AIGO — High-Risk AI System Example
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-002
Document Type: Implementation Example
Example Type: High-Risk AI System
Related Framework: AIGO AI Governance Operating Framework
1. Purpose
This document provides an illustrative end-to-end example of how AIGO can be applied to an AI system presenting a significantly higher level of risk than the basic AI system described in the previous example. The purpose is to demonstrate how increased risk can result in:- stronger governance;
- enhanced accountability;
- deeper risk assessment;
- increased control requirements;
- stronger human oversight;
- enhanced evidence requirements;
- more restrictive approval;
- increased monitoring;
- more frequent assurance;
- formal change assessment;
- controlled continuation or retirement.
2. Example Organization
For this example, the organization is ExampleCorp, a fictional organization with an established AIGO governance program. ExampleCorp operates a large recruitment function and uses AI to assist with candidate screening and prioritization. Because the system may influence employment-related decisions, ExampleCorp applies enhanced governance.3. Example AI System
The example AI system is called: ExampleCorp Candidate Assessment Assistant The system analyzes candidate information and generates a recommendation concerning whether a candidate should progress to the next stage of recruitment. The system does not have final hiring authority. A designated human decision-maker remains responsible for the final recruitment decision.4. Intended Purpose
The system is intended to:- assist recruitment personnel in reviewing candidate information;
- identify candidates meeting defined job-related criteria;
- prioritize candidates for human review;
- identify potentially relevant qualifications;
- support consistent processing of high volumes of applications.
- make autonomous hiring decisions;
- reject candidates without human review;
- infer protected characteristics;
- evaluate candidates using unrelated personal attributes;
- replace recruitment professionals.
5. Example System Profile
6. Why Enhanced Governance Is Required
The system can influence decisions affecting individuals. Potential consequences include:- unfair treatment;
- discrimination;
- inappropriate exclusion;
- privacy impacts;
- inaccurate candidate evaluation;
- lack of transparency;
- automation bias;
- reputational damage;
- regulatory exposure.
7. Governance Model
The governance structure is strengthened compared with a standard AI system.8. Enhanced Governance Roles
9. Governance Requirements
The system must not proceed to operational use until:- the system is registered;
- its intended purpose is documented;
- classification is completed;
- risk assessment is completed;
- applicable legal requirements are identified;
- controls are implemented;
- testing is completed;
- human oversight is established;
- evidence is available;
- residual risk is formally considered;
- required approval is granted.
10. AIGO Lifecycle
The high-risk system follows the same fundamental AIGO lifecycle, but with enhanced controls.11. Stage 1 — Governance
The organization identifies the system as requiring enhanced governance before technical deployment. The AI Governance Authority appoints responsible roles and establishes the governance conditions.12. Governance Decision
ExampleCorp determines: Governance Level: Enhanced Reason:- the system influences employment-related decisions;
- individuals may be materially affected;
- errors may result in unfair outcomes;
- regulatory obligations may apply;
- human oversight is essential.
13. Stage 2 — Identify
The system is formally registered in the AI inventory. The registration captures:- system identity;
- purpose;
- owner;
- business process;
- affected persons;
- data;
- model provider;
- technical architecture;
- dependencies;
- lifecycle stage.
14. High-Risk AI Inventory Record
15. Stage 3 — Classification
Classification is performed using the AIGO AI Classification Procedure. Factors considered include:- impact on individuals;
- decision significance;
- degree of automation;
- affected population;
- sensitivity of data;
- potential discrimination;
- legal obligations;
- operational dependency;
- severity of potential harm.
16. Example Classification Result
AIGO Classification: High-Risk AI System The classification is based on the system’s role in an employment-related decision process.17. Classification Assessment
18. Classification Consequence
The classification automatically increases governance requirements.19. Stage 4 — Context Assessment
Before assessing individual risks, ExampleCorp documents the system context. The context includes:- recruitment process;
- candidate population;
- jurisdictions;
- job categories;
- decision-makers;
- data sources;
- model characteristics;
- organizational objectives;
- legal requirements.
20. Affected Stakeholders
Stakeholders include:- job applicants;
- recruitment personnel;
- hiring managers;
- HR leadership;
- legal and compliance teams;
- privacy function;
- security function;
- AI governance authority;
- executive management.
21. Stage 5 — Risk Assessment
A detailed AI risk assessment is performed. Risk categories include:- fairness;
- discrimination;
- privacy;
- security;
- accuracy;
- robustness;
- explainability;
- transparency;
- human oversight;
- misuse;
- third-party dependency;
- operational continuity;
- legal and regulatory exposure.
22. High-Risk AI Risk Register
23. Risk Treatment Principle
For a high-risk system, ExampleCorp does not rely solely on accepting residual risk. The organization first seeks to:- eliminate unnecessary risks;
- reduce risks through design;
- implement preventive controls;
- implement detective controls;
- establish human oversight;
- monitor residual risks;
- formally document accepted residual risks.
24. Risk Treatment Hierarchy
25. Example Risk Treatments
26. Stage 6 — Control Design
Controls are designed specifically for the high-risk nature of the system. Controls include:- purpose limitation;
- data governance;
- access control;
- model validation;
- performance testing;
- fairness testing;
- human oversight;
- output review;
- incident management;
- monitoring;
- change management;
- assurance;
- supplier management.
27. Enhanced Control Set
28. Human Oversight
Human oversight is a core control. The system may provide recommendations, but the final decision remains with an authorized human.29. Human Decision Requirements
The human decision-maker must:- understand the AI system’s role;
- review relevant information;
- consider whether the recommendation is reasonable;
- be able to challenge the output;
- be able to override the recommendation;
- avoid treating the AI output as automatically correct;
- record the final decision where required.
30. Automation Bias Control
ExampleCorp recognizes automation bias as a specific risk. Controls include:- user training;
- explicit human decision responsibility;
- explanation of system limitations;
- mandatory review;
- random quality checks;
- override monitoring.
31. Data Governance
The organization evaluates:- data source legitimacy;
- data quality;
- relevance;
- accuracy;
- representativeness;
- retention;
- access;
- provenance;
- inappropriate attributes.
32. Data Governance Decision
The system is prohibited from using unnecessary personal information. Only information relevant to the approved recruitment purpose may be processed.33. Model Validation
Before deployment, the technical and governance teams validate:- accuracy;
- reliability;
- robustness;
- performance;
- fairness;
- known limitations;
- failure conditions.
34. Validation Evidence
Example evidence includes:35. Fairness Assessment
ExampleCorp performs an appropriate fairness assessment based on applicable law, available data, and organizational requirements. The assessment considers whether system outputs could systematically disadvantage particular groups. Potential findings require investigation before deployment.36. Fairness Decision
If material unexplained disparities are identified, deployment is not automatically permitted. The organization may:- modify the system;
- modify data;
- introduce additional controls;
- restrict the use case;
- require additional human review;
- suspend deployment.
37. Stage 7 — Control Assessment
Every critical control must be assessed before approval.38. Stage 8 — Approval
Approval requires enhanced governance authority. The system cannot be deployed solely on the basis of technical acceptance. The approval decision considers:- legal requirements;
- risk;
- controls;
- testing;
- fairness;
- human oversight;
- evidence;
- residual risk;
- business necessity.
39. Approval Chain
40. Approval Conditions
Approval may include conditions such as:- limited initial deployment;
- mandatory human review;
- restricted user population;
- enhanced monitoring;
- periodic fairness testing;
- mandatory incident reporting;
- scheduled reassessment.
41. Example Approval Record
42. Stage 9 — Controlled Deployment
Deployment is performed in stages. ExampleCorp begins with a limited pilot.43. Pilot Conditions
The pilot requires:- restricted users;
- restricted job categories;
- increased human review;
- enhanced monitoring;
- incident escalation;
- predefined stop criteria.
44. Stop Criteria
Deployment must be paused if:- serious discrimination concerns arise;
- material control failure occurs;
- unauthorized data is processed;
- system performance falls below threshold;
- significant unexplained model behavior occurs;
- required human oversight fails.
45. Stage 10 — Operation
During operation, ExampleCorp continuously manages:- system performance;
- candidate-impact indicators;
- incidents;
- user behavior;
- model changes;
- supplier changes;
- control effectiveness.
46. Operational Control Model
47. Stage 11 — Monitoring
Monitoring is more intensive than for a standard AI system. Monitoring includes:- accuracy;
- performance;
- fairness indicators;
- override rates;
- complaints;
- incidents;
- system drift;
- data changes;
- model changes;
- control failures.
48. Example Monitoring Metrics
49. Monitoring Escalation
50. Stage 12 — Incident Example
Suppose monitoring identifies a significant difference in candidate prioritization between demographic groups. The issue is treated as a potential high-severity AI governance incident.51. Incident Record
52. Incident Response
53. Immediate Containment
ExampleCorp may temporarily:- suspend automated recommendations;
- require manual candidate review;
- restrict affected job categories;
- preserve evidence;
- notify relevant governance functions;
- begin root-cause analysis.
54. Root Cause Analysis
The investigation may consider:- training data;
- data representation;
- model behavior;
- feature selection;
- system configuration;
- implementation changes;
- user behavior;
- supplier changes.
55. Corrective Action
Possible corrective actions include:- retraining;
- data correction;
- model modification;
- additional controls;
- revised thresholds;
- enhanced human review;
- restriction of system use;
- additional validation.
56. Stage 13 — Assurance
High-risk AI requires stronger assurance. Assurance may be:- more frequent;
- independent;
- evidence-based;
- risk-focused;
- triggered by significant events.
57. Assurance Scope
Assurance examines:- governance;
- system purpose;
- classification;
- risk;
- controls;
- data;
- model validation;
- fairness;
- human oversight;
- monitoring;
- incidents;
- changes;
- evidence;
- management decisions.
58. Assurance Finding
Example assurance finding: Finding HR-F001 — Human Override Monitoring Insufficient The organization has documented human override requirements, but override behavior is not being consistently monitored.59. Corrective Action
60. Stage 14 — Change Management
High-risk systems require formal reassessment for material changes. Changes include:- new model;
- new data;
- new provider;
- new purpose;
- new user population;
- new geography;
- new decision context;
- significant model update.
61. Material Change Flow
62. Example Material Change
ExampleCorp proposes using the system for executive recruitment. This is considered a material change because:- the affected population changes;
- decision significance increases;
- risk profile changes;
- governance expectations may change.
63. Change Decision
The organization requires:- new risk assessment;
- classification review;
- legal review;
- additional testing;
- control reassessment;
- new approval.
64. Stage 15 — Periodic Review
The system undergoes scheduled management review. The review considers:- current risk;
- incidents;
- control performance;
- monitoring;
- complaints;
- model changes;
- regulatory changes;
- business necessity;
- assurance findings.
65. Management Review Decision
Possible decisions:66. Residual Risk
After controls are implemented, ExampleCorp determines residual risk. Residual risk must be:- documented;
- understood;
- within approved tolerance;
- assigned to an accountable owner;
- periodically reviewed.
67. Risk Acceptance
Formal risk acceptance requires appropriate authority.68. Example Risk Acceptance
69. Stage 16 — Improvement
Lessons from:- incidents;
- monitoring;
- assurance;
- user feedback;
- regulatory developments;
- technology changes;
70. Continual Improvement Cycle
71. Stage 17 — Continue, Restrict, Suspend or Retire
At the end of each review cycle, the organization determines the appropriate lifecycle decision. Possible outcomes:- continue;
- continue with conditions;
- restrict;
- suspend;
- replace;
- retire.
72. Retirement Decision
Retirement may be triggered by:- unacceptable residual risk;
- repeated control failure;
- inability to maintain fairness;
- obsolete technology;
- regulatory prohibition;
- business discontinuation;
- replacement by a safer solution.
73. Retirement Flow
74. High-Risk AI Evidence Package
The evidence package is more extensive than for a standard AI system.75. End-to-End Traceability
76. Example Traceability Matrix
77. Relationship to ISO/IEC 42001
The example demonstrates how an AIGO high-risk AI governance process can support management-system activities associated with:- organizational context;
- leadership;
- planning;
- risk management;
- operational controls;
- performance evaluation;
- management review;
- continual improvement.
78. Relationship to NIST AI RMF
The example can also be represented through the four NIST AI RMF Functions.79. Comparison With Basic AI Example
80. Key Governance Lessons
This example demonstrates that higher AI risk should result in proportionately stronger governance. Important principles include:- classification must influence governance intensity;
- affected persons must be considered;
- risk assessment must address potential harm;
- controls must address identified risks;
- human oversight must be meaningful;
- technical validation is not sufficient by itself;
- fairness and impact considerations require evidence;
- approval must be based on evidence;
- monitoring must continue throughout operation;
- material changes require reassessment;
- incidents must feed continual improvement;
- retirement must be governed as carefully as deployment.
81. Minimum High-Risk AI Governance Package
A high-risk AI system should generally have, at minimum:- system registration;
- documented purpose;
- identified stakeholders;
- classification;
- comprehensive risk assessment;
- risk treatment;
- control assessment;
- data governance;
- model validation;
- appropriate impact/fairness assessment;
- human oversight;
- approval;
- monitoring;
- incident management;
- assurance;
- change management;
- management review;
- documented lifecycle decision.
82. Example Final Operational State
At the conclusion of this example: System: Active under enhanced governance Lifecycle Stage: Operate / Monitor Classification: High-Risk Human Oversight: Mandatory Risk: Residual risk formally accepted Controls: Operational Monitoring: Enhanced Assurance: Periodic and independent Approval: Conditional / controlled Decision: Continue with conditions83. Final Governance Model
84. Relationship to Future AIGO Templates
This example provides requirements that should later be reflected in AIGO templates, including:- high-risk AI system profile;
- enhanced classification assessment;
- high-risk risk assessment;
- impact/fairness assessment;
- model validation record;
- human oversight record;
- enhanced control assessment;
- approval record;
- monitoring record;
- incident record;
- assurance record;
- change assessment;
- risk acceptance record;
- lifecycle decision record.
85. Document Status
Document: AIGO — High-Risk AI System Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-002
Document Type: Implementation Example
Example Type: High-Risk AI System
This document provides an illustrative example of enhanced AIGO governance for an AI system presenting significant potential impact and risk.
86. End of Example Document
AIGO — High-Risk AI System Example Document ID:AIGO-EXAMPLE-002
Version: 0.1
Status: Draft
End of Document