AIGO — AI Classification Example
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-004
Document Type: Implementation Example
Example Type: AI System Classification
1. Purpose
This document provides an illustrative example of how an organization can classify an AI system using the AIGO AI Governance Operating Framework. The example demonstrates how an organization can determine:- whether a system qualifies as an AI system under its governance framework;
- the intended purpose of the system;
- the context in which the system operates;
- affected stakeholders;
- potential impact;
- risk characteristics;
- governance classification;
- required oversight;
- required controls;
- approval requirements;
- lifecycle treatment.
2. Example Organization
For this example, the organization is ExampleCorp, a fictional organization implementing AIGO. ExampleCorp operates an AI-enabled recruitment system and must determine the appropriate governance classification before deployment.3. AI System Under Classification
System Name: Candidate Assessment Assistant AI System ID:AI-HR-001
Business Function: Human Resources
Intended Purpose: Assist authorized recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations.
Decision Authority: Human recruitment personnel.
Autonomous Decision: No.
Lifecycle Stage: Pre-deployment.
4. Classification Objective
The objective is to determine the governance classification applicable to the AI system before deployment. The classification decision will determine:- governance requirements;
- risk assessment requirements;
- control requirements;
- documentation requirements;
- approval authority;
- monitoring requirements;
- assurance requirements;
- change-management requirements.
5. Classification Principles
AIGO classification is based on the characteristics and context of the AI system rather than technology alone. Classification should consider:- intended purpose;
- affected persons;
- decision significance;
- degree of automation;
- potential harm;
- sensitivity of data;
- operating environment;
- reversibility of decisions;
- human oversight;
- regulatory context;
- security considerations;
- scale of deployment.
6. Classification Lifecycle
7. Step 1 — Confirm AI System Status
The first step is to determine whether the system falls within the organization’s definition of an AI system. The Candidate Assessment Assistant uses an AI model to analyze candidate information and generate recommendations. Determination: Yes. The system is therefore subject to AIGO AI governance requirements.8. Step 2 — Define Intended Purpose
The intended purpose is:To assist authorized recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations.The system is not intended to:
- make final hiring decisions;
- automatically reject candidates;
- determine employment eligibility without human involvement;
- make decisions outside the recruitment process.
9. Intended-Purpose Record
10. Step 3 — Identify Affected Persons
The primary affected persons are job applicants. Secondary stakeholders include:- recruitment personnel;
- hiring managers;
- HR leadership;
- compliance personnel;
- risk management;
- AI governance personnel.
11. Step 4 — Determine Decision Significance
The classification assessment considers whether the AI system contributes to decisions that may materially affect individuals. The Candidate Assessment Assistant influences candidate prioritization. Although the system does not make the final decision, its outputs may influence human decision-making. Decision Significance: High.12. Step 5 — Determine Degree of Automation
The system produces recommendations. A human recruitment professional is required to review and make the final decision.
The system is therefore classified as human-in-the-loop decision support.
13. Step 6 — Assess Potential Impact
Potential adverse impacts include:- unfair candidate prioritization;
- discriminatory outcomes;
- inaccurate assessment;
- reduced employment opportunity;
- privacy impact;
- reputational harm;
- lack of transparency;
- automation bias.
14. Step 7 — Assess Data Sensitivity
The system processes candidate information. Potential information includes:- identity information;
- education;
- employment history;
- professional qualifications;
- application responses;
- other recruitment-related information.
15. Step 8 — Assess Human Oversight
Human oversight is mandatory. Recruitment personnel must:- review AI recommendations;
- consider additional information;
- challenge recommendations where appropriate;
- override AI outputs where necessary;
- document material decisions;
- escalate suspected harmful behavior.
16. Human Oversight Test
The following questions are applied:17. Step 9 — Assess Reversibility
The classification process considers whether decisions influenced by the system can be reversed. A recruitment decision may be reversible in some circumstances, but missed opportunities can cause harm that cannot always be fully restored. Reversibility: Limited. This increases the required level of governance.18. Step 10 — Assess Scale
The organization expects the system to process approximately 100,000 applications annually. Scale therefore increases the potential aggregate impact of errors or biased outcomes. Deployment Scale: Large.19. Step 11 — Assess Risk Characteristics
The initial assessment identifies the following characteristics:20. Classification Decision Model
AIGO classification can be represented as:21. Example AIGO Classification Levels
For this example, ExampleCorp uses four governance classes.
These classes are organizational governance categories and should be adapted to the organization’s approved classification methodology.
22. Class 1 — Limited Governance
Class 1 applies to systems with relatively low potential impact. Typical characteristics:- low-impact purpose;
- limited affected persons;
- low-risk outputs;
- no material individual decision;
- limited data sensitivity;
- strong reversibility.
23. Class 2 — Standard Governance
Class 2 applies to systems with moderate governance implications. Typical characteristics:- moderate operational impact;
- limited individual impact;
- manageable risk;
- standard monitoring;
- normal human oversight.
24. Class 3 — Enhanced Governance
Class 3 applies to systems with significant potential impact. Typical characteristics:- significant individual impact;
- sensitive data;
- material decisions;
- elevated fairness or privacy risk;
- increased monitoring requirements;
- enhanced assurance.
25. Class 4 — Critical Governance
Class 4 applies where AI operation may create severe, systemic, or difficult-to-reverse consequences. Typical characteristics:- potentially severe harm;
- critical infrastructure or safety implications;
- highly consequential decisions;
- significant autonomy;
- insufficient reversibility;
- major systemic exposure.
26. Candidate Assessment Classification
The Candidate Assessment Assistant demonstrates:- significant impact on individuals;
- potential employment consequences;
- sensitive personal information;
- potential discrimination;
- large deployment scale;
- limited reversibility;
- meaningful but not autonomous human decision-making.
27. Classification Result
28. Classification Rationale
The system is classified as Class 3 because it can materially influence employment opportunities and processes personal information concerning individuals. The presence of human oversight reduces risk but does not remove the system’s governance significance. The classification therefore reflects the system’s context and potential impact, not simply its technical architecture.29. Classification Controls
Class 3 systems require enhanced governance. Example requirements include:- formal AI system registration;
- documented intended purpose;
- formal risk assessment;
- documented classification;
- control assessment;
- human oversight;
- fairness assessment;
- privacy assessment;
- security assessment;
- monitoring;
- incident management;
- change management;
- periodic assurance;
- management review.
30. Classification-to-Governance Relationship
31. Classification-to-Risk Relationship
The classification does not replace risk assessment. Instead:32. Classification and Risk Assessment
The classification provides an initial governance view. The risk assessment provides a more detailed analysis of individual risks. Therefore: Classification ≠ Risk Assessment Classification answers:How much governance attention does this system require?Risk assessment answers:
What specific risks does this system present and how should they be treated?
33. Classification and Control Selection
Classification influences the minimum expected control set. For example:34. Classification Approval
The classification must be reviewed by an authorized governance role. For this example: Classification Owner: AI System Owner Reviewer: AI Risk Manager Governance Authority: AI Governance Committee Approval: AI Governance Committee35. Classification Approval Record
36. Classification Evidence
The following evidence supports the classification:- AI system registration;
- system description;
- intended-purpose statement;
- data-flow description;
- stakeholder assessment;
- impact assessment;
- risk assessment;
- human oversight design;
- privacy assessment;
- security assessment;
- classification record;
- approval record.
37. Classification Traceability
38. Classification Record
AI System ID:AI-HR-001
System Name: Candidate Assessment Assistant
Business Owner: Chief People Officer
AI System Owner: Head of Talent Technology
Purpose: Recruitment decision support
Classification: Class 3 — Enhanced Governance
Decision Authority: Human recruitment personnel
Human Oversight: Mandatory
Risk Assessment: Required
Enhanced Monitoring: Required
Assurance: Required
39. Classification Lifecycle
Classification must be maintained throughout the AI system lifecycle.40. Classification Review Triggers
Reclassification should be considered when:- intended purpose changes;
- decision authority changes;
- automation increases;
- affected populations change;
- deployment scale increases;
- new data types are introduced;
- material model changes occur;
- risk level increases;
- significant incidents occur;
- new legal or regulatory obligations apply;
- human oversight is reduced;
- system scope expands.
41. Example Reclassification Scenario
ExampleCorp later decides to allow the system to automatically reject candidates who fail predefined criteria. This materially changes the governance characteristics. The system now has:- increased automation;
- greater decision impact;
- reduced human intervention;
- increased potential for irreversible harm.
42. Reclassification Assessment
43. Reclassification Decision
The organization determines that the proposed change cannot be implemented under the existing classification without additional governance review. The system must undergo:- updated classification;
- updated risk assessment;
- control reassessment;
- impact assessment;
- approval review.
44. Classification Monitoring
Classification should be monitored using indicators such as:- number of material changes;
- changes in user population;
- changes in affected population;
- changes in decision authority;
- incidents;
- complaints;
- risk-level changes;
- control failures;
- model changes.
45. Classification Review Frequency
ExampleCorp reviews Class 3 systems:- at least annually;
- after material changes;
- after significant incidents;
- after material changes in context;
- when risk assessments indicate a changed risk profile.
46. Classification Decision Tree
47. Classification Quality Review
Before approval, reviewers should verify:- purpose is clearly stated;
- scope is complete;
- affected persons are identified;
- decision significance is understood;
- automation level is accurate;
- potential harms are considered;
- data sensitivity is documented;
- reversibility is considered;
- human oversight is validated;
- classification rationale is documented.
48. Classification Exceptions
Exceptions to normal classification rules must be documented. An exception record should include:- system identifier;
- classification rule;
- requested exception;
- reason;
- risk implications;
- compensating controls;
- approval authority;
- expiration date;
- review date.
49. Classification Evidence Chain
50. Relationship to AIGO Procedures
Classification should be implemented through the applicable AIGO procedures, particularly:- AI Governance Procedure;
- AI System Registration Procedure;
- AI Classification Procedure;
- AI Risk Assessment Procedure;
- AI Control Assessment Procedure;
- AI Approval Procedure;
- AI Change Management Procedure;
- AI Monitoring Procedure;
- AI Assurance Procedure.
51. Relationship to AIGO Controls
Classification determines the governance intensity applied to the AI system. The classification should therefore be traceable to:- required controls;
- control owners;
- implementation status;
- evidence;
- monitoring;
- assurance.
52. Relationship to ISO/IEC 42001
The classification process can support an AI management system by providing structured information about:- AI system context;
- risk and opportunity management;
- lifecycle governance;
- operational controls;
- monitoring;
- performance evaluation;
- continual improvement.
53. Relationship to NIST AI RMF
The example aligns conceptually with NIST AI RMF activities.54. Classification Summary
The Candidate Assessment Assistant is classified as: AIGO Governance Class 3 — Enhanced Governance The classification is based on:- significant impact on individuals;
- employment-related decision support;
- sensitive information;
- potential discrimination;
- large-scale deployment;
- limited reversibility;
- meaningful human oversight.
55. Final Classification Decision
Classification: Class 3 — Enhanced Governance Status: Approved Conditions:- formal risk assessment;
- enhanced controls;
- mandatory human oversight;
- fairness monitoring;
- privacy and security assessment;
- periodic assurance;
- quarterly governance review.
56. Example Classification Record
57. Key Lessons
57.1 Classification Is Contextual
Classification depends on what the AI system does and how it is used.57.2 Classification Is Not Risk Assessment
Classification determines governance intensity; risk assessment identifies and evaluates specific risks.57.3 Human Oversight Does Not Automatically Reduce Classification
Human oversight is important but does not eliminate the potential impact of the system.57.4 Classification Must Be Maintained
A classification established at deployment may become inappropriate as the system changes.57.5 Classification Must Be Evidence-Based
Classification decisions should be supported by documented evidence and an explicit rationale.58. AIGO Classification Model
The complete classification model can be summarized as:59. Minimum Classification Record
AIGO implementations should maintain, at minimum:- AI system identifier;
- system name;
- intended purpose;
- business owner;
- AI system owner;
- affected persons;
- decision significance;
- automation level;
- data sensitivity;
- potential impact;
- reversibility;
- deployment scale;
- risk profile;
- classification;
- classification rationale;
- required governance;
- required controls;
- approval authority;
- approval decision;
- evidence;
- review date;
- reclassification triggers.
60. Document Status
Document: AIGO — AI Classification Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-004
Document Type: Implementation Example
Example Type: AI System Classification
This document provides an illustrative example of how an AI system can be classified within the AIGO AI Governance Operating Framework.
61. End of Example Document
AIGO — AI Classification Example Document ID:AIGO-EXAMPLE-004
Version: 0.1
Status: Draft
End of Document