Skip to main content

AIGO — AI Governance Operating Framework

AI System Classification Procedure

Version: 0.1
Status: Draft
Working Name: AIGO
Full Name: AI Governance Operating Framework
Document Identifier: AIGO-PROC-004

1. Purpose

This procedure defines the process for classifying AI systems according to their governance significance, risk, impact, autonomy, and applicable requirements. The classification process provides a consistent basis for determining the level of governance, controls, oversight, assurance, and approval required for an AI system.

2. Scope

This procedure applies to AI systems within the organization’s AIGO governance scope. It applies to:
  • new AI systems;
  • existing AI systems;
  • material changes to AI systems;
  • AI models;
  • generative AI systems;
  • AI agents;
  • third-party AI services;
  • AI-enabled business processes; and
  • AI systems requiring periodic reclassification.

3. Objectives

The objectives of AI system classification are to:
  • establish a consistent classification approach;
  • identify governance significance;
  • determine appropriate governance requirements;
  • support risk assessment;
  • determine control requirements;
  • determine approval requirements;
  • support proportional oversight;
  • support monitoring and assurance; and
  • maintain traceability of classification decisions.

4. Classification Principles

Classification should be:
  • risk-based;
  • proportionate;
  • evidence-based;
  • consistent;
  • transparent;
  • documented;
  • reviewable; and
  • lifecycle-oriented.
Classification should not be treated as a substitute for a detailed risk assessment where a risk assessment is required.

5. Classification Authority

The organization should designate an authority responsible for establishing and maintaining classification requirements. Classification decisions may be performed by:
  • AI governance;
  • risk management;
  • system owners;
  • designated assessors; or
  • an AI governance committee.
Higher-impact or disputed classifications should be subject to appropriate governance review.

6. Classification Trigger

Classification should be performed when:
  • a new AI system is registered;
  • a new AI use case is proposed;
  • a material system change occurs;
  • intended purpose changes;
  • autonomy increases;
  • data sensitivity changes;
  • affected stakeholders change;
  • regulatory requirements change;
  • risk changes materially; or
  • periodic review is due.

7. Classification Inputs

The classification should consider available information about:
  • intended purpose;
  • users;
  • affected individuals;
  • AI capability;
  • autonomy;
  • data;
  • decisions;
  • actions;
  • business criticality;
  • security;
  • privacy;
  • regulatory requirements;
  • external exposure;
  • potential impact; and
  • system dependencies.

8. Classification Factors

The following factors should be considered where relevant:
  • potential impact;
  • business criticality;
  • safety;
  • privacy;
  • security;
  • fairness;
  • regulatory significance;
  • autonomy;
  • decision significance;
  • data sensitivity;
  • external exposure;
  • reversibility;
  • scale;
  • affected population; and
  • dependency on third parties.

9. Impact

Classification should consider the potential consequences of incorrect, harmful, unavailable, manipulated, or inappropriate AI outputs or actions. Impact may include:
  • physical harm;
  • financial harm;
  • privacy harm;
  • security harm;
  • discrimination;
  • legal consequences;
  • operational disruption;
  • reputational damage; and
  • societal impact.

10. Business Criticality

The classification should consider the importance of the AI system to business operations. Business criticality may be assessed based on:
  • dependency;
  • operational importance;
  • service availability;
  • financial importance;
  • customer impact;
  • regulatory importance; and
  • availability of alternatives.

11. Safety Significance

Where AI may affect physical safety, classification should consider:
  • potential injury;
  • hazardous environments;
  • safety-critical decisions;
  • autonomous actions;
  • failure consequences;
  • emergency response; and
  • recovery capability.

12. Privacy Significance

Classification should consider whether the AI system:
  • processes personal data;
  • processes sensitive data;
  • performs profiling;
  • makes decisions affecting individuals;
  • creates privacy risks; or
  • operates at significant scale.

13. Security Significance

Classification should consider:
  • system exposure;
  • privileged access;
  • sensitive data;
  • critical infrastructure;
  • external interfaces;
  • model manipulation;
  • autonomous actions; and
  • potential security impact.

14. Decision Significance

The classification should consider whether AI outputs support or determine decisions affecting:
  • individuals;
  • customers;
  • employees;
  • financial outcomes;
  • access to services;
  • eligibility;
  • safety;
  • legal status; or
  • other material interests.

15. Autonomy

The level of AI autonomy should be considered. A representative scale may include:
  1. Informational.
  2. Assistive.
  3. Advisory.
  4. Action-supporting.
  5. Action-executing with human approval.
  6. Autonomous action.
Higher autonomy may require increased governance and control requirements.

16. Human Oversight

Classification should consider the availability and effectiveness of human oversight. Factors may include:
  • whether a human reviews outputs;
  • whether intervention is possible;
  • whether intervention is timely;
  • whether the human has sufficient expertise;
  • whether the human can override the system; and
  • whether the human understands system limitations.

17. Reversibility

Classification should consider whether AI decisions or actions can be reversed. Highly irreversible actions may require stronger governance requirements. Examples include:
  • permanent data changes;
  • financial transactions;
  • legal decisions;
  • safety actions;
  • irreversible operational actions; and
  • decisions with lasting effects on individuals.

18. Scale

The scale of AI use should be considered. Factors may include:
  • number of users;
  • number of affected individuals;
  • transaction volume;
  • geographic scope;
  • frequency of use;
  • number of decisions; and
  • business dependency.

19. External Exposure

Classification should consider whether the AI system interacts directly with:
  • customers;
  • citizens;
  • suppliers;
  • public users;
  • regulators;
  • external organizations; or
  • other external stakeholders.

20. Regulatory Significance

The organization should consider applicable legal and regulatory requirements. Classification should identify whether the AI system is subject to:
  • specific regulatory obligations;
  • contractual obligations;
  • industry requirements;
  • internal restrictions; or
  • other formal governance requirements.

21. Third-Party Dependency

The classification should consider dependency on external AI providers. Factors may include:
  • provider criticality;
  • concentration;
  • service availability;
  • model changes;
  • contractual limitations;
  • data processing;
  • provider transparency; and
  • exit capability.

22. Classification Levels

The organization may establish a classification scale appropriate to its governance model. A representative four-level structure is:
  1. Class 1 — Limited Governance
  2. Class 2 — Standard Governance
  3. Class 3 — Enhanced Governance
  4. Class 4 — Critical Governance
The organization may adapt these levels without changing the underlying AIGO governance principles.

23. Class 1 — Limited Governance

Class 1 may apply to AI systems with limited potential impact and limited governance significance. Typical characteristics may include:
  • low business criticality;
  • limited external impact;
  • low sensitivity of data;
  • limited autonomy;
  • readily reversible outcomes; and
  • low foreseeable harm.
Basic registration, ownership, risk consideration, and appropriate controls should still apply.

24. Class 2 — Standard Governance

Class 2 may apply to AI systems with ordinary organizational significance. Typical characteristics may include:
  • moderate business importance;
  • standard data sensitivity;
  • limited decision impact;
  • moderate operational dependency; and
  • manageable risk.
Standard governance requirements should apply.

25. Class 3 — Enhanced Governance

Class 3 may apply to AI systems with significant risk or impact. Characteristics may include:
  • significant business criticality;
  • sensitive data;
  • material decisions;
  • substantial external impact;
  • significant autonomy;
  • meaningful safety or security concerns; or
  • significant regulatory requirements.
Enhanced assessment, controls, monitoring, and assurance should generally apply.

26. Class 4 — Critical Governance

Class 4 may apply to AI systems where failure, misuse, or inappropriate operation could result in severe consequences. Characteristics may include:
  • critical business dependency;
  • significant safety impact;
  • severe potential harm;
  • highly consequential decisions;
  • significant autonomous actions;
  • critical infrastructure dependency; or
  • substantial regulatory significance.
Critical governance should include enhanced oversight and formal approval.

27. Classification Determination

The assessor should evaluate the relevant classification factors and determine the appropriate classification. The determination should consider the highest material governance factor rather than relying solely on an average score.

28. Classification Evidence

The classification decision should be supported by appropriate evidence. Evidence may include:
  • system documentation;
  • risk assessment;
  • data assessment;
  • security assessment;
  • privacy assessment;
  • business impact assessment;
  • technical documentation;
  • stakeholder analysis; and
  • regulatory analysis.

29. Classification Record

The classification record should contain:
  • AI system identifier;
  • system name;
  • classification;
  • assessment date;
  • assessor;
  • classification factors;
  • rationale;
  • supporting evidence;
  • approval where required; and
  • review date.

30. Classification Rationale

The classification rationale should explain why the selected classification is appropriate. The rationale should identify:
  • key factors;
  • highest-impact considerations;
  • relevant risks;
  • relevant controls;
  • significant assumptions; and
  • any classification limitations.

31. Classification Review

Classification should be reviewed when:
  • system characteristics change;
  • risks change;
  • intended purpose changes;
  • autonomy increases;
  • new users are introduced;
  • data changes materially;
  • regulatory requirements change; or
  • the scheduled review date is reached.

32. Reclassification

An AI system should be reclassified when material changes affect its governance significance. Reclassification may result in:
  • higher classification;
  • lower classification; or
  • unchanged classification with updated rationale.
A lower classification should be supported by evidence.

33. Emergency Reclassification

Where a serious incident or significant new risk occurs, the organization may perform an expedited classification review. The system may be temporarily subject to a higher governance level while assessment is completed.

34. Disputed Classification

Where stakeholders disagree on classification, the issue should be escalated to the designated governance authority. Pending resolution, the organization should apply the more conservative classification where appropriate.

35. Classification and Risk

Classification and risk assessment should be linked but remain distinct. Classification determines governance significance. Risk assessment determines specific risks and required treatments. Both should be maintained and reviewed together.

36. Classification and Controls

Classification should inform the level of control requirements. Higher classifications may require:
  • additional controls;
  • stronger testing;
  • increased monitoring;
  • additional human oversight;
  • independent assurance;
  • stronger documentation; and
  • higher approval authority.

37. Classification and Approval

Approval authority should be proportionate to classification. Higher classifications should generally require approval from more senior or specialized governance authorities.

38. Classification and Monitoring

Monitoring requirements should be proportionate to classification. Higher-classification AI systems may require:
  • more frequent monitoring;
  • more indicators;
  • lower alert thresholds;
  • stronger escalation;
  • more frequent reviews; and
  • independent assurance.

39. Classification and Assurance

Classification should inform assurance planning. Higher classifications may require:
  • formal validation;
  • independent review;
  • control testing;
  • audit;
  • red-team testing;
  • model assessment; and
  • periodic assurance.

40. Classification of Third-Party AI

Third-party AI systems should be classified using the same governance principles as internally developed AI systems. Provider assurances should not automatically reduce the organization’s classification responsibility.

41. Classification of Generative AI

Generative AI systems should be classified according to actual use and impact rather than technology label alone. Factors may include:
  • output use;
  • user population;
  • data;
  • external exposure;
  • automation;
  • tool access;
  • decision support; and
  • downstream consequences.

42. Classification of AI Agents

AI agents should be classified according to their capabilities and authority. The assessment should consider:
  • tools;
  • permissions;
  • action scope;
  • autonomy;
  • transaction authority;
  • human approval;
  • reversibility;
  • monitoring; and
  • failure handling.

43. Classification of Embedded AI

AI functionality embedded within another product or service should be classified based on its actual governance significance. The organization should consider the AI component and the broader system context.

44. Classification of AI Models

Where an AI model is independently governed, classification should consider:
  • model capability;
  • intended use;
  • deployment;
  • access;
  • downstream applications;
  • potential misuse; and
  • associated risks.

45. Classification During Procurement

AI systems should be considered for classification during procurement where possible. Procurement teams should provide sufficient information to support:
  • initial classification;
  • risk assessment;
  • supplier review;
  • contractual requirements; and
  • approval.

46. Classification Before Deployment

An AI system should receive its required final classification before production deployment. Outstanding classification issues should be resolved or formally accepted by the appropriate authority.

47. Classification After Deployment

Classification should remain active after deployment. Operational evidence should be used to determine whether the classification remains appropriate.

48. Classification Reporting

The AI governance function should maintain appropriate reporting on classifications. Reporting may include:
  • systems by class;
  • changes in classification;
  • high and critical systems;
  • overdue reviews;
  • disputed classifications; and
  • reclassification events.

49. Classification Metrics

Organizations may establish classification metrics. Examples include:
  • classification completion rate;
  • overdue classifications;
  • reclassification frequency;
  • high-risk population;
  • critical systems;
  • classification disputes; and
  • classification review completion.

50. Record Retention

Classification records should be retained according to applicable organizational and legal requirements. Historical classifications should remain traceable where necessary.

51. Exceptions

Exceptions to this procedure should be:
  • documented;
  • risk assessed;
  • approved by the appropriate authority;
  • time limited where appropriate; and
  • periodically reviewed.

52. Responsibilities

AI System Owner
  • provide accurate system information;
  • support classification;
  • notify material changes;
  • implement resulting requirements; and
  • support reclassification.
AI Governance Function
  • maintain classification methodology;
  • provide oversight;
  • review material classifications;
  • manage disputes; and
  • report classification status.
Risk Function
  • support risk-based classification;
  • review material risk considerations; and
  • support escalation.
Specialist Functions
  • provide security, privacy, legal, compliance, safety, technical, or other specialist input where required.

53. Classification Workflow

The standard classification workflow should be:
  1. Identify classification trigger.
  2. Gather system information.
  3. Define assessment context.
  4. Identify relevant classification factors.
  5. Assess impact and significance.
  6. Assess autonomy and reversibility.
  7. Consider data, security, privacy, and regulatory factors.
  8. Determine proposed classification.
  9. Document rationale.
  10. Obtain review where required.
  11. Record classification.
  12. Apply resulting governance requirements.
  13. Monitor for reclassification triggers.

54. Continuous Improvement

The classification process should be improved based on:
  • operational experience;
  • incidents;
  • risk assessments;
  • assurance findings;
  • audit results;
  • regulatory developments;
  • stakeholder feedback; and
  • changes in AI technology.

55. Procedure Review

This procedure should be reviewed periodically and when material changes occur. Review triggers may include:
  • changes to AIGO requirements;
  • changes to risk methodology;
  • new AI technologies;
  • regulatory developments;
  • significant incidents;
  • assurance findings; and
  • implementation experience.
Material changes should be versioned and approved according to applicable document governance requirements.

56. Procedure Status

Document: AIGO AI System Classification Procedure Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-PROC-004 Document Type: Operational Procedure This procedure establishes the operational process for determining and maintaining the governance classification of AI systems throughout their lifecycle.