Skip to main content

AIGO — AI Governance Operating Framework

AI Approval Template

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-TPL-007 Document Type: AI Approval Template Template Purpose: Controlled Authorization of AI System Deployment, Operation, Change, Continuation, Suspension, or Retirement

1. Template Purpose

This template provides the controlled structure for making and documenting an AIGO governance approval decision concerning an AI system. The approval record establishes traceability between:
  • AI system;
  • intended purpose;
  • classification;
  • risk assessment;
  • risk treatment;
  • controls;
  • control assessment;
  • testing and validation;
  • human oversight;
  • security;
  • privacy;
  • monitoring;
  • incident readiness;
  • change management;
  • evidence;
  • residual risk;
  • approval conditions;
  • decision authority;
  • deployment or lifecycle authorization.
Approval is a governance decision. It does not mean that all risk has been eliminated. Where residual risk remains, the organization should determine whether formal risk acceptance is also required. This template does not replace the organization’s approved AIGO AI Approval Procedure.

2. Approval Instructions

Complete all applicable sections. Where information is not available, record: Pending — [reason] Where a field does not apply, record: Not Applicable — [reason] The approval record should reference authoritative supporting records rather than duplicate them unnecessarily. Recommended identifiers include:
  • AI System ID;
  • Approval ID;
  • Risk Assessment ID;
  • Control Assessment ID;
  • Classification Record ID;
  • Evidence ID;
  • Change ID;
  • Incident ID;
  • Monitoring ID;
  • Assurance ID;
  • Risk Acceptance ID.

3. Approval Record

3.1 Identification

AI System ID: Approval ID: Approval Version: System Name: System Version: Approval Type:
  • Initial Deployment
  • Continued Operation
  • Material Change
  • Post-Change
  • Resumption After Suspension
  • Emergency
  • Retirement
  • Other
Approval Status:
  • Draft
  • Under Review
  • Pending Decision
  • Approved
  • Approved with Conditions
  • Deferred
  • Rejected
  • Suspended
  • Revoked
  • Closed

3.2 Approval Administration

Approval Owner: Approval Requestor: Business Owner: AI System Owner: Risk Owner: Approval Authority: Date Submitted: Decision Date: Effective Date: Expiry / Review Date: Next Review Date:

4. Approval Scope

4.1 Scope of Decision

What is being approved?

4.2 Approved AI System

System / Component / Change Covered:

4.3 Approved Purpose

Approved Intended Purpose:

4.4 Approved Use

Approved Use:

4.5 Approved Users

Authorized User Groups:

4.6 Approved Deployment Scope

Business Units / Jurisdictions / Environments / Locations:

4.7 Restrictions

Restrictions on the approval:

4.8 Exclusions

Activities, functions, users, environments, or uses not covered by this approval:

5. Approval Trigger and Background

5.1 Approval Trigger

Reason Approval Is Required:

5.2 Background

Business / Governance Background:

5.3 Previous Approval

Previous Approval ID: Previous Decision: Reason New Approval Is Required:

6. AI System Summary

6.1 System Description

Brief Description:

6.2 AI Capability

Applicable AI Capability / Capabilities:

6.3 Current Lifecycle Stage

AIGO Lifecycle Stage:

6.4 Classification

AIGO Classification:

6.5 Business Criticality

Business Criticality:
  • Low
  • Medium
  • High
  • Critical
Rationale:

7. Intended Purpose Review

7.1 Intended Purpose

Approved Intended Purpose:

7.2 Intended Use

Approved Intended Use:

7.3 Prohibited / Restricted Use

Prohibited Uses: Restricted Uses:

7.4 Purpose Change

Has the intended purpose changed since the previous approval?
  • Yes
  • No
  • Not Applicable
If yes, describe:

8. Classification Review

8.1 Classification Record

Classification Record ID: Classification Date: Classification Owner: Classification Reviewer:

8.2 Classification Result

Classification:

8.3 Classification Adequacy

Is the existing classification still appropriate?
  • Yes
  • No
  • Reassessment Required
Rationale:

8.4 Classification Evidence

Evidence IDs:

9. Risk Assessment Review

9.1 Risk Assessment

Risk Assessment ID: Assessment Date: Risk Owner: Assessment Status:

9.2 Inherent Risk

Overall Inherent Risk:

9.3 Residual Risk

Overall Residual Risk:

9.4 Highest Risks

9.5 Risk Status

Overall Risk Status:
  • Within Tolerance
  • Conditionally Within Tolerance
  • Above Tolerance
  • Unresolved
  • Requires Escalation
Rationale:

10. Risk Treatment Review

10.1 Treatment Status

Risk Treatment Status:
  • Complete
  • Substantially Complete
  • Partially Complete
  • Outstanding
  • Not Required

10.2 Outstanding Treatments

10.3 Treatment Adequacy

Conclusion:

11. Control Assessment Review

11.1 Control Assessment

Control Assessment ID: Assessment Date: Assessor: Overall Control Rating:

11.2 Control Summary

11.3 Critical Control Status

Are all critical controls implemented and effective?
  • Yes
  • No
  • Partially
  • Not Tested
Rationale:

11.4 Control Conditions

Control-related approval conditions:

12. Open Findings

12.1 Finding Register

12.2 Critical / High Findings

Critical or High Findings:

12.3 Finding Disposition

Required Decision:
  • Close Before Approval
  • Accept with Conditions
  • Risk Acceptance Required
  • Defer Approval
  • Reject Approval
  • Other
Rationale:

13. Evidence Review

13.1 Evidence Package

Evidence Repository: Evidence Owner:

13.2 Required Evidence

13.3 Evidence Completeness

Evidence Status:
  • Complete
  • Substantially Complete
  • Partially Complete
  • Incomplete
Evidence Gaps:

13.4 Evidence Quality

Evidence Quality:
  • Strong
  • Adequate
  • Moderate
  • Weak
  • Insufficient
Rationale:

14. Testing and Validation Review

14.1 Testing Status

Testing Status:
  • Not Required
  • Planned
  • In Progress
  • Complete
  • Passed
  • Passed with Conditions
  • Failed

14.2 Testing Records

14.3 Validation Conclusion

Validation Conclusion:

14.4 Outstanding Testing

Outstanding Tests / Conditions:

15. Human Oversight Review

15.1 Oversight Requirement

Human Oversight Required:

15.2 Oversight Model

Oversight Model:
  • Human-in-the-Loop
  • Human-on-the-Loop
  • Human-in-Command
  • Human Review
  • Other

15.3 Oversight Capability

15.4 Oversight Conclusion

Conclusion:

16. Security Review

16.1 Security Assessment

Security Assessment ID: Status:

16.2 Security Review Result

Result:
  • Approved
  • Approved with Conditions
  • Remediation Required
  • Rejected
  • Not Applicable
Rationale:

16.3 Security Conditions

Security Conditions:

17. Privacy Review

17.1 Privacy Assessment

Privacy Assessment ID: Status:

17.2 Privacy Review Result

Result:
  • Approved
  • Approved with Conditions
  • Remediation Required
  • Rejected
  • Not Applicable
Rationale:

17.3 Privacy Conditions

Privacy Conditions:

18. Fairness, Impact, and Responsible AI Review

18.1 Assessment Applicability

Fairness / Impact Assessment Applicable:

18.2 Assessment Reference

Assessment ID:

18.3 Review Result

Result:
  • Approved
  • Approved with Conditions
  • Remediation Required
  • Rejected
  • Not Applicable
Rationale:

18.4 Conditions

Fairness / Impact Conditions:

19. Monitoring Readiness

19.1 Monitoring Plan

Monitoring Plan ID: Monitoring Owner: Monitoring Frequency:

19.2 Monitoring Status

Monitoring Readiness:
  • Ready
  • Ready with Conditions
  • Not Ready
  • Not Applicable

19.3 Monitoring Indicators

19.4 Enhanced Monitoring

Enhanced Monitoring Required: Trigger: Duration:

20. Incident Readiness

20.1 Incident Procedure

Incident Management Procedure:

20.2 Incident Readiness Status

Status:
  • Ready
  • Ready with Conditions
  • Not Ready
  • Not Applicable

20.3 Incident Response Evidence

Evidence IDs:

20.4 Incident Conditions

Conditions:

21. Change Management Readiness

21.1 Change Procedure

Change Management Procedure:

21.2 Change Readiness

Status:
  • Ready
  • Ready with Conditions
  • Not Ready
  • Not Applicable

21.3 Material Change Criteria

Applicable Material Change Criteria:

21.4 Change Approval Requirement

Required Change Approval Authority:

21.5 Rollback

Rollback Required / Available: Rollback Conditions:

22. Operational Readiness

22.1 Operational Status

Operational Readiness:
  • Ready
  • Ready with Conditions
  • Not Ready
  • Not Applicable

22.2 Operational Requirements

Assess:
  • ownership;
  • staffing;
  • training;
  • technical support;
  • monitoring;
  • incident response;
  • security;
  • privacy;
  • controls;
  • evidence;
  • business continuity.
Operational Assessment:

22.3 Training

Training Requirement: Training Status: Training Evidence IDs:

23. Business Continuity and Recovery

23.1 Continuity Requirements

Business Continuity Requirement:

23.2 Recovery Capability

Recovery Requirement:

23.3 Recovery Validation

Validation Status: Evidence ID:

24. Third-Party Readiness

24.1 Third-Party Dependencies

24.2 Supplier Risk

Supplier Risk Status:

24.3 Supplier Conditions

Conditions:

25. Residual Risk and Risk Acceptance

25.1 Residual Risk

Overall Residual Risk:

25.2 Risk Tolerance

Within Approved Risk Tolerance:
  • Yes
  • No
  • Conditional

25.3 Risk Acceptance Required

Formal Risk Acceptance Required:
  • Yes
  • No
  • Pending

25.4 Risk Acceptance Record

Risk Acceptance ID: Acceptance Authority: Acceptance Date: Conditions: Expiry / Review Date:

26. Approval Decision Options

AIGO approval may result in:
  • Approved
  • Approved with Conditions
  • Deferred
  • Rejected
  • Suspended
  • Revoked

27. Approval Decision

27.1 Decision

Final Decision:

27.2 Decision Rationale

Rationale:

27.3 Approved Scope

Approved Scope:

27.4 Approval Restrictions

Restrictions:

27.5 Conditions


28. Approval Authority

28.1 Decision Authority

Approval Authority: Authority Basis:

28.2 Required Reviews Completed


29. Delegated Authority

29.1 Delegated Approval

Delegated Authority Used: Delegate: Delegation Reference: Delegation Conditions:

29.2 Delegation Verification

Authority Verified By: Verification Date:

30. Segregation of Duties

The approval process should separate, where practical:
  • approval request;
  • risk assessment;
  • control assessment;
  • technical implementation;
  • assurance;
  • final approval.

30.1 Role Separation


31. Approval Conditions and Follow-Up

31.1 Conditions Register

31.2 Condition Verification

Verification Owner: Verification Method: Verification Evidence:

32. Deployment Authorization

Complete this section when the approval authorizes deployment.

32.1 Deployment Decision

Deployment Authorized:

32.2 Deployment Scope

Authorized Environment / Location:

32.3 Deployment Authority

Authorized By: Authorization Date:

32.4 Deployment Conditions

Conditions:

32.5 Deployment Evidence

Evidence IDs:

33. Post-Approval Requirements

33.1 Monitoring

Required Monitoring:

33.2 Assurance

Required Assurance:

33.3 Management Review

Required Management Review:

33.4 Risk Review

Required Risk Review:

33.5 Condition Review

Condition Review Date:

34. Approval Review Triggers

Approval should be reconsidered following:
  • material changes;
  • significant incidents;
  • material risk increases;
  • critical control failures;
  • significant monitoring deviations;
  • classification changes;
  • new legal or regulatory requirements;
  • significant supplier changes;
  • material changes in intended use;
  • loss of required human oversight.
Additional Triggers:

35. Approval Suspension

35.1 Suspension Criteria

Approval may be suspended where:
  • unacceptable risk emerges;
  • critical controls fail;
  • required human oversight is unavailable;
  • serious incidents occur;
  • unauthorized material changes occur;
  • operation exceeds approved scope.
Applicable Criteria:

35.2 Suspension Authority

Suspension Authority:

35.3 Suspension Record

Suspension ID: Suspension Date: Reason: Conditions for Resumption:

36. Approval Revocation

36.1 Revocation Criteria

Criteria:

36.2 Revocation Authority

Revocation Authority:

36.3 Revocation Record

Revocation ID: Date: Reason: Required Follow-Up:

37. Continuation Approval

Where this template is used for continued operation:

37.1 Continuation Review

Review Period: Operational Performance: Risk Status: Control Status: Monitoring Status: Incident Status: Assurance Status:

37.2 Continuation Decision

Decision:
  • Continue
  • Continue with Conditions
  • Restrict
  • Suspend
  • Change Required
  • Retire
Rationale:

38. Change Approval

Where this template is used for a material change:

38.1 Change Information

Change ID: Change Description: Change Classification:

38.2 Change Impact

Impact Assessment:

38.3 Change Risk

Risk Assessment Reference: Residual Risk:

38.4 Change Testing

Testing Status:

38.5 Change Decision

Decision:
  • Approved
  • Approved with Conditions
  • Deferred
  • Rejected
Conditions:

39. Emergency Approval

Where emergency approval is used:

39.1 Emergency Trigger

Emergency Reason:

39.2 Immediate Risk

Immediate Risk Assessment:

39.3 Emergency Authority

Emergency Approval Authority: Authority Basis:

39.4 Immediate Controls

Controls:

39.5 Retrospective Review

Retrospective Review Required: Review Due Date: Review Owner:

40. Evidence Profile

40.1 Evidence Repository

Evidence Repository: Evidence Owner:

40.2 Approval Evidence

40.3 Evidence Completeness

Evidence Status:
  • Complete
  • Substantially Complete
  • Partially Complete
  • Incomplete
Evidence Gaps:

41. Approval Traceability

The approval should maintain traceability to the records supporting the decision.

42. Approval Decision Workflow


43. Approval Completion Checklist

  • Approval ID assigned
  • AI System ID identified
  • Approval type identified
  • Approval scope defined
  • Intended purpose reviewed
  • Classification reviewed
  • Risk assessment reviewed
  • Risk treatment reviewed
  • Control assessment completed
  • Critical controls reviewed
  • Open findings reviewed
  • Evidence reviewed
  • Testing / validation reviewed
  • Human oversight verified
  • Security review completed where applicable
  • Privacy review completed where applicable
  • Fairness / impact review completed where applicable
  • Monitoring readiness assessed
  • Incident readiness assessed
  • Change-management readiness assessed
  • Operational readiness assessed
  • Business continuity assessed where applicable
  • Third-party readiness assessed where applicable
  • Residual risk determined
  • Risk acceptance determined
  • Required reviews completed
  • Conditions recorded
  • Approval authority verified
  • Segregation of duties considered
  • Final decision recorded
  • Deployment authorization recorded where applicable
  • Post-approval requirements established
  • Review triggers established
  • Evidence linked
  • Related AIGO records linked

44. Approval Communication

44.1 Communication Recipients

Recipients:

44.2 Communication Date

Date:

44.3 Communication Content

The approval communication should identify:
  • decision;
  • approved scope;
  • conditions;
  • restrictions;
  • effective date;
  • review date;
  • owner;
  • escalation requirements.
Communication Reference:

45. Approval Change History


46. Template Usage Instructions

This template should be completed according to the organization’s approved AIGO AI Approval Procedure. Approval should be based on sufficient evidence and appropriate governance authority. An approval decision should not be treated as valid where:
  • the approval authority lacks authority;
  • mandatory reviews are incomplete;
  • material risks are unknown;
  • critical controls are absent;
  • required human oversight is unavailable;
  • evidence is insufficient to support the decision.
Conditional approval should identify:
  • each condition;
  • owner;
  • due date;
  • verification method;
  • consequences of non-completion.
Approval should be reconsidered whenever material changes, significant incidents, significant control failures, risk increases, classification changes, or other defined triggers occur.

47. Template Governance

47.1 Template Owner

Template Owner:

47.2 Template Review

Review Frequency: Next Review Date:

47.3 Template Change Control

Changes to this template should be managed through the applicable AIGO document and change-management process. Material changes should consider their effect on:
  • AI Approval Procedure;
  • AI System Registration;
  • AI System Profile;
  • Classification;
  • Risk Assessment;
  • Control Assessment;
  • Risk Acceptance;
  • Monitoring;
  • Incident Management;
  • Change Management;
  • Assurance;
  • schemas;
  • mappings;
  • tools.

48. Document Control


49. Template Status

Document: AIGO — AI Approval Template Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-TPL-007 Document Type: AI Approval Template This template provides the controlled structure for evaluating evidence, risk, controls, readiness, conditions, and governance authority when approving AI-system deployment, continued operation, material change, resumption, suspension, or retirement.

50. End of Template

AIGO — AI Approval Template Document ID: AIGO-TPL-007 Version: 0.1 Status: Draft End of Template