2 Purpose
Effective AI governance depends on people understanding both the capabilities and limitations of AI systems.32.3 Governance Expectations
Organizations should identify relevant competence requirements for:- leadership;
- AI governance personnel;
- system owners;
- developers;
- AI engineers;
- security personnel;
- privacy personnel;
- risk teams;
- auditors;
- procurement teams; and
- AI users.
32.4 Role-Based Competence
Competence requirements should be appropriate to the person’s responsibilities. For example:- executives may require AI governance awareness;
- system owners may require lifecycle and risk knowledge;
- developers may require technical AI safety and security knowledge;
- governance teams may require risk and compliance knowledge; and
- users may require practical AI usage guidance.
32.5 AI Literacy
Organizations should provide appropriate education or guidance regarding:- AI capabilities;
- AI limitations;
- hallucination risks;
- privacy;
- security;
- appropriate use;
- prohibited use;
- human oversight; and
- reporting mechanisms.
32.6 Ongoing Development
AI competence should be reviewed and updated as technologies, risks, and organizational practices evolve.32.7 Evidence
Evidence may include:- training records;
- competency assessments;
- role descriptions;
- learning materials;
- awareness communications; and
- competency reviews.
32.8 Principle Outcome
The intended outcome is that people interacting with AI systems have sufficient knowledge and competence to perform their responsibilities appropriately.33. Governance Integration
Identifier:AIGO-PRN-024
33.1 Principle Statement
AI governance should be integrated with existing organizational governance structures rather than operating as an isolated activity.33.2 Purpose
Organizations commonly maintain existing governance systems for areas such as:- information security;
- privacy;
- risk;
- compliance;
- quality;
- business continuity;
- records management;
- procurement;
- internal audit; and
- enterprise architecture.
33.3 Governance Expectations
Organizations should identify relevant relationships between AIGO and existing organizational governance processes.33.4 Policy Integration
AI governance requirements may be incorporated into existing:- policies;
- procedures;
- standards;
- risk processes;
- approval processes;
- change management;
- incident management; and
- assurance processes.
33.5 Avoiding Duplication
Organizations should avoid unnecessary duplication between AI governance and existing governance requirements. Where an existing control already addresses a relevant AI risk, the organization may use that control where appropriate.33.6 Cross-Functional Governance
AI governance should support collaboration between relevant business and technical functions.33.7 Governance Committees
Organizations may establish dedicated AI governance committees or integrate AI governance responsibilities into existing committees.33.8 Evidence
Evidence may include:- governance structures;
- policy mappings;
- committee records;
- responsibility matrices;
- integrated risk registers; and
- assurance reports.
33.9 Principle Outcome
The intended outcome is that AI governance becomes part of the organization’s overall governance ecosystem rather than an isolated technical activity.34. Continuous Accountability
Identifier:AIGO-PRN-025
34.1 Principle Statement
Accountability for AI systems should remain active throughout their operational lifecycle and should evolve when system capabilities, ownership, risks, or organizational circumstances change.34.2 Purpose
AI systems can change significantly after initial deployment. Models may be updated, workflows may evolve, data sources may change, and system capabilities may expand. Accountability should therefore remain active rather than ending at initial approval.34.3 Governance Expectations
Organizations should periodically confirm:- system ownership;
- risk ownership;
- governance responsibilities;
- approval status;
- monitoring responsibilities;
- incident responsibilities; and
- escalation authority.
34.4 Ownership Changes
Changes in ownership should be formally documented.34.5 Organizational Changes
Organizational restructuring should trigger an assessment of whether AI governance responsibilities remain appropriately assigned.34.6 Capability Expansion
Where an AI system gains new capabilities, governance responsibilities and risk assessments should be reviewed as appropriate.34.7 Decommissioning Accountability
Accountability should remain assigned until relevant retirement activities have been completed.34.8 Evidence
Evidence may include:- ownership records;
- governance reviews;
- updated responsibility matrices;
- change records;
- approval records; and
- retirement documentation.
34.9 Principle Outcome
The intended outcome is that clear accountability remains associated with AI systems for as long as the organization remains responsible for them.35. Principle Review and Evolution
Identifier:AIGO-PRN-026
35.1 Principle Statement
AIGO principles should be periodically reviewed and evolved to remain relevant to changes in AI technology, organizational practices, risks, standards, regulations, and governance expectations.35.2 Purpose
AI governance is an evolving discipline. AIGO should therefore remain adaptable while maintaining a stable foundation of governance principles.35.3 Review Triggers
AIGO principles may be reviewed following:- major technological developments;
- significant AI incidents;
- emerging risks;
- changes in external standards;
- regulatory developments;
- industry experience;
- implementation feedback;
- research findings; or
- significant changes to the AIGO framework.
35.4 Change Management
Changes to principles should follow the AIGO framework’s documented governance and version-control processes.35.5 Stability and Continuity
Changes should preserve sufficient continuity to allow organizations to understand the relationship between different framework versions.35.6 Community and Stakeholder Input
Where appropriate, AIGO development may consider feedback from:- organizations;
- practitioners;
- researchers;
- auditors;
- security professionals;
- legal and compliance professionals;
- AI developers;
- governance specialists; and
- other relevant stakeholders.
35.7 Versioning
Material changes to principles should be reflected in an appropriate framework version.35.8 Evidence
Evidence of principle evolution may include:- change records;
- issue records;
- review reports;
- stakeholder feedback;
- version history; and
- governance decisions.
35.9 Principle Outcome
The intended outcome is that AIGO remains current, practical, technology-independent, and capable of adapting to the continuing evolution of AI governance.36. Principles Summary
The AIGO Framework Principles establish a common foundation for AI governance across organizations and AI system types. The principles defined in this document are:37. Relationship to the AIGO Framework
The principles in this document provide the conceptual foundation for the broader AIGO framework. The principles should be translated into progressively more operational elements through: Principles → Domains → Requirements → Controls → Procedures → Evidence → Assurance This structure allows organizations to move from high-level governance expectations to practical implementation.38. Relationship to External Standards and Requirements
AIGO principles may be mapped to relevant external standards, frameworks, laws, regulations, contractual requirements, and organizational policies. Such mappings should be maintained separately from the core principles where practical. External mappings should not change the fundamental technology-independent nature of AIGO. Organizations remain responsible for determining which external requirements apply to their specific circumstances.39. Implementation Independence
Organizations may implement these principles using different:- governance structures;
- technologies;
- AI frameworks;
- software architectures;
- cloud platforms;
- model providers;
- operating models; and
- organizational processes.
40. Final Principle Statement
The AIGO Framework Principles provide the foundation for establishing responsible, accountable, risk-based, transparent, secure, and continuously improving AI governance. The principles are intended to provide a common governance language while allowing organizations to adapt implementation to their specific:- objectives;
- risks;
- organizational structures;
- technologies;
- industries;
- jurisdictions; and
- AI maturity.
41. Document Status
Document: AIGO Framework Principles Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Type: Framework Foundation Identifier Range:AIGO-PRN-001 through AIGO-PRN-026
This document is part of the AIGO Framework and should be maintained according to the framework’s governance, versioning, review, and change-management processes.