> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AIGO Framework Principles v0.1

# AIGO — AI Governance Operating Framework

## Framework Principles

**Version:** 0.1\
**Status:** Draft\
**Working Name:** AIGO\
**Full Name:** AI Governance Operating Framework

***

### 1. Purpose of the Principles

The AIGO Framework Principles define the fundamental governance expectations that should guide the design, implementation, operation, monitoring, and continuous improvement of AI systems.

The principles provide the foundation for the AIGO governance model and establish a common basis for organizational decision-making.

***

### 2. Application of the Principles

Organizations should use the AIGO principles when establishing AI governance policies, procedures, controls, responsibilities, risk management activities, and operational practices.

The principles should be considered throughout the AI system lifecycle.

They may be applied to:

* AI strategy;
* AI system design;
* AI development;
* AI procurement;
* AI deployment;
* AI operation;
* AI monitoring;
* AI change management;
* AI incident management; and
* AI system retirement.

***

### 3. Principle Structure

Each AIGO principle should define:

* principle identifier;
* principle name;
* principle statement;
* purpose;
* governance expectations;
* implementation considerations;
* evidence considerations; and
* related AIGO domains or controls where applicable.

***

### 4. Core AIGO Principles

The AIGO framework establishes a core set of principles covering areas including:

* accountability and responsibility;
* human oversight;
* risk-based governance;
* transparency;
* traceability;
* security;
* privacy;
* data governance;
* reliability and resilience;
* fairness and appropriate treatment;
* proportionality;
* lifecycle governance;
* continuous monitoring;
* continuous improvement;
* third-party governance;
* evidence-based assurance; and
* technology independence.

These principles establish the foundation for the governance domains and controls defined elsewhere in the AIGO framework.

***

### 5. Principle Identification

Each AIGO principle should have a stable identifier.

A conceptual identifier format is:

`AIGO-PRN-001`

Additional principles may use:

`AIGO-PRN-002`

`AIGO-PRN-003`

`AIGO-PRN-004`

The final identifier convention should be defined consistently across the AIGO framework.

***

### 6. Relationship to Controls

AIGO principles establish high-level governance expectations.

Controls should translate these expectations into specific organizational requirements.

A conceptual relationship is:

**Principle → Governance Requirement → Control → Procedure → Evidence**

This relationship should allow organizations to trace operational activities back to the fundamental principles of the framework.

***

### 7. Relationship to Risk

AIGO principles should be applied using a risk-based approach.

Not every AI system presents the same level or type of risk.

Organizations should consider the characteristics, purpose, impact, autonomy, data, users, deployment environment, and other relevant factors when determining how principles should be implemented.

***

### 8. Relationship to Organizational Context

Organizations may adapt the implementation of AIGO principles according to:

* organizational size;
* industry;
* jurisdiction;
* AI maturity;
* system complexity;
* risk exposure;
* business objectives;
* regulatory environment; and
* organizational policies.

Adaptation should not remove accountability for identifying and managing material AI risks.

***

### 9. Principle Governance

AIGO principles should be reviewed periodically to ensure that they remain relevant to:

* emerging AI technologies;
* changing AI risks;
* organizational experience;
* external standards;
* regulatory developments;
* security developments; and
* evolving governance practices.

Changes to principles should follow the AIGO framework change-management process.

***

### 10. Accountability and Responsibility

**Identifier:** `AIGO-PRN-001`

#### 10.1 Principle Statement

Organizations should establish clear accountability and responsibility for the governance, development, deployment, operation, monitoring, and retirement of AI systems.

AI governance responsibilities should be assigned to identifiable roles, functions, or organizational authorities.

Responsibility should not be assumed to belong exclusively to technical teams or AI developers.

***

#### 10.2 Purpose

The purpose of this principle is to ensure that AI-related decisions have clear ownership and that organizations can determine who is responsible for:

* approving AI systems;
* managing AI risks;
* implementing controls;
* monitoring system performance;
* responding to incidents;
* maintaining evidence;
* reviewing changes; and
* making decisions throughout the AI lifecycle.

***

#### 10.3 Governance Expectations

Organizations should:

* define AI governance responsibilities;
* assign accountable owners for AI systems;
* define decision-making authority;
* establish escalation paths;
* document relevant responsibilities;
* separate responsibilities where appropriate;
* ensure appropriate management oversight; and
* periodically review assigned responsibilities.

***

#### 10.4 AI System Ownership

Each AI system should have an identifiable owner or accountable organizational function.

The AI System Owner should have sufficient authority and organizational support to coordinate governance activities relevant to the system.

***

#### 10.5 Responsibility Across the Lifecycle

Responsibilities should be considered throughout the AI system lifecycle.

Relevant responsibilities may exist during:

* conception;
* assessment;
* design;
* development;
* testing;
* approval;
* deployment;
* operation;
* monitoring;
* change;
* incident response; and
* retirement.

***

#### 10.6 Shared Responsibility

AI governance may involve multiple organizational functions.

Relevant responsibilities may be distributed across:

* executive leadership;
* business owners;
* AI governance teams;
* risk and compliance;
* legal;
* privacy;
* information security;
* engineering;
* data teams;
* AI operations;
* procurement;
* internal audit; and
* end users.

Shared responsibility should not result in unclear accountability.

***

#### 10.7 Accountability Matrix

Organizations should establish an appropriate responsibility model for significant AI systems.

This may include a responsibility matrix such as:

* Responsible;
* Accountable;
* Consulted; and
* Informed.

Organizations may use RACI or another suitable responsibility model.

***

#### 10.8 Separation of Duties

Organizations should consider separation of duties where the level of risk or organizational context requires it.

For example, where appropriate, the person responsible for implementing an AI system may not be the sole person responsible for approving its production deployment.

***

#### 10.9 Management Accountability

Organizational leadership should provide appropriate oversight of AI governance.

Leadership responsibilities may include:

* approving AI governance policies;
* establishing organizational expectations;
* allocating resources;
* reviewing significant AI risks;
* approving risk acceptance where appropriate; and
* ensuring governance responsibilities are effectively assigned.

***

#### 10.10 Delegated Authority

Organizations may delegate AI governance responsibilities.

Delegated responsibilities should be:

* clearly defined;
* documented;
* appropriately authorized;
* supported by sufficient competence; and
* subject to appropriate oversight.

Delegation should not remove overall organizational accountability.

***

#### 10.11 Competence and Authority

Individuals assigned AI governance responsibilities should have appropriate competence, resources, and authority to perform their responsibilities.

Competence may include knowledge of:

* AI technologies;
* organizational processes;
* risk management;
* security;
* privacy;
* data governance;
* applicable requirements; and
* relevant AIGO requirements.

***

#### 10.12 Documentation

Organizations should maintain appropriate documentation of AI governance responsibilities.

Documentation may include:

* organizational policies;
* role descriptions;
* responsibility matrices;
* governance committee structures;
* approval records;
* system ownership records; and
* escalation procedures.

***

#### 10.13 Accountability for Third-Party AI

Where an organization uses third-party AI systems or services, it should establish internal accountability for their use.

Use of an external provider should not automatically eliminate the organization's responsibility for appropriate governance of the AI capability within its environment.

***

#### 10.14 Accountability for Autonomous Systems

Where an AI system can independently perform actions, organizations should establish clear human and organizational accountability for the system's authorized behavior.

Autonomy should not be treated as a transfer of organizational responsibility to the AI system.

***

#### 10.15 Accountability for AI-Assisted Decisions

Where AI contributes materially to a decision affecting individuals, customers, employees, or other stakeholders, appropriate responsibility for the decision process should remain assigned to authorized human or organizational decision-makers.

***

#### 10.16 Escalation

Organizations should establish escalation mechanisms for significant:

* AI incidents;
* governance failures;
* unexpected system behavior;
* security events;
* privacy events;
* material risk changes;
* control failures; and
* regulatory concerns.

***

#### 10.17 Periodic Review

AI governance responsibilities should be reviewed periodically and whenever significant changes occur.

Reviews may be triggered by:

* organizational restructuring;
* changes in AI system ownership;
* major technology changes;
* changes in risk classification;
* new regulatory requirements;
* significant incidents; or
* changes to business processes.

***

#### 10.18 Evidence

Evidence demonstrating implementation of this principle may include:

* approved policies;
* responsibility matrices;
* role descriptions;
* governance committee records;
* system ownership records;
* approval records;
* escalation procedures;
* training records; and
* periodic governance reviews.

***

#### 10.19 Principle Outcome

The intended outcome of this principle is that an organization can clearly identify:

* who owns an AI system;
* who is responsible for its operation;
* who approves significant decisions;
* who manages relevant risks;
* who monitors the system;
* who responds to incidents; and
* who has authority to intervene or stop the system when necessary.

***

### 11. Human Oversight

**Identifier:** `AIGO-PRN-002`

#### 11.1 Principle Statement

AI systems should operate with an appropriate level of human oversight proportionate to their purpose, autonomy, potential impact, and associated risks.

***

#### 11.2 Purpose

Human oversight is intended to ensure that organizations retain appropriate control over AI systems and can identify, review, challenge, intervene in, or stop AI-supported activities when necessary.

***

#### 11.3 Governance Expectations

Organizations should determine:

* whether human oversight is required;
* the appropriate level of oversight;
* who performs the oversight;
* when intervention is required;
* what decisions require human approval; and
* how oversight activities are documented.

***

#### 11.4 Proportional Oversight

The level of human oversight should be proportionate to factors such as:

* potential harm;
* system autonomy;
* decision impact;
* uncertainty;
* affected stakeholders;
* operational environment; and
* ability to reverse an AI-generated action.

***

#### 11.5 Human Intervention

Where appropriate, authorized individuals should have the ability to:

* pause an AI process;
* reject an AI recommendation;
* override an AI decision;
* modify system behavior;
* disable an AI capability; or
* initiate emergency procedures.

***

#### 11.6 Oversight Competence

Individuals responsible for human oversight should have sufficient knowledge and authority to understand the relevant AI system and appropriately evaluate its outputs or actions.

***

#### 11.7 Automation Boundaries

Organizations should define boundaries for what an AI system may perform autonomously and what activities require human authorization.

***

#### 11.8 Evidence

Evidence may include:

* oversight procedures;
* approval records;
* intervention logs;
* escalation records;
* system configuration;
* access permissions;
* monitoring records; and
* training records.

***

#### 11.9 Principle Outcome

The intended outcome is that AI autonomy remains appropriately controlled and that authorized humans retain meaningful oversight over AI systems where required by risk and context.

***

### 12. Risk-Based Governance

**Identifier:** `AIGO-PRN-003`

#### 12.1 Principle Statement

AI governance should be based on the risks, potential impacts, characteristics, and context of each AI system.

Organizations should avoid applying identical governance requirements to every AI system regardless of risk.

***

#### 12.2 Purpose

The purpose of this principle is to ensure that governance resources and controls are proportionate to the potential risks associated with an AI system.

***

#### 12.3 Governance Expectations

Organizations should:

* identify relevant AI risks;
* assess potential impacts;
* determine an appropriate risk level;
* establish controls proportionate to risk;
* document significant risk decisions;
* monitor changes in risk; and
* periodically reassess AI systems.

***

#### 12.4 Risk Factors

Relevant risk factors may include:

* intended purpose;
* affected individuals or groups;
* potential harm;
* level of autonomy;
* decision-making authority;
* sensitivity of data;
* system complexity;
* model capabilities;
* external dependencies;
* operational environment;
* reversibility of actions;
* scale of deployment; and
* likelihood and severity of potential impacts.

***

#### 12.5 Risk Classification

Organizations should establish an appropriate method for classifying AI system risk.

AIGO may support classifications such as:

* low risk;
* moderate risk;
* high risk; and
* critical or restricted risk.

Organizations may use alternative classification models where appropriate.

***

#### 12.6 Proportionality

Governance requirements should be proportionate to the level of risk.

Higher-risk systems may require additional:

* assessments;
* approvals;
* testing;
* monitoring;
* human oversight;
* documentation;
* security controls;
* privacy controls;
* incident management; and
* assurance activities.

***

#### 12.7 Risk Acceptance

Where residual AI risk remains after controls are implemented, organizations should establish an appropriate risk acceptance process.

Risk acceptance should be performed by an authorized individual or organizational function with appropriate authority.

***

#### 12.8 Risk Escalation

AI risks should be escalated when they exceed established organizational thresholds or when new information materially changes the risk profile.

***

#### 12.9 Continuous Risk Assessment

AI risk should not be treated as a one-time assessment.

Organizations should reassess risk when:

* system functionality changes;
* models change;
* data sources change;
* deployment environments change;
* new use cases are introduced;
* incidents occur;
* new vulnerabilities are identified;
* external requirements change; or
* system behavior materially changes.

***

#### 12.10 Evidence

Evidence may include:

* AI risk assessments;
* risk classification records;
* risk registers;
* risk acceptance records;
* mitigation plans;
* review records;
* escalation records; and
* monitoring results.

***

#### 12.11 Principle Outcome

The intended outcome is that AI governance is proportionate to risk and that significant AI risks are identified, assessed, managed, monitored, and appropriately accepted or escalated.

***

### 13. Transparency and Explainability

**Identifier:** `AIGO-PRN-004`

#### 13.1 Principle Statement

Organizations should provide an appropriate level of transparency regarding AI systems, their purpose, capabilities, limitations, governance, and relevant decisions.

***

#### 13.2 Purpose

Transparency enables relevant stakeholders to understand how an AI system is used, what role it performs, what limitations may exist, and where responsibility lies.

***

#### 13.3 Governance Expectations

Organizations should document appropriate information about AI systems, including where relevant:

* system purpose;
* intended use;
* prohibited or restricted use;
* system owner;
* relevant data sources;
* model or service dependencies;
* significant limitations;
* known risks;
* human oversight;
* monitoring arrangements; and
* change history.

***

#### 13.4 Stakeholder Transparency

The level and form of transparency should be appropriate to the stakeholder.

Relevant stakeholders may include:

* employees;
* customers;
* users;
* management;
* regulators;
* auditors;
* affected individuals;
* suppliers; and
* internal governance functions.

***

#### 13.5 AI Interaction Disclosure

Where appropriate, organizations should inform users when they are interacting with an AI system rather than a human.

The implementation of such disclosure should consider the applicable organizational, legal, regulatory, and contextual requirements.

***

#### 13.6 Explainability

Where AI outputs materially influence decisions or actions, organizations should consider whether an appropriate explanation of the relevant process or outcome is required.

Explainability should be proportionate to:

* system complexity;
* decision impact;
* risk;
* affected stakeholders; and
* applicable requirements.

***

#### 13.7 Limitations

Organizations should communicate relevant limitations of AI systems where those limitations could materially affect the interpretation or use of outputs.

Examples may include:

* uncertainty;
* known failure conditions;
* data limitations;
* model limitations;
* unsupported use cases; and
* known accuracy limitations.

***

#### 13.8 Documentation

Organizations should maintain appropriate documentation that enables authorized stakeholders to understand the AI system and its governance.

***

#### 13.9 Evidence

Evidence may include:

* AI system documentation;
* user notices;
* system descriptions;
* model documentation;
* limitation statements;
* decision records;
* governance records; and
* communication materials.

***

#### 13.10 Principle Outcome

The intended outcome is that relevant stakeholders have sufficient information to understand the role, purpose, limitations, and governance of an AI system.

***

### 14. Traceability and Recordkeeping

**Identifier:** `AIGO-PRN-005`

#### 14.1 Principle Statement

Organizations should maintain sufficient records and traceability to understand the lifecycle, configuration, decisions, changes, and significant events associated with AI systems.

***

#### 14.2 Purpose

Traceability supports accountability, investigation, monitoring, assurance, incident response, and continuous improvement.

***

#### 14.3 Governance Expectations

Organizations should establish appropriate mechanisms for recording:

* AI system identity;
* ownership;
* approvals;
* risk assessments;
* relevant versions;
* significant configuration changes;
* data sources;
* model or provider changes;
* significant incidents;
* monitoring results;
* governance decisions; and
* retirement activities.

***

#### 14.4 Lifecycle Traceability

Organizations should maintain sufficient information to establish the history of an AI system throughout its lifecycle.

This may include traceability from:

**Idea → Assessment → Design → Development → Testing → Approval → Deployment → Operation → Change → Retirement**

***

#### 14.5 Change Traceability

Material changes to AI systems should be documented.

Changes may include:

* model changes;
* prompt or instruction changes;
* data source changes;
* retrieval changes;
* system architecture changes;
* agent behavior changes;
* permission changes;
* vendor changes; and
* significant configuration changes.

***

#### 14.6 Evidence Integrity

Records used as governance evidence should be maintained with appropriate controls to protect their integrity, availability, and accessibility.

***

#### 14.7 Retention

Organizations should establish appropriate retention requirements for AI governance records based on:

* organizational policy;
* business requirements;
* risk;
* contractual obligations;
* applicable requirements; and
* the nature of the record.

***

#### 14.8 Accessibility

Authorized personnel should be able to access relevant AI governance records when required for:

* audits;
* investigations;
* incident response;
* risk assessments;
* management review; and
* regulatory or contractual activities.

***

#### 14.9 Evidence

Evidence may include:

* AI system inventories;
* version records;
* change logs;
* approval records;
* risk assessments;
* incident records;
* monitoring records;
* audit trails; and
* retirement records.

***

#### 14.10 Principle Outcome

The intended outcome is that organizations can reconstruct relevant aspects of an AI system's lifecycle and governance history when required.

***

### 15. Security

**Identifier:** `AIGO-PRN-006`

#### 15.1 Principle Statement

AI systems should be protected against security threats and unauthorized use throughout their lifecycle.

***

#### 15.2 Purpose

The purpose of this principle is to ensure that AI systems, their data, models, interfaces, infrastructure, and supporting services are subject to appropriate security governance.

***

#### 15.3 Governance Expectations

Organizations should consider security risks affecting:

* AI models;
* applications;
* APIs;
* prompts and instructions;
* data;
* retrieval systems;
* agents;
* tools;
* integrations;
* infrastructure;
* identities;
* credentials; and
* third-party services.

***

#### 15.4 Access Control

Access to AI systems and supporting resources should be controlled according to organizational security requirements and risk.

Access should follow appropriate principles such as:

* least privilege;
* need to know;
* role-based access; and
* appropriate authentication.

***

#### 15.5 AI-Specific Threats

Organizations should consider threats relevant to AI systems, including where applicable:

* prompt injection;
* malicious instructions;
* unauthorized model access;
* data leakage;
* sensitive information exposure;
* malicious or manipulated training data;
* retrieval manipulation;
* unauthorized tool execution;
* excessive agent permissions;
* model abuse; and
* supply-chain risks.

***

#### 15.6 Security Testing

AI systems should undergo security testing proportionate to their risk and intended use.

Testing may include:

* vulnerability assessment;
* adversarial testing;
* access-control testing;
* prompt injection testing;
* data leakage testing;
* abuse testing; and
* security configuration review.

***

#### 15.7 Security Monitoring

Organizations should monitor relevant security events and indicators associated with AI systems.

***

#### 15.8 Incident Response

AI-related security incidents should be incorporated into appropriate organizational incident response processes.

***

#### 15.9 Third-Party Security

Organizations should consider the security posture of third-party AI providers, models, APIs, tools, and services used within AI systems.

***

#### 15.10 Evidence

Evidence may include:

* access-control records;
* security assessments;
* vulnerability reports;
* penetration testing results;
* monitoring records;
* incident records;
* security reviews; and
* third-party assessments.

***

#### 15.11 Principle Outcome

The intended outcome is that AI systems are protected against reasonably foreseeable security threats throughout their lifecycle.

***

### 16. Privacy and Data Protection

**Identifier:** `AIGO-PRN-007`

#### 16.1 Principle Statement

Organizations should govern the collection, use, processing, storage, transmission, and disposal of personal data within AI systems in accordance with applicable requirements and organizational policies.

***

#### 16.2 Purpose

The purpose of this principle is to ensure that privacy and data protection considerations are integrated into AI governance rather than treated as an isolated activity.

***

#### 16.3 Governance Expectations

Organizations should consider:

* whether personal data is processed;
* the purpose of processing;
* data minimization;
* appropriate access;
* retention;
* data sharing;
* third-party processing;
* security;
* privacy risks; and
* applicable data protection requirements.

***

#### 16.4 Data Minimization

AI systems should use only the data reasonably necessary for their intended purpose, where applicable requirements and organizational policies require such limitation.

***

#### 16.5 Sensitive Data

Organizations should identify and appropriately govern sensitive or otherwise protected information processed by AI systems.

***

#### 16.6 Privacy Risk Assessment

Where appropriate, organizations should conduct privacy risk assessments before deploying or materially changing AI systems that process personal data.

***

#### 16.7 Third-Party Processing

Organizations should understand relevant privacy implications when personal data is transmitted to external AI providers or other third parties.

***

#### 16.8 Data Retention

Organizations should establish appropriate retention and deletion practices for personal data processed by AI systems.

***

#### 16.9 Evidence

Evidence may include:

* privacy assessments;
* data inventories;
* data-flow documentation;
* processing records;
* retention policies;
* contractual records;
* access records; and
* privacy review decisions.

***

#### 16.10 Principle Outcome

The intended outcome is that privacy and data protection risks associated with AI systems are identified, assessed, controlled, and monitored appropriately.

***

### 17. Data Governance

**Identifier:** `AIGO-PRN-008`

#### 17.1 Principle Statement

Data used by or produced by AI systems should be governed according to its purpose, quality, sensitivity, provenance, lifecycle, and associated risks.

***

#### 17.2 Purpose

The purpose of this principle is to establish confidence that data supporting AI systems is appropriately managed and fit for its intended use.

***

#### 17.3 Governance Expectations

Organizations should consider:

* data provenance;
* data quality;
* data relevance;
* data integrity;
* data sensitivity;
* data ownership;
* access rights;
* retention;
* transformation;
* lineage; and
* intended use.

***

#### 17.4 Data Quality

Organizations should establish appropriate data quality expectations for AI systems where data quality could materially affect system performance or risk.

***

#### 17.5 Data Provenance

Where practical, organizations should maintain information about the origin and relevant processing history of important data used by AI systems.

***

#### 17.6 Data Lineage

For higher-risk AI systems, organizations should consider maintaining sufficient lineage information to understand how important data moves through the AI system.

***

#### 17.7 Data Access

Access to AI-related data should be governed according to organizational security, privacy, and data governance requirements.

***

#### 17.8 Data Change

Material changes to important data sources should be evaluated for their potential effect on AI system behavior and risk.

***

#### 17.9 Evidence

Evidence may include:

* data inventories;
* data dictionaries;
* lineage records;
* data quality assessments;
* data ownership records;
* access records;
* source documentation; and
* data review records.

***

#### 17.10 Principle Outcome

The intended outcome is that organizations understand and appropriately govern the data that materially supports AI system behavior and outcomes.

***

### 18. Reliability, Resilience, and Performance

**Identifier:** `AIGO-PRN-009`

#### 18.1 Principle Statement

AI systems should be designed, deployed, and operated with appropriate levels of reliability, resilience, availability, and performance according to their intended purpose and risk.

***

#### 18.2 Purpose

The purpose of this principle is to reduce the likelihood and impact of AI system failures and ensure that organizations can respond appropriately when failures occur.

***

#### 18.3 Governance Expectations

Organizations should establish appropriate expectations for:

* availability;
* reliability;
* performance;
* capacity;
* error handling;
* recovery;
* continuity; and
* operational resilience.

***

#### 18.4 Failure Management

Organizations should consider foreseeable AI system failure conditions and define appropriate responses.

***

#### 18.5 Graceful Degradation

Where appropriate, AI systems should be capable of degrading safely when:

* models are unavailable;
* external services fail;
* data sources become unavailable;
* confidence is insufficient;
* system limits are exceeded; or
* unexpected behavior is detected.

***

#### 18.6 Business Continuity

AI systems supporting important business processes should be considered within relevant business continuity and disaster recovery planning.

***

#### 18.7 Performance Monitoring

Organizations should monitor relevant performance indicators according to the purpose and risk of the AI system.

***

#### 18.8 Evidence

Evidence may include:

* performance metrics;
* service-level records;
* availability records;
* incident reports;
* recovery tests;
* continuity plans;
* capacity assessments; and
* monitoring records.

***

#### 18.9 Principle Outcome

The intended outcome is that AI systems operate reliably within their intended context and that organizations can respond effectively to failures or disruptions.

***

### 19. Fairness and Appropriate Treatment

**Identifier:** `AIGO-PRN-010`

#### 19.1 Principle Statement

Organizations should consider whether AI systems may produce unjustified or inappropriate differences in outcomes or treatment and should manage relevant risks according to their context and applicable requirements.

***

#### 19.2 Purpose

The purpose of this principle is to encourage organizations to identify and manage risks associated with unfair or inappropriate AI outcomes.

***

#### 19.3 Governance Expectations

Organizations should consider:

* affected populations;
* intended outcomes;
* relevant differences in treatment;
* data limitations;
* potential bias;
* system performance across relevant groups;
* applicable requirements; and
* appropriate mitigation measures.

***

#### 19.4 Contextual Assessment

Fairness considerations should be assessed according to the intended purpose and context of the AI system.

A single fairness metric or approach may not be appropriate for every AI use case.

***

#### 19.5 Testing

Where relevant, organizations should evaluate AI system behavior for potential unfair or inappropriate outcomes.

***

#### 19.6 Monitoring

For systems where fairness-related risks are material, organizations should monitor relevant indicators over time.

***

#### 19.7 Evidence

Evidence may include:

* impact assessments;
* testing results;
* monitoring reports;
* risk assessments;
* mitigation decisions; and
* governance reviews.

***

#### 19.8 Principle Outcome

The intended outcome is that relevant risks of unfair or inappropriate AI outcomes are identified, evaluated, and managed according to the system's context and risk.

***

### 20. Lifecycle Governance

**Identifier:** `AIGO-PRN-011`

#### 20.1 Principle Statement

AI systems should be governed throughout their lifecycle rather than only at the point of deployment.

***

#### 20.2 Purpose

The purpose of this principle is to ensure that governance remains active from initial conception through retirement.

***

#### 20.3 Governance Expectations

Organizations should establish governance activities across relevant lifecycle stages, including:

* initiation;
* assessment;
* design;
* development;
* testing;
* approval;
* deployment;
* operation;
* monitoring;
* change;
* review; and
* retirement.

***

#### 20.4 Lifecycle Gates

Organizations may establish governance gates requiring specific approvals or evidence before an AI system progresses to the next lifecycle stage.

***

#### 20.5 Change Management

Material changes should trigger an appropriate review to determine whether:

* risk has changed;
* controls remain appropriate;
* testing should be repeated;
* approval is still valid; or
* additional governance activities are required.

***

#### 20.6 Retirement

Organizations should establish appropriate procedures for retiring AI systems.

Retirement may include:

* disabling services;
* removing access;
* handling retained data;
* preserving required records;
* terminating third-party services; and
* updating inventories.

***

#### 20.7 Evidence

Evidence may include:

* lifecycle records;
* approval gates;
* change requests;
* testing records;
* deployment approvals;
* monitoring records; and
* retirement records.

***

#### 20.8 Principle Outcome

The intended outcome is that AI governance remains active and traceable throughout the complete lifecycle of an AI system.

***

### 21. Continuous Monitoring

**Identifier:** `AIGO-PRN-012`

#### 21.1 Principle Statement

AI systems should be monitored throughout their operational lifecycle to identify material changes, failures, unexpected behavior, emerging risks, and deviations from intended performance or governance requirements.

#### 21.2 Purpose

The purpose of this principle is to ensure that organizations do not rely solely on pre-deployment assessments and that relevant AI risks continue to be managed during operation.

#### 21.3 Governance Expectations

Organizations should establish monitoring appropriate to the AI system's:

* purpose;
* risk level;
* autonomy;
* operational environment;
* expected performance;
* data dependencies; and
* potential impact.

#### 21.4 Monitoring Areas

Where relevant, monitoring may include:

* system availability;
* performance;
* output quality;
* accuracy;
* errors;
* abnormal behavior;
* security events;
* privacy events;
* data changes;
* model changes;
* usage patterns;
* policy violations;
* incidents; and
* emerging risks.

#### 21.5 Monitoring Thresholds

Organizations should establish appropriate thresholds or indicators for determining when investigation or escalation is required.

#### 21.6 Human Review

Monitoring results should be reviewed by appropriately authorized personnel when automated monitoring alone is insufficient.

#### 21.7 Monitoring Changes

Monitoring requirements should be reviewed when material changes are made to an AI system or its operating environment.

#### 21.8 Evidence

Evidence may include:

* monitoring dashboards;
* performance reports;
* alerts;
* logs;
* review records;
* incident records;
* investigation records; and
* escalation records.

#### 21.9 Principle Outcome

The intended outcome is that material changes, failures, and emerging risks are detected and addressed during the operational lifecycle of AI systems.

***

### 22. Continuous Improvement

**Identifier:** `AIGO-PRN-013`

#### 22.1 Principle Statement

AI governance should be continuously reviewed and improved based on operational experience, incidents, assessments, monitoring results, technological developments, organizational changes, and emerging risks.

#### 22.2 Purpose

The purpose of this principle is to ensure that AI governance does not become static as AI technologies, organizational practices, and risks evolve.

#### 22.3 Governance Expectations

Organizations should establish mechanisms to:

* review governance performance;
* identify deficiencies;
* analyze incidents;
* evaluate lessons learned;
* update controls;
* improve procedures;
* address recurring issues; and
* monitor emerging AI risks.

#### 22.4 Lessons Learned

Significant incidents, failures, investigations, assessments, and operational experiences should be used to identify opportunities for improvement.

#### 22.5 Corrective Actions

Where governance deficiencies are identified, organizations should establish appropriate corrective actions.

Corrective actions should have:

* an identified owner;
* appropriate priority;
* defined actions;
* appropriate target dates; and
* evidence of completion where required.

#### 22.6 Framework Improvement

Organizations using AIGO should periodically review whether the framework remains appropriate for their organizational context.

AIGO itself should also evolve through its framework governance and version-management processes.

#### 22.7 Evidence

Evidence may include:

* management reviews;
* corrective action records;
* lessons-learned reports;
* improvement plans;
* updated procedures;
* revised controls; and
* governance review records.

#### 22.8 Principle Outcome

The intended outcome is that AI governance continuously improves based on evidence, experience, changing risks, and organizational needs.

***

### 23. Third-Party and Supply Chain Governance

**Identifier:** `AIGO-PRN-014`

#### 23.1 Principle Statement

Organizations should appropriately govern third-party AI systems, models, services, tools, data sources, infrastructure, and other dependencies that materially contribute to an AI capability.

#### 23.2 Purpose

AI systems frequently depend on external providers and components.

Third-party dependencies may introduce risks related to:

* security;
* privacy;
* availability;
* reliability;
* data processing;
* intellectual property;
* contractual obligations;
* model behavior;
* service changes; and
* concentration or dependency.

#### 23.3 Governance Expectations

Organizations should assess relevant third-party risks before adopting significant AI services and periodically thereafter.

#### 23.4 Third-Party Assessment

Depending on risk, assessment may consider:

* provider identity;
* service purpose;
* security controls;
* privacy practices;
* data processing;
* service availability;
* model or service limitations;
* change management;
* incident management;
* contractual terms; and
* exit arrangements.

#### 23.5 Contractual Requirements

Where appropriate, organizations should establish contractual requirements covering relevant AI governance expectations.

These may include:

* security;
* privacy;
* confidentiality;
* service availability;
* incident notification;
* data handling;
* audit or assurance;
* change notification; and
* termination requirements.

#### 23.6 Dependency Management

Organizations should maintain sufficient visibility into significant third-party dependencies supporting AI systems.

#### 23.7 Provider Changes

Material changes by third-party providers should be evaluated where they may affect:

* system behavior;
* risk;
* security;
* privacy;
* performance;
* availability; or
* governance requirements.

#### 23.8 Exit Planning

For important AI services, organizations should consider appropriate exit, replacement, or contingency strategies.

#### 23.9 Evidence

Evidence may include:

* supplier assessments;
* contracts;
* security assessments;
* privacy assessments;
* service-level agreements;
* provider documentation;
* dependency inventories;
* review records; and
* exit plans.

#### 23.10 Principle Outcome

The intended outcome is that material third-party AI dependencies are identified, assessed, monitored, and governed according to their risk and organizational importance.

***

### 24. Evidence-Based Assurance

**Identifier:** `AIGO-PRN-015`

#### 24.1 Principle Statement

AI governance should be supported by sufficient objective evidence to demonstrate that defined requirements, controls, procedures, and decisions have been implemented and operated appropriately.

#### 24.2 Purpose

Evidence enables organizations to demonstrate governance activities and supports:

* management oversight;
* internal assurance;
* audits;
* investigations;
* risk management;
* continuous improvement; and
* accountability.

#### 24.3 Governance Expectations

Organizations should determine what evidence is required for important governance activities.

Evidence requirements should be proportionate to:

* risk;
* system importance;
* regulatory context;
* organizational requirements; and
* assurance needs.

#### 24.4 Evidence Types

Evidence may include:

* policies;
* procedures;
* assessments;
* approvals;
* test results;
* monitoring records;
* logs;
* training records;
* incident records;
* risk decisions;
* meeting records; and
* audit results.

#### 24.5 Evidence Traceability

Where practical, evidence should be traceable to:

* a governance requirement;
* a control;
* an AI system;
* an owner;
* a date or relevant period; and
* the activity being demonstrated.

#### 24.6 Evidence Integrity

Organizations should protect important governance evidence from unauthorized alteration, deletion, or inappropriate access.

#### 24.7 Evidence Retention

Evidence should be retained according to applicable organizational, contractual, legal, regulatory, and risk requirements.

#### 24.8 Assurance Activities

Organizations may perform assurance activities such as:

* internal reviews;
* control assessments;
* independent assessments;
* audits;
* testing;
* management reviews; and
* external assurance.

#### 24.9 Evidence Gaps

Where required evidence is unavailable or incomplete, organizations should assess the resulting governance risk and determine appropriate corrective action.

#### 24.10 Principle Outcome

The intended outcome is that organizations can demonstrate, with appropriate evidence, how AI governance requirements are implemented and operated.

***

### 25. Proportionality

**Identifier:** `AIGO-PRN-016`

#### 25.1 Principle Statement

AI governance requirements should be proportionate to the characteristics, purpose, risk, impact, complexity, and organizational context of an AI system.

#### 25.2 Purpose

Proportionality prevents governance from becoming unnecessarily burdensome for low-risk systems while ensuring that higher-risk systems receive appropriate scrutiny.

#### 25.3 Governance Expectations

Organizations should consider the appropriate level of:

* documentation;
* assessment;
* approval;
* testing;
* monitoring;
* human oversight;
* security;
* privacy review;
* assurance; and
* evidence.

#### 25.4 Risk-Based Scaling

Higher-risk systems should generally receive more extensive governance activities than low-risk systems where appropriate.

#### 25.5 Small and Low-Risk Systems

Organizations should be able to implement simplified governance processes for AI systems where the associated risks are demonstrably limited.

Simplification should not eliminate necessary safeguards.

#### 25.6 High-Risk Systems

Higher-risk AI systems may require enhanced:

* management oversight;
* risk assessment;
* testing;
* human oversight;
* monitoring;
* documentation;
* security controls;
* incident management; and
* independent assurance.

#### 25.7 Organizational Context

Proportionality should consider organizational circumstances, including:

* size;
* resources;
* industry;
* AI maturity;
* regulatory environment;
* operational complexity; and
* risk appetite.

#### 25.8 Evidence

Organizations should document significant decisions regarding the proportional application of governance requirements.

#### 25.9 Principle Outcome

The intended outcome is that AIGO governance remains practical, effective, and appropriate to the risks and circumstances of each organization and AI system.

***

### 26. Technology Independence

**Identifier:** `AIGO-PRN-017`

#### 26.1 Principle Statement

AIGO governance requirements should remain independent of specific AI technologies, programming languages, development frameworks, model providers, cloud platforms, and implementation architectures unless a specific technology dependency is necessary to address a defined risk.

#### 26.2 Purpose

Technology independence allows organizations to apply AIGO across evolving AI technologies without requiring fundamental changes to the governance framework whenever technology changes.

#### 26.3 Governance Expectations

AIGO requirements should primarily describe:

* governance outcomes;
* responsibilities;
* risks;
* controls;
* evidence;
* decision-making; and
* assurance expectations.

Technical implementation details may be addressed through supporting guidance where necessary.

#### 26.4 Framework Independence

Organizations should be able to implement AIGO alongside technologies and frameworks such as:

* Python;
* AI and machine learning frameworks;
* agent frameworks;
* RAG systems;
* chatbot platforms;
* workflow systems;
* cloud AI services;
* proprietary AI platforms; and
* open-source AI technologies.

AIGO should not require the adoption of any particular technology.

#### 26.5 Implementation Flexibility

Organizations may select appropriate technologies and implementation methods provided that the resulting implementation satisfies applicable governance requirements.

#### 26.6 Technology Evolution

AIGO should be reviewed periodically to ensure that its governance model remains applicable to emerging technologies and AI architectures.

#### 26.7 Technology-Neutral Controls

Where practical, AIGO controls should describe the governance objective rather than prescribe a specific technical mechanism.

#### 26.8 Exceptions

A specific technical requirement may be introduced where necessary to address a defined security, privacy, safety, reliability, or governance risk.

Such requirements should be justified and documented.

#### 26.9 Evidence

Evidence may include:

* architecture documentation;
* technology assessments;
* governance decisions;
* control implementation records;
* risk assessments; and
* technical assurance records.

#### 26.10 Principle Outcome

The intended outcome is that AIGO remains applicable across different AI technologies and implementation approaches while maintaining consistent governance expectations.

***

### 27. Responsible and Sustainable AI

**Identifier:** `AIGO-PRN-018`

#### 27.1 Principle Statement

Organizations should consider the broader organizational, societal, environmental, and operational impacts of AI systems and should seek to use AI in a responsible and sustainable manner appropriate to their context.

#### 27.2 Purpose

AI systems may create benefits while also producing broader impacts beyond immediate technical or business objectives.

Organizations should therefore consider relevant impacts throughout the AI lifecycle.

#### 27.3 Governance Expectations

Where relevant, organizations should consider:

* resource consumption;
* environmental impact;
* social impact;
* workforce impact;
* accessibility;
* stakeholder impact;
* responsible use;
* misuse risks; and
* long-term operational sustainability.

#### 27.4 Appropriate Use

Organizations should define appropriate uses for AI systems and establish restrictions where specific uses may create unacceptable or disproportionate risks.

#### 27.5 Sustainability Considerations

Where material to the organization's objectives or risk profile, organizations may consider:

* computational resource consumption;
* infrastructure efficiency;
* model selection;
* system utilization;
* data storage;
* service dependencies; and
* lifecycle efficiency.

#### 27.6 Stakeholder Impact

Organizations should consider potentially affected stakeholders when introducing or materially changing AI systems.

#### 27.7 Workforce Considerations

Where AI materially affects employees or work processes, organizations should consider appropriate organizational change, communication, training, and oversight.

#### 27.8 Accessibility

Where AI systems are intended for use by diverse populations, organizations should consider relevant accessibility requirements and practical usability.

#### 27.9 Evidence

Evidence may include:

* impact assessments;
* sustainability assessments;
* stakeholder reviews;
* organizational policies;
* usage restrictions;
* accessibility assessments; and
* management decisions.

#### 27.10 Principle Outcome

The intended outcome is that AI systems are implemented and operated in a manner that considers relevant broader impacts and supports responsible and sustainable organizational use.

***

### 28. Security and Safety by Design

**Identifier:** `AIGO-PRN-019`

#### 28.1 Principle Statement

AI systems should incorporate appropriate security and safety considerations from the earliest stages of their lifecycle rather than relying solely on controls added after deployment.

#### 28.2 Purpose

The purpose of this principle is to encourage organizations to identify and address foreseeable AI security and safety risks during planning, design, development, procurement, and implementation.

#### 28.3 Governance Expectations

Organizations should consider relevant security and safety risks during:

* system conception;
* requirements definition;
* architecture;
* development;
* testing;
* deployment;
* operation; and
* change management.

#### 28.4 Preventive Controls

Where appropriate, organizations should prioritize preventive controls that reduce the likelihood of harmful or unauthorized behavior.

#### 28.5 Defense in Depth

Higher-risk AI systems should consider multiple layers of protection rather than relying on a single safeguard.

Controls may include:

* access controls;
* input validation;
* output validation;
* monitoring;
* human approval;
* rate limiting;
* isolation;
* fallback mechanisms; and
* emergency shutdown capabilities.

#### 28.6 Safety Boundaries

Organizations should define appropriate boundaries for AI system behavior, particularly where systems have autonomous capabilities or can affect external systems.

#### 28.7 Testing Before Deployment

Appropriate security and safety testing should be performed before deployment according to the system's risk.

#### 28.8 Evidence

Evidence may include:

* architecture reviews;
* threat assessments;
* safety assessments;
* security testing;
* control testing;
* approval records; and
* deployment reviews.

#### 28.9 Principle Outcome

The intended outcome is that relevant AI security and safety risks are considered and addressed throughout the system lifecycle rather than treated solely as post-deployment concerns.

***

### 29. Human-Centered AI

**Identifier:** `AIGO-PRN-020`

#### 29.1 Principle Statement

AI systems should be designed and operated with appropriate consideration for the people who use, depend upon, are affected by, or interact with them.

#### 29.2 Purpose

The purpose of this principle is to ensure that AI governance considers human needs, capabilities, limitations, expectations, and potential impacts.

#### 29.3 Governance Expectations

Organizations should consider:

* user needs;
* user understanding;
* accessibility;
* usability;
* human oversight;
* potential user errors;
* reliance on AI outputs;
* stakeholder impact; and
* appropriate communication.

#### 29.4 Human Decision-Making

Where AI supports human decision-making, organizations should ensure that users understand the appropriate role and limitations of the AI system.

#### 29.5 Automation Bias

Organizations should consider the risk that users may place excessive trust in AI outputs.

Where appropriate, organizations should implement measures such as:

* user guidance;
* warnings;
* review requirements;
* confidence indicators;
* verification procedures; and
* escalation mechanisms.

#### 29.6 User Feedback

Where appropriate, organizations should provide mechanisms for users to report:

* incorrect outputs;
* harmful behavior;
* unexpected behavior;
* usability problems;
* security concerns; and
* governance concerns.

#### 29.7 Accessibility

AI systems should consider appropriate accessibility requirements for their intended users and affected stakeholders.

#### 29.8 Evidence

Evidence may include:

* user research;
* usability assessments;
* accessibility assessments;
* training materials;
* user feedback;
* incident reports; and
* system improvement records.

#### 29.9 Principle Outcome

The intended outcome is that AI systems support people appropriately and that human users and affected stakeholders are not exposed to unnecessary or avoidable risks caused by poor governance or system design.

***

### 30. Controlled Autonomy

**Identifier:** `AIGO-PRN-021`

#### 30.1 Principle Statement

AI systems capable of autonomous or semi-autonomous actions should operate within clearly defined authority, permissions, boundaries, and oversight mechanisms.

#### 30.2 Purpose

Autonomous AI systems can perform actions beyond generating information.

Examples include systems that can:

* execute software;
* access databases;
* call external APIs;
* send communications;
* modify records;
* create transactions;
* manage workflows;
* make operational decisions; or
* coordinate other AI agents.

Such capabilities require appropriate governance controls.

#### 30.3 Governance Expectations

Organizations should define:

* authorized actions;
* prohibited actions;
* permission boundaries;
* approval requirements;
* escalation conditions;
* monitoring requirements;
* intervention mechanisms; and
* emergency controls.

#### 30.4 Least Privilege

Autonomous AI systems should receive only the permissions necessary to perform their authorized functions.

#### 30.5 Action Authorization

Actions with material consequences should require an appropriate level of authorization according to risk.

#### 30.6 Tool Governance

Tools and external capabilities available to autonomous AI systems should be governed according to their potential impact.

#### 30.7 Agent-to-Agent Interaction

Where multiple AI agents interact, organizations should consider:

* communication boundaries;
* delegated authority;
* shared resources;
* cascading failures;
* conflicting objectives;
* escalation; and
* accountability.

#### 30.8 Autonomous Workflow Controls

Organizations should establish controls for autonomous workflows where an AI system can initiate or complete business activities without direct human interaction at every step.

#### 30.9 Emergency Intervention

Where appropriate, authorized personnel should have mechanisms to suspend, restrict, or terminate autonomous AI activity.

#### 30.10 Evidence

Evidence may include:

* permission configurations;
* tool inventories;
* workflow definitions;
* authorization records;
* monitoring logs;
* intervention records;
* testing results; and
* incident records.

#### 30.11 Principle Outcome

The intended outcome is that AI autonomy remains bounded, authorized, observable, and controllable according to the risks associated with the system.

***

### 31. AI System and Model Integrity

**Identifier:** `AIGO-PRN-022`

#### 31.1 Principle Statement

Organizations should maintain appropriate integrity and control over AI models, system configurations, instructions, components, and other artifacts that materially influence AI system behavior.

#### 31.2 Purpose

AI system behavior may depend on multiple components rather than a single model.

Relevant components may include:

* models;
* prompts;
* system instructions;
* retrieval sources;
* tools;
* workflows;
* policies;
* configuration;
* code;
* datasets; and
* external services.

#### 31.3 Governance Expectations

Organizations should establish appropriate controls for identifying, managing, approving, and changing important AI system components.

#### 31.4 Version Management

Material AI components should be version-controlled where practical.

#### 31.5 Configuration Management

Important configurations should be documented and protected against unauthorized modification.

#### 31.6 Model Changes

Material model changes should be evaluated to determine whether additional:

* testing;
* risk assessment;
* approval;
* monitoring; or
* documentation

is required.

#### 31.7 Prompt and Instruction Management

Where prompts or system instructions materially influence system behavior, organizations should establish appropriate change and access controls.

#### 31.8 Retrieval and Knowledge Sources

Where RAG or similar architectures are used, organizations should appropriately govern important knowledge sources and retrieval configurations.

#### 31.9 Evidence

Evidence may include:

* version records;
* configuration records;
* change approvals;
* model inventories;
* prompt repositories;
* data-source inventories;
* deployment records; and
* testing results.

#### 31.10 Principle Outcome

The intended outcome is that important components influencing AI behavior remain identifiable, controlled, and traceable.

***

### 32. AI Literacy and Organizational Competence

**Identifier:** `AIGO-PRN-023`

#### 32.1 Principle Statement

Organizations should ensure that individuals involved in the governance, development, deployment, operation, oversight, or use of AI systems have appropriate knowledge and competence for their responsibilities.

#### 32.2 Purpose

Effective AI governance depends on people understanding both the capabilities and limitations of AI systems.

#### 32.3 Governance Expectations

Organizations should identify relevant competence requirements for:

* leadership;
* AI governance personnel;
* system owners;
* developers;
* AI engineers;
* security personnel;
* privacy personnel;
* risk teams;
* auditors;
* procurement teams; and
* AI users.

#### 32.4 Role-Based Competence

Competence requirements should be appropriate to the person's responsibilities.

For example:

* executives may require AI governance awareness;
* system owners may require lifecycle and risk knowledge;
* developers may require technical AI safety and security knowledge;
* governance teams may require risk and compliance knowledge; and
* users may require practical AI usage guidance.

#### 32.5 AI Literacy

Organizations should provide appropriate education or guidance regarding:

* AI capabilities;
* AI limitations;
* hallucination risks;
* privacy;
* security;
* appropriate use;
* prohibited use;
* human oversight; and
* reporting mechanisms.

#### 32.6 Ongoing Development

AI competence should be reviewed and updated as technologies, risks, and organizational practices evolve.

#### 32.7 Evidence

Evidence may include:

* training records;
* competency assessments;
* role descriptions;
* learning materials;
* awareness communications; and
* competency reviews.

#### 32.8 Principle Outcome

The intended outcome is that people interacting with AI systems have sufficient knowledge and competence to perform their responsibilities appropriately.

***

### 33. Governance Integration

**Identifier:** `AIGO-PRN-024`

#### 33.1 Principle Statement

AI governance should be integrated with existing organizational governance structures rather than operating as an isolated activity.

#### 33.2 Purpose

Organizations commonly maintain existing governance systems for areas such as:

* information security;
* privacy;
* risk;
* compliance;
* quality;
* business continuity;
* records management;
* procurement;
* internal audit; and
* enterprise architecture.

AI governance should coordinate with these functions where appropriate.

#### 33.3 Governance Expectations

Organizations should identify relevant relationships between AIGO and existing organizational governance processes.

#### 33.4 Policy Integration

AI governance requirements may be incorporated into existing:

* policies;
* procedures;
* standards;
* risk processes;
* approval processes;
* change management;
* incident management; and
* assurance processes.

#### 33.5 Avoiding Duplication

Organizations should avoid unnecessary duplication between AI governance and existing governance requirements.

Where an existing control already addresses a relevant AI risk, the organization may use that control where appropriate.

#### 33.6 Cross-Functional Governance

AI governance should support collaboration between relevant business and technical functions.

#### 33.7 Governance Committees

Organizations may establish dedicated AI governance committees or integrate AI governance responsibilities into existing committees.

#### 33.8 Evidence

Evidence may include:

* governance structures;
* policy mappings;
* committee records;
* responsibility matrices;
* integrated risk registers; and
* assurance reports.

#### 33.9 Principle Outcome

The intended outcome is that AI governance becomes part of the organization's overall governance ecosystem rather than an isolated technical activity.

***

### 34. Continuous Accountability

**Identifier:** `AIGO-PRN-025`

#### 34.1 Principle Statement

Accountability for AI systems should remain active throughout their operational lifecycle and should evolve when system capabilities, ownership, risks, or organizational circumstances change.

#### 34.2 Purpose

AI systems can change significantly after initial deployment.

Models may be updated, workflows may evolve, data sources may change, and system capabilities may expand.

Accountability should therefore remain active rather than ending at initial approval.

#### 34.3 Governance Expectations

Organizations should periodically confirm:

* system ownership;
* risk ownership;
* governance responsibilities;
* approval status;
* monitoring responsibilities;
* incident responsibilities; and
* escalation authority.

#### 34.4 Ownership Changes

Changes in ownership should be formally documented.

#### 34.5 Organizational Changes

Organizational restructuring should trigger an assessment of whether AI governance responsibilities remain appropriately assigned.

#### 34.6 Capability Expansion

Where an AI system gains new capabilities, governance responsibilities and risk assessments should be reviewed as appropriate.

#### 34.7 Decommissioning Accountability

Accountability should remain assigned until relevant retirement activities have been completed.

#### 34.8 Evidence

Evidence may include:

* ownership records;
* governance reviews;
* updated responsibility matrices;
* change records;
* approval records; and
* retirement documentation.

#### 34.9 Principle Outcome

The intended outcome is that clear accountability remains associated with AI systems for as long as the organization remains responsible for them.

***

### 35. Principle Review and Evolution

**Identifier:** `AIGO-PRN-026`

#### 35.1 Principle Statement

AIGO principles should be periodically reviewed and evolved to remain relevant to changes in AI technology, organizational practices, risks, standards, regulations, and governance expectations.

#### 35.2 Purpose

AI governance is an evolving discipline.

AIGO should therefore remain adaptable while maintaining a stable foundation of governance principles.

#### 35.3 Review Triggers

AIGO principles may be reviewed following:

* major technological developments;
* significant AI incidents;
* emerging risks;
* changes in external standards;
* regulatory developments;
* industry experience;
* implementation feedback;
* research findings; or
* significant changes to the AIGO framework.

#### 35.4 Change Management

Changes to principles should follow the AIGO framework's documented governance and version-control processes.

#### 35.5 Stability and Continuity

Changes should preserve sufficient continuity to allow organizations to understand the relationship between different framework versions.

#### 35.6 Community and Stakeholder Input

Where appropriate, AIGO development may consider feedback from:

* organizations;
* practitioners;
* researchers;
* auditors;
* security professionals;
* legal and compliance professionals;
* AI developers;
* governance specialists; and
* other relevant stakeholders.

#### 35.7 Versioning

Material changes to principles should be reflected in an appropriate framework version.

#### 35.8 Evidence

Evidence of principle evolution may include:

* change records;
* issue records;
* review reports;
* stakeholder feedback;
* version history; and
* governance decisions.

#### 35.9 Principle Outcome

The intended outcome is that AIGO remains current, practical, technology-independent, and capable of adapting to the continuing evolution of AI governance.

***

### 36. Principles Summary

The AIGO Framework Principles establish a common foundation for AI governance across organizations and AI system types.

The principles defined in this document are:

| Identifier     | Principle                                 |
| -------------- | ----------------------------------------- |
| `AIGO-PRN-001` | Accountability and Responsibility         |
| `AIGO-PRN-002` | Human Oversight                           |
| `AIGO-PRN-003` | Risk-Based Governance                     |
| `AIGO-PRN-004` | Transparency and Explainability           |
| `AIGO-PRN-005` | Traceability and Recordkeeping            |
| `AIGO-PRN-006` | Security                                  |
| `AIGO-PRN-007` | Privacy and Data Protection               |
| `AIGO-PRN-008` | Data Governance                           |
| `AIGO-PRN-009` | Reliability, Resilience, and Performance  |
| `AIGO-PRN-010` | Fairness and Appropriate Treatment        |
| `AIGO-PRN-011` | Lifecycle Governance                      |
| `AIGO-PRN-012` | Continuous Monitoring                     |
| `AIGO-PRN-013` | Continuous Improvement                    |
| `AIGO-PRN-014` | Third-Party and Supply Chain Governance   |
| `AIGO-PRN-015` | Evidence-Based Assurance                  |
| `AIGO-PRN-016` | Proportionality                           |
| `AIGO-PRN-017` | Technology Independence                   |
| `AIGO-PRN-018` | Responsible and Sustainable AI            |
| `AIGO-PRN-019` | Security and Safety by Design             |
| `AIGO-PRN-020` | Human-Centered AI                         |
| `AIGO-PRN-021` | Controlled Autonomy                       |
| `AIGO-PRN-022` | AI System and Model Integrity             |
| `AIGO-PRN-023` | AI Literacy and Organizational Competence |
| `AIGO-PRN-024` | Governance Integration                    |
| `AIGO-PRN-025` | Continuous Accountability                 |
| `AIGO-PRN-026` | Principle Review and Evolution            |

***

### 37. Relationship to the AIGO Framework

The principles in this document provide the conceptual foundation for the broader AIGO framework.

The principles should be translated into progressively more operational elements through:

**Principles → Domains → Requirements → Controls → Procedures → Evidence → Assurance**

This structure allows organizations to move from high-level governance expectations to practical implementation.

***

### 38. Relationship to External Standards and Requirements

AIGO principles may be mapped to relevant external standards, frameworks, laws, regulations, contractual requirements, and organizational policies.

Such mappings should be maintained separately from the core principles where practical.

External mappings should not change the fundamental technology-independent nature of AIGO.

Organizations remain responsible for determining which external requirements apply to their specific circumstances.

***

### 39. Implementation Independence

Organizations may implement these principles using different:

* governance structures;
* technologies;
* AI frameworks;
* software architectures;
* cloud platforms;
* model providers;
* operating models; and
* organizational processes.

AIGO does not require the adoption of a specific implementation technology.

***

### 40. Final Principle Statement

The AIGO Framework Principles provide the foundation for establishing responsible, accountable, risk-based, transparent, secure, and continuously improving AI governance.

The principles are intended to provide a common governance language while allowing organizations to adapt implementation to their specific:

* objectives;
* risks;
* organizational structures;
* technologies;
* industries;
* jurisdictions; and
* AI maturity.

The principles should be implemented together with the other components of the AIGO framework, including governance domains, controls, roles, lifecycle requirements, risk management, maturity models, profiles, procedures, templates, and evidence requirements.

AIGO principles should be treated as a foundation for governance rather than as a substitute for applicable laws, regulations, standards, contractual requirements, professional advice, or organizational policies.

***

### 41. Document Status

**Document:** AIGO Framework Principles

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Type:** Framework Foundation

**Identifier Range:** `AIGO-PRN-001` through `AIGO-PRN-026`

This document is part of the AIGO Framework and should be maintained according to the framework's governance, versioning, review, and change-management processes.
