Skip to main content

AIGO — AI Classification Example

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-004 Document Type: Implementation Example Example Type: AI System Classification

1. Purpose

This document provides an illustrative example of how an organization can classify an AI system using the AIGO AI Governance Operating Framework. The example demonstrates how an organization can determine:
  • whether a system qualifies as an AI system under its governance framework;
  • the intended purpose of the system;
  • the context in which the system operates;
  • affected stakeholders;
  • potential impact;
  • risk characteristics;
  • governance classification;
  • required oversight;
  • required controls;
  • approval requirements;
  • lifecycle treatment.
This document is an implementation example and does not constitute legal or regulatory advice.

2. Example Organization

For this example, the organization is ExampleCorp, a fictional organization implementing AIGO. ExampleCorp operates an AI-enabled recruitment system and must determine the appropriate governance classification before deployment.

3. AI System Under Classification

System Name: Candidate Assessment Assistant AI System ID: AI-HR-001 Business Function: Human Resources Intended Purpose: Assist authorized recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations. Decision Authority: Human recruitment personnel. Autonomous Decision: No. Lifecycle Stage: Pre-deployment.

4. Classification Objective

The objective is to determine the governance classification applicable to the AI system before deployment. The classification decision will determine:
  • governance requirements;
  • risk assessment requirements;
  • control requirements;
  • documentation requirements;
  • approval authority;
  • monitoring requirements;
  • assurance requirements;
  • change-management requirements.

5. Classification Principles

AIGO classification is based on the characteristics and context of the AI system rather than technology alone. Classification should consider:
  1. intended purpose;
  2. affected persons;
  3. decision significance;
  4. degree of automation;
  5. potential harm;
  6. sensitivity of data;
  7. operating environment;
  8. reversibility of decisions;
  9. human oversight;
  10. regulatory context;
  11. security considerations;
  12. scale of deployment.

6. Classification Lifecycle


7. Step 1 — Confirm AI System Status

The first step is to determine whether the system falls within the organization’s definition of an AI system. The Candidate Assessment Assistant uses an AI model to analyze candidate information and generate recommendations. Determination: Yes. The system is therefore subject to AIGO AI governance requirements.

8. Step 2 — Define Intended Purpose

The intended purpose is:
To assist authorized recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations.
The system is not intended to:
  • make final hiring decisions;
  • automatically reject candidates;
  • determine employment eligibility without human involvement;
  • make decisions outside the recruitment process.

9. Intended-Purpose Record


10. Step 3 — Identify Affected Persons

The primary affected persons are job applicants. Secondary stakeholders include:
  • recruitment personnel;
  • hiring managers;
  • HR leadership;
  • compliance personnel;
  • risk management;
  • AI governance personnel.
Because the system may influence employment opportunities, the impact on affected persons is considered significant.

11. Step 4 — Determine Decision Significance

The classification assessment considers whether the AI system contributes to decisions that may materially affect individuals. The Candidate Assessment Assistant influences candidate prioritization. Although the system does not make the final decision, its outputs may influence human decision-making. Decision Significance: High.

12. Step 5 — Determine Degree of Automation

The system produces recommendations. A human recruitment professional is required to review and make the final decision. The system is therefore classified as human-in-the-loop decision support.

13. Step 6 — Assess Potential Impact

Potential adverse impacts include:
  • unfair candidate prioritization;
  • discriminatory outcomes;
  • inaccurate assessment;
  • reduced employment opportunity;
  • privacy impact;
  • reputational harm;
  • lack of transparency;
  • automation bias.
Potential impact is therefore assessed as High.

14. Step 7 — Assess Data Sensitivity

The system processes candidate information. Potential information includes:
  • identity information;
  • education;
  • employment history;
  • professional qualifications;
  • application responses;
  • other recruitment-related information.
The organization must determine whether additional sensitive or special-category information is processed. Data Sensitivity: High.

15. Step 8 — Assess Human Oversight

Human oversight is mandatory. Recruitment personnel must:
  • review AI recommendations;
  • consider additional information;
  • challenge recommendations where appropriate;
  • override AI outputs where necessary;
  • document material decisions;
  • escalate suspected harmful behavior.
Human oversight must be meaningful rather than merely procedural.

16. Human Oversight Test

The following questions are applied:

17. Step 9 — Assess Reversibility

The classification process considers whether decisions influenced by the system can be reversed. A recruitment decision may be reversible in some circumstances, but missed opportunities can cause harm that cannot always be fully restored. Reversibility: Limited. This increases the required level of governance.

18. Step 10 — Assess Scale

The organization expects the system to process approximately 100,000 applications annually. Scale therefore increases the potential aggregate impact of errors or biased outcomes. Deployment Scale: Large.

19. Step 11 — Assess Risk Characteristics

The initial assessment identifies the following characteristics:

20. Classification Decision Model

AIGO classification can be represented as:

21. Example AIGO Classification Levels

For this example, ExampleCorp uses four governance classes. These classes are organizational governance categories and should be adapted to the organization’s approved classification methodology.

22. Class 1 — Limited Governance

Class 1 applies to systems with relatively low potential impact. Typical characteristics:
  • low-impact purpose;
  • limited affected persons;
  • low-risk outputs;
  • no material individual decision;
  • limited data sensitivity;
  • strong reversibility.
Example: An AI tool used to summarize internal meeting notes.

23. Class 2 — Standard Governance

Class 2 applies to systems with moderate governance implications. Typical characteristics:
  • moderate operational impact;
  • limited individual impact;
  • manageable risk;
  • standard monitoring;
  • normal human oversight.
Example: An internal AI assistant used for administrative workflow support.

24. Class 3 — Enhanced Governance

Class 3 applies to systems with significant potential impact. Typical characteristics:
  • significant individual impact;
  • sensitive data;
  • material decisions;
  • elevated fairness or privacy risk;
  • increased monitoring requirements;
  • enhanced assurance.
Example: An AI system supporting recruitment prioritization.

25. Class 4 — Critical Governance

Class 4 applies where AI operation may create severe, systemic, or difficult-to-reverse consequences. Typical characteristics:
  • potentially severe harm;
  • critical infrastructure or safety implications;
  • highly consequential decisions;
  • significant autonomy;
  • insufficient reversibility;
  • major systemic exposure.
Such systems require the highest governance authority and assurance.

26. Candidate Assessment Classification

The Candidate Assessment Assistant demonstrates:
  • significant impact on individuals;
  • potential employment consequences;
  • sensitive personal information;
  • potential discrimination;
  • large deployment scale;
  • limited reversibility;
  • meaningful but not autonomous human decision-making.
The system is therefore classified as: AIGO Governance Class 3 — Enhanced Governance

27. Classification Result


28. Classification Rationale

The system is classified as Class 3 because it can materially influence employment opportunities and processes personal information concerning individuals. The presence of human oversight reduces risk but does not remove the system’s governance significance. The classification therefore reflects the system’s context and potential impact, not simply its technical architecture.

29. Classification Controls

Class 3 systems require enhanced governance. Example requirements include:
  • formal AI system registration;
  • documented intended purpose;
  • formal risk assessment;
  • documented classification;
  • control assessment;
  • human oversight;
  • fairness assessment;
  • privacy assessment;
  • security assessment;
  • monitoring;
  • incident management;
  • change management;
  • periodic assurance;
  • management review.

30. Classification-to-Governance Relationship


31. Classification-to-Risk Relationship

The classification does not replace risk assessment. Instead:
A Class 3 system still requires a detailed risk assessment.

32. Classification and Risk Assessment

The classification provides an initial governance view. The risk assessment provides a more detailed analysis of individual risks. Therefore: Classification ≠ Risk Assessment Classification answers:
How much governance attention does this system require?
Risk assessment answers:
What specific risks does this system present and how should they be treated?

33. Classification and Control Selection

Classification influences the minimum expected control set. For example:

34. Classification Approval

The classification must be reviewed by an authorized governance role. For this example: Classification Owner: AI System Owner Reviewer: AI Risk Manager Governance Authority: AI Governance Committee Approval: AI Governance Committee

35. Classification Approval Record


36. Classification Evidence

The following evidence supports the classification:
  • AI system registration;
  • system description;
  • intended-purpose statement;
  • data-flow description;
  • stakeholder assessment;
  • impact assessment;
  • risk assessment;
  • human oversight design;
  • privacy assessment;
  • security assessment;
  • classification record;
  • approval record.

37. Classification Traceability


38. Classification Record

AI System ID: AI-HR-001 System Name: Candidate Assessment Assistant Business Owner: Chief People Officer AI System Owner: Head of Talent Technology Purpose: Recruitment decision support Classification: Class 3 — Enhanced Governance Decision Authority: Human recruitment personnel Human Oversight: Mandatory Risk Assessment: Required Enhanced Monitoring: Required Assurance: Required

39. Classification Lifecycle

Classification must be maintained throughout the AI system lifecycle.

40. Classification Review Triggers

Reclassification should be considered when:
  • intended purpose changes;
  • decision authority changes;
  • automation increases;
  • affected populations change;
  • deployment scale increases;
  • new data types are introduced;
  • material model changes occur;
  • risk level increases;
  • significant incidents occur;
  • new legal or regulatory obligations apply;
  • human oversight is reduced;
  • system scope expands.

41. Example Reclassification Scenario

ExampleCorp later decides to allow the system to automatically reject candidates who fail predefined criteria. This materially changes the governance characteristics. The system now has:
  • increased automation;
  • greater decision impact;
  • reduced human intervention;
  • increased potential for irreversible harm.
The original classification must therefore be reassessed.

42. Reclassification Assessment


43. Reclassification Decision

The organization determines that the proposed change cannot be implemented under the existing classification without additional governance review. The system must undergo:
  • updated classification;
  • updated risk assessment;
  • control reassessment;
  • impact assessment;
  • approval review.
Deployment of the changed functionality is therefore paused pending reassessment.

44. Classification Monitoring

Classification should be monitored using indicators such as:
  • number of material changes;
  • changes in user population;
  • changes in affected population;
  • changes in decision authority;
  • incidents;
  • complaints;
  • risk-level changes;
  • control failures;
  • model changes.

45. Classification Review Frequency

ExampleCorp reviews Class 3 systems:
  • at least annually;
  • after material changes;
  • after significant incidents;
  • after material changes in context;
  • when risk assessments indicate a changed risk profile.
Higher-risk systems may require more frequent review.

46. Classification Decision Tree


47. Classification Quality Review

Before approval, reviewers should verify:
  • purpose is clearly stated;
  • scope is complete;
  • affected persons are identified;
  • decision significance is understood;
  • automation level is accurate;
  • potential harms are considered;
  • data sensitivity is documented;
  • reversibility is considered;
  • human oversight is validated;
  • classification rationale is documented.

48. Classification Exceptions

Exceptions to normal classification rules must be documented. An exception record should include:
  • system identifier;
  • classification rule;
  • requested exception;
  • reason;
  • risk implications;
  • compensating controls;
  • approval authority;
  • expiration date;
  • review date.
Exceptions must not be used to avoid required governance.

49. Classification Evidence Chain


50. Relationship to AIGO Procedures

Classification should be implemented through the applicable AIGO procedures, particularly:
  • AI Governance Procedure;
  • AI System Registration Procedure;
  • AI Classification Procedure;
  • AI Risk Assessment Procedure;
  • AI Control Assessment Procedure;
  • AI Approval Procedure;
  • AI Change Management Procedure;
  • AI Monitoring Procedure;
  • AI Assurance Procedure.

51. Relationship to AIGO Controls

Classification determines the governance intensity applied to the AI system. The classification should therefore be traceable to:
  • required controls;
  • control owners;
  • implementation status;
  • evidence;
  • monitoring;
  • assurance.

52. Relationship to ISO/IEC 42001

The classification process can support an AI management system by providing structured information about:
  • AI system context;
  • risk and opportunity management;
  • lifecycle governance;
  • operational controls;
  • monitoring;
  • performance evaluation;
  • continual improvement.
The organization must separately determine applicable ISO/IEC 42001 requirements.

53. Relationship to NIST AI RMF

The example aligns conceptually with NIST AI RMF activities.

54. Classification Summary

The Candidate Assessment Assistant is classified as: AIGO Governance Class 3 — Enhanced Governance The classification is based on:
  • significant impact on individuals;
  • employment-related decision support;
  • sensitive information;
  • potential discrimination;
  • large-scale deployment;
  • limited reversibility;
  • meaningful human oversight.

55. Final Classification Decision

Classification: Class 3 — Enhanced Governance Status: Approved Conditions:
  • formal risk assessment;
  • enhanced controls;
  • mandatory human oversight;
  • fairness monitoring;
  • privacy and security assessment;
  • periodic assurance;
  • quarterly governance review.

56. Example Classification Record


57. Key Lessons

57.1 Classification Is Contextual

Classification depends on what the AI system does and how it is used.

57.2 Classification Is Not Risk Assessment

Classification determines governance intensity; risk assessment identifies and evaluates specific risks.

57.3 Human Oversight Does Not Automatically Reduce Classification

Human oversight is important but does not eliminate the potential impact of the system.

57.4 Classification Must Be Maintained

A classification established at deployment may become inappropriate as the system changes.

57.5 Classification Must Be Evidence-Based

Classification decisions should be supported by documented evidence and an explicit rationale.

58. AIGO Classification Model

The complete classification model can be summarized as:

59. Minimum Classification Record

AIGO implementations should maintain, at minimum:
  • AI system identifier;
  • system name;
  • intended purpose;
  • business owner;
  • AI system owner;
  • affected persons;
  • decision significance;
  • automation level;
  • data sensitivity;
  • potential impact;
  • reversibility;
  • deployment scale;
  • risk profile;
  • classification;
  • classification rationale;
  • required governance;
  • required controls;
  • approval authority;
  • approval decision;
  • evidence;
  • review date;
  • reclassification triggers.

60. Document Status

Document: AIGO — AI Classification Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-004 Document Type: Implementation Example Example Type: AI System Classification This document provides an illustrative example of how an AI system can be classified within the AIGO AI Governance Operating Framework.

61. End of Example Document

AIGO — AI Classification Example Document ID: AIGO-EXAMPLE-004 Version: 0.1 Status: Draft End of Document