Skip to main content

AIGO — AI Governance Operating Framework

AI System Profile Template

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-TPL-003 Document Type: AI System Profile Template Template Purpose: Controlled Profile of an AI System

1. Template Purpose

This template provides the detailed profile of an AI system registered within the AIGO AI Governance Operating Framework. The AI System Profile expands upon the basic registration record by documenting the system’s:
  • purpose;
  • intended and restricted uses;
  • business context;
  • stakeholders;
  • lifecycle;
  • technical architecture;
  • model;
  • data;
  • interfaces;
  • dependencies;
  • human oversight;
  • risk characteristics;
  • controls;
  • monitoring;
  • security;
  • privacy;
  • fairness and impact considerations;
  • testing and validation;
  • operational constraints;
  • governance status;
  • evidence;
  • change history.
The profile should provide a sufficiently complete representation of the AI system for governance, risk management, assessment, approval, monitoring, assurance, and change management. The profile is a controlled record and should be updated when material system characteristics change. This template does not replace the AI System Registration record, detailed technical documentation, risk assessment, control assessment, or other required AIGO records.

2. Template Completion Instructions

Complete all applicable fields. Where information is not yet available, record: Pending — [reason] Where a field does not apply, record: Not Applicable — [reason] Use controlled identifiers wherever possible. Recommended identifiers include:
  • AI System ID;
  • Profile ID;
  • Risk ID;
  • Control ID;
  • Assessment ID;
  • Approval ID;
  • Change ID;
  • Incident ID;
  • Monitoring ID;
  • Assurance ID;
  • Evidence ID.

3. Profile Identification

3.1 Profile Record

AI System ID: Profile Record ID: System Name: System Short Name / Acronym: System Version: Profile Version: Profile Status: Profile Owner: System Owner: Business Owner: Technical Owner: Date Created: Last Updated: Next Review Date:

3.2 Profile Status

Current Status:
  • Draft
  • Under Review
  • Approved
  • Operational
  • Restricted
  • Suspended
  • Under Change
  • Retiring
  • Retired
Status Effective Date: Status Rationale:

4. System Overview

4.1 Executive Description

Provide a concise description of the AI system:

4.2 System Objective

What organizational objective does the system support?

4.3 Business Process

Business process supported:

4.4 Primary Function

Primary system function:

4.5 AI Capability

Select or describe applicable capabilities:
  • Classification
  • Prediction
  • Recommendation
  • Ranking
  • Generation
  • Retrieval
  • Detection
  • Optimization
  • Forecasting
  • Decision Support
  • Conversational Interaction
  • Natural Language Processing
  • Computer Vision
  • Speech / Audio
  • Multimodal Processing
  • Other
Applicable Capabilities:

5. Intended Purpose and Use

5.1 Intended Purpose

Approved intended purpose:

5.2 Intended Use

Describe the approved use of the system:

5.3 Intended Users

Authorized user groups:

5.4 Intended Operating Conditions

Conditions under which the system is intended to operate:

5.5 Restricted Uses

Restricted uses:

5.6 Prohibited Uses

Prohibited uses:

5.7 Misuse Considerations

Foreseeable misuse or inappropriate use scenarios:

5.8 Use Limitations

Known limitations on system use:

6. System Context

6.1 Organizational Context

Relevant organizational context:

6.2 Operational Context

Operational environment:

6.3 Regulatory / Jurisdictional Context

Jurisdictions and regulatory context:

6.4 Business Criticality

Business Criticality:
  • Low
  • Medium
  • High
  • Critical
Rationale:

6.5 Dependency Criticality

Dependency on system availability or outputs:

7. Stakeholders and Affected Persons

7.1 Stakeholders

7.2 Affected Persons

Who may be affected by the system or its outputs?

7.3 Impacted Groups

Groups potentially affected by system operation:

7.4 Stakeholder Engagement

Engagement activities: Stakeholder Evidence IDs:

8. System Lifecycle

8.1 Current Lifecycle Stage

Select the applicable AIGO lifecycle stage:
  • Govern
  • Identify
  • Classify
  • Assess
  • Treat
  • Approve
  • Deploy
  • Operate
  • Monitor
  • Assure
  • Improve
  • Change
  • Continue
  • Retire
Current Stage:

8.2 Lifecycle History

8.3 Next Lifecycle Stage

Planned Next Stage: Entry Conditions: Exit Conditions:

9. System Architecture

9.1 Architecture Description

System architecture summary:

9.2 Architecture Diagram Reference

Architecture Diagram ID / Location:

9.3 Major Components

9.4 Interfaces

9.5 Technical Dependencies

Technical dependencies:

10. Model Profile

10.1 Model Identification

Model ID: Model Name: Model Version: Model Family:

10.2 Model Type

Model Type / Architecture:

10.3 Model Purpose

Role of the model within the AI system:

10.4 Model Provider

Provider: Provider Type:
  • Internal
  • External
  • Open Source
  • Commercial
  • Managed Service
  • Other

10.5 Model Version Control

Model version-control process:

10.6 Model Dependencies

Model dependencies:

10.7 Model Documentation

Model Documentation Reference:

10.8 Model Limitations

Known model limitations:

11. Data Profile

11.1 Data Categories

Select applicable categories:
  • Public
  • Internal
  • Confidential
  • Proprietary
  • Personal Data
  • Sensitive Personal Data
  • Employee Data
  • Customer Data
  • Financial Data
  • Health Data
  • Operational Data
  • Technical Data
  • Other
Applicable Categories:

11.2 Data Sources

11.3 Data Inputs

Primary data inputs:

11.4 Data Outputs

Data outputs generated by the system:

11.5 Data Processing

Describe how data is processed:

11.6 Data Transformation

Data transformations or preprocessing:

11.7 Data Quality

Data quality requirements: Data Quality Owner:

11.8 Data Lineage

Data lineage reference:

11.9 Data Retention

Retention Requirements:

11.10 Data Disposal

Disposal / deletion requirements:

12. Data Governance

12.1 Data Ownership

Data Owner:

12.2 Data Access

Authorized data access roles:

12.3 Data Controls

Applicable controls may include:
  • data minimization;
  • validation;
  • quality monitoring;
  • lineage;
  • access control;
  • retention;
  • deletion;
  • confidentiality;
  • integrity;
  • provenance.
Applicable Controls:

12.4 Data Governance Assessment

Assessment ID: Assessment Status: Assessment Date:

12.5 Data Governance Evidence

Evidence IDs:

13. User Interaction

13.1 User Types

13.2 User Workflow

Describe the typical user interaction:

13.3 User Responsibilities

User responsibilities:

13.4 User Restrictions

Restrictions:

14. Human Oversight

14.1 Oversight Requirement

Human Oversight Required:

14.2 Oversight Model

Select applicable model:
  • Human-in-the-loop
  • Human-on-the-loop
  • Human-in-command
  • Human review only
  • No human intervention
  • Other
Oversight Model:

14.3 Oversight Role

Responsible Role:

14.4 Human Authority

Who has authority to challenge, override, approve, or reject AI outputs?

14.5 Oversight Activities

  • review;
  • challenge;
  • override;
  • escalation;
  • approval;
  • decision;
  • monitoring.
Applicable Activities:

14.6 Oversight Limitations

Known limitations:

14.7 Oversight Evidence

Evidence IDs:

15. AI Outputs and Decision Impact

15.1 Output Types

15.2 Decision Influence

Does the AI output influence a decision?
  • No
  • Limited
  • Moderate
  • Significant
  • Critical
Decision Influence Description:

15.3 Final Decision Authority

Final decision-maker:

15.4 Reversibility

Can decisions influenced by the AI system be reversed?
  • Fully
  • Substantially
  • Partially
  • Limited
  • No
Rationale:

16. AI Classification Profile

16.1 Governance Classification

AIGO Classification: Classification Date: Classification Owner: Reviewer: Approval Authority:

16.2 Classification Factors

Classification may consider:
  • intended purpose;
  • affected persons;
  • decision significance;
  • autonomy;
  • impact;
  • potential harm;
  • data sensitivity;
  • security;
  • privacy;
  • fairness;
  • safety;
  • deployment scale;
  • reversibility;
  • regulatory requirements;
  • human oversight.
Relevant Factors:

16.3 Classification Rationale

Rationale:

16.4 Reclassification Triggers

Triggers:

17. Risk Profile

17.1 Risk Assessment

Risk Assessment ID: Risk Assessment Date: Risk Owner: Assessment Status:

17.2 Overall Risk

Inherent Risk: Residual Risk: Risk Status:

17.3 Key Risks

17.4 Risk Categories

Potential categories include:
  • Governance
  • Strategic
  • Legal / Regulatory
  • Privacy
  • Security
  • Fairness
  • Safety
  • Reliability
  • Robustness
  • Transparency
  • Explainability
  • Human Oversight
  • Data
  • Model
  • Operational
  • Third Party
  • Reputational
  • Financial
  • Other
Applicable Risk Categories:

17.5 Risk Acceptance

Residual Risk Acceptance Required: Risk Acceptance Record ID: Acceptance Authority:

18. Control Profile

18.1 Applicable Controls

18.2 Critical Controls

Critical controls:

18.3 Control Effectiveness

Overall Control Effectiveness:

18.4 Control Exceptions

Exceptions: Exception Record IDs:

19. Security Profile

19.1 Security Classification

Security Classification:

19.2 Security Architecture

Security Architecture Reference:

19.3 Security Controls

Applicable Security Controls:

19.4 Security Assessment

Security Assessment ID: Assessment Status:

19.5 Security Monitoring

Security Monitoring Requirements:

19.6 Security Incidents

Security Incident Record IDs:

20. Privacy Profile

20.1 Privacy Applicability

Privacy Requirements Applicable:

20.2 Privacy Assessment

Privacy Assessment ID: Assessment Status:

20.3 Privacy Controls

Applicable Privacy Controls:

20.4 Privacy Monitoring

Privacy Monitoring Requirements:

20.5 Privacy Incidents

Privacy Incident Record IDs:

21. Fairness, Impact, and Responsible AI Profile

21.1 Applicability

Fairness / Impact Assessment Applicable:

21.2 Assessment Reference

Assessment ID: Assessment Date:

21.3 Potential Impact Areas

Potential considerations include:
  • fairness;
  • discrimination;
  • accessibility;
  • individual impact;
  • stakeholder impact;
  • transparency;
  • explainability;
  • safety;
  • societal impact.
Applicable Areas:

21.4 Assessment Summary

Summary:

21.5 Monitoring Requirements

Fairness / Impact Monitoring:

22. Model Performance and Validation

22.1 Performance Requirements

Performance Objectives:

22.2 Performance Metrics

22.3 Validation Status

Validation Status: Validation ID: Validation Date: Validation Owner:

22.4 Testing

Applicable testing may include:
  • functional;
  • performance;
  • robustness;
  • security;
  • privacy;
  • fairness;
  • explainability;
  • human oversight;
  • resilience;
  • regression.
Applicable Testing:

22.5 Testing Evidence

Evidence IDs:

22.6 Known Performance Limitations

Limitations:

23. Monitoring Profile

23.1 Monitoring Plan

Monitoring Plan ID: Monitoring Owner: Monitoring Frequency:

23.2 Monitoring Indicators

23.3 Enhanced Monitoring

Enhanced Monitoring Required: Trigger: Duration:

23.4 Monitoring Status

Current Monitoring Status: Open Monitoring Issues:

24. Incident Profile

24.1 Incident Management

Incident Procedure: Incident Owner:

24.2 Incident Triggers

Incident Trigger Conditions:

24.3 Incident History


25. Change Profile

25.1 Change Management

Change Procedure: Change Owner:

25.2 Change History

25.3 Known Change Triggers

Material change triggers:
  • model change;
  • model version change;
  • data change;
  • purpose change;
  • supplier change;
  • architecture change;
  • user population change;
  • control change;
  • regulatory change.
Additional Triggers:

26. Third-Party Profile

26.1 Suppliers

26.2 Supplier Risk

Supplier Risk Assessment ID: Risk Level:

26.3 Supplier Controls

Applicable Supplier Controls:

26.4 Supplier Assurance

Assurance Evidence:

27. Operational Profile

27.1 Operating Environment

Production Environment: Operating Location: Operating Hours / Availability:

27.2 Operational Dependencies

Operational dependencies:

27.3 Business Continuity

Business Continuity Requirements:

27.4 Recovery Requirements

Recovery Objectives / Requirements:

27.5 Service Ownership

Operational Owner: Support Owner:

28. Approval and Authorization Profile

28.1 Approval Status

Current Approval Status:
  • Not Required
  • Pending
  • Approved
  • Approved with Conditions
  • Deferred
  • Rejected
  • Suspended

28.2 Approval Record

Approval ID: Approval Authority: Approval Date: Effective Date: Review Date:

28.3 Approval Conditions

Conditions:

28.4 Deployment Authorization

Deployment Authorization ID: Authorized By: Authorization Date:

29. Evidence Profile

29.1 Evidence Repository

Evidence Repository: Evidence Owner:

29.2 Key Evidence

29.3 Evidence Status

Evidence Completeness:
  • Complete
  • Substantially Complete
  • Partially Complete
  • Incomplete
  • Under Review
Known Evidence Gaps:

29.4 Evidence Retention

Retention Requirement: Retention Owner: Disposition Requirement:

30. Assurance Profile

30.1 Assurance Requirements

Assurance Required: Assurance Frequency: Assurance Owner:

30.2 Assurance Records

30.3 Open Findings


31. Governance Status

31.1 Current Status

AI System Governance Status:
  • Under Registration
  • Under Assessment
  • Approved
  • Operational
  • Restricted
  • Under Review
  • Suspended
  • Retiring
  • Retired

31.2 Status Rationale

Rationale:

31.3 Current Governance Conditions

Conditions:

31.4 Open Actions


32. Review and Reassessment

32.1 Periodic Review

Review Frequency: Next Review Date: Review Owner:

32.2 Triggered Review

Review should be considered after:
  • significant incidents;
  • material changes;
  • material risk changes;
  • control failures;
  • significant monitoring deviations;
  • classification changes;
  • regulatory changes;
  • supplier changes;
  • material stakeholder concerns.
Additional Triggers:

32.3 Latest Review

Review Date: Review Outcome: Required Actions:

33. Continual Improvement

33.1 Improvement Sources

Improvement opportunities may originate from:
  • monitoring;
  • incidents;
  • assurance;
  • risk assessments;
  • control assessments;
  • stakeholder feedback;
  • management review;
  • changes;
  • lessons learned;
  • technology developments;
  • regulatory developments.

33.2 Improvement Records


34. Retirement Profile

34.1 Retirement Status

Retirement Status:
  • Not Planned
  • Under Consideration
  • Approved
  • In Progress
  • Completed

34.2 Retirement Trigger

Reason / Trigger:

34.3 Retirement Approval

Retirement Approval ID: Approval Authority: Approval Date:

34.4 Retirement Evidence

Evidence IDs:

35. Profile Review and Approval

35.1 Prepared By

Name: Role: Date:

35.2 Reviewed By

Name: Role: Date:

35.3 Approved By

Name: Role: Date:

35.4 Profile Decision

Decision:
  • Approved
  • Approved with Conditions
  • Returned for Revision
  • Rejected
  • Deferred
Conditions:

36. Profile Change History


37. Profile Traceability

The AI System Profile should maintain links to relevant AIGO records.

38. Profile Completion Checklist

  • Profile ID assigned
  • AI System ID assigned
  • System name recorded
  • System owner assigned
  • Business owner assigned
  • Technical owner assigned
  • System objective documented
  • Intended purpose documented
  • Intended use documented
  • Restricted uses documented
  • Prohibited uses documented
  • Operating context documented
  • Stakeholders identified
  • Affected persons identified
  • Lifecycle stage recorded
  • Architecture documented
  • Model profile completed
  • Data profile completed
  • Data governance documented
  • User interaction documented
  • Human oversight documented
  • Decision impact documented
  • Classification recorded
  • Risk profile linked
  • Controls linked
  • Security profile completed
  • Privacy profile completed where applicable
  • Fairness / impact profile completed where applicable
  • Testing and validation recorded
  • Monitoring profile completed
  • Incident profile completed
  • Change profile completed
  • Third-party profile completed where applicable
  • Operational profile completed
  • Approval status recorded
  • Evidence profile completed
  • Assurance profile completed
  • Current governance status recorded
  • Review date established
  • Improvement records linked
  • Retirement status recorded
  • Related AIGO records linked
  • Profile reviewed and approved

39. Template Usage Instructions

This template should be completed according to the organization’s approved AI System Registration, Governance, Classification, Risk Assessment, Control Assessment, Approval, Monitoring, Assurance, Change Management, Incident Management, and Retirement procedures. The AI System Profile should serve as the detailed controlled description of the AI system throughout its lifecycle. The profile should be updated when material information changes, including:
  • purpose;
  • system architecture;
  • model;
  • model version;
  • data;
  • stakeholders;
  • users;
  • classification;
  • risk;
  • controls;
  • suppliers;
  • deployment environment;
  • monitoring;
  • approval;
  • lifecycle stage.
The profile should reference specialized records rather than duplicating authoritative information where practical.

40. Template Governance

40.1 Template Owner

Template Owner:

40.2 Template Review

Review Frequency: Next Review Date:

40.3 Template Change Control

Changes to this template should be managed through the applicable AIGO document and change-management process. Material changes should consider their effect on:
  • AI System Registration Procedure;
  • AI System Profiles;
  • Classification Procedure;
  • Risk Assessment Procedure;
  • Control Assessment Procedure;
  • Approval Procedure;
  • Monitoring Procedure;
  • Assurance Procedure;
  • Incident Management Procedure;
  • Change Management Procedure;
  • Retirement Procedure;
  • Evidence architecture;
  • schemas;
  • mappings;
  • tools.

41. Document Control


42. Template Status

Document: AIGO — AI System Profile Template Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-TPL-003 Document Type: AI System Profile Template This template provides the detailed controlled profile of an AI system and establishes the baseline information required to support AIGO governance, risk management, lifecycle management, control assessment, approval, monitoring, assurance, change management, and retirement.

43. End of Template

AIGO — AI System Profile Template Document ID: AIGO-TPL-003 Version: 0.1 Status: Draft End of Template