> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 06 AIGO AI Control Assessment Template v0.1

# AIGO — AI Governance Operating Framework

## AI Control Assessment Template

**Version:** 0.1
**Status:** Draft
**Working Name:** AIGO
**Full Name:** AI Governance Operating Framework
**Document Identifier:** `AIGO-TPL-006`
**Document Type:** AI Control Assessment Template
**Template Purpose:** Controlled Assessment of AI Governance and Risk Controls

***

# 1. Template Purpose

This template provides the controlled structure for assessing the design, implementation, operation, effectiveness, evidence, and remediation of controls applicable to an AI system or AI governance process.

The control assessment should establish traceability between:

* AI system;
* governance requirement;
* risk;
* control objective;
* control;
* control owner;
* procedure;
* control activity;
* evidence;
* design effectiveness;
* implementation status;
* operating effectiveness;
* findings;
* corrective action;
* retesting;
* residual risk;
* assurance;
* management decision.

A control assessment does not replace the organization's approved AIGO AI Control Assessment Procedure.

***

# 2. Assessment Instructions

Complete all applicable sections.

Where information is not available, record:

**Pending — \[reason]**

Where a field does not apply, record:

**Not Applicable — \[reason]**

Each material control should have a unique Control ID.

Recommended identifiers include:

* AI System ID;
* Control Assessment ID;
* Control ID;
* Risk ID;
* Procedure ID;
* Evidence ID;
* Finding ID;
* Corrective Action ID;
* Assurance ID;
* Approval ID.

Control conclusions should be based on sufficient evidence and approved assessment criteria.

***

# 3. Assessment Record

## 3.1 Identification

**AI System ID:**

**Control Assessment ID:**

**Assessment Version:**

**Assessment Type:**

* Initial
* Periodic
* Triggered
* Post-Incident
* Post-Change
* Reassessment
* Pre-Approval
* Post-Implementation

**Assessment Status:**

* Draft
* In Progress
* Under Review
* Approved
* Approved with Conditions
* Remediation Required
* Closed

**Assessment Owner:**

**Lead Assessor:**

**Control Owner:**

**Reviewer:**

**Approval Authority:**

**Assessment Date:**

**Effective Date:**

**Next Review Date:**

***

# 4. AI System Context

## 4.1 System Information

**AI System Name:**

**AI System Version:**

**AI System Owner:**

**Business Owner:**

**Technical Owner:**

**Current Lifecycle Stage:**

**AIGO Classification:**

## 4.2 Intended Purpose

**Approved Intended Purpose:**

## 4.3 Assessment Context

**Context relevant to this control assessment:**

***

# 5. Assessment Scope

## 5.1 Control Scope

**Control / Control Family Being Assessed:**

## 5.2 Lifecycle Scope

Select applicable stages:

* Govern
* Identify
* Classify
* Assess
* Treat
* Approve
* Deploy
* Operate
* Monitor
* Assure
* Improve
* Change
* Continue
* Retire

**Applicable Lifecycle Stages:**

## 5.3 Organizational Scope

**Business Units / Functions Covered:**

## 5.4 Geographic Scope

**Jurisdictions / Locations Covered:**

## 5.5 Exclusions

**Excluded Controls / Activities:**

**Exclusion Rationale:**

***

# 6. Control Identification

## 6.1 Control Information

**Control ID:**

**Control Name:**

**Control Family:**

**Control Type:**

* Preventive
* Detective
* Corrective
* Directive
* Compensating
* Other

**Control Criticality:**

* Low
* Medium
* High
* Critical

## 6.2 Control Objective

**Control Objective:**

## 6.3 Control Requirement

**Requirement Addressed:**

## 6.4 Control Description

**Describe what the control requires or does:**

## 6.5 Control Frequency

**Control Frequency:**

* Continuous
* Real-Time
* Daily
* Weekly
* Monthly
* Quarterly
* Annual
* Event-Driven
* Other

**Frequency Rationale:**

***

# 7. Control Ownership

## 7.1 Control Owner

**Control Owner:**

**Role / Position:**

**Accountability:**

## 7.2 Control Performer

**Control Performer(s):**

## 7.3 Control Reviewer

**Control Reviewer:**

## 7.4 Control Approval Authority

**Approval Authority:**

## 7.5 Segregation of Duties

**Segregation-of-Duties Requirements:**

***

# 8. Risk Relationship

## 8.1 Risks Addressed

| Risk ID | Risk | Risk Level | Control Relationship |
| ------- | ---- | ---------- | -------------------- |
|         |      |            |                      |
|         |      |            |                      |
|         |      |            |                      |

## 8.2 Risk Treatment Relationship

**How the control reduces or manages the identified risk:**

## 8.3 Residual Risk Relationship

**Expected contribution to residual-risk reduction:**

***

# 9. Procedure Relationship

## 9.1 Applicable Procedure

**Procedure Name:**

**Procedure ID / Reference:**

## 9.2 Control Activity

**How the procedure operationalizes the control:**

## 9.3 Control Execution

**Describe how the control is performed:**

## 9.4 Control Execution Evidence

**Evidence generated by control execution:**

***

# 10. Control Design Assessment

Control design assessment determines whether the control, if implemented and operated as specified, is capable of achieving its objective.

## 10.1 Design Criteria

Assess:

* clear objective;
* risk alignment;
* defined ownership;
* appropriate frequency;
* appropriate authority;
* appropriate coverage;
* appropriate segregation;
* defined exception handling;
* defined escalation;
* defined evidence.

## 10.2 Design Assessment

**Design Rating:**

* Effective
* Partially Effective
* Ineffective
* Not Assessed

**Design Rationale:**

## 10.3 Design Gaps

**Identified Design Gaps:**

***

# 11. Control Implementation Assessment

## 11.1 Implementation Status

**Implementation Status:**

* Fully Implemented
* Substantially Implemented
* Partially Implemented
* Not Implemented
* Not Verified

## 11.2 Implementation Evidence

**Implementation Evidence:**

## 11.3 Implementation Gaps

**Implementation Gaps:**

***

# 12. Control Operating Effectiveness

## 12.1 Operating Assessment

**Operating Effectiveness:**

* Effective
* Partially Effective
* Ineffective
* Not Tested

## 12.2 Operating Period

**Assessment Period:**

## 12.3 Operating Evidence

**Evidence of Actual Operation:**

## 12.4 Operating Exceptions

**Exceptions Identified:**

## 12.5 Operating Rationale

**Rationale:**

***

# 13. Evidence Assessment

## 13.1 Evidence Requirements

The assessment should determine whether evidence demonstrates:

* what was performed;
* who performed it;
* when it was performed;
* what result was obtained;
* whether exceptions occurred;
* how exceptions were handled.

## 13.2 Evidence Quality

**Evidence Quality:**

* Strong
* Adequate
* Moderate
* Weak
* Missing

**Rationale:**

## 13.3 Evidence Characteristics

| Evidence Characteristic | Assessment | Rationale |
| ----------------------- | ---------- | --------- |
| Relevance               |            |           |
| Completeness            |            |           |
| Accuracy                |            |           |
| Authenticity            |            |           |
| Timeliness              |            |           |
| Traceability            |            |           |
| Integrity               |            |           |

***

# 14. Control Testing

## 14.1 Testing Method

Applicable methods may include:

* inquiry;
* observation;
* inspection;
* walkthrough;
* reperformance;
* technical testing;
* sample testing;
* data analysis;
* automated testing;
* independent validation.

**Testing Methods Used:**

## 14.2 Test Plan

**Test Plan ID:**

**Test Objective:**

## 14.3 Test Procedures

**Test Procedures:**

## 14.4 Test Population

**Population:**

## 14.5 Sample

**Sample Size:**

**Sampling Method:**

**Sampling Rationale:**

***

# 15. Test Results

| Test ID | Test Description | Expected Result | Actual Result | Pass / Fail | Evidence |
| ------- | ---------------- | --------------- | ------------- | ----------- | -------- |
|         |                  |                 |               |             |          |
|         |                  |                 |               |             |          |
|         |                  |                 |               |             |          |

## 15.1 Test Conclusion

**Overall Test Conclusion:**

***

# 16. Control Assessment Rating

## 16.1 Rating Scale

| Rating              | Definition                                                                                      |
| ------------------- | ----------------------------------------------------------------------------------------------- |
| Effective           | Control is appropriately designed, implemented, operating, and supported by sufficient evidence |
| Partially Effective | Control operates but has material limitations                                                   |
| Ineffective         | Control does not adequately achieve its objective                                               |
| Not Implemented     | Control has not been implemented                                                                |
| Not Tested          | Sufficient evidence is unavailable to determine effectiveness                                   |

## 16.2 Overall Control Rating

**Overall Rating:**

* Effective
* Partially Effective
* Ineffective
* Not Implemented
* Not Tested

**Overall Rationale:**

***

# 17. Control Maturity

Where appropriate, assess control maturity.

| Level | Description |
| ----- | ----------- |
| 1     | Ad Hoc      |
| 2     | Defined     |
| 3     | Repeatable  |
| 4     | Managed     |
| 5     | Optimized   |

**Control Maturity Level:**

**Maturity Rationale:**

***

# 18. Control Findings

## 18.1 Findings Register

| Finding ID | Finding | Severity | Root Cause | Owner | Status |
| ---------- | ------- | -------- | ---------- | ----- | ------ |
|            |         |          |            |       |        |
|            |         |          |            |       |        |
|            |         |          |            |       |        |

## 18.2 Finding Severity

| Severity    | Meaning                                             |
| ----------- | --------------------------------------------------- |
| Critical    | Immediate significant control failure               |
| High        | Material weakness requiring priority action         |
| Medium      | Significant weakness requiring remediation          |
| Low         | Limited weakness or improvement opportunity         |
| Observation | Improvement opportunity without material deficiency |

***

# 19. Individual Control Finding

## 19.1 Finding Identification

**Finding ID:**

**Control ID:**

**Finding Title:**

**Severity:**

## 19.2 Criterion

**Expected Requirement / Criterion:**

## 19.3 Condition

**Observed Condition:**

## 19.4 Evidence

**Supporting Evidence:**

## 19.5 Cause

**Root Cause / Contributing Cause:**

## 19.6 Risk

**Potential Risk / Impact:**

## 19.7 Recommendation

**Recommended Action:**

***

# 20. Corrective Action

## 20.1 Corrective Action Record

**Corrective Action ID:**

**Finding ID:**

**Action Owner:**

**Priority:**

**Target Date:**

**Status:**

## 20.2 Action

**Corrective Action:**

## 20.3 Root Cause Response

**How the action addresses the root cause:**

## 20.4 Required Evidence

**Closure Evidence Required:**

***

# 21. Corrective Action Tracking

| Action ID | Finding | Owner | Priority | Due Date | Evidence | Status |
| --------- | ------- | ----- | -------- | -------- | -------- | ------ |
|           |         |       |          |          |          |        |
|           |         |       |          |          |          |        |

***

# 22. Retesting and Effectiveness Verification

## 22.1 Retest Required

**Retest Required:**

## 22.2 Retest ID

**Retest ID:**

## 22.3 Retest Method

**Retest Method:**

## 22.4 Retest Result

**Result:**

* Effective
* Partially Effective
* Ineffective
* Not Complete

**Result Rationale:**

## 22.5 Corrective Action Effectiveness

**Is the corrective action effective?**

* Yes
* Partially
* No
* Not Yet Determined

**Effectiveness Rationale:**

***

# 23. Residual Risk

## 23.1 Risk Before Assessment

**Risk Level Before Control Assessment:**

## 23.2 Risk After Control Assessment

**Residual Risk Level:**

## 23.3 Control Contribution

**How the control contributes to residual-risk reduction:**

## 23.4 Risk Acceptance

**Risk Acceptance Required:**

**Risk Acceptance Record ID:**

**Acceptance Authority:**

***

# 24. Control Exceptions

## 24.1 Exception

**Exception ID:**

**Control Requirement:**

**Reason for Exception:**

**Risk:**

**Compensating Controls:**

**Requested Duration:**

**Owner:**

**Approval Authority:**

## 24.2 Exception Monitoring

**Monitoring Requirements:**

**Review Date:**

**Expiry Date:**

***

# 25. Control Monitoring

## 25.1 Monitoring Requirements

**Control Monitoring Method:**

**Monitoring Frequency:**

**Monitoring Owner:**

## 25.2 Control Indicators

| Indicator | Threshold | Frequency | Owner | Escalation | Evidence |
| --------- | --------- | --------- | ----- | ---------- | -------- |
|           |           |           |       |            |          |
|           |           |           |       |            |          |

## 25.3 Threshold Breach

**Threshold Breach Process:**

***

# 26. Control Change Assessment

## 26.1 Changes Affecting Control

**Recent or Planned Changes:**

## 26.2 Change Impact

**Impact on Control Design / Operation:**

## 26.3 Reassessment Requirement

**Control Reassessment Required:**

* Yes
* No
* Pending

**Rationale:**

***

# 27. Lifecycle Assessment

Assess the control across relevant AIGO lifecycle stages.

| Lifecycle Stage | Applicable | Control Status | Evidence | Assessment |
| --------------- | ---------- | -------------- | -------- | ---------- |
| Govern          |            |                |          |            |
| Identify        |            |                |          |            |
| Classify        |            |                |          |            |
| Assess          |            |                |          |            |
| Treat           |            |                |          |            |
| Approve         |            |                |          |            |
| Deploy          |            |                |          |            |
| Operate         |            |                |          |            |
| Monitor         |            |                |          |            |
| Assure          |            |                |          |            |
| Improve         |            |                |          |            |
| Change          |            |                |          |            |
| Continue        |            |                |          |            |
| Retire          |            |                |          |            |

***

# 28. Control Dependencies

## 28.1 Upstream Dependencies

**Controls / Processes Required Before This Control:**

## 28.2 Downstream Dependencies

**Controls / Processes Depending on This Control:**

## 28.3 Shared Controls

**Shared Controls / Common Services:**

***

# 29. Control Evidence Profile

## 29.1 Evidence Repository

**Evidence Repository:**

**Evidence Owner:**

## 29.2 Evidence Register

| Evidence ID | Evidence Type | Description | Owner | Date | Location | Status |
| ----------- | ------------- | ----------- | ----- | ---- | -------- | ------ |
|             |               |             |       |      |          |        |
|             |               |             |       |      |          |        |
|             |               |             |       |      |          |        |

## 29.3 Evidence Gaps

**Evidence Gaps:**

***

# 30. Assurance Relationship

## 30.1 Assurance Requirements

**Assurance Applicable:**

**Assurance Frequency:**

**Assurance Owner:**

## 30.2 Related Assurance

| Assurance ID | Date | Scope | Result | Findings | Status |
| ------------ | ---- | ----- | ------ | -------- | ------ |
|              |      |       |        |          |        |
|              |      |       |        |          |        |

***

# 31. Incident Relationship

## 31.1 Related Incidents

| Incident ID | Date | Severity | Control Impact | Corrective Action | Status |
| ----------- | ---- | -------- | -------------- | ----------------- | ------ |
|             |      |          |                |                   |        |
|             |      |          |                |                   |        |

## 31.2 Incident-Driven Reassessment

**Did an incident trigger this assessment?**

* Yes
* No

**Incident Reference:**

***

# 32. Change Relationship

## 32.1 Related Changes

| Change ID | Date | Description | Control Impact | Approval | Status |
| --------- | ---- | ----------- | -------------- | -------- | ------ |
|           |      |             |                |          |        |
|           |      |             |                |          |        |

## 32.2 Change-Driven Reassessment

**Did a change trigger this control assessment?**

* Yes
* No

**Change Reference:**

***

# 33. Control-to-Risk Traceability

```text id="aq4x0a" theme={null}
Governance Requirement
       ↓
Risk
       ↓
Control Objective
       ↓
Control
       ↓
Procedure
       ↓
Control Activity
       ↓
Evidence
       ↓
Assessment
       ↓
Residual Risk
```

## 33.1 Traceability Matrix

| Control ID | Risk ID | Procedure | Evidence ID | Assessment | Residual Risk |
| ---------- | ------- | --------- | ----------- | ---------- | ------------- |
|            |         |           |             |            |               |
|            |         |           |             |            |               |
|            |         |           |             |            |               |

***

# 34. Control-to-Lifecycle Traceability

| Control ID | Lifecycle Stage | Objective | Activity | Evidence | Status |
| ---------- | --------------- | --------- | -------- | -------- | ------ |
|            |                 |           |          |          |        |
|            |                 |           |          |          |        |
|            |                 |           |          |          |        |

***

# 35. Control-to-Evidence Traceability

| Control ID | Evidence ID | Evidence Type | Owner | Date | Assessment Result |
| ---------- | ----------- | ------------- | ----- | ---- | ----------------- |
|            |             |               |       |      |                   |
|            |             |               |       |      |                   |
|            |             |               |       |      |                   |

***

# 36. Management Review

## 36.1 Management Review Required

**Required:**

## 36.2 Review Reference

**Review ID:**

**Review Date:**

## 36.3 Management Review Outcome

**Outcome:**

## 36.4 Management Actions

**Actions:**

***

# 37. Overall Assessment Conclusion

**Overall Control Assessment Conclusion:**

## 37.1 Key Strengths

*
*
*

## 37.2 Key Weaknesses

*
*
*

## 37.3 Key Findings

*
*
*

## 37.4 Residual Risk Position

**Residual Risk Position:**

## 37.5 Recommendation

**Recommended Governance Decision:**

***

# 38. Assessment Approval

## 38.1 Prepared By

**Name:**

**Role:**

**Date:**

## 38.2 Reviewed By

**Name:**

**Role:**

**Date:**

## 38.3 Approved By

**Name:**

**Role:**

**Date:**

## 38.4 Approval Decision

**Decision:**

* Approved
* Approved with Conditions
* Remediation Required
* Deferred
* Rejected

**Conditions:**

***

# 39. Assessment Review Schedule

## 39.1 Periodic Review

**Review Frequency:**

**Next Review Date:**

**Review Owner:**

## 39.2 Triggered Reassessment

Reassessment should be considered following:

* material incidents;
* significant control failures;
* material AI-system changes;
* risk changes;
* monitoring threshold breaches;
* regulatory changes;
* assurance findings;
* changes in control ownership;
* changes in operating environment.

**Additional Triggers:**

***

# 40. Assessment Change History

| Version | Date | Change                     | Changed By | Reviewer | Approval |
| ------- | ---- | -------------------------- | ---------- | -------- | -------- |
| 0.1     |      | Initial control assessment |            |          |          |
|         |      |                            |            |          |          |

***

# 41. Assessment Traceability

The control assessment should maintain links to relevant AIGO records.

| AIGO Record            | Identifier |
| ---------------------- | ---------- |
| Governance Record      |            |
| AI System Registration |            |
| AI System Profile      |            |
| Classification Record  |            |
| Risk Assessment        |            |
| Procedure              |            |
| Approval Record        |            |
| Monitoring Record      |            |
| Incident Records       |            |
| Change Records         |            |
| Assurance Records      |            |
| Risk Acceptance Record |            |
| Improvement Records    |            |
| Evidence Records       |            |

***

# 42. Control Assessment Completion Checklist

* [ ] Assessment ID assigned
* [ ] AI System ID identified
* [ ] Control ID identified
* [ ] Control objective documented
* [ ] Control owner assigned
* [ ] Risk relationships documented
* [ ] Procedure relationship documented
* [ ] Assessment scope defined
* [ ] Lifecycle scope defined
* [ ] Control design assessed
* [ ] Implementation status assessed
* [ ] Operating effectiveness assessed
* [ ] Evidence reviewed
* [ ] Evidence quality assessed
* [ ] Testing method documented
* [ ] Test population identified
* [ ] Sampling method documented where applicable
* [ ] Test results recorded
* [ ] Overall control rating assigned
* [ ] Control maturity assessed where applicable
* [ ] Findings documented
* [ ] Root causes assessed
* [ ] Corrective actions assigned
* [ ] Retesting requirements determined
* [ ] Residual risk assessed
* [ ] Risk acceptance assessed
* [ ] Exceptions documented where applicable
* [ ] Monitoring requirements defined
* [ ] Change relationship reviewed
* [ ] Incident relationship reviewed
* [ ] Assurance relationship reviewed
* [ ] Evidence gaps recorded
* [ ] Management review completed where required
* [ ] Assessment approved
* [ ] Next review date established
* [ ] Related AIGO records linked

***

# 43. Template Usage Instructions

This template should be completed according to the organization's approved AIGO AI Control Assessment Procedure.

Control assessments should evaluate more than documentation existence.

The assessor should determine whether the control is:

* appropriately designed;
* implemented;
* operating;
* supported by sufficient evidence;
* effective in addressing the applicable risk or requirement.

A control should not be rated effective solely because a procedure or policy exists.

Where deficiencies are identified, the assessment should establish:

* finding;
* root cause;
* risk;
* corrective action;
* owner;
* target date;
* evidence;
* retest;
* effectiveness conclusion.

Control assessments should be repeated when material risks, systems, processes, controls, suppliers, regulations, or operating environments change.

***

# 44. Template Governance

## 44.1 Template Owner

**Template Owner:**

## 44.2 Template Review

**Review Frequency:**

**Next Review Date:**

## 44.3 Template Change Control

Changes to this template should be managed through the applicable AIGO document and change-management process.

Material changes should consider their effect on:

* AI Control Assessment Procedure;
* Governance Controls;
* Risk Assessment;
* AI System Profile;
* AI System Registration;
* Approval;
* Monitoring;
* Assurance;
* Incident Management;
* Change Management;
* Risk Acceptance;
* schemas;
* mappings;
* tools.

***

# 45. Document Control

| Field               | Value                                 |
| ------------------- | ------------------------------------- |
| Document            | AIGO — AI Control Assessment Template |
| Version             | 0.1                                   |
| Status              | Draft                                 |
| Document Identifier | `AIGO-TPL-006`                        |
| Document Type       | AI Control Assessment Template        |
| Template Owner      |                                       |
| Approved By         |                                       |
| Approval Date       |                                       |
| Effective Date      |                                       |
| Next Review Date    |                                       |

***

# 46. Template Status

**Document:** AIGO — AI Control Assessment Template

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-TPL-006`

**Document Type:** AI Control Assessment Template

This template provides the controlled structure for assessing AI governance and risk controls, including design, implementation, operation, evidence, effectiveness, findings, corrective action, retesting, residual risk, and assurance.

***

# 47. End of Template

**AIGO — AI Control Assessment Template**

**Document ID:** `AIGO-TPL-006`

**Version:** 0.1

**Status:** Draft

**End of Template**
