AIGO — AI Governance Operating Framework
AI Monitoring Template
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-TPL-009
Document Type: AI Monitoring Template
Template Purpose: Controlled Monitoring of AI System Performance, Risk, Controls, and Governance
1. Template Purpose
This template provides the controlled structure for establishing, operating, reviewing, and improving monitoring of an AI system under the AIGO AI Governance Operating Framework. Monitoring should provide evidence that an AI system continues to operate within approved:- performance parameters;
- risk tolerance;
- control requirements;
- governance conditions;
- security requirements;
- privacy requirements;
- fairness requirements;
- human-oversight requirements;
- operational requirements.
- investigation;
- risk reassessment;
- control reassessment;
- incident management;
- change management;
- escalation;
- suspension;
- corrective action;
- assurance;
- continual improvement.
2. Monitoring Instructions
Complete all applicable sections. Where information is unavailable, record: Pending — [reason] Where a field does not apply, record: Not Applicable — [reason] Use stable identifiers wherever possible. Recommended identifiers include:- AI System ID;
- Monitoring Plan ID;
- Monitoring Review ID;
- Indicator ID;
- Alert ID;
- Risk ID;
- Control ID;
- Incident ID;
- Change ID;
- Evidence ID;
- Assurance ID;
- Improvement ID.
3. Monitoring Record
3.1 Identification
AI System ID: Monitoring Plan ID: Monitoring Version: System Name: System Version: Monitoring Status:- Draft
- Under Review
- Approved
- Active
- Suspended
- Under Revision
- Retired
4. Monitoring Scope
4.1 System Scope
AI system / component covered:4.2 Operational Scope
Business processes / operations covered:4.3 Geographic Scope
Jurisdictions / locations covered:4.4 Lifecycle Scope
Select applicable stages:- Deploy
- Operate
- Monitor
- Assure
- Improve
- Change
- Continue
- Retire
4.5 Monitoring Exclusions
Excluded systems, indicators, or activities: Exclusion Rationale:5. Monitoring Objectives
5.1 Primary Objectives
Monitoring objectives may include:- detect performance degradation;
- detect data-quality problems;
- detect data drift;
- detect model drift;
- detect fairness concerns;
- detect security events;
- detect privacy issues;
- detect control failures;
- detect unauthorized changes;
- detect human-oversight issues;
- support risk management;
- support incident management;
- support change management;
- provide governance evidence.
5.2 Monitoring Outcomes
Expected Monitoring Outcomes:6. Monitoring Governance
6.1 Monitoring Owner
Monitoring Owner: Role: Responsibilities:6.2 Monitoring Review Authority
Review Authority:6.3 Escalation Authority
Escalation Authority:6.4 Segregation of Duties
Monitoring / Review / Escalation Separation Requirements:7. Monitoring Architecture
7.1 Monitoring Architecture Description
Architecture:7.2 Monitoring Sources
Potential sources include:- application logs;
- model telemetry;
- data-quality systems;
- security systems;
- privacy systems;
- business systems;
- user feedback;
- incident systems;
- control systems;
- assurance records.
7.3 Data Collection
Collection Method: Collection Frequency:7.4 Monitoring Repository
Repository / Platform:8. Monitoring Categories
Monitoring may cover:- Technical Performance
- Model Performance
- Data Quality
- Data Drift
- Model Drift
- Fairness
- Human Oversight
- Security
- Privacy
- Safety
- Reliability
- Transparency
- Operational Performance
- Governance
- Risk
- Controls
- Third-Party Dependencies
- Incidents
- Changes
- Compliance / Regulatory Requirements
9. Monitoring Indicator Register
10. Indicator Definition
10.1 Indicator Identification
Indicator ID: Indicator Name: Category: Owner:10.2 Indicator Purpose
Purpose:10.3 Measurement Definition
Definition:10.4 Measurement Method
Method / Formula / Measurement Approach:10.5 Data Source
Source:10.6 Frequency
Measurement Frequency:10.7 Reporting Frequency
Reporting Frequency:11. Threshold Management
11.1 Threshold Types
Thresholds may include:- normal operating range;
- warning threshold;
- escalation threshold;
- critical threshold;
- mandatory stop / suspension threshold.
11.2 Threshold Register
11.3 Threshold Rationale
Rationale for thresholds:11.4 Threshold Review
Threshold Review Frequency: Threshold Change Authority:12. Technical Performance Monitoring
12.1 Technical Indicators
Potential indicators include:- availability;
- uptime;
- response time;
- latency;
- error rate;
- processing failures;
- service capacity;
- infrastructure health.
12.2 Technical Thresholds
12.3 Technical Response
Response to Technical Breach:13. Model Performance Monitoring
13.1 Model Indicators
Potential indicators include:- accuracy;
- precision;
- recall;
- error rate;
- false positives;
- false negatives;
- response quality;
- output consistency.
13.2 Model Thresholds
13.3 Model Performance Review
Review Method: Performance Review Owner:14. Data Quality Monitoring
14.1 Data Quality Indicators
Potential indicators include:- completeness;
- accuracy;
- validity;
- consistency;
- timeliness;
- duplication;
- missing values;
- unexpected values.
14.2 Data Quality Thresholds
14.3 Data Quality Response
Response Process:15. Data Drift Monitoring
15.1 Drift Indicators
Indicators:15.2 Baseline
Baseline Reference:15.3 Drift Threshold
Threshold:15.4 Drift Response
15.5 Drift Evidence
Evidence IDs:16. Model Drift Monitoring
16.1 Model Drift Indicators
Indicators:16.2 Drift Detection Method
Method:16.3 Drift Threshold
Threshold:16.4 Drift Response
Response:17. Fairness Monitoring
17.1 Applicability
Fairness Monitoring Applicable:17.2 Fairness Indicators
Potential indicators include:- subgroup performance;
- error-rate differences;
- false-positive differences;
- false-negative differences;
- selection-rate differences;
- outcome disparities.
17.3 Fairness Thresholds
17.4 Fairness Response
Response to Material Fairness Deviation:17.5 Fairness Evidence
Evidence IDs:18. Human Oversight Monitoring
18.1 Oversight Indicators
Potential indicators include:- override rate;
- challenge rate;
- escalation rate;
- human-review completion;
- review timeliness;
- reviewer error;
- user complaints.
18.2 Oversight Thresholds
18.3 Oversight Response
Response:19. Security Monitoring
19.1 Security Indicators
Potential indicators include:- unauthorized access;
- authentication failures;
- privilege escalation;
- abnormal API activity;
- suspicious inputs;
- vulnerability status;
- security alerts.
19.2 Security Escalation
Security Escalation Process:19.3 Security Evidence
Evidence IDs:20. Privacy Monitoring
20.1 Privacy Indicators
Potential indicators include:- unauthorized data access;
- data-processing deviations;
- retention exceptions;
- sensitive-data exposure;
- privacy complaints;
- privacy incidents.
20.2 Privacy Escalation
Privacy Escalation Process:20.3 Privacy Evidence
Evidence IDs:21. Safety and Reliability Monitoring
21.1 Safety Indicators
Applicable Safety Indicators:21.2 Reliability Indicators
Applicable Reliability Indicators:21.3 Safety / Reliability Thresholds
22. Operational Monitoring
22.1 Operational Indicators
Potential indicators include:- process completion;
- operational errors;
- business workflow failures;
- service availability;
- user support requests;
- transaction volume.
22.2 Operational Thresholds
Thresholds:23. Governance Monitoring
23.1 Governance Indicators
Potential indicators include:- required reviews completed;
- overdue reviews;
- risk assessments completed;
- control assessments completed;
- approvals current;
- evidence completeness;
- management reviews completed;
- exceptions within expiry.
23.2 Governance Thresholds
24. Risk Monitoring
24.1 Risk Indicators
24.2 Risk Threshold Breach
Required Response:24.3 Risk Reassessment Trigger
Conditions triggering risk reassessment:25. Control Monitoring
25.1 Control Indicators
25.2 Control Failure
Control Failure Response:25.3 Control Reassessment
Control Reassessment Trigger:26. Third-Party Monitoring
26.1 Supplier Indicators
Potential indicators include:- service availability;
- supplier incidents;
- security issues;
- model changes;
- contract breaches;
- assurance status;
- service degradation.
26.2 Supplier Thresholds
Thresholds:26.3 Supplier Escalation
Escalation Process:27. Incident Monitoring
27.1 Incident Indicators
Indicators:27.2 Incident Trigger Conditions
Monitoring may trigger incident management where:- material thresholds are breached;
- potential harm is identified;
- unauthorized operation occurs;
- security compromise is suspected;
- fairness deterioration is material;
- required controls fail.
27.3 Incident Procedure
Incident Procedure:28. Change Monitoring
28.1 Change Indicators
Potential indicators include:- unauthorized changes;
- model changes;
- configuration changes;
- data-pipeline changes;
- supplier changes;
- architecture changes.
28.2 Change Trigger
Monitoring conditions that require change-management review:28.3 Change Procedure
Change Procedure:29. Alert Management
29.1 Alert Register
29.2 Alert Severity
29.3 Alert Validation
Validation Method:29.4 False Positive Management
False Positive Handling:30. Monitoring Response
30.1 Response Model
30.2 Response Options
Potential responses include:- continue monitoring;
- investigate;
- increase monitoring;
- correct;
- treat risk;
- open incident;
- initiate change;
- reassess classification;
- suspend operation;
- rollback;
- retire.
31. Escalation
31.1 Escalation Path
Escalation Path:31.2 Escalation Authority
Authority:31.3 Escalation Timeframes
32. Enhanced Monitoring
32.1 Trigger
Enhanced Monitoring Trigger:32.2 Duration
Duration:32.3 Enhanced Indicators
Indicators:32.4 Enhanced Review
Review Frequency:32.5 Exit Criteria
Criteria for returning to normal monitoring:33. Monitoring Review
33.1 Review Record
Monitoring Review ID: Review Period: Review Date: Reviewer: Monitoring Owner:33.2 Review Results
Overall Monitoring Status:- Normal
- Acceptable with Observation
- Warning
- Escalated
- Critical
33.3 Key Findings
33.4 Key Actions
34. Monitoring Report
34.1 Reporting Period
Period:34.2 Executive Summary
Summary:34.3 Indicator Results
34.4 Incidents
Incidents During Period:34.5 Changes
Changes During Period:34.6 Risk Changes
Risk Changes:34.7 Control Changes
Control Changes:34.8 Recommendations
Recommendations:35. Monitoring Evidence
35.1 Evidence Repository
Monitoring Evidence Repository: Evidence Owner:35.2 Evidence Register
35.3 Evidence Completeness
Evidence Status:- Complete
- Substantially Complete
- Partially Complete
- Incomplete
36. Monitoring Data Quality
Monitoring itself should be subject to quality controls.36.1 Monitoring Data Quality
Assess:- completeness;
- accuracy;
- timeliness;
- availability;
- integrity;
- consistency.
36.2 Monitoring Failure
Known Monitoring Failures:36.3 Monitoring Recovery
Recovery Actions:37. Monitoring Independence
37.1 Independence Requirements
Independence Requirements:37.2 Review Independence
Reviewer Independence:37.3 Conflict Management
Conflict-of-Interest Controls:38. Monitoring and Assurance
38.1 Assurance Relationship
Assurance Required: Assurance Frequency: Assurance Owner:38.2 Related Assurance Records
39. Monitoring and Incident Relationship
39.1 Related Incidents
39.2 Incident-Triggered Monitoring
Enhanced Monitoring Required: Reason:40. Monitoring and Change Relationship
40.1 Related Changes
40.2 Change-Triggered Monitoring
Enhanced Monitoring Required: Reason:41. Monitoring and Risk Relationship
41.1 Related Risks
41.2 Risk Reassessment Trigger
Monitoring Conditions Requiring Risk Reassessment:42. Monitoring and Control Relationship
42.1 Related Controls
42.2 Control Reassessment Trigger
Conditions Requiring Control Reassessment:43. Monitoring Traceability
43.1 Traceability Matrix
44. Continual Improvement
44.1 Improvement Sources
Monitoring improvement opportunities may originate from:- recurring alerts;
- false positives;
- false negatives;
- incidents;
- assurance findings;
- risk changes;
- control failures;
- changes in AI behavior;
- stakeholder feedback.
44.2 Improvement Actions
45. Monitoring Review and Approval
45.1 Prepared By
Name: Role: Date:45.2 Reviewed By
Name: Role: Date:45.3 Approved By
Name: Role: Date:45.4 Monitoring Plan Decision
Decision:- Approved
- Approved with Conditions
- Returned for Revision
- Deferred
- Rejected
46. Monitoring Review Schedule
46.1 Periodic Review
Review Frequency: Next Review Date: Review Owner:46.2 Triggered Review
Review should be considered after:- material incidents;
- material changes;
- significant risk changes;
- control failures;
- monitoring-system failures;
- regulatory changes;
- significant threshold breaches;
- assurance findings.
47. Monitoring Change History
48. Monitoring Completion Checklist
- Monitoring Plan ID assigned
- AI System ID identified
- Monitoring owner assigned
- Monitoring objectives documented
- Scope defined
- Monitoring architecture documented
- Sources identified
- Indicators defined
- Measurement methods defined
- Frequencies defined
- Thresholds defined
- Threshold authority identified
- Technical monitoring defined
- Model monitoring defined
- Data-quality monitoring defined
- Data-drift monitoring defined
- Model-drift monitoring defined
- Fairness monitoring defined where applicable
- Human-oversight monitoring defined
- Security monitoring defined
- Privacy monitoring defined where applicable
- Safety / reliability monitoring defined where applicable
- Operational monitoring defined
- Governance monitoring defined
- Risk monitoring defined
- Control monitoring defined
- Third-party monitoring defined where applicable
- Incident triggers defined
- Change triggers defined
- Alert process defined
- Escalation process defined
- Enhanced monitoring conditions defined
- Review process defined
- Reporting requirements defined
- Evidence requirements defined
- Monitoring-data quality requirements defined
- Assurance relationship defined
- Incident relationship defined
- Change relationship defined
- Risk relationship defined
- Control relationship defined
- Improvement process defined
- Plan reviewed and approved
49. Template Usage Instructions
This template should be completed according to the organization’s approved AIGO AI Monitoring Procedure. Monitoring should be designed according to the risk and characteristics of the AI system. Monitoring should not focus only on technical performance. Where relevant, it should also consider:- risk;
- controls;
- fairness;
- privacy;
- security;
- human oversight;
- incidents;
- changes;
- governance;
- stakeholder impacts.
50. Template Governance
50.1 Template Owner
Template Owner:50.2 Template Review
Review Frequency: Next Review Date:50.3 Template Change Control
Changes to this template should be managed through the applicable AIGO document and change-management process. Material changes should consider their effect on:- AI Monitoring Procedure;
- AI System Profile;
- AI Risk Assessment;
- AI Control Assessment;
- AI Incident Management;
- AI Change Management;
- AI Assurance;
- Risk Acceptance;
- Management Review;
- schemas;
- mappings;
- tools.
51. Document Control
52. Template Status
Document: AIGO — AI Monitoring Template Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-TPL-009
Document Type: AI Monitoring Template
This template provides the controlled structure for defining, operating, reviewing, escalating, evidencing, and improving monitoring of AI-system performance, risk, controls, governance, and operating conditions throughout the AIGO lifecycle.
53. End of Template
AIGO — AI Monitoring Template Document ID:AIGO-TPL-009
Version: 0.1
Status: Draft
End of Template