Skip to main content

AIGO — AI Assurance Example

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-010 Document Type: Implementation Example Example Type: AI Assurance

1. Purpose

This document provides an illustrative example of how an organization can plan, perform, document, review, and close AI assurance activities using the AIGO AI Governance Operating Framework. The example demonstrates how AI assurance connects:
  • governance;
  • AI system lifecycle;
  • risk management;
  • controls;
  • monitoring;
  • evidence;
  • independent review;
  • findings;
  • corrective action;
  • management decisions;
  • continual improvement.
This document is an implementation example and does not constitute legal, regulatory, audit, certification, or legal-compliance advice.

2. Example Organization

For this example, the organization is ExampleCorp, a fictional organization implementing AIGO. The organization operates an AI-enabled recruitment-support system.

3. AI System

System Name: Candidate Assessment Assistant AI System ID: AI-HR-001 Business Function: Human Resources Classification: Class 3 — Enhanced Governance Lifecycle Stage: Operate System Owner: HR AI System Owner Model Owner: AI/ML Engineering Lead Risk Owner: Enterprise Risk Manager

4. Assurance Scenario

ExampleCorp has operated the Candidate Assessment Assistant for several months. Management requires an assurance review to determine whether the AI governance framework is operating as intended. The review focuses on:
  • governance;
  • risk management;
  • controls;
  • monitoring;
  • evidence;
  • human oversight;
  • change management;
  • incident management.

5. Assurance Objective

The assurance engagement is designed to determine whether:
  1. governance requirements are implemented;
  2. risks are identified and managed;
  3. controls are appropriately designed;
  4. controls operate effectively;
  5. monitoring is functioning;
  6. evidence is sufficient;
  7. material changes are governed;
  8. incidents are handled appropriately;
  9. human oversight is functioning;
  10. identified weaknesses are corrected.

6. Assurance Principle

AI assurance should provide confidence about the effectiveness of AI governance. It should not simply confirm that documentation exists.

7. Assurance Lifecycle


8. Assurance Scope

The assurance review covers:
  • AI governance;
  • AI risk management;
  • control effectiveness;
  • monitoring;
  • change management;
  • human oversight;
  • incident management;
  • evidence management.

9. Assurance Period

Review Period: January–June 2026 Assurance ID: ASSUR-AI-001 Lead Reviewer: AI Assurance Lead Review Sponsor: AI Governance Committee

10. Assurance Criteria

The review uses approved AIGO requirements, controls, procedures, and records as evaluation criteria. The review may also consider applicable external requirements and organizational policies.

11. Assurance Criteria Sources

Criteria may include:
  • AIGO Framework Charter;
  • AIGO Principles;
  • AIGO Governance Domains;
  • AIGO Governance Roles;
  • AIGO AI Governance Lifecycle;
  • AIGO AI Risk Management;
  • AIGO Governance Controls;
  • AIGO procedures;
  • approved organizational policies;
  • applicable regulatory requirements;
  • applicable standards and frameworks.

12. Assurance Independence

Where practical, the assurance reviewer should be sufficiently independent from the activities being reviewed. For this example:
  • the reviewer does not own the AI system;
  • the reviewer did not implement the reviewed controls;
  • the reviewer reports findings to an appropriate governance authority.

13. Assurance Planning

The assurance lead prepares:
  • engagement scope;
  • objectives;
  • criteria;
  • methodology;
  • evidence requirements;
  • testing approach;
  • interviews;
  • sampling approach;
  • reporting requirements.

14. Risk-Based Assurance

Assurance effort is prioritized according to risk. Example:

15. Assurance Work Program

The review includes:
  1. document review;
  2. interviews;
  3. control walkthroughs;
  4. evidence inspection;
  5. sample testing;
  6. monitoring review;
  7. risk review;
  8. change review;
  9. incident review;
  10. management discussion.

16. Evidence Collection

Evidence may include:
  • policies;
  • procedures;
  • risk assessments;
  • control assessments;
  • model documentation;
  • monitoring records;
  • test results;
  • approval records;
  • change records;
  • incident records;
  • meeting minutes;
  • training records;
  • system logs.

17. Evidence Quality

Evidence is evaluated for:
  • relevance;
  • completeness;
  • authenticity;
  • accuracy;
  • timeliness;
  • traceability;
  • reliability.

18. Evidence Hierarchy

A practical evidence hierarchy may be: Evidence value depends on context and the assurance objective.

19. Governance Testing

The assurance reviewer examines whether:
  • governance roles are assigned;
  • responsibilities are understood;
  • decisions are documented;
  • governance meetings occur;
  • escalation routes exist;
  • accountability is established.

20. Governance Finding Example

Finding ID: FND-AI-001 Area: Governance Observation: Governance responsibilities are documented, but one operational team has not formally acknowledged its assigned responsibility. Risk: Accountability may be unclear. Severity: Medium.

21. Risk Management Testing

The reviewer examines:
  • risk identification;
  • risk assessment;
  • risk treatment;
  • risk acceptance;
  • risk review;
  • risk monitoring.

22. Risk Management Result

Sample testing confirms that:
  • risks are documented;
  • risk owners are assigned;
  • treatment plans exist;
  • residual risk is reviewed.
Conclusion: Generally effective.

23. Control Testing

The reviewer evaluates selected controls.

24. Monitoring Control Finding

Finding ID: FND-AI-002 Area: Monitoring Observation: Monitoring operated as designed, but one monthly governance review was completed late. Risk: Delayed identification of emerging governance issues. Severity: Low. Recommendation: Reinforce monitoring review scheduling and escalation.

25. Human Oversight Testing

The assurance reviewer verifies whether authorized personnel can:
  • review AI outputs;
  • challenge recommendations;
  • override outputs;
  • escalate concerns;
  • identify system limitations.

26. Human Oversight Result

Sample testing confirms that human reviewers can override AI recommendations. Conclusion: Effective.

27. Change Management Testing

The reviewer selects a sample of material changes. The review evaluates:
  • change classification;
  • impact assessment;
  • risk assessment;
  • control assessment;
  • testing;
  • approval;
  • deployment;
  • monitoring;
  • closure.

28. Change Management Result

Sample testing confirms that the selected material change:
  • was registered;
  • was risk assessed;
  • was tested;
  • was approved;
  • was monitored;
  • was formally closed.
Conclusion: Effective.

29. Incident Management Testing

The reviewer examines whether incidents:
  • are identified;
  • are classified;
  • are recorded;
  • are investigated;
  • are escalated;
  • receive corrective action;
  • are closed appropriately.

30. Incident Management Result

No material AI incidents occurred during the review period. The reviewer confirms that the incident-management process is documented and tested through simulation. Conclusion: Design appears effective.

31. Assurance Sampling

The reviewer selects samples using a risk-based approach. Example: Sampling methodology should be documented.

32. Assurance Test Result

The reviewer records: Population: 12 material AI changes Sample: 4 Exceptions: 0 Conclusion: No exceptions identified in the sample. Sampling does not provide absolute assurance that no additional exceptions exist.

33. Finding Classification

Findings may be classified as:

34. Finding Structure

Each finding should include:
  • finding ID;
  • criterion;
  • condition;
  • evidence;
  • cause;
  • risk;
  • impact;
  • severity;
  • recommendation;
  • management response;
  • owner;
  • target date.

35. Finding Example

Finding ID

FND-AI-002

Criterion

Required governance monitoring reviews should be completed according to the approved monitoring schedule.

Condition

One monthly review was completed after the scheduled date.

Cause

The review reminder mechanism was not configured for automatic escalation.

Risk

Governance issues may not be identified promptly.

Severity

Low.

36. Recommendation

ExampleCorp should:
  1. configure automated reminders;
  2. establish escalation for overdue reviews;
  3. assign backup ownership;
  4. monitor completion performance.

37. Management Response

Management Response: Accepted. Action Owner: AI Governance Lead Target Date: 30 September 2026 Action: Implement automated monitoring-review reminders and escalation.

38. Corrective Action

The corrective action is registered as: Action ID: CAPA-AI-002 Finding: FND-AI-002 Owner: AI Governance Lead Status: Open

39. Corrective Action Verification

After implementation, assurance verifies:
  • reminder configuration;
  • escalation logic;
  • evidence of operation;
  • completion records.
If the corrective action is effective, the finding can be closed.

40. Assurance Finding Lifecycle


41. Assurance Conclusion Categories

Possible conclusions include:
  • Effective;
  • Generally Effective;
  • Partially Effective;
  • Ineffective;
  • Unable to Conclude.
The conclusion should reflect the evidence obtained and the defined assurance criteria.

42. Example Assurance Conclusion

Overall Conclusion: Generally Effective The review identified two findings:
  • one medium governance accountability finding;
  • one low monitoring-process finding.
No critical or high-severity findings were identified. The AI governance framework is operating generally effectively, subject to completion of corrective actions.

43. Assurance Report

The final assurance report contains:
  1. executive summary;
  2. scope;
  3. objectives;
  4. criteria;
  5. methodology;
  6. limitations;
  7. findings;
  8. management responses;
  9. corrective actions;
  10. overall conclusion.

44. Executive Summary Example

ExampleCorp’s AI governance assurance review assessed the Candidate Assessment Assistant across governance, risk, controls, monitoring, human oversight, change management, and incident management. The review concluded that the governance framework is generally effective. Two findings were identified and assigned corrective actions.

45. Assurance Limitations

The assurance review does not provide absolute assurance. Limitations may include:
  • sampling;
  • incomplete evidence;
  • system access restrictions;
  • unavailable historical records;
  • time limitations;
  • reliance on management representations;
  • technical limitations.

46. Assurance Evidence Chain


47. Assurance and Risk

Assurance should provide information about whether risk-management processes are functioning as intended. Assurance does not replace management’s responsibility to own and manage risk.

48. Assurance and Controls

Assurance evaluates whether selected controls:
  • are appropriately designed;
  • are implemented;
  • operate effectively;
  • generate sufficient evidence.

49. Assurance and Monitoring

Monitoring provides operational information. Assurance evaluates whether monitoring itself is appropriate and effective.

50. Assurance and Change Management

Assurance may sample AI changes to determine whether:
  • material changes were identified;
  • risk was reassessed;
  • controls were assessed;
  • testing was completed;
  • approval occurred;
  • deployment was controlled.

51. Assurance and Incident Management

Assurance may evaluate whether incidents were:
  • detected;
  • classified;
  • investigated;
  • escalated;
  • resolved;
  • documented;
  • reviewed for lessons learned.

52. Assurance and Human Oversight

Assurance evaluates whether human oversight exists in practice, not merely whether it is documented. Evidence may include:
  • override records;
  • review records;
  • escalation records;
  • training;
  • interviews;
  • system functionality.

53. Assurance and Evidence

Assurance depends on evidence that is sufficiently reliable for the assurance objective. A documented control without evidence of operation may not be sufficient to conclude that the control operates effectively.

54. Assurance and Continual Improvement

Assurance findings should feed continual improvement.

55. Assurance Escalation

Critical findings should be escalated immediately according to organizational governance requirements. High-severity findings should receive priority remediation. Medium and low findings should be tracked to closure.

56. Critical Finding Example

If the assurance reviewer discovers that a material AI system is operating without required approval, the matter should be escalated immediately. Potential actions include:
  • management escalation;
  • risk reassessment;
  • suspension;
  • incident review;
  • emergency governance decision.

57. Assurance Follow-Up

Follow-up activities determine whether:
  • corrective actions were implemented;
  • corrective actions were effective;
  • findings remain open;
  • residual risk is acceptable.

58. Assurance Closure

An assurance engagement may be closed when:
  • testing is complete;
  • findings are documented;
  • report is issued;
  • management responses are recorded;
  • corrective actions are assigned;
  • governance acceptance is recorded.
Open corrective actions may remain active after the engagement itself is closed.

59. Assurance Checklist

  • Assurance objective defined
  • Scope defined
  • Criteria defined
  • Independence considered
  • Risk assessment completed
  • Assurance plan approved
  • Evidence requirements defined
  • Evidence collected
  • Testing completed
  • Samples documented
  • Findings validated
  • Findings classified
  • Management responses obtained
  • Corrective actions assigned
  • Assurance conclusion issued
  • Report approved
  • Follow-up scheduled
  • Corrective actions verified
  • Findings closed where appropriate
  • Lessons learned recorded

60. Assurance Traceability

A complete assurance record should connect:

61. Assurance Roles


62. Segregation of Duties

Where practical:
  • control owners should not provide their own independent assurance;
  • system owners should not independently approve their own assurance conclusions;
  • assurance reviewers should maintain sufficient objectivity.

63. Assurance Reporting Frequency

Assurance frequency should be risk-based. Example: The exact schedule should be established by the organization’s governance framework.

64. Triggered Assurance

Additional assurance may be initiated after:
  • material AI incidents;
  • significant model changes;
  • major risk changes;
  • regulatory developments;
  • control failures;
  • significant monitoring alerts;
  • repeated findings.

65. Triggered Assurance Model


66. Assurance Maturity

An organization may progressively mature its assurance capabilities.

Level 1 — Ad Hoc

Assurance is performed reactively.

Level 2 — Defined

Assurance procedures are documented.

Level 3 — Repeatable

Assurance is performed consistently.

Level 4 — Risk-Based

Assurance is prioritized according to AI risk.

Level 5 — Integrated

Assurance is integrated with monitoring, risk, controls, incidents, changes, and continual improvement.

67. Assurance Dashboard

A governance dashboard may report:

68. Management Review

Assurance results should be presented to appropriate governance bodies. Management review should consider:
  • findings;
  • trends;
  • corrective actions;
  • residual risk;
  • control effectiveness;
  • recurring weaknesses;
  • improvement opportunities.

69. Assurance and Management Decision

Management may determine to:
  • accept the conclusion;
  • require additional action;
  • increase monitoring;
  • change controls;
  • reassess risk;
  • initiate a change;
  • suspend a system;
  • commission additional assurance.

70. Relationship to AIGO Procedures

This example should be implemented through the applicable AIGO procedures, particularly:
  • AI Assurance Procedure;
  • AI Governance Procedure;
  • AI Risk Assessment Procedure;
  • AI Control Assessment Procedure;
  • AI Monitoring Procedure;
  • AI Change Management Procedure;
  • AI Incident Management Procedure;
  • AI Approval Procedure;
  • Continuous Improvement Procedure.

71. Relationship to AIGO Controls

The assurance example demonstrates interaction between:
  • governance controls;
  • risk controls;
  • control-assessment controls;
  • monitoring controls;
  • evidence controls;
  • change-management controls;
  • incident-management controls;
  • assurance controls;
  • continual-improvement controls.

72. Relationship to ISO/IEC 42001

AI assurance can support an AI management system by providing evaluation of governance processes, controls, performance, risk management, documented information, corrective action, and continual improvement. Applicable ISO/IEC 42001 requirements should be evaluated separately by the implementing organization.

73. Relationship to NIST AI RMF

The assurance process can support activities associated with:

74. Complete Assurance Model


75. Key Assurance Principles

75.1 Assurance Must Be Evidence-Based

Conclusions should be supported by appropriate evidence.

75.2 Assurance Must Be Risk-Based

Higher-risk AI systems require greater assurance attention.

75.3 Assurance Must Be Objective

Reviewers should maintain appropriate independence and objectivity.

75.4 Assurance Must Test Operation

Documentation alone does not demonstrate operational effectiveness.

75.5 Findings Must Lead to Action

Material weaknesses should result in defined corrective actions.

75.6 Corrective Actions Must Be Verified

Closing an action requires evidence that the intended result was achieved.

75.7 Assurance Must Support Improvement

Assurance should strengthen the AI governance system over time.

76. Final Assurance Decision

ExampleCorp concludes that the Candidate Assessment Assistant’s AI governance arrangements are generally effective. Two findings remain subject to corrective action. No critical or high-severity weaknesses were identified. The AI system remains approved for operation, subject to continued monitoring and completion of corrective actions.

77. Document Status

Document: AIGO — AI Assurance Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-EXAMPLE-010 Document Type: Implementation Example Example Type: AI Assurance This document provides an illustrative example of how AI assurance can be planned, performed, evidenced, reported, remediated, verified, and integrated into the AIGO governance lifecycle.

78. End of Example Document

AIGO — AI Assurance Example Document ID: AIGO-EXAMPLE-010 Version: 0.1 Status: Draft End of Document