AIGO — Basic AI System Example
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-001
Document Type: Implementation Example
Example Type: Basic AI System
Related Framework: AIGO AI Governance Operating Framework
1. Purpose
This document provides a complete example of how a basic AI system can be governed using the AIGO AI Governance Operating Framework. The example is intended to demonstrate the practical application of:- AI system registration;
- AI system identification;
- classification;
- risk assessment;
- control selection;
- approval;
- deployment;
- operation;
- monitoring;
- assurance;
- improvement;
- change management;
- continuation or retirement.
2. Example Organization
For this example, the organization is a fictional company named ExampleCorp. ExampleCorp is a medium-sized organization that uses AI to improve internal business operations. The organization has established an AIGO-based AI governance program covering AI systems used within the organization.3. Example AI System
The example AI system is called ExampleCorp Internal Knowledge Assistant. The system provides employees with an AI-powered interface for searching and summarizing internal organizational information.3.1 System Purpose
The system is intended to:- help employees locate internal information;
- summarize approved internal documents;
- answer questions about organizational procedures;
- provide references to source documents.
3.2 Intended Users
The intended users are:- employees;
- approved contractors;
- authorized internal support personnel.
3.3 Intended Environment
The system operates within ExampleCorp’s internal technology environment.4. Example System Profile
5. Governance Context
The system is subject to AIGO governance because it:- uses AI;
- processes organizational information;
- produces outputs used by employees;
- introduces potential reliability and confidentiality risks;
- depends on external technology components.
6. Governance Objective
The governance objective is to ensure that the AI system:- has an accountable owner;
- has a documented purpose;
- is appropriately classified;
- has undergone risk assessment;
- has appropriate controls;
- is approved before operational use;
- is monitored;
- produces appropriate evidence;
- is periodically assured;
- is changed or retired through controlled processes.
7. AIGO Lifecycle Application
The system follows the AIGO lifecycle:8. Stage 1 — Governance
The organization first establishes governance responsibility for the system.8.1 Governance Decisions
ExampleCorp assigns:- an executive sponsor;
- an AI system owner;
- a technical owner;
- a risk owner;
- control owners.
8.2 Governance Outcome
The system has a defined governance structure before implementation proceeds.9. Governance Roles
10. Stage 2 — Identify
The organization identifies the AI system and establishes its system profile.10.1 Identification Activities
The organization records:- system name;
- purpose;
- owner;
- users;
- technology;
- dependencies;
- data;
- lifecycle stage;
- third parties.
10.2 Identification Outcome
The system is entered into the organizational AI inventory.11. Example AI Inventory Record
12. Stage 3 — Classify
ExampleCorp applies its AI classification procedure. The classification considers:- intended purpose;
- affected persons;
- business criticality;
- data sensitivity;
- autonomy;
- potential harm;
- regulatory exposure;
- operational impact.
13. Example Classification
The system is classified as: AIGO Classification: Standard AI System The classification is based on the system being:- internally used;
- decision-supporting rather than decision-making;
- not directly determining employee rights;
- subject to human review;
- limited to internal organizational information.
14. Classification Decision
15. Stage 4 — Assess Risk
ExampleCorp performs an AI risk assessment. The assessment identifies risks related to:- inaccurate information;
- inappropriate recommendations;
- confidentiality;
- unauthorized access;
- hallucination;
- model dependency;
- supplier dependency;
- data leakage;
- inadequate monitoring.
16. Example Risk Register
17. Risk Treatment
ExampleCorp selects proportionate controls. Treatment measures include:- source citation;
- access control;
- data restrictions;
- human oversight;
- user guidance;
- monitoring;
- incident escalation;
- supplier management.
18. Risk Treatment Record
19. Stage 5 — Select Controls
Controls are selected based on:- identified risks;
- system classification;
- organizational requirements;
- lifecycle stage;
- applicable governance requirements.
20. Example Control Set
21. Control Implementation
Each selected control is implemented through an applicable AIGO procedure.22. Stage 6 — Control Assessment
Before approval, ExampleCorp verifies that required controls are implemented.23. Stage 7 — Approval
The system requires approval before operational deployment. Approval considers:- classification;
- risk;
- controls;
- residual risk;
- evidence;
- readiness.
24. Approval Decision
ExampleCorp determines that:- required controls are implemented;
- residual risk is acceptable;
- operational ownership is established;
- monitoring is ready;
- users have received appropriate guidance.
25. Approval Record
26. Stage 8 — Deploy
The system is deployed according to the approved deployment plan. Deployment controls include:- production access;
- configuration validation;
- security validation;
- user provisioning;
- monitoring activation;
- incident readiness.
27. Deployment Readiness
28. Stage 9 — Operate
During operation, the system performs its intended business function. Operational activities include:- user support;
- content maintenance;
- access management;
- monitoring;
- issue management;
- supplier management.
29. Operational Responsibilities
The System Owner is responsible for ensuring that:- the system remains within approved scope;
- controls remain operational;
- risks are monitored;
- incidents are escalated;
- changes are controlled.
30. Stage 10 — Monitor
ExampleCorp monitors the system continuously or periodically according to risk. Monitoring areas include:- system availability;
- output quality;
- user complaints;
- incidents;
- access violations;
- security events;
- content freshness;
- control effectiveness.
31. Example Monitoring Metrics
32. Monitoring Thresholds
Thresholds should trigger defined responses.33. Stage 11 — Incident Management
Suppose ExampleCorp identifies an incident in which the system provides an outdated internal procedure to an employee. The incident is recorded.34. Example Incident
35. Incident Response
36. Stage 12 — Assurance
Periodic assurance evaluates whether the governance system continues to operate effectively. Assurance considers:- controls;
- evidence;
- risk;
- monitoring;
- incidents;
- changes;
- compliance;
- governance decisions.
37. Example Assurance Review
The assurance function reviews:- AI inventory record;
- classification;
- risk assessment;
- control implementation;
- evidence;
- monitoring records;
- incidents;
- change records;
- approval;
- management review.
38. Assurance Result
Example assurance conclusion: Generally Effective — Improvement Required A minor weakness is identified in the frequency of content-source reviews.39. Corrective Action
ExampleCorp establishes a corrective action:40. Stage 13 — Improve
The corrective action is implemented. ExampleCorp updates:- procedure;
- monitoring;
- control frequency;
- evidence requirements.
41. Improvement Cycle
42. Stage 14 — Change Management
Later, ExampleCorp decides to expand the system so that it can provide information from a new sensitive business repository. This is a material change. The change must therefore follow the AIGO change-management procedure.43. Change Assessment
The organization assesses:- changed purpose;
- new data;
- new stakeholders;
- increased risk;
- changed classification;
- changed controls;
- new security requirements.
44. Example Change Record
45. Change Decision
The change may result in:46. Lifecycle Reassessment
If the change materially increases risk, ExampleCorp may require:- new risk assessment;
- new controls;
- additional assurance;
- revised approval;
- enhanced monitoring.
47. Continuation Decision
At periodic review, the organization determines whether the AI system should:- continue;
- change;
- suspend;
- retire.
48. Continuation Decision Model
49. Example Continuation Decision
ExampleCorp determines that:- business need remains;
- risks remain within tolerance;
- controls remain effective;
- monitoring is operating;
- no material incidents remain unresolved.
50. Example Evidence Set
The complete example generates evidence such as:51. End-to-End Traceability
52. Example AIGO Traceability Matrix
53. Example Decision Chain
54. Example NIST AI RMF Relationship
The example can also be viewed through the NIST AI RMF Functions.55. Example ISO/IEC 42001 Relationship
The example also provides implementation evidence relevant to an AI management-system approach, including:- organizational context;
- leadership;
- planning;
- risk management;
- operational controls;
- performance evaluation;
- improvement.
56. Example Control Lifecycle
57. Example Governance Lifecycle
58. Lessons from the Example
The example demonstrates several important AIGO principles:- AI governance begins before deployment;
- ownership must be established early;
- classification influences governance depth;
- risk drives control selection;
- controls require operational procedures;
- implementation requires evidence;
- approval should be evidence-based;
- monitoring continues after deployment;
- incidents feed improvement;
- material changes trigger reassessment;
- lifecycle governance is continuous.
59. Common Mistakes Demonstrated
Organizations should avoid:- deploying before approval;
- relying on informal ownership;
- treating classification as permanent;
- conducting risk assessment without treatment;
- implementing controls without evidence;
- monitoring without thresholds;
- closing incidents without lessons learned;
- making material changes without reassessment.
60. Example Minimum Evidence Package
For a basic AI system, a minimum governance evidence package may include:- system profile;
- classification;
- risk assessment;
- control assessment;
- approval;
- monitoring evidence;
- incident records;
- periodic review;
- assurance evidence.
61. Example Operational Status
At the end of this example: System: Active Lifecycle Stage: Operate / Monitor Classification: Standard Risk: Moderate Controls: Operational Monitoring: Active Assurance: Periodic Residual Risk: Accepted within organizational tolerance Decision: Continue62. Example Final State
63. Reusability of This Example
This example can serve as a reference when implementing AIGO for other AI systems. The exact controls, risks, roles, evidence, and approval requirements should be adapted according to:- organizational context;
- AI-system purpose;
- risk;
- impact;
- regulatory requirements;
- applicable standards;
- lifecycle stage.
64. Relationship to Templates
This example should later inform the design of AIGO templates. Potential template candidates include:- AI system registration;
- AI system profile;
- classification;
- risk assessment;
- control assessment;
- approval;
- monitoring;
- incident;
- assurance;
- change management;
- continuation decision.
65. Relationship to Procedures
This example demonstrates the practical use of the AIGO procedures, including:- AI Governance Procedure;
- AI System Registration Procedure;
- AI Risk Assessment Procedure;
- AI Classification Procedure;
- AI Control Assessment Procedure;
- AI Approval Procedure;
- AI Change Management Procedure;
- AI Incident Management Procedure;
- AI Monitoring Procedure;
- AI Assurance Procedure;
- AI Risk Acceptance Procedure;
- AI Retirement Procedure;
- Continuous Improvement Procedure.
66. Example Governance Principle
The central principle demonstrated by this example is:No AI system should move through its lifecycle without appropriate governance, risk evaluation, controls, accountability, evidence, and decision authority.
67. Document Status
Document: AIGO — Basic AI System Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-001
Document Type: Implementation Example
Example Type: Basic AI System
This document provides an illustrative end-to-end example of applying AIGO to a standard internal AI system.
68. End of Example Document
AIGO — Basic AI System Example Document ID:AIGO-EXAMPLE-001
Version: 0.1
Status: Draft
End of Document