AIGO — ISO/IEC 42001 Control Mapping
AIGO — AI Governance Operating Framework
Version: 0.1Status: Draft
Working Name: AIGO
Full Name: AI Governance Operating Framework
Document Identifier: AIGO-MAP-ISO42001-003
Mapping Standard: ISO/IEC 42001
Mapping Type: Control Mapping
1. Purpose
This document defines the control-level mapping between ISO/IEC 42001 and the AIGO AI Governance Operating Framework. The purpose of this mapping is to establish traceability between the AI management controls identified by ISO/IEC 42001 and the AIGO governance control architecture. The mapping provides a basis for:- control implementation;
- control ownership;
- control assessment;
- risk treatment;
- assurance;
- evidence collection;
- gap analysis; and
- continual improvement.
2. Scope
This document focuses on the relationship between ISO/IEC 42001 AI management controls and AIGO governance controls. The mapping covers the major control areas associated with:- policies related to AI;
- internal organization;
- resources for AI systems;
- impact assessment;
- AI system lifecycle;
- data;
- information for interested parties;
- use of AI systems;
- third-party relationships;
- monitoring;
- documentation;
- human oversight;
- technical and organizational measures;
- responsible AI governance; and
- continual improvement.
3. Control Mapping Principles
3.1 Control Traceability
Each mapped ISO/IEC 42001 control should identify the corresponding AIGO control or control family.3.2 Control Ownership
Each AIGO control should have an identifiable control owner or accountable governance role.3.3 Risk Alignment
Controls should be connected to identified AI risks and risk-treatment decisions.3.4 Lifecycle Alignment
Controls should be applicable to the relevant stages of the AI governance lifecycle.3.5 Evidence Alignment
Controls should generate or reference evidence demonstrating implementation and operation.3.6 Assurance Alignment
Controls should be capable of assessment through monitoring, control assessment, assurance, audit, or other appropriate evaluation mechanisms.4. Control Relationship Types
The following relationship types are used in this mapping.4.1 Direct
The AIGO control directly addresses the intent of the corresponding ISO/IEC 42001 control.4.2 Supporting
The AIGO control provides supporting governance capability.4.3 Partial
The AIGO control addresses only part of the external control requirement.4.4 Complementary
The AIGO control provides additional governance capability beyond the external control.4.5 Organizational Implementation
AIGO provides a control framework, but the organization must implement and operate the control.4.6 Gap
A corresponding AIGO control does not yet provide sufficient coverage.5. AIGO Control Architecture
The AIGO control architecture is maintained in:framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md
The control architecture should provide:
- control identifier;
- control name;
- control objective;
- control description;
- applicability;
- control owner;
- implementation guidance;
- evidence;
- monitoring;
- assessment;
- risk relationship; and
- lifecycle relationship.
6. Control Mapping Structure
Each mapping should establish the following relationship:ISO/IEC 42001 Control
↓
AIGO Control
↓
Control Objective
↓
Risk Relationship
↓
Lifecycle Relationship
↓
Control Owner
↓
Implementation Procedure
↓
Evidence
↓
Monitoring
↓
Assurance
---
### 7. ISO/IEC 42001 Control Group A — Policies Related to AI
#### 7.1 AI Policy and Governance
ISO/IEC 42001 controls relating to AI policy are mapped primarily to the AIGO Charter, Principles, Governance Domains, and Governance Controls.
**Primary AIGO References:**
- `framework/01-charter/`
- `framework/02-principles/`
- `framework/03-domains/`
- `framework/07-controls/`
**Relationship:** Direct
**Status:** Covered
---
#### 7.2 AI Governance Objectives
AI governance objectives are supported through AIGO principles, governance objectives, controls, and maturity objectives.
**Primary AIGO References:**
- `framework/02-principles/`
- `framework/07-controls/`
- `framework/08-maturity/`
**Relationship:** Direct
**Status:** Covered
---
### 8. ISO/IEC 42001 Control Group B — Internal Organization
#### 8.1 Governance Structure
AIGO defines governance structures through governance domains and governance roles.
**Primary AIGO References:**
- `framework/03-domains/`
- `framework/04-roles/`
**Relationship:** Direct
**Status:** Covered
---
#### 8.2 Roles and Responsibilities
AIGO establishes accountability and responsibility for AI governance.
Roles may include responsibility for:
- AI systems;
- risks;
- controls;
- approvals;
- monitoring;
- incidents;
- assurance; and
- retirement.
**Primary AIGO Reference:**
`framework/04-roles/AIGO-Governance-Roles-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
#### 8.3 Segregation of Responsibilities
AIGO governance roles should support appropriate separation between:
- system development;
- system operation;
- risk ownership;
- control ownership;
- approval;
- assurance; and
- independent review.
**Primary AIGO References:**
- `framework/04-roles/`
- `framework/07-controls/`
**Relationship:** Supporting
**Status:** Covered
---
### 9. ISO/IEC 42001 Control Group C — Resources for AI Systems
#### 9.1 AI Resources
AIGO recognizes the need to govern resources supporting AI systems.
Resources may include:
- people;
- data;
- models;
- infrastructure;
- computing resources;
- software;
- external services;
- documentation; and
- operational capabilities.
**Primary AIGO References:**
- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Supporting
**Status:** Requires Organizational Implementation
---
#### 9.2 Competence and Capability
AIGO governance roles and maturity architecture provide a basis for establishing competence requirements.
**Primary AIGO References:**
- `framework/04-roles/`
- `framework/08-maturity/`
**Relationship:** Supporting
**Status:** Requires Organizational Implementation
---
### 10. ISO/IEC 42001 Control Group D — Assessing AI Impacts
#### 10.1 AI Impact Assessment
AIGO risk management provides the principal governance mechanism for identifying and evaluating potential impacts associated with AI systems.
Impact considerations may include:
- individuals;
- groups;
- organizations;
- society;
- safety;
- security;
- privacy;
- fairness;
- human rights;
- operational consequences; and
- other material impacts.
**Primary AIGO References:**
- `framework/06-risk/`
- `framework/09-profiles/`
**Relationship:** Direct
**Status:** Covered
---
#### 10.2 Impact Assessment Integration
Impact assessment should be integrated with:
- AI system classification;
- risk assessment;
- lifecycle decisions;
- control selection;
- approval;
- monitoring; and
- change management.
**Supporting Procedures:**
- `guidance/02-procedures/03-AIGO-AI-Risk-Assessment-Procedure-v0.1.md`
- `guidance/02-procedures/04-AIGO-AI-Classification-Procedure-v0.1.md`
- `guidance/02-procedures/06-AIGO-AI-Approval-Procedure-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 11. ISO/IEC 42001 Control Group E — AI System Lifecycle
#### 11.1 Lifecycle Governance
AIGO provides lifecycle governance from planning through retirement.
**Primary AIGO Reference:**
`framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
#### 11.2 Lifecycle Risk Management
AI risks should be assessed and managed throughout the AI lifecycle.
Lifecycle risk activities include:
- initial risk identification;
- design-stage assessment;
- development-stage assessment;
- testing and validation;
- deployment approval;
- operational monitoring;
- change assessment;
- incident response; and
- retirement assessment.
**Primary AIGO References:**
- `framework/05-lifecycle/`
- `framework/06-risk/`
**Relationship:** Direct
**Status:** Covered
---
#### 11.3 Lifecycle Control Application
AIGO controls should be assigned according to the lifecycle stage and risk profile of the AI system.
**Primary AIGO References:**
- `framework/05-lifecycle/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Direct
**Status:** Covered
---
### 12. ISO/IEC 42001 Control Group F — Data for AI Systems
#### 12.1 Data Governance
AIGO recognizes data as a governed AI resource and risk factor.
Data governance should address:
- data sources;
- data ownership;
- data quality;
- data suitability;
- data provenance;
- data access;
- data protection;
- data use;
- data retention; and
- data-related risks.
**Primary AIGO References:**
- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Supporting
**Status:** Covered
---
#### 12.2 Data Risk
Data-related risks should be identified and assessed within the AIGO AI risk-management process.
Potential risks include:
- inaccurate data;
- incomplete data;
- biased data;
- inappropriate data use;
- unauthorized access;
- data leakage;
- provenance uncertainty; and
- inappropriate retention.
**Primary AIGO Reference:**
`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
#### 12.3 Data Controls
Appropriate data controls should be selected based on:
- system classification;
- risk;
- intended purpose;
- applicable requirements;
- lifecycle stage; and
- organizational context.
**Primary AIGO Reference:**
`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 13. ISO/IEC 42001 Control Group G — Information for Interested Parties
#### 13.1 AI System Information
AIGO AI System Profiles provide structured information that can support governance and communication regarding AI systems.
**Primary AIGO Reference:**
`framework/09-profiles/AIGO-AI-System-Profiles-v0.1.md`
**Relationship:** Complementary
**Status:** Covered
---
#### 13.2 Transparency and Communication
AIGO principles and controls support appropriate transparency and communication concerning AI systems.
Relevant considerations may include:
- intended purpose;
- system ownership;
- significant risks;
- limitations;
- human oversight;
- monitoring;
- incidents; and
- material changes.
**Primary AIGO References:**
- `framework/02-principles/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Supporting
**Status:** Covered
---
### 14. ISO/IEC 42001 Control Group H — Use of AI Systems
#### 14.1 Authorized AI Use
AIGO governance requires AI systems to operate within their approved scope and intended purpose.
**Primary AIGO References:**
- `framework/05-lifecycle/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Direct
**Status:** Covered
---
#### 14.2 Human Oversight
AIGO governance controls should establish appropriate human oversight based on:
- AI system risk;
- system classification;
- decision impact;
- level of autonomy;
- operating environment; and
- potential consequences.
**Primary AIGO References:**
- `framework/04-roles/`
- `framework/06-risk/`
- `framework/07-controls/`
**Relationship:** Direct
**Status:** Covered
---
#### 14.3 AI System Monitoring
AI systems should be monitored throughout operation.
Monitoring should consider:
- performance;
- risk indicators;
- control effectiveness;
- incidents;
- anomalies;
- material changes; and
- emerging risks.
**Primary AIGO References:**
- `framework/07-controls/`
- `framework/08-maturity/`
**Supporting Procedure:**
`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 15. ISO/IEC 42001 Control Group I — Third-Party and Supplier Relationships
#### 15.1 Third-Party AI Services
AIGO governance should extend to material third-party AI systems and services.
Third-party considerations may include:
- supplier identity;
- service scope;
- AI system dependencies;
- contractual requirements;
- risk;
- data handling;
- security;
- performance;
- monitoring;
- incident management; and
- termination.
**Primary AIGO References:**
- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Supporting
**Status:** Covered
---
#### 15.2 Third-Party Risk
Third-party AI risks should be incorporated into the AIGO risk-management process.
**Primary AIGO Reference:**
`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 16. ISO/IEC 42001 Control Group J — Monitoring and Measurement
#### 16.1 AI Governance Monitoring
AIGO establishes monitoring as a core governance capability.
Monitoring may address:
- AI system performance;
- governance performance;
- risk indicators;
- control effectiveness;
- incidents;
- compliance indicators;
- assurance findings; and
- maturity indicators.
**Primary AIGO References:**
- `framework/07-controls/`
- `framework/08-maturity/`
**Supporting Procedure:**
`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
#### 16.2 Control Effectiveness Monitoring
Controls should be monitored to determine whether they remain:
- implemented;
- operating;
- effective;
- appropriate;
- proportionate; and
- aligned with current risk.
**Primary AIGO Reference:**
`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 17. ISO/IEC 42001 Control Group K — Documentation and Records
#### 17.1 Governance Documentation
AIGO requires governance information to be maintained throughout the AI lifecycle.
Relevant documentation may include:
- governance decisions;
- AI system profiles;
- risk assessments;
- classification decisions;
- control assessments;
- approvals;
- changes;
- incidents;
- monitoring results;
- assurance results; and
- retirement records.
**Primary AIGO References:**
- `framework/05-lifecycle/`
- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`
**Relationship:** Direct
**Status:** Covered
---
#### 17.2 Records and Evidence
AIGO evidence requirements should demonstrate both the implementation and operation of controls.
Evidence may include:
- approved records;
- assessments;
- reports;
- logs;
- monitoring results;
- review records;
- decision records;
- audit results; and
- corrective-action records.
**Relationship:** Direct
**Status:** Covered
---
### 18. ISO/IEC 42001 Control Group L — Human Oversight
#### 18.1 Human Oversight Governance
AIGO recognizes human oversight as a governance mechanism for managing AI system autonomy and decision impact.
**Primary AIGO References:**
- `framework/04-roles/`
- `framework/06-risk/`
- `framework/07-controls/`
**Relationship:** Direct
**Status:** Covered
---
#### 18.2 Human Intervention
Human intervention requirements should be determined based on:
- system risk;
- decision impact;
- autonomy;
- operating conditions;
- foreseeable misuse;
- failure modes; and
- organizational requirements.
**Primary AIGO References:**
- `framework/06-risk/`
- `framework/07-controls/`
**Relationship:** Direct
**Status:** Covered
---
### 19. ISO/IEC 42001 Control Group M — Technical and Organizational Measures
#### 19.1 Technical Measures
AIGO governance controls may require technical measures appropriate to identified risks.
Potential areas include:
- access control;
- security;
- monitoring;
- logging;
- validation;
- testing;
- robustness;
- resilience;
- data protection; and
- system controls.
**Primary AIGO Reference:**
`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
**Relationship:** Supporting
**Status:** Covered
---
#### 19.2 Organizational Measures
Organizational measures may include:
- policies;
- procedures;
- governance roles;
- approvals;
- training;
- oversight;
- monitoring;
- assurance; and
- corrective action.
**Primary AIGO References:**
- `framework/03-domains/`
- `framework/04-roles/`
- `framework/07-controls/`
**Relationship:** Direct
**Status:** Covered
---
### 20. ISO/IEC 42001 Control Group N — AI Incidents
#### 20.1 AI Incident Management
AIGO establishes a dedicated AI incident-management process.
Incident management should address:
- detection;
- classification;
- escalation;
- containment;
- investigation;
- response;
- corrective action;
- communication;
- lessons learned; and
- closure.
**Supporting Procedure:**
`guidance/02-procedures/08-AIGO-AI-Incident-Management-Procedure-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 21. ISO/IEC 42001 Control Group O — AI Change Management
#### 21.1 AI Change Governance
AIGO provides a dedicated change-management process for material AI changes.
Changes may include:
- model changes;
- data changes;
- architecture changes;
- deployment changes;
- significant configuration changes;
- changes in intended purpose;
- changes in operating environment; and
- changes in third-party dependencies.
**Supporting Procedure:**
`guidance/02-procedures/07-AIGO-AI-Change-Management-Procedure-v0.1.md`
**Relationship:** Complementary
**Status:** Covered
---
### 22. ISO/IEC 42001 Control Group P — AI Approval
#### 22.1 AI Approval Governance
AIGO establishes controlled approval before significant AI systems or changes are placed into operation.
Approval should consider:
- classification;
- risk;
- controls;
- testing;
- validation;
- human oversight;
- monitoring;
- residual risk; and
- accountable authority.
**Supporting Procedure:**
`guidance/02-procedures/06-AIGO-AI-Approval-Procedure-v0.1.md`
**Relationship:** Supporting
**Status:** Covered
---
### 23. ISO/IEC 42001 Control Group Q — AI Risk Acceptance
#### 23.1 Residual Risk Acceptance
AIGO provides a dedicated process for accepting residual AI risks.
Risk acceptance should be:
- authorized;
- documented;
- time-bounded where appropriate;
- risk-informed;
- traceable; and
- subject to review.
**Primary AIGO Reference:**
`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`
**Supporting Procedure:**
`guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md`
**Relationship:** Complementary
**Status:** Covered
---
### 24. ISO/IEC 42001 Control Group R — AI Assurance
#### 24.1 AI Assurance
AIGO establishes assurance as a governance capability for evaluating whether AI governance arrangements are appropriate and effective.
Assurance may cover:
- governance;
- risks;
- controls;
- lifecycle;
- monitoring;
- incidents;
- system performance; and
- continual improvement.
**Primary AIGO Reference:**
`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
**Supporting Procedure:**
`guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`
**Relationship:** Complementary
**Status:** Covered
---
### 25. ISO/IEC 42001 Control Group S — AI Retirement
#### 25.1 AI System Retirement
AIGO provides governance for controlled AI system retirement.
Retirement should consider:
- system shutdown;
- data;
- access;
- dependencies;
- records;
- residual risks;
- contractual requirements;
- security;
- stakeholder communication; and
- closure verification.
**Primary AIGO Reference:**
`framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`
**Supporting Procedure:**
`guidance/02-procedures/12-AIGO-AI-Retirement-Procedure-v0.1.md`
**Relationship:** Complementary
**Status:** Covered
---
### 26. ISO/IEC 42001 Control Group T — Continual Improvement
#### 26.1 Continual Improvement
AIGO establishes continual improvement as a permanent governance activity.
Improvement inputs may include:
- incidents;
- monitoring;
- control assessments;
- assurance;
- audits;
- risk assessments;
- regulatory developments;
- stakeholder feedback;
- technological developments; and
- maturity assessments.
**Primary AIGO Reference:**
`framework/08-maturity/AIGO-AI-Governance-Maturity-v0.1.md`
**Supporting Guidance:**
`guidance/01-implementation/08-AIGO-Continuous-Improvement-v0.1.md`
**Supporting Procedure:**
`guidance/02-procedures/13-AIGO-Continuous-Improvement-Procedure-v0.1.md`
**Relationship:** Direct
**Status:** Covered
---
### 27. Control Ownership Model
Every material AIGO control should have an accountable owner.
Control ownership should identify:
- control owner;
- accountable role;
- implementation responsibility;
- evidence responsibility;
- monitoring responsibility;
- review responsibility; and
- escalation authority.
**Primary AIGO Reference:**
`framework/04-roles/AIGO-Governance-Roles-v0.1.md`
---
### 28. Control-to-Risk Relationship
AIGO controls should be linked to AI risks.
The control relationship should follow:
```text
AI Risk
↓
Risk Treatment
↓
AIGO Control
↓
Control Implementation
↓
Control Evidence
↓
Control Monitoring
↓
Residual Risk
This relationship provides traceability between risk decisions and control implementation.
---
### 29. Control-to-Lifecycle Relationship
Controls should be associated with relevant AI governance lifecycle stages.
The lifecycle relationship should follow:
```text
Lifecycle Stage
↓
Applicable Risk
↓
Applicable Control
↓
Control Implementation
↓
Evidence
↓
Monitoring
This ensures that controls remain relevant as an AI system progresses through its lifecycle.
---
### 30. Control Assessment Model
AIGO controls should be assessed according to their implementation and effectiveness.
Control assessment should consider:
1. Whether the control is defined.
2. Whether ownership is assigned.
3. Whether the control is implemented.
4. Whether evidence exists.
5. Whether the control operates as intended.
6. Whether the control remains appropriate.
7. Whether the control reduces the intended risk.
8. Whether corrective action is required.
**Supporting Procedure:**
`guidance/02-procedures/05-AIGO-AI-Control-Assessment-Procedure-v0.1.md`
---
### 31. Control Status Model
The following status values should be used when evaluating AIGO controls.
| Status | Meaning |
|---|---|
| Not Assessed | Control has not yet been evaluated |
| Planned | Control implementation is planned |
| Defined | Control has been formally defined |
| Implemented | Control has been implemented |
| Operating | Control is operating |
| Effective | Control effectiveness has been demonstrated |
| Partially Effective | Control operates but has identified weaknesses |
| Ineffective | Control does not adequately address the intended risk |
| Retired | Control is no longer applicable or has been withdrawn |
---
### 32. Control Evidence Model
Control evidence should be sufficient to demonstrate implementation and operation.
Evidence may include:
- policies;
- procedures;
- approvals;
- assessments;
- system records;
- logs;
- reports;
- monitoring results;
- review records;
- assurance reports;
- incident records;
- corrective-action records; and
- management decisions.
---
### 33. Control Monitoring
Control monitoring should evaluate whether controls remain appropriate and effective.
Monitoring may include:
- control performance indicators;
- risk indicators;
- exceptions;
- incidents;
- control failures;
- overdue actions;
- assessment findings;
- assurance findings; and
- changes in the operating environment.
**Supporting Procedure:**
`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`
---
### 34. Control Assurance
Control assurance should provide an independent or appropriately objective assessment of control design and effectiveness.
Assurance activities may include:
- control reviews;
- evidence reviews;
- testing;
- sampling;
- internal assessments;
- independent assessments;
- audit activities; and
- management review.
**Supporting Procedure:**
`guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`
---
### 35. Control Exceptions
Control exceptions should be formally recorded when:
- a control cannot be implemented;
- a control is temporarily unavailable;
- evidence is incomplete;
- a control fails;
- a control is bypassed;
- a control becomes ineffective; or
- an approved deviation exists.
Each material exception should identify:
- exception description;
- affected control;
- affected AI system;
- associated risk;
- justification;
- compensating controls;
- owner;
- approval;
- expiry or review date; and
- remediation.
---
### 36. Control Improvement
Control improvement should be triggered when:
- risks change;
- incidents occur;
- controls fail;
- assurance identifies weaknesses;
- monitoring identifies deterioration;
- regulations change;
- technology changes; or
- governance objectives change.
Improvement actions should be incorporated into the AIGO continuous-improvement process.
---
### 37. Master Control Mapping Matrix
| Control Area | Primary AIGO Component | Relationship | Status |
|---|---|---|---|
| AI Policy | Charter and Principles | Direct | Covered |
| Governance Structure | Governance Domains | Direct | Covered |
| Roles and Responsibilities | Governance Roles | Direct | Covered |
| Resources | Risk, Controls and Profiles | Supporting | Organizational Implementation |
| Competence | Roles and Maturity | Supporting | Organizational Implementation |
| AI Impact Assessment | Risk Management | Direct | Covered |
| Lifecycle Governance | AI Governance Lifecycle | Direct | Covered |
| Data Governance | Risk and Controls | Supporting | Covered |
| AI System Information | System Profiles | Complementary | Covered |
| Human Oversight | Roles, Risk and Controls | Direct | Covered |
| AI System Monitoring | Controls and Monitoring | Direct | Covered |
| Documentation | Lifecycle, Risk, Controls and Profiles | Direct | Covered |
| Third-Party Governance | Risk and Controls | Supporting | Covered |
| Incident Management | Procedures and Controls | Direct | Covered |
| Change Management | Lifecycle and Procedures | Complementary | Covered |
| Approval | Roles, Lifecycle and Procedures | Supporting | Covered |
| Risk Acceptance | Risk Management and Procedures | Complementary | Covered |
| Assurance | Controls and Assurance Procedure | Complementary | Covered |
| Retirement | Lifecycle and Retirement Procedure | Complementary | Covered |
| Continual Improvement | Maturity and Improvement | Direct | Covered |
---
### 38. Control Traceability Requirements
For each material control, the AIGO repository should be capable of tracing:
1. External control reference.
2. AIGO control identifier.
3. Control objective.
4. Control owner.
5. Applicable AI risks.
6. Applicable lifecycle stages.
7. Implementation procedure.
8. Required evidence.
9. Monitoring requirements.
10. Assurance requirements.
11. Control status.
12. Improvement actions.
---
### 39. Organizational Implementation Boundary
AIGO provides the control architecture and governance requirements.
Organizations remain responsible for determining:
- applicable controls;
- control ownership;
- implementation methods;
- technical implementation;
- operational procedures;
- evidence;
- monitoring;
- assurance; and
- corrective actions.
The applicability and implementation of controls should be determined according to organizational context, AI system characteristics, risk, and applicable requirements.
---
### 40. Mapping Limitations
This control mapping:
- does not reproduce ISO/IEC 42001 control text;
- does not replace ISO/IEC 42001;
- does not constitute certification;
- does not constitute legal advice;
- does not guarantee conformity;
- does not replace organizational control implementation; and
- should be reviewed when AIGO or ISO/IEC 42001 requirements change.
---
### 41. Control Mapping Governance
This document should be maintained as a controlled AIGO mapping artifact.
Changes should be reviewed when:
- AIGO controls change;
- AIGO risks change;
- lifecycle requirements change;
- operational procedures change;
- assurance findings identify control gaps;
- ISO/IEC 42001 changes;
- applicable regulations change; or
- significant technology changes occur.
---
### 42. Related AIGO Documents
The following AIGO documents are directly related to this control mapping:
- `framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`
- `framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
- `framework/04-roles/AIGO-Governance-Roles-v0.1.md`
- `framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`
- `framework/09-profiles/AIGO-AI-System-Profiles-v0.1.md`
Supporting implementation documents include:
- `guidance/01-implementation/05-AIGO-Control-Implementation-v0.1.md`
- `guidance/01-implementation/06-AIGO-Lifecycle-Implementation-v0.1.md`
- `guidance/01-implementation/07-AIGO-Monitoring-Assurance-Implementation-v0.1.md`
- `guidance/01-implementation/08-AIGO-Continuous-Improvement-v0.1.md`
Supporting procedures include:
- `guidance/02-procedures/05-AIGO-AI-Control-Assessment-Procedure-v0.1.md`
- `guidance/02-procedures/07-AIGO-AI-Change-Management-Procedure-v0.1.md`
- `guidance/02-procedures/08-AIGO-AI-Incident-Management-Procedure-v0.1.md`
- `guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`
- `guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`
- `guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md`
- `guidance/02-procedures/12-AIGO-AI-Retirement-Procedure-v0.1.md`
- `guidance/02-procedures/13-AIGO-Continuous-Improvement-Procedure-v0.1.md`
---
### 43. Document Control
| Field | Value |
|---|---|
| Document | AIGO — ISO/IEC 42001 Control Mapping |
| Version | 0.1 |
| Status | Draft |
| Working Name | AIGO |
| Full Name | AI Governance Operating Framework |
| Document Identifier | AIGO-MAP-ISO42001-003 |
| Mapping Standard | ISO/IEC 42001 |
| Mapping Type | Control Mapping |
| Owner | |
| Approved By | |
| Approval Date | |
| Next Review Date | |
---
### 44. Document Status
**Document:** AIGO — ISO/IEC 42001 Control Mapping
**Version:** 0.1
**Status:** Draft
**Working Name:** AIGO
**Full Name:** AI Governance Operating Framework
**Document Identifier:** `AIGO-MAP-ISO42001-003`
**Document Type:** Control Mapping
This document establishes the control-level relationship between ISO/IEC 42001 and the AIGO AI Governance Operating Framework and provides the foundation for detailed control implementation, assessment, monitoring, evidence, assurance, and continual improvement.
---
