Skip to main content

AIGO — High-Risk AI System Example

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-002 Document Type: Implementation Example Example Type: High-Risk AI System Related Framework: AIGO AI Governance Operating Framework

1. Purpose

This document provides an illustrative end-to-end example of how AIGO can be applied to an AI system presenting a significantly higher level of risk than the basic AI system described in the previous example. The purpose is to demonstrate how increased risk can result in:
  • stronger governance;
  • enhanced accountability;
  • deeper risk assessment;
  • increased control requirements;
  • stronger human oversight;
  • enhanced evidence requirements;
  • more restrictive approval;
  • increased monitoring;
  • more frequent assurance;
  • formal change assessment;
  • controlled continuation or retirement.
This example is illustrative. Actual governance requirements should be determined according to the organization’s context, applicable law, regulatory requirements, standards, contracts, and the characteristics of the AI system.

2. Example Organization

For this example, the organization is ExampleCorp, a fictional organization with an established AIGO governance program. ExampleCorp operates a large recruitment function and uses AI to assist with candidate screening and prioritization. Because the system may influence employment-related decisions, ExampleCorp applies enhanced governance.

3. Example AI System

The example AI system is called: ExampleCorp Candidate Assessment Assistant The system analyzes candidate information and generates a recommendation concerning whether a candidate should progress to the next stage of recruitment. The system does not have final hiring authority. A designated human decision-maker remains responsible for the final recruitment decision.

4. Intended Purpose

The system is intended to:
  • assist recruitment personnel in reviewing candidate information;
  • identify candidates meeting defined job-related criteria;
  • prioritize candidates for human review;
  • identify potentially relevant qualifications;
  • support consistent processing of high volumes of applications.
The system is not intended to:
  • make autonomous hiring decisions;
  • reject candidates without human review;
  • infer protected characteristics;
  • evaluate candidates using unrelated personal attributes;
  • replace recruitment professionals.

5. Example System Profile


6. Why Enhanced Governance Is Required

The system can influence decisions affecting individuals. Potential consequences include:
  • unfair treatment;
  • discrimination;
  • inappropriate exclusion;
  • privacy impacts;
  • inaccurate candidate evaluation;
  • lack of transparency;
  • automation bias;
  • reputational damage;
  • regulatory exposure.
Accordingly, ExampleCorp applies enhanced AIGO governance.

7. Governance Model

The governance structure is strengthened compared with a standard AI system.

8. Enhanced Governance Roles


9. Governance Requirements

The system must not proceed to operational use until:
  • the system is registered;
  • its intended purpose is documented;
  • classification is completed;
  • risk assessment is completed;
  • applicable legal requirements are identified;
  • controls are implemented;
  • testing is completed;
  • human oversight is established;
  • evidence is available;
  • residual risk is formally considered;
  • required approval is granted.

10. AIGO Lifecycle

The high-risk system follows the same fundamental AIGO lifecycle, but with enhanced controls.

11. Stage 1 — Governance

The organization identifies the system as requiring enhanced governance before technical deployment. The AI Governance Authority appoints responsible roles and establishes the governance conditions.

12. Governance Decision

ExampleCorp determines: Governance Level: Enhanced Reason:
  • the system influences employment-related decisions;
  • individuals may be materially affected;
  • errors may result in unfair outcomes;
  • regulatory obligations may apply;
  • human oversight is essential.

13. Stage 2 — Identify

The system is formally registered in the AI inventory. The registration captures:
  • system identity;
  • purpose;
  • owner;
  • business process;
  • affected persons;
  • data;
  • model provider;
  • technical architecture;
  • dependencies;
  • lifecycle stage.

14. High-Risk AI Inventory Record


15. Stage 3 — Classification

Classification is performed using the AIGO AI Classification Procedure. Factors considered include:
  • impact on individuals;
  • decision significance;
  • degree of automation;
  • affected population;
  • sensitivity of data;
  • potential discrimination;
  • legal obligations;
  • operational dependency;
  • severity of potential harm.

16. Example Classification Result

AIGO Classification: High-Risk AI System The classification is based on the system’s role in an employment-related decision process.

17. Classification Assessment


18. Classification Consequence

The classification automatically increases governance requirements.

19. Stage 4 — Context Assessment

Before assessing individual risks, ExampleCorp documents the system context. The context includes:
  • recruitment process;
  • candidate population;
  • jurisdictions;
  • job categories;
  • decision-makers;
  • data sources;
  • model characteristics;
  • organizational objectives;
  • legal requirements.

20. Affected Stakeholders

Stakeholders include:
  • job applicants;
  • recruitment personnel;
  • hiring managers;
  • HR leadership;
  • legal and compliance teams;
  • privacy function;
  • security function;
  • AI governance authority;
  • executive management.

21. Stage 5 — Risk Assessment

A detailed AI risk assessment is performed. Risk categories include:
  • fairness;
  • discrimination;
  • privacy;
  • security;
  • accuracy;
  • robustness;
  • explainability;
  • transparency;
  • human oversight;
  • misuse;
  • third-party dependency;
  • operational continuity;
  • legal and regulatory exposure.

22. High-Risk AI Risk Register


23. Risk Treatment Principle

For a high-risk system, ExampleCorp does not rely solely on accepting residual risk. The organization first seeks to:
  1. eliminate unnecessary risks;
  2. reduce risks through design;
  3. implement preventive controls;
  4. implement detective controls;
  5. establish human oversight;
  6. monitor residual risks;
  7. formally document accepted residual risks.

24. Risk Treatment Hierarchy


25. Example Risk Treatments


26. Stage 6 — Control Design

Controls are designed specifically for the high-risk nature of the system. Controls include:
  • purpose limitation;
  • data governance;
  • access control;
  • model validation;
  • performance testing;
  • fairness testing;
  • human oversight;
  • output review;
  • incident management;
  • monitoring;
  • change management;
  • assurance;
  • supplier management.

27. Enhanced Control Set


28. Human Oversight

Human oversight is a core control. The system may provide recommendations, but the final decision remains with an authorized human.

29. Human Decision Requirements

The human decision-maker must:
  • understand the AI system’s role;
  • review relevant information;
  • consider whether the recommendation is reasonable;
  • be able to challenge the output;
  • be able to override the recommendation;
  • avoid treating the AI output as automatically correct;
  • record the final decision where required.

30. Automation Bias Control

ExampleCorp recognizes automation bias as a specific risk. Controls include:
  • user training;
  • explicit human decision responsibility;
  • explanation of system limitations;
  • mandatory review;
  • random quality checks;
  • override monitoring.

31. Data Governance

The organization evaluates:
  • data source legitimacy;
  • data quality;
  • relevance;
  • accuracy;
  • representativeness;
  • retention;
  • access;
  • provenance;
  • inappropriate attributes.

32. Data Governance Decision

The system is prohibited from using unnecessary personal information. Only information relevant to the approved recruitment purpose may be processed.

33. Model Validation

Before deployment, the technical and governance teams validate:
  • accuracy;
  • reliability;
  • robustness;
  • performance;
  • fairness;
  • known limitations;
  • failure conditions.

34. Validation Evidence

Example evidence includes:

35. Fairness Assessment

ExampleCorp performs an appropriate fairness assessment based on applicable law, available data, and organizational requirements. The assessment considers whether system outputs could systematically disadvantage particular groups. Potential findings require investigation before deployment.

36. Fairness Decision

If material unexplained disparities are identified, deployment is not automatically permitted. The organization may:
  • modify the system;
  • modify data;
  • introduce additional controls;
  • restrict the use case;
  • require additional human review;
  • suspend deployment.

37. Stage 7 — Control Assessment

Every critical control must be assessed before approval.

38. Stage 8 — Approval

Approval requires enhanced governance authority. The system cannot be deployed solely on the basis of technical acceptance. The approval decision considers:
  • legal requirements;
  • risk;
  • controls;
  • testing;
  • fairness;
  • human oversight;
  • evidence;
  • residual risk;
  • business necessity.

39. Approval Chain


40. Approval Conditions

Approval may include conditions such as:
  • limited initial deployment;
  • mandatory human review;
  • restricted user population;
  • enhanced monitoring;
  • periodic fairness testing;
  • mandatory incident reporting;
  • scheduled reassessment.

41. Example Approval Record


42. Stage 9 — Controlled Deployment

Deployment is performed in stages. ExampleCorp begins with a limited pilot.

43. Pilot Conditions

The pilot requires:
  • restricted users;
  • restricted job categories;
  • increased human review;
  • enhanced monitoring;
  • incident escalation;
  • predefined stop criteria.

44. Stop Criteria

Deployment must be paused if:
  • serious discrimination concerns arise;
  • material control failure occurs;
  • unauthorized data is processed;
  • system performance falls below threshold;
  • significant unexplained model behavior occurs;
  • required human oversight fails.

45. Stage 10 — Operation

During operation, ExampleCorp continuously manages:
  • system performance;
  • candidate-impact indicators;
  • incidents;
  • user behavior;
  • model changes;
  • supplier changes;
  • control effectiveness.

46. Operational Control Model


47. Stage 11 — Monitoring

Monitoring is more intensive than for a standard AI system. Monitoring includes:
  • accuracy;
  • performance;
  • fairness indicators;
  • override rates;
  • complaints;
  • incidents;
  • system drift;
  • data changes;
  • model changes;
  • control failures.

48. Example Monitoring Metrics


49. Monitoring Escalation


50. Stage 12 — Incident Example

Suppose monitoring identifies a significant difference in candidate prioritization between demographic groups. The issue is treated as a potential high-severity AI governance incident.

51. Incident Record


52. Incident Response


53. Immediate Containment

ExampleCorp may temporarily:
  • suspend automated recommendations;
  • require manual candidate review;
  • restrict affected job categories;
  • preserve evidence;
  • notify relevant governance functions;
  • begin root-cause analysis.

54. Root Cause Analysis

The investigation may consider:
  • training data;
  • data representation;
  • model behavior;
  • feature selection;
  • system configuration;
  • implementation changes;
  • user behavior;
  • supplier changes.

55. Corrective Action

Possible corrective actions include:
  • retraining;
  • data correction;
  • model modification;
  • additional controls;
  • revised thresholds;
  • enhanced human review;
  • restriction of system use;
  • additional validation.

56. Stage 13 — Assurance

High-risk AI requires stronger assurance. Assurance may be:
  • more frequent;
  • independent;
  • evidence-based;
  • risk-focused;
  • triggered by significant events.

57. Assurance Scope

Assurance examines:
  1. governance;
  2. system purpose;
  3. classification;
  4. risk;
  5. controls;
  6. data;
  7. model validation;
  8. fairness;
  9. human oversight;
  10. monitoring;
  11. incidents;
  12. changes;
  13. evidence;
  14. management decisions.

58. Assurance Finding

Example assurance finding: Finding HR-F001 — Human Override Monitoring Insufficient The organization has documented human override requirements, but override behavior is not being consistently monitored.

59. Corrective Action


60. Stage 14 — Change Management

High-risk systems require formal reassessment for material changes. Changes include:
  • new model;
  • new data;
  • new provider;
  • new purpose;
  • new user population;
  • new geography;
  • new decision context;
  • significant model update.

61. Material Change Flow


62. Example Material Change

ExampleCorp proposes using the system for executive recruitment. This is considered a material change because:
  • the affected population changes;
  • decision significance increases;
  • risk profile changes;
  • governance expectations may change.
The existing approval does not automatically authorize the new use.

63. Change Decision

The organization requires:
  • new risk assessment;
  • classification review;
  • legal review;
  • additional testing;
  • control reassessment;
  • new approval.

64. Stage 15 — Periodic Review

The system undergoes scheduled management review. The review considers:
  • current risk;
  • incidents;
  • control performance;
  • monitoring;
  • complaints;
  • model changes;
  • regulatory changes;
  • business necessity;
  • assurance findings.

65. Management Review Decision

Possible decisions:

66. Residual Risk

After controls are implemented, ExampleCorp determines residual risk. Residual risk must be:
  • documented;
  • understood;
  • within approved tolerance;
  • assigned to an accountable owner;
  • periodically reviewed.

67. Risk Acceptance

Formal risk acceptance requires appropriate authority.

68. Example Risk Acceptance


69. Stage 16 — Improvement

Lessons from:
  • incidents;
  • monitoring;
  • assurance;
  • user feedback;
  • regulatory developments;
  • technology changes;
are incorporated into the governance system.

70. Continual Improvement Cycle


71. Stage 17 — Continue, Restrict, Suspend or Retire

At the end of each review cycle, the organization determines the appropriate lifecycle decision. Possible outcomes:
  • continue;
  • continue with conditions;
  • restrict;
  • suspend;
  • replace;
  • retire.

72. Retirement Decision

Retirement may be triggered by:
  • unacceptable residual risk;
  • repeated control failure;
  • inability to maintain fairness;
  • obsolete technology;
  • regulatory prohibition;
  • business discontinuation;
  • replacement by a safer solution.

73. Retirement Flow


74. High-Risk AI Evidence Package

The evidence package is more extensive than for a standard AI system.

75. End-to-End Traceability


76. Example Traceability Matrix


77. Relationship to ISO/IEC 42001

The example demonstrates how an AIGO high-risk AI governance process can support management-system activities associated with:
  • organizational context;
  • leadership;
  • planning;
  • risk management;
  • operational controls;
  • performance evaluation;
  • management review;
  • continual improvement.
The precise applicability of ISO/IEC 42001 requirements must be assessed against the organization’s implementation and the applicable standard.

78. Relationship to NIST AI RMF

The example can also be represented through the four NIST AI RMF Functions.

79. Comparison With Basic AI Example


80. Key Governance Lessons

This example demonstrates that higher AI risk should result in proportionately stronger governance. Important principles include:
  1. classification must influence governance intensity;
  2. affected persons must be considered;
  3. risk assessment must address potential harm;
  4. controls must address identified risks;
  5. human oversight must be meaningful;
  6. technical validation is not sufficient by itself;
  7. fairness and impact considerations require evidence;
  8. approval must be based on evidence;
  9. monitoring must continue throughout operation;
  10. material changes require reassessment;
  11. incidents must feed continual improvement;
  12. retirement must be governed as carefully as deployment.

81. Minimum High-Risk AI Governance Package

A high-risk AI system should generally have, at minimum:
  • system registration;
  • documented purpose;
  • identified stakeholders;
  • classification;
  • comprehensive risk assessment;
  • risk treatment;
  • control assessment;
  • data governance;
  • model validation;
  • appropriate impact/fairness assessment;
  • human oversight;
  • approval;
  • monitoring;
  • incident management;
  • assurance;
  • change management;
  • management review;
  • documented lifecycle decision.
The actual minimum package should be determined by applicable organizational and legal requirements.

82. Example Final Operational State

At the conclusion of this example: System: Active under enhanced governance Lifecycle Stage: Operate / Monitor Classification: High-Risk Human Oversight: Mandatory Risk: Residual risk formally accepted Controls: Operational Monitoring: Enhanced Assurance: Periodic and independent Approval: Conditional / controlled Decision: Continue with conditions

83. Final Governance Model


84. Relationship to Future AIGO Templates

This example provides requirements that should later be reflected in AIGO templates, including:
  • high-risk AI system profile;
  • enhanced classification assessment;
  • high-risk risk assessment;
  • impact/fairness assessment;
  • model validation record;
  • human oversight record;
  • enhanced control assessment;
  • approval record;
  • monitoring record;
  • incident record;
  • assurance record;
  • change assessment;
  • risk acceptance record;
  • lifecycle decision record.
Templates should be finalized only after the examples, framework, procedures, and mappings have been sufficiently validated.

85. Document Status

Document: AIGO — High-Risk AI System Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-002 Document Type: Implementation Example Example Type: High-Risk AI System This document provides an illustrative example of enhanced AIGO governance for an AI system presenting significant potential impact and risk.

86. End of Example Document

AIGO — High-Risk AI System Example Document ID: AIGO-EXAMPLE-002 Version: 0.1 Status: Draft End of Document