AIGO — AI Assurance Example
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-010
Document Type: Implementation Example
Example Type: AI Assurance
1. Purpose
This document provides an illustrative example of how an organization can plan, perform, document, review, and close AI assurance activities using the AIGO AI Governance Operating Framework. The example demonstrates how AI assurance connects:- governance;
- AI system lifecycle;
- risk management;
- controls;
- monitoring;
- evidence;
- independent review;
- findings;
- corrective action;
- management decisions;
- continual improvement.
2. Example Organization
For this example, the organization is ExampleCorp, a fictional organization implementing AIGO. The organization operates an AI-enabled recruitment-support system.3. AI System
System Name: Candidate Assessment Assistant AI System ID:AI-HR-001
Business Function: Human Resources
Classification: Class 3 — Enhanced Governance
Lifecycle Stage: Operate
System Owner: HR AI System Owner
Model Owner: AI/ML Engineering Lead
Risk Owner: Enterprise Risk Manager
4. Assurance Scenario
ExampleCorp has operated the Candidate Assessment Assistant for several months. Management requires an assurance review to determine whether the AI governance framework is operating as intended. The review focuses on:- governance;
- risk management;
- controls;
- monitoring;
- evidence;
- human oversight;
- change management;
- incident management.
5. Assurance Objective
The assurance engagement is designed to determine whether:- governance requirements are implemented;
- risks are identified and managed;
- controls are appropriately designed;
- controls operate effectively;
- monitoring is functioning;
- evidence is sufficient;
- material changes are governed;
- incidents are handled appropriately;
- human oversight is functioning;
- identified weaknesses are corrected.
6. Assurance Principle
AI assurance should provide confidence about the effectiveness of AI governance. It should not simply confirm that documentation exists.7. Assurance Lifecycle
8. Assurance Scope
The assurance review covers:- AI governance;
- AI risk management;
- control effectiveness;
- monitoring;
- change management;
- human oversight;
- incident management;
- evidence management.
9. Assurance Period
Review Period: January–June 2026 Assurance ID:ASSUR-AI-001
Lead Reviewer: AI Assurance Lead
Review Sponsor: AI Governance Committee
10. Assurance Criteria
The review uses approved AIGO requirements, controls, procedures, and records as evaluation criteria. The review may also consider applicable external requirements and organizational policies.11. Assurance Criteria Sources
Criteria may include:- AIGO Framework Charter;
- AIGO Principles;
- AIGO Governance Domains;
- AIGO Governance Roles;
- AIGO AI Governance Lifecycle;
- AIGO AI Risk Management;
- AIGO Governance Controls;
- AIGO procedures;
- approved organizational policies;
- applicable regulatory requirements;
- applicable standards and frameworks.
12. Assurance Independence
Where practical, the assurance reviewer should be sufficiently independent from the activities being reviewed. For this example:- the reviewer does not own the AI system;
- the reviewer did not implement the reviewed controls;
- the reviewer reports findings to an appropriate governance authority.
13. Assurance Planning
The assurance lead prepares:- engagement scope;
- objectives;
- criteria;
- methodology;
- evidence requirements;
- testing approach;
- interviews;
- sampling approach;
- reporting requirements.
14. Risk-Based Assurance
Assurance effort is prioritized according to risk. Example:15. Assurance Work Program
The review includes:- document review;
- interviews;
- control walkthroughs;
- evidence inspection;
- sample testing;
- monitoring review;
- risk review;
- change review;
- incident review;
- management discussion.
16. Evidence Collection
Evidence may include:- policies;
- procedures;
- risk assessments;
- control assessments;
- model documentation;
- monitoring records;
- test results;
- approval records;
- change records;
- incident records;
- meeting minutes;
- training records;
- system logs.
17. Evidence Quality
Evidence is evaluated for:- relevance;
- completeness;
- authenticity;
- accuracy;
- timeliness;
- traceability;
- reliability.
18. Evidence Hierarchy
A practical evidence hierarchy may be:
Evidence value depends on context and the assurance objective.
19. Governance Testing
The assurance reviewer examines whether:- governance roles are assigned;
- responsibilities are understood;
- decisions are documented;
- governance meetings occur;
- escalation routes exist;
- accountability is established.
20. Governance Finding Example
Finding ID:FND-AI-001
Area: Governance
Observation: Governance responsibilities are documented, but one operational team has not formally acknowledged its assigned responsibility.
Risk: Accountability may be unclear.
Severity: Medium.
21. Risk Management Testing
The reviewer examines:- risk identification;
- risk assessment;
- risk treatment;
- risk acceptance;
- risk review;
- risk monitoring.
22. Risk Management Result
Sample testing confirms that:- risks are documented;
- risk owners are assigned;
- treatment plans exist;
- residual risk is reviewed.
23. Control Testing
The reviewer evaluates selected controls.24. Monitoring Control Finding
Finding ID:FND-AI-002
Area: Monitoring
Observation: Monitoring operated as designed, but one monthly governance review was completed late.
Risk: Delayed identification of emerging governance issues.
Severity: Low.
Recommendation: Reinforce monitoring review scheduling and escalation.
25. Human Oversight Testing
The assurance reviewer verifies whether authorized personnel can:- review AI outputs;
- challenge recommendations;
- override outputs;
- escalate concerns;
- identify system limitations.
26. Human Oversight Result
Sample testing confirms that human reviewers can override AI recommendations. Conclusion: Effective.27. Change Management Testing
The reviewer selects a sample of material changes. The review evaluates:- change classification;
- impact assessment;
- risk assessment;
- control assessment;
- testing;
- approval;
- deployment;
- monitoring;
- closure.
28. Change Management Result
Sample testing confirms that the selected material change:- was registered;
- was risk assessed;
- was tested;
- was approved;
- was monitored;
- was formally closed.
29. Incident Management Testing
The reviewer examines whether incidents:- are identified;
- are classified;
- are recorded;
- are investigated;
- are escalated;
- receive corrective action;
- are closed appropriately.
30. Incident Management Result
No material AI incidents occurred during the review period. The reviewer confirms that the incident-management process is documented and tested through simulation. Conclusion: Design appears effective.31. Assurance Sampling
The reviewer selects samples using a risk-based approach. Example:
Sampling methodology should be documented.
32. Assurance Test Result
The reviewer records: Population: 12 material AI changes Sample: 4 Exceptions: 0 Conclusion: No exceptions identified in the sample. Sampling does not provide absolute assurance that no additional exceptions exist.33. Finding Classification
Findings may be classified as:34. Finding Structure
Each finding should include:- finding ID;
- criterion;
- condition;
- evidence;
- cause;
- risk;
- impact;
- severity;
- recommendation;
- management response;
- owner;
- target date.
35. Finding Example
Finding ID
FND-AI-002
Criterion
Required governance monitoring reviews should be completed according to the approved monitoring schedule.Condition
One monthly review was completed after the scheduled date.Cause
The review reminder mechanism was not configured for automatic escalation.Risk
Governance issues may not be identified promptly.Severity
Low.36. Recommendation
ExampleCorp should:- configure automated reminders;
- establish escalation for overdue reviews;
- assign backup ownership;
- monitor completion performance.
37. Management Response
Management Response: Accepted. Action Owner: AI Governance Lead Target Date: 30 September 2026 Action: Implement automated monitoring-review reminders and escalation.38. Corrective Action
The corrective action is registered as: Action ID:CAPA-AI-002
Finding: FND-AI-002
Owner: AI Governance Lead
Status: Open
39. Corrective Action Verification
After implementation, assurance verifies:- reminder configuration;
- escalation logic;
- evidence of operation;
- completion records.
40. Assurance Finding Lifecycle
41. Assurance Conclusion Categories
Possible conclusions include:- Effective;
- Generally Effective;
- Partially Effective;
- Ineffective;
- Unable to Conclude.
42. Example Assurance Conclusion
Overall Conclusion: Generally Effective The review identified two findings:- one medium governance accountability finding;
- one low monitoring-process finding.
43. Assurance Report
The final assurance report contains:- executive summary;
- scope;
- objectives;
- criteria;
- methodology;
- limitations;
- findings;
- management responses;
- corrective actions;
- overall conclusion.
44. Executive Summary Example
ExampleCorp’s AI governance assurance review assessed the Candidate Assessment Assistant across governance, risk, controls, monitoring, human oversight, change management, and incident management. The review concluded that the governance framework is generally effective. Two findings were identified and assigned corrective actions.45. Assurance Limitations
The assurance review does not provide absolute assurance. Limitations may include:- sampling;
- incomplete evidence;
- system access restrictions;
- unavailable historical records;
- time limitations;
- reliance on management representations;
- technical limitations.
46. Assurance Evidence Chain
47. Assurance and Risk
Assurance should provide information about whether risk-management processes are functioning as intended. Assurance does not replace management’s responsibility to own and manage risk.48. Assurance and Controls
Assurance evaluates whether selected controls:- are appropriately designed;
- are implemented;
- operate effectively;
- generate sufficient evidence.
49. Assurance and Monitoring
Monitoring provides operational information. Assurance evaluates whether monitoring itself is appropriate and effective.50. Assurance and Change Management
Assurance may sample AI changes to determine whether:- material changes were identified;
- risk was reassessed;
- controls were assessed;
- testing was completed;
- approval occurred;
- deployment was controlled.
51. Assurance and Incident Management
Assurance may evaluate whether incidents were:- detected;
- classified;
- investigated;
- escalated;
- resolved;
- documented;
- reviewed for lessons learned.
52. Assurance and Human Oversight
Assurance evaluates whether human oversight exists in practice, not merely whether it is documented. Evidence may include:- override records;
- review records;
- escalation records;
- training;
- interviews;
- system functionality.
53. Assurance and Evidence
Assurance depends on evidence that is sufficiently reliable for the assurance objective. A documented control without evidence of operation may not be sufficient to conclude that the control operates effectively.54. Assurance and Continual Improvement
Assurance findings should feed continual improvement.55. Assurance Escalation
Critical findings should be escalated immediately according to organizational governance requirements. High-severity findings should receive priority remediation. Medium and low findings should be tracked to closure.56. Critical Finding Example
If the assurance reviewer discovers that a material AI system is operating without required approval, the matter should be escalated immediately. Potential actions include:- management escalation;
- risk reassessment;
- suspension;
- incident review;
- emergency governance decision.
57. Assurance Follow-Up
Follow-up activities determine whether:- corrective actions were implemented;
- corrective actions were effective;
- findings remain open;
- residual risk is acceptable.
58. Assurance Closure
An assurance engagement may be closed when:- testing is complete;
- findings are documented;
- report is issued;
- management responses are recorded;
- corrective actions are assigned;
- governance acceptance is recorded.
59. Assurance Checklist
- Assurance objective defined
- Scope defined
- Criteria defined
- Independence considered
- Risk assessment completed
- Assurance plan approved
- Evidence requirements defined
- Evidence collected
- Testing completed
- Samples documented
- Findings validated
- Findings classified
- Management responses obtained
- Corrective actions assigned
- Assurance conclusion issued
- Report approved
- Follow-up scheduled
- Corrective actions verified
- Findings closed where appropriate
- Lessons learned recorded
60. Assurance Traceability
A complete assurance record should connect:61. Assurance Roles
62. Segregation of Duties
Where practical:- control owners should not provide their own independent assurance;
- system owners should not independently approve their own assurance conclusions;
- assurance reviewers should maintain sufficient objectivity.
63. Assurance Reporting Frequency
Assurance frequency should be risk-based. Example:
The exact schedule should be established by the organization’s governance framework.
64. Triggered Assurance
Additional assurance may be initiated after:- material AI incidents;
- significant model changes;
- major risk changes;
- regulatory developments;
- control failures;
- significant monitoring alerts;
- repeated findings.
65. Triggered Assurance Model
66. Assurance Maturity
An organization may progressively mature its assurance capabilities.Level 1 — Ad Hoc
Assurance is performed reactively.Level 2 — Defined
Assurance procedures are documented.Level 3 — Repeatable
Assurance is performed consistently.Level 4 — Risk-Based
Assurance is prioritized according to AI risk.Level 5 — Integrated
Assurance is integrated with monitoring, risk, controls, incidents, changes, and continual improvement.67. Assurance Dashboard
A governance dashboard may report:68. Management Review
Assurance results should be presented to appropriate governance bodies. Management review should consider:- findings;
- trends;
- corrective actions;
- residual risk;
- control effectiveness;
- recurring weaknesses;
- improvement opportunities.
69. Assurance and Management Decision
Management may determine to:- accept the conclusion;
- require additional action;
- increase monitoring;
- change controls;
- reassess risk;
- initiate a change;
- suspend a system;
- commission additional assurance.
70. Relationship to AIGO Procedures
This example should be implemented through the applicable AIGO procedures, particularly:- AI Assurance Procedure;
- AI Governance Procedure;
- AI Risk Assessment Procedure;
- AI Control Assessment Procedure;
- AI Monitoring Procedure;
- AI Change Management Procedure;
- AI Incident Management Procedure;
- AI Approval Procedure;
- Continuous Improvement Procedure.
71. Relationship to AIGO Controls
The assurance example demonstrates interaction between:- governance controls;
- risk controls;
- control-assessment controls;
- monitoring controls;
- evidence controls;
- change-management controls;
- incident-management controls;
- assurance controls;
- continual-improvement controls.
72. Relationship to ISO/IEC 42001
AI assurance can support an AI management system by providing evaluation of governance processes, controls, performance, risk management, documented information, corrective action, and continual improvement. Applicable ISO/IEC 42001 requirements should be evaluated separately by the implementing organization.73. Relationship to NIST AI RMF
The assurance process can support activities associated with:74. Complete Assurance Model
75. Key Assurance Principles
75.1 Assurance Must Be Evidence-Based
Conclusions should be supported by appropriate evidence.75.2 Assurance Must Be Risk-Based
Higher-risk AI systems require greater assurance attention.75.3 Assurance Must Be Objective
Reviewers should maintain appropriate independence and objectivity.75.4 Assurance Must Test Operation
Documentation alone does not demonstrate operational effectiveness.75.5 Findings Must Lead to Action
Material weaknesses should result in defined corrective actions.75.6 Corrective Actions Must Be Verified
Closing an action requires evidence that the intended result was achieved.75.7 Assurance Must Support Improvement
Assurance should strengthen the AI governance system over time.76. Final Assurance Decision
ExampleCorp concludes that the Candidate Assessment Assistant’s AI governance arrangements are generally effective. Two findings remain subject to corrective action. No critical or high-severity weaknesses were identified. The AI system remains approved for operation, subject to continued monitoring and completion of corrective actions.77. Document Status
Document: AIGO — AI Assurance Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-010
Document Type: Implementation Example
Example Type: AI Assurance
This document provides an illustrative example of how AI assurance can be planned, performed, evidenced, reported, remediated, verified, and integrated into the AIGO governance lifecycle.
78. End of Example Document
AIGO — AI Assurance Example Document ID:AIGO-EXAMPLE-010
Version: 0.1
Status: Draft
End of Document