Skip to main content

AIGO — AI Approval Example

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-006 Document Type: Implementation Example Example Type: AI System Approval

1. Purpose

This document provides an illustrative example of how an organization can apply the AIGO AI Approval process before an AI system is deployed, materially changed, continued, suspended, or retired. The example demonstrates how approval can integrate:
  • AI system registration;
  • AI classification;
  • risk assessment;
  • control assessment;
  • evidence review;
  • human oversight;
  • security and privacy review;
  • operational readiness;
  • residual-risk evaluation;
  • management decision;
  • approval conditions;
  • post-approval monitoring;
  • change management.
This document is an example and does not constitute legal, regulatory, audit, certification, or legal-compliance advice.

2. Example Organization

For this example, the organization is ExampleCorp, a fictional organization implementing AIGO. The organization intends to deploy an AI-enabled recruitment-support system.

3. AI System

System Name: Candidate Assessment Assistant AI System ID: AI-HR-001 Business Function: Human Resources System Owner: HR AI System Owner Business Owner: HR Director Model Owner: AI/ML Engineering Lead Risk Owner: Enterprise Risk Manager Classification: Class 3 — Enhanced Governance Lifecycle Stage: Deployment Readiness

4. Approval Objective

The approval process determines whether the AI system is sufficiently governed and ready to:
  • deploy;
  • continue operating;
  • undergo a material change;
  • resume operation following suspension.
Approval is based on documented evidence rather than informal authorization.

5. Approval Principle

AIGO treats approval as a governance decision. Approval should consider:
  1. intended purpose;
  2. classification;
  3. applicable requirements;
  4. identified risks;
  5. implemented controls;
  6. control effectiveness;
  7. evidence quality;
  8. residual risk;
  9. operational readiness;
  10. human oversight;
  11. monitoring readiness;
  12. incident readiness;
  13. change-management readiness.

6. Approval Lifecycle


7. Approval Trigger

ExampleCorp initiates approval because the Candidate Assessment Assistant has reached the deployment-readiness stage. The approval cannot proceed until the required governance records have been assembled.

8. Approval Package

The approval package contains:

9. System Registration Review

The approval authority first verifies that the system is registered. Required information includes:
  • system identifier;
  • system owner;
  • business owner;
  • intended purpose;
  • users;
  • affected stakeholders;
  • lifecycle status;
  • classification;
  • suppliers;
  • dependencies.
Registration Status: Approved for assessment.

10. Intended Purpose

The Candidate Assessment Assistant is intended to support recruitment personnel by:
  • organizing candidate information;
  • identifying relevant experience;
  • generating structured candidate summaries;
  • providing recruitment-support recommendations.
The system does not make the final hiring decision.

11. Prohibited or Restricted Uses

ExampleCorp establishes that the system must not:
  • autonomously reject candidates;
  • make final hiring decisions;
  • generate decisions using prohibited personal characteristics;
  • bypass human review;
  • be used outside its approved purpose without reassessment;
  • be materially changed without change approval.

12. AI Classification

The system is classified as: Class 3 — Enhanced Governance The classification is based on:
  • use in employment-related processes;
  • potential impact on individuals;
  • sensitivity of decisions;
  • potential fairness risks;
  • need for meaningful human oversight.
The classification determines the required governance depth.

13. Risk Assessment Summary

The assessment identifies risks including:

14. Risk Treatment Summary

Risk treatments include:
  • human review;
  • fairness testing;
  • data-quality controls;
  • access control;
  • privacy controls;
  • monitoring;
  • change management;
  • approval controls;
  • incident management;
  • transparency measures.

15. Control Assessment Summary

Overall Control Environment: Partially Effective

16. Approval Readiness Model

Approval readiness is not determined solely by the control score.

17. Human Oversight Review

The approval authority verifies that:
  • human decision-makers are identified;
  • reviewers receive appropriate training;
  • AI outputs can be challenged;
  • AI outputs can be overridden;
  • final decisions remain under authorized human responsibility;
  • automation bias is addressed.
Result: Satisfactory.

18. Human Override

The system must provide an explicit mechanism for authorized personnel to reject or override AI recommendations. Overrides should be logged where required. Example:

19. Privacy Review

The privacy review verifies:
  • data categories;
  • purpose limitation;
  • access restrictions;
  • retention;
  • data minimization;
  • authorized processing;
  • privacy risks;
  • incident procedures.
Privacy Review: Approved.

20. Security Review

The security review considers:
  • authentication;
  • authorization;
  • privileged access;
  • logging;
  • vulnerability management;
  • secure configuration;
  • supplier dependencies;
  • incident response.
Security Review: Approved.

21. Monitoring Readiness

The system has defined monitoring indicators for:
  • model performance;
  • error rates;
  • fairness indicators;
  • override frequency;
  • incidents;
  • complaints;
  • drift;
  • control failures.
However, some escalation thresholds remain under development. Monitoring Readiness: Conditional.

22. Incident Readiness

ExampleCorp has an AI incident procedure covering:
  • incident identification;
  • reporting;
  • classification;
  • escalation;
  • containment;
  • investigation;
  • corrective action;
  • recovery;
  • lessons learned.
A full operational incident test has not yet occurred. Incident Readiness: Conditional.

23. Change Management Readiness

The system is subject to controlled change management. Material changes require:
  • change identification;
  • impact assessment;
  • risk reassessment;
  • control reassessment;
  • testing;
  • approval;
  • documentation.
Change Readiness: Satisfactory.

24. Evidence Package

The approval package contains evidence including:

25. Evidence Sufficiency

Evidence is evaluated for:
  • completeness;
  • authenticity;
  • relevance;
  • timeliness;
  • traceability;
  • integrity.
The approval authority determines that the evidence package is sufficient for a conditional approval decision.

26. Residual Risk

Following implementation of controls, the residual risks are assessed.

27. Residual Risk Decision

The residual risk is not zero. The approval authority determines that the remaining risk is acceptable only subject to defined conditions. This distinction is important:
Approval does not mean that all risk has been eliminated.

28. Approval Conditions

The following conditions are imposed:
  1. complete the fairness monitoring cycle;
  2. finalize monitoring escalation thresholds;
  3. conduct an AI incident-management tabletop exercise;
  4. complete the outstanding risk reassessment;
  5. maintain human review of final recruitment decisions.

29. Approval Decision

Decision: Conditionally Approved Approval Scope: Production deployment within the documented intended purpose. Conditions: All conditions in Section 28 must be tracked to completion. Approval Authority: AI Governance Committee.

30. Approval Decision Model


31. Approval Outcomes

AIGO supports four primary outcomes.

32. Approval Deferral

Approval should be deferred when:
  • material evidence is missing;
  • risk cannot be adequately assessed;
  • mandatory controls are not implemented;
  • ownership is unclear;
  • human oversight is insufficient;
  • required approvals are unavailable.

33. Approval Rejection

Approval may be rejected where:
  • residual risk is unacceptable;
  • critical controls cannot be implemented;
  • intended use cannot be governed adequately;
  • required oversight cannot be established;
  • material risks cannot be treated or accepted;
  • the system conflicts with organizational governance requirements.

34. Approval Authority

The approval authority must have sufficient authority to make the decision. ExampleCorp assigns the AI Governance Committee responsibility for Class 3 approval. The committee includes representatives from:
  • AI governance;
  • business ownership;
  • risk;
  • privacy;
  • security;
  • legal/compliance where applicable;
  • technical/model ownership;
  • assurance where appropriate.

35. Segregation of Duties

Where practical:
  • system owner prepares the approval package;
  • risk function evaluates risk;
  • control owners provide evidence;
  • approval authority makes the decision;
  • assurance may independently review the decision.
The person requesting approval should not unilaterally approve the system.

36. Approval Record

AIGO maintains a formal approval record.

37. Approval Conditions Register


38. Approval Evidence Chain


39. Deployment Authorization

Following the conditional approval decision, deployment authorization is limited to the approved scope. The system must not:
  • expand beyond the approved purpose;
  • change classification without review;
  • materially change without approval;
  • disable required controls;
  • remove human oversight.

40. Post-Approval Monitoring

Approval does not terminate governance. After deployment, ExampleCorp monitors:
  • system performance;
  • control effectiveness;
  • risk indicators;
  • fairness;
  • incidents;
  • complaints;
  • changes;
  • residual risk.

41. Approval Review Triggers

Approval must be reconsidered when:
  • intended purpose changes;
  • system functionality materially changes;
  • model architecture changes materially;
  • data sources change materially;
  • risk increases;
  • material incidents occur;
  • significant control failures occur;
  • applicable requirements change;
  • monitoring identifies significant deterioration.

42. Triggered Reapproval


43. Approval Suspension

The approval authority may suspend approval where:
  • critical control failure occurs;
  • unacceptable risk emerges;
  • serious incident occurs;
  • required human oversight becomes unavailable;
  • system operates outside approved scope;
  • material unauthorized change occurs.
Suspension should be documented and communicated to affected stakeholders.

44. Approval Revocation

Approval may be revoked where the organization determines that continued operation is no longer acceptable. Revocation may trigger:
  • system suspension;
  • containment;
  • stakeholder notification;
  • incident management;
  • corrective action;
  • retirement assessment.

45. Approval and Risk Acceptance

Approval and risk acceptance are related but distinct decisions. Approval: Authorization to operate within defined conditions. Risk Acceptance: Formal decision to accept identified residual risk. A system may require both.

46. Example Risk Acceptance

For the Candidate Assessment Assistant: Risk: Fairness monitoring delay Residual Risk: High Risk Owner: Enterprise Risk Manager Decision: Temporarily accepted subject to corrective action. Expiration: Until the next formal review or earlier if risk conditions change.

47. Approval and Control Effectiveness

Approval should consider control effectiveness. A system with multiple ineffective critical controls should normally not receive unconditional approval. The decision should reflect:
  • control criticality;
  • risk severity;
  • evidence quality;
  • compensating controls;
  • management acceptance.

48. Approval and Evidence Quality

Insufficient evidence may prevent approval even when the control is believed to exist. For example:

49. Approval and Human Oversight

Human oversight is a key approval consideration for systems where AI outputs may affect people or material decisions. Approval should verify that:
  • oversight is meaningful;
  • reviewers have authority;
  • reviewers have sufficient information;
  • override mechanisms exist;
  • responsibility remains clear.

50. Approval and Continuous Improvement

Approval records should feed continual improvement. Lessons from:
  • incidents;
  • monitoring;
  • audits;
  • assessments;
  • complaints;
  • control failures;
  • changes
should be used to improve future approval decisions.

51. Management Reporting

The AI Governance Committee should receive appropriate information regarding:
  • pending approvals;
  • conditional approvals;
  • overdue conditions;
  • rejected systems;
  • suspended systems;
  • material residual risks;
  • recurring control deficiencies.

52. Approval Status Dashboard

Example:

53. Approval Traceability

The approval decision should be traceable to the information on which it was based.

54. Minimum Approval Record

An AIGO approval record should contain, as applicable:
  • AI system identifier;
  • system name;
  • intended purpose;
  • classification;
  • owner;
  • risk owner;
  • approval authority;
  • approval type;
  • assessment results;
  • control status;
  • evidence status;
  • residual risk;
  • conditions;
  • decision;
  • decision date;
  • effective date;
  • review date;
  • approver;
  • approval status.

55. Approval Checklist

  • AI system registered
  • Intended purpose documented
  • Classification completed
  • Applicable requirements identified
  • Risk assessment completed
  • Risk treatment documented
  • Controls identified
  • Controls assessed
  • Evidence reviewed
  • Human oversight verified
  • Privacy review completed
  • Security review completed
  • Monitoring plan approved
  • Incident process established
  • Change process established
  • Residual risk assessed
  • Conditions documented
  • Approval authority identified
  • Approval decision recorded
  • Post-approval monitoring established

56. Example Approval Meeting

The AI Governance Committee reviews:
  1. system purpose;
  2. classification;
  3. risk assessment;
  4. control assessment;
  5. open findings;
  6. evidence;
  7. residual risk;
  8. operational readiness;
  9. approval conditions.
The committee determines that the system may proceed under conditional approval.

57. Example Approval Minutes

Meeting: AI Governance Committee Subject: Candidate Assessment Assistant Decision: Conditionally Approved Key Conditions:
  • fairness monitoring;
  • monitoring thresholds;
  • incident exercise;
  • risk reassessment;
  • ongoing human oversight.
Next Review: TBD

58. Approval Communication

The approval decision should be communicated to relevant stakeholders. Communication should include:
  • system;
  • approved scope;
  • decision;
  • conditions;
  • restrictions;
  • effective date;
  • review date;
  • responsible owners.

59. Unauthorized Operation

If an AI system is found operating without required approval, the organization should initiate the applicable governance process. Potential actions include:
  • immediate escalation;
  • scope restriction;
  • temporary suspension;
  • risk assessment;
  • control assessment;
  • retrospective approval review;
  • incident assessment.

60. Approval Exceptions

Exceptions to the normal approval process should be:
  • explicitly justified;
  • documented;
  • risk assessed;
  • time limited;
  • approved by authorized personnel;
  • subject to retrospective review.
Exceptions should not become an alternative routine approval process.

61. Approval Record Retention

Approval records should be retained according to applicable organizational document-control and retention requirements. The record should remain traceable throughout the AI system lifecycle.

62. Approval and Lifecycle

Approval is lifecycle-dependent. A system may require different approval decisions at:
  • initial deployment;
  • material change;
  • major model update;
  • significant risk change;
  • continued operation;
  • post-incident recovery;
  • retirement.

63. Lifecycle Approval Model


64. Approval Decision Quality

A high-quality approval decision should be:
  • informed;
  • documented;
  • evidence-based;
  • risk-aware;
  • authorized;
  • traceable;
  • reviewable;
  • reversible where necessary.

65. Example Final Approval Statement

ExampleCorp determines that the Candidate Assessment Assistant is conditionally approved for deployment within its documented intended purpose. The approval is subject to the conditions identified in the approval conditions register. The system owner remains accountable for compliance with the approved operating conditions and must escalate material changes, incidents, control failures, or changes in residual risk.

66. Relationship to AIGO Procedures

This example should be implemented through the applicable AIGO procedures, particularly:
  • AI Governance Procedure;
  • AI System Registration Procedure;
  • AI Classification Procedure;
  • AI Risk Assessment Procedure;
  • AI Control Assessment Procedure;
  • AI Approval Procedure;
  • AI Change Management Procedure;
  • AI Monitoring Procedure;
  • AI Assurance Procedure;
  • AI Risk Acceptance Procedure;
  • AI Incident Management Procedure;
  • AI Retirement Procedure.

67. Relationship to AIGO Controls

The approval process demonstrates how AIGO controls are integrated into a governance decision. Approval should not operate as an isolated administrative step. It should consume outputs from:
  • registration;
  • classification;
  • risk management;
  • control assessment;
  • evidence management;
  • monitoring;
  • assurance.

68. Relationship to ISO/IEC 42001

The approval process can support an AI management system by providing documented governance decisions, responsibilities, risk considerations, operational controls, evidence, and continual-review mechanisms. Applicable ISO/IEC 42001 requirements should be determined separately by the implementing organization.

69. Relationship to NIST AI RMF

The approval process can support activities associated with:

70. Key Lessons

70.1 Approval Is a Governance Decision

Approval is not merely a signature.

70.2 Approval Requires Evidence

The decision should be supported by documented information.

70.3 Approval Does Not Eliminate Risk

Residual risk may remain after approval.

70.4 Conditional Approval Is Useful

Conditions allow organizations to manage controlled residual issues while maintaining explicit accountability.

70.5 Approval Must Continue Through the Lifecycle

Material changes and significant events may require reassessment or reapproval.

70.6 Approval Must Be Traceable

A reviewer should be able to reconstruct why the organization approved, deferred, rejected, or suspended a system.

71. Complete Approval Model


72. Document Status

Document: AIGO — AI Approval Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-006 Document Type: Implementation Example Example Type: AI System Approval This document provides an illustrative example of how an AI system approval decision can be performed and documented within the AIGO AI Governance Operating Framework.

73. End of Example Document

AIGO — AI Approval Example Document ID: AIGO-EXAMPLE-006 Version: 0.1 Status: Draft End of Document