> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 03 AIGO ISO 42001 Control Mapping v0.1

# AIGO — ISO/IEC 42001 Control Mapping

## AIGO — AI Governance Operating Framework

**Version:** 0.1\
**Status:** Draft\
**Working Name:** AIGO\
**Full Name:** AI Governance Operating Framework\
**Document Identifier:** AIGO-MAP-ISO42001-003\
**Mapping Standard:** ISO/IEC 42001\
**Mapping Type:** Control Mapping

***

### 1. Purpose

This document defines the control-level mapping between ISO/IEC 42001 and the AIGO AI Governance Operating Framework.

The purpose of this mapping is to establish traceability between the AI management controls identified by ISO/IEC 42001 and the AIGO governance control architecture.

The mapping provides a basis for:

* control implementation;
* control ownership;
* control assessment;
* risk treatment;
* assurance;
* evidence collection;
* gap analysis; and
* continual improvement.

***

### 2. Scope

This document focuses on the relationship between ISO/IEC 42001 AI management controls and AIGO governance controls.

The mapping covers the major control areas associated with:

* policies related to AI;
* internal organization;
* resources for AI systems;
* impact assessment;
* AI system lifecycle;
* data;
* information for interested parties;
* use of AI systems;
* third-party relationships;
* monitoring;
* documentation;
* human oversight;
* technical and organizational measures;
* responsible AI governance; and
* continual improvement.

This document does not reproduce the text of ISO/IEC 42001 controls.

***

### 3. Control Mapping Principles

#### 3.1 Control Traceability

Each mapped ISO/IEC 42001 control should identify the corresponding AIGO control or control family.

#### 3.2 Control Ownership

Each AIGO control should have an identifiable control owner or accountable governance role.

#### 3.3 Risk Alignment

Controls should be connected to identified AI risks and risk-treatment decisions.

#### 3.4 Lifecycle Alignment

Controls should be applicable to the relevant stages of the AI governance lifecycle.

#### 3.5 Evidence Alignment

Controls should generate or reference evidence demonstrating implementation and operation.

#### 3.6 Assurance Alignment

Controls should be capable of assessment through monitoring, control assessment, assurance, audit, or other appropriate evaluation mechanisms.

***

### 4. Control Relationship Types

The following relationship types are used in this mapping.

#### 4.1 Direct

The AIGO control directly addresses the intent of the corresponding ISO/IEC 42001 control.

#### 4.2 Supporting

The AIGO control provides supporting governance capability.

#### 4.3 Partial

The AIGO control addresses only part of the external control requirement.

#### 4.4 Complementary

The AIGO control provides additional governance capability beyond the external control.

#### 4.5 Organizational Implementation

AIGO provides a control framework, but the organization must implement and operate the control.

#### 4.6 Gap

A corresponding AIGO control does not yet provide sufficient coverage.

***

### 5. AIGO Control Architecture

The AIGO control architecture is maintained in:

`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`

The control architecture should provide:

* control identifier;
* control name;
* control objective;
* control description;
* applicability;
* control owner;
* implementation guidance;
* evidence;
* monitoring;
* assessment;
* risk relationship; and
* lifecycle relationship.

***

### 6. Control Mapping Structure

Each mapping should establish the following relationship:

````text theme={null}
ISO/IEC 42001 Control
        ↓
AIGO Control
        ↓
Control Objective
        ↓
Risk Relationship
        ↓
Lifecycle Relationship
        ↓
Control Owner
        ↓
Implementation Procedure
        ↓
Evidence
        ↓
Monitoring
        ↓
Assurance

--- 

### 7. ISO/IEC 42001 Control Group A — Policies Related to AI

#### 7.1 AI Policy and Governance

ISO/IEC 42001 controls relating to AI policy are mapped primarily to the AIGO Charter, Principles, Governance Domains, and Governance Controls.

**Primary AIGO References:**

- `framework/01-charter/`
- `framework/02-principles/`
- `framework/03-domains/`
- `framework/07-controls/`

**Relationship:** Direct

**Status:** Covered

---

#### 7.2 AI Governance Objectives

AI governance objectives are supported through AIGO principles, governance objectives, controls, and maturity objectives.

**Primary AIGO References:**

- `framework/02-principles/`
- `framework/07-controls/`
- `framework/08-maturity/`

**Relationship:** Direct

**Status:** Covered

---

### 8. ISO/IEC 42001 Control Group B — Internal Organization

#### 8.1 Governance Structure

AIGO defines governance structures through governance domains and governance roles.

**Primary AIGO References:**

- `framework/03-domains/`
- `framework/04-roles/`

**Relationship:** Direct

**Status:** Covered

---

#### 8.2 Roles and Responsibilities

AIGO establishes accountability and responsibility for AI governance.

Roles may include responsibility for:

- AI systems;
- risks;
- controls;
- approvals;
- monitoring;
- incidents;
- assurance; and
- retirement.

**Primary AIGO Reference:**

`framework/04-roles/AIGO-Governance-Roles-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

#### 8.3 Segregation of Responsibilities

AIGO governance roles should support appropriate separation between:

- system development;
- system operation;
- risk ownership;
- control ownership;
- approval;
- assurance; and
- independent review.

**Primary AIGO References:**

- `framework/04-roles/`
- `framework/07-controls/`

**Relationship:** Supporting

**Status:** Covered

---

### 9. ISO/IEC 42001 Control Group C — Resources for AI Systems

#### 9.1 AI Resources

AIGO recognizes the need to govern resources supporting AI systems.

Resources may include:

- people;
- data;
- models;
- infrastructure;
- computing resources;
- software;
- external services;
- documentation; and
- operational capabilities.

**Primary AIGO References:**

- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Supporting

**Status:** Requires Organizational Implementation

---

#### 9.2 Competence and Capability

AIGO governance roles and maturity architecture provide a basis for establishing competence requirements.

**Primary AIGO References:**

- `framework/04-roles/`
- `framework/08-maturity/`

**Relationship:** Supporting

**Status:** Requires Organizational Implementation

---

### 10. ISO/IEC 42001 Control Group D — Assessing AI Impacts

#### 10.1 AI Impact Assessment

AIGO risk management provides the principal governance mechanism for identifying and evaluating potential impacts associated with AI systems.

Impact considerations may include:

- individuals;
- groups;
- organizations;
- society;
- safety;
- security;
- privacy;
- fairness;
- human rights;
- operational consequences; and
- other material impacts.

**Primary AIGO References:**

- `framework/06-risk/`
- `framework/09-profiles/`

**Relationship:** Direct

**Status:** Covered

---

#### 10.2 Impact Assessment Integration

Impact assessment should be integrated with:

- AI system classification;
- risk assessment;
- lifecycle decisions;
- control selection;
- approval;
- monitoring; and
- change management.

**Supporting Procedures:**

- `guidance/02-procedures/03-AIGO-AI-Risk-Assessment-Procedure-v0.1.md`
- `guidance/02-procedures/04-AIGO-AI-Classification-Procedure-v0.1.md`
- `guidance/02-procedures/06-AIGO-AI-Approval-Procedure-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 11. ISO/IEC 42001 Control Group E — AI System Lifecycle

#### 11.1 Lifecycle Governance

AIGO provides lifecycle governance from planning through retirement.

**Primary AIGO Reference:**

`framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

#### 11.2 Lifecycle Risk Management

AI risks should be assessed and managed throughout the AI lifecycle.

Lifecycle risk activities include:

- initial risk identification;
- design-stage assessment;
- development-stage assessment;
- testing and validation;
- deployment approval;
- operational monitoring;
- change assessment;
- incident response; and
- retirement assessment.

**Primary AIGO References:**

- `framework/05-lifecycle/`
- `framework/06-risk/`

**Relationship:** Direct

**Status:** Covered

---

#### 11.3 Lifecycle Control Application

AIGO controls should be assigned according to the lifecycle stage and risk profile of the AI system.

**Primary AIGO References:**

- `framework/05-lifecycle/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Direct

**Status:** Covered

---

### 12. ISO/IEC 42001 Control Group F — Data for AI Systems

#### 12.1 Data Governance

AIGO recognizes data as a governed AI resource and risk factor.

Data governance should address:

- data sources;
- data ownership;
- data quality;
- data suitability;
- data provenance;
- data access;
- data protection;
- data use;
- data retention; and
- data-related risks.

**Primary AIGO References:**

- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Supporting

**Status:** Covered

---

#### 12.2 Data Risk

Data-related risks should be identified and assessed within the AIGO AI risk-management process.

Potential risks include:

- inaccurate data;
- incomplete data;
- biased data;
- inappropriate data use;
- unauthorized access;
- data leakage;
- provenance uncertainty; and
- inappropriate retention.

**Primary AIGO Reference:**

`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

#### 12.3 Data Controls

Appropriate data controls should be selected based on:

- system classification;
- risk;
- intended purpose;
- applicable requirements;
- lifecycle stage; and
- organizational context.

**Primary AIGO Reference:**

`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 13. ISO/IEC 42001 Control Group G — Information for Interested Parties

#### 13.1 AI System Information

AIGO AI System Profiles provide structured information that can support governance and communication regarding AI systems.

**Primary AIGO Reference:**

`framework/09-profiles/AIGO-AI-System-Profiles-v0.1.md`

**Relationship:** Complementary

**Status:** Covered

---

#### 13.2 Transparency and Communication

AIGO principles and controls support appropriate transparency and communication concerning AI systems.

Relevant considerations may include:

- intended purpose;
- system ownership;
- significant risks;
- limitations;
- human oversight;
- monitoring;
- incidents; and
- material changes.

**Primary AIGO References:**

- `framework/02-principles/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Supporting

**Status:** Covered

---

### 14. ISO/IEC 42001 Control Group H — Use of AI Systems

#### 14.1 Authorized AI Use

AIGO governance requires AI systems to operate within their approved scope and intended purpose.

**Primary AIGO References:**

- `framework/05-lifecycle/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Direct

**Status:** Covered

---

#### 14.2 Human Oversight

AIGO governance controls should establish appropriate human oversight based on:

- AI system risk;
- system classification;
- decision impact;
- level of autonomy;
- operating environment; and
- potential consequences.

**Primary AIGO References:**

- `framework/04-roles/`
- `framework/06-risk/`
- `framework/07-controls/`

**Relationship:** Direct

**Status:** Covered

---

#### 14.3 AI System Monitoring

AI systems should be monitored throughout operation.

Monitoring should consider:

- performance;
- risk indicators;
- control effectiveness;
- incidents;
- anomalies;
- material changes; and
- emerging risks.

**Primary AIGO References:**

- `framework/07-controls/`
- `framework/08-maturity/`

**Supporting Procedure:**

`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 15. ISO/IEC 42001 Control Group I — Third-Party and Supplier Relationships

#### 15.1 Third-Party AI Services

AIGO governance should extend to material third-party AI systems and services.

Third-party considerations may include:

- supplier identity;
- service scope;
- AI system dependencies;
- contractual requirements;
- risk;
- data handling;
- security;
- performance;
- monitoring;
- incident management; and
- termination.

**Primary AIGO References:**

- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Supporting

**Status:** Covered

---

#### 15.2 Third-Party Risk

Third-party AI risks should be incorporated into the AIGO risk-management process.

**Primary AIGO Reference:**

`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 16. ISO/IEC 42001 Control Group J — Monitoring and Measurement

#### 16.1 AI Governance Monitoring

AIGO establishes monitoring as a core governance capability.

Monitoring may address:

- AI system performance;
- governance performance;
- risk indicators;
- control effectiveness;
- incidents;
- compliance indicators;
- assurance findings; and
- maturity indicators.

**Primary AIGO References:**

- `framework/07-controls/`
- `framework/08-maturity/`

**Supporting Procedure:**

`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

#### 16.2 Control Effectiveness Monitoring

Controls should be monitored to determine whether they remain:

- implemented;
- operating;
- effective;
- appropriate;
- proportionate; and
- aligned with current risk.

**Primary AIGO Reference:**

`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 17. ISO/IEC 42001 Control Group K — Documentation and Records

#### 17.1 Governance Documentation

AIGO requires governance information to be maintained throughout the AI lifecycle.

Relevant documentation may include:

- governance decisions;
- AI system profiles;
- risk assessments;
- classification decisions;
- control assessments;
- approvals;
- changes;
- incidents;
- monitoring results;
- assurance results; and
- retirement records.

**Primary AIGO References:**

- `framework/05-lifecycle/`
- `framework/06-risk/`
- `framework/07-controls/`
- `framework/09-profiles/`

**Relationship:** Direct

**Status:** Covered

---

#### 17.2 Records and Evidence

AIGO evidence requirements should demonstrate both the implementation and operation of controls.

Evidence may include:

- approved records;
- assessments;
- reports;
- logs;
- monitoring results;
- review records;
- decision records;
- audit results; and
- corrective-action records.

**Relationship:** Direct

**Status:** Covered

---

### 18. ISO/IEC 42001 Control Group L — Human Oversight

#### 18.1 Human Oversight Governance

AIGO recognizes human oversight as a governance mechanism for managing AI system autonomy and decision impact.

**Primary AIGO References:**

- `framework/04-roles/`
- `framework/06-risk/`
- `framework/07-controls/`

**Relationship:** Direct

**Status:** Covered

---

#### 18.2 Human Intervention

Human intervention requirements should be determined based on:

- system risk;
- decision impact;
- autonomy;
- operating conditions;
- foreseeable misuse;
- failure modes; and
- organizational requirements.

**Primary AIGO References:**

- `framework/06-risk/`
- `framework/07-controls/`

**Relationship:** Direct

**Status:** Covered

---

### 19. ISO/IEC 42001 Control Group M — Technical and Organizational Measures

#### 19.1 Technical Measures

AIGO governance controls may require technical measures appropriate to identified risks.

Potential areas include:

- access control;
- security;
- monitoring;
- logging;
- validation;
- testing;
- robustness;
- resilience;
- data protection; and
- system controls.

**Primary AIGO Reference:**

`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`

**Relationship:** Supporting

**Status:** Covered

---

#### 19.2 Organizational Measures

Organizational measures may include:

- policies;
- procedures;
- governance roles;
- approvals;
- training;
- oversight;
- monitoring;
- assurance; and
- corrective action.

**Primary AIGO References:**

- `framework/03-domains/`
- `framework/04-roles/`
- `framework/07-controls/`

**Relationship:** Direct

**Status:** Covered

---

### 20. ISO/IEC 42001 Control Group N — AI Incidents

#### 20.1 AI Incident Management

AIGO establishes a dedicated AI incident-management process.

Incident management should address:

- detection;
- classification;
- escalation;
- containment;
- investigation;
- response;
- corrective action;
- communication;
- lessons learned; and
- closure.

**Supporting Procedure:**

`guidance/02-procedures/08-AIGO-AI-Incident-Management-Procedure-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 21. ISO/IEC 42001 Control Group O — AI Change Management

#### 21.1 AI Change Governance

AIGO provides a dedicated change-management process for material AI changes.

Changes may include:

- model changes;
- data changes;
- architecture changes;
- deployment changes;
- significant configuration changes;
- changes in intended purpose;
- changes in operating environment; and
- changes in third-party dependencies.

**Supporting Procedure:**

`guidance/02-procedures/07-AIGO-AI-Change-Management-Procedure-v0.1.md`

**Relationship:** Complementary

**Status:** Covered

---

### 22. ISO/IEC 42001 Control Group P — AI Approval

#### 22.1 AI Approval Governance

AIGO establishes controlled approval before significant AI systems or changes are placed into operation.

Approval should consider:

- classification;
- risk;
- controls;
- testing;
- validation;
- human oversight;
- monitoring;
- residual risk; and
- accountable authority.

**Supporting Procedure:**

`guidance/02-procedures/06-AIGO-AI-Approval-Procedure-v0.1.md`

**Relationship:** Supporting

**Status:** Covered

---

### 23. ISO/IEC 42001 Control Group Q — AI Risk Acceptance

#### 23.1 Residual Risk Acceptance

AIGO provides a dedicated process for accepting residual AI risks.

Risk acceptance should be:

- authorized;
- documented;
- time-bounded where appropriate;
- risk-informed;
- traceable; and
- subject to review.

**Primary AIGO Reference:**

`framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`

**Supporting Procedure:**

`guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md`

**Relationship:** Complementary

**Status:** Covered

---

### 24. ISO/IEC 42001 Control Group R — AI Assurance

#### 24.1 AI Assurance

AIGO establishes assurance as a governance capability for evaluating whether AI governance arrangements are appropriate and effective.

Assurance may cover:

- governance;
- risks;
- controls;
- lifecycle;
- monitoring;
- incidents;
- system performance; and
- continual improvement.

**Primary AIGO Reference:**

`framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`

**Supporting Procedure:**

`guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`

**Relationship:** Complementary

**Status:** Covered

---

### 25. ISO/IEC 42001 Control Group S — AI Retirement

#### 25.1 AI System Retirement

AIGO provides governance for controlled AI system retirement.

Retirement should consider:

- system shutdown;
- data;
- access;
- dependencies;
- records;
- residual risks;
- contractual requirements;
- security;
- stakeholder communication; and
- closure verification.

**Primary AIGO Reference:**

`framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`

**Supporting Procedure:**

`guidance/02-procedures/12-AIGO-AI-Retirement-Procedure-v0.1.md`

**Relationship:** Complementary

**Status:** Covered

---

### 26. ISO/IEC 42001 Control Group T — Continual Improvement

#### 26.1 Continual Improvement

AIGO establishes continual improvement as a permanent governance activity.

Improvement inputs may include:

- incidents;
- monitoring;
- control assessments;
- assurance;
- audits;
- risk assessments;
- regulatory developments;
- stakeholder feedback;
- technological developments; and
- maturity assessments.

**Primary AIGO Reference:**

`framework/08-maturity/AIGO-AI-Governance-Maturity-v0.1.md`

**Supporting Guidance:**

`guidance/01-implementation/08-AIGO-Continuous-Improvement-v0.1.md`

**Supporting Procedure:**

`guidance/02-procedures/13-AIGO-Continuous-Improvement-Procedure-v0.1.md`

**Relationship:** Direct

**Status:** Covered

---

### 27. Control Ownership Model

Every material AIGO control should have an accountable owner.

Control ownership should identify:

- control owner;
- accountable role;
- implementation responsibility;
- evidence responsibility;
- monitoring responsibility;
- review responsibility; and
- escalation authority.

**Primary AIGO Reference:**

`framework/04-roles/AIGO-Governance-Roles-v0.1.md`

---

### 28. Control-to-Risk Relationship

AIGO controls should be linked to AI risks.

The control relationship should follow:

```text
AI Risk
    ↓
Risk Treatment
    ↓
AIGO Control
    ↓
Control Implementation
    ↓
Control Evidence
    ↓
Control Monitoring
    ↓
Residual Risk

This relationship provides traceability between risk decisions and control implementation.

---

### 29. Control-to-Lifecycle Relationship

Controls should be associated with relevant AI governance lifecycle stages.

The lifecycle relationship should follow:

```text
Lifecycle Stage
    ↓
Applicable Risk
    ↓
Applicable Control
    ↓
Control Implementation
    ↓
Evidence
    ↓
Monitoring

This ensures that controls remain relevant as an AI system progresses through its lifecycle.

---

### 30. Control Assessment Model

AIGO controls should be assessed according to their implementation and effectiveness.

Control assessment should consider:

1. Whether the control is defined.
2. Whether ownership is assigned.
3. Whether the control is implemented.
4. Whether evidence exists.
5. Whether the control operates as intended.
6. Whether the control remains appropriate.
7. Whether the control reduces the intended risk.
8. Whether corrective action is required.

**Supporting Procedure:**

`guidance/02-procedures/05-AIGO-AI-Control-Assessment-Procedure-v0.1.md`

---

### 31. Control Status Model

The following status values should be used when evaluating AIGO controls.

| Status | Meaning |
|---|---|
| Not Assessed | Control has not yet been evaluated |
| Planned | Control implementation is planned |
| Defined | Control has been formally defined |
| Implemented | Control has been implemented |
| Operating | Control is operating |
| Effective | Control effectiveness has been demonstrated |
| Partially Effective | Control operates but has identified weaknesses |
| Ineffective | Control does not adequately address the intended risk |
| Retired | Control is no longer applicable or has been withdrawn |

---

### 32. Control Evidence Model

Control evidence should be sufficient to demonstrate implementation and operation.

Evidence may include:

- policies;
- procedures;
- approvals;
- assessments;
- system records;
- logs;
- reports;
- monitoring results;
- review records;
- assurance reports;
- incident records;
- corrective-action records; and
- management decisions.

---

### 33. Control Monitoring

Control monitoring should evaluate whether controls remain appropriate and effective.

Monitoring may include:

- control performance indicators;
- risk indicators;
- exceptions;
- incidents;
- control failures;
- overdue actions;
- assessment findings;
- assurance findings; and
- changes in the operating environment.

**Supporting Procedure:**

`guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`

---

### 34. Control Assurance

Control assurance should provide an independent or appropriately objective assessment of control design and effectiveness.

Assurance activities may include:

- control reviews;
- evidence reviews;
- testing;
- sampling;
- internal assessments;
- independent assessments;
- audit activities; and
- management review.

**Supporting Procedure:**

`guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`

---

### 35. Control Exceptions

Control exceptions should be formally recorded when:

- a control cannot be implemented;
- a control is temporarily unavailable;
- evidence is incomplete;
- a control fails;
- a control is bypassed;
- a control becomes ineffective; or
- an approved deviation exists.

Each material exception should identify:

- exception description;
- affected control;
- affected AI system;
- associated risk;
- justification;
- compensating controls;
- owner;
- approval;
- expiry or review date; and
- remediation.

---

### 36. Control Improvement

Control improvement should be triggered when:

- risks change;
- incidents occur;
- controls fail;
- assurance identifies weaknesses;
- monitoring identifies deterioration;
- regulations change;
- technology changes; or
- governance objectives change.

Improvement actions should be incorporated into the AIGO continuous-improvement process.

---

### 37. Master Control Mapping Matrix

| Control Area | Primary AIGO Component | Relationship | Status |
|---|---|---|---|
| AI Policy | Charter and Principles | Direct | Covered |
| Governance Structure | Governance Domains | Direct | Covered |
| Roles and Responsibilities | Governance Roles | Direct | Covered |
| Resources | Risk, Controls and Profiles | Supporting | Organizational Implementation |
| Competence | Roles and Maturity | Supporting | Organizational Implementation |
| AI Impact Assessment | Risk Management | Direct | Covered |
| Lifecycle Governance | AI Governance Lifecycle | Direct | Covered |
| Data Governance | Risk and Controls | Supporting | Covered |
| AI System Information | System Profiles | Complementary | Covered |
| Human Oversight | Roles, Risk and Controls | Direct | Covered |
| AI System Monitoring | Controls and Monitoring | Direct | Covered |
| Documentation | Lifecycle, Risk, Controls and Profiles | Direct | Covered |
| Third-Party Governance | Risk and Controls | Supporting | Covered |
| Incident Management | Procedures and Controls | Direct | Covered |
| Change Management | Lifecycle and Procedures | Complementary | Covered |
| Approval | Roles, Lifecycle and Procedures | Supporting | Covered |
| Risk Acceptance | Risk Management and Procedures | Complementary | Covered |
| Assurance | Controls and Assurance Procedure | Complementary | Covered |
| Retirement | Lifecycle and Retirement Procedure | Complementary | Covered |
| Continual Improvement | Maturity and Improvement | Direct | Covered |

---

### 38. Control Traceability Requirements

For each material control, the AIGO repository should be capable of tracing:

1. External control reference.
2. AIGO control identifier.
3. Control objective.
4. Control owner.
5. Applicable AI risks.
6. Applicable lifecycle stages.
7. Implementation procedure.
8. Required evidence.
9. Monitoring requirements.
10. Assurance requirements.
11. Control status.
12. Improvement actions.

---

### 39. Organizational Implementation Boundary

AIGO provides the control architecture and governance requirements.

Organizations remain responsible for determining:

- applicable controls;
- control ownership;
- implementation methods;
- technical implementation;
- operational procedures;
- evidence;
- monitoring;
- assurance; and
- corrective actions.

The applicability and implementation of controls should be determined according to organizational context, AI system characteristics, risk, and applicable requirements.

---

### 40. Mapping Limitations

This control mapping:

- does not reproduce ISO/IEC 42001 control text;
- does not replace ISO/IEC 42001;
- does not constitute certification;
- does not constitute legal advice;
- does not guarantee conformity;
- does not replace organizational control implementation; and
- should be reviewed when AIGO or ISO/IEC 42001 requirements change.

---

### 41. Control Mapping Governance

This document should be maintained as a controlled AIGO mapping artifact.

Changes should be reviewed when:

- AIGO controls change;
- AIGO risks change;
- lifecycle requirements change;
- operational procedures change;
- assurance findings identify control gaps;
- ISO/IEC 42001 changes;
- applicable regulations change; or
- significant technology changes occur.

---

### 42. Related AIGO Documents

The following AIGO documents are directly related to this control mapping:

- `framework/06-risk/AIGO-AI-Risk-Management-v0.1.md`
- `framework/07-controls/AIGO-AI-Governance-Controls-v0.1.md`
- `framework/04-roles/AIGO-Governance-Roles-v0.1.md`
- `framework/05-lifecycle/AIGO-AI-Governance-Lifecycle-v0.1.md`
- `framework/09-profiles/AIGO-AI-System-Profiles-v0.1.md`

Supporting implementation documents include:

- `guidance/01-implementation/05-AIGO-Control-Implementation-v0.1.md`
- `guidance/01-implementation/06-AIGO-Lifecycle-Implementation-v0.1.md`
- `guidance/01-implementation/07-AIGO-Monitoring-Assurance-Implementation-v0.1.md`
- `guidance/01-implementation/08-AIGO-Continuous-Improvement-v0.1.md`

Supporting procedures include:

- `guidance/02-procedures/05-AIGO-AI-Control-Assessment-Procedure-v0.1.md`
- `guidance/02-procedures/07-AIGO-AI-Change-Management-Procedure-v0.1.md`
- `guidance/02-procedures/08-AIGO-AI-Incident-Management-Procedure-v0.1.md`
- `guidance/02-procedures/09-AIGO-AI-Monitoring-Procedure-v0.1.md`
- `guidance/02-procedures/10-AIGO-AI-Assurance-Procedure-v0.1.md`
- `guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md`
- `guidance/02-procedures/12-AIGO-AI-Retirement-Procedure-v0.1.md`
- `guidance/02-procedures/13-AIGO-Continuous-Improvement-Procedure-v0.1.md`

---

### 43. Document Control

| Field | Value |
|---|---|
| Document | AIGO — ISO/IEC 42001 Control Mapping |
| Version | 0.1 |
| Status | Draft |
| Working Name | AIGO |
| Full Name | AI Governance Operating Framework |
| Document Identifier | AIGO-MAP-ISO42001-003 |
| Mapping Standard | ISO/IEC 42001 |
| Mapping Type | Control Mapping |
| Owner | |
| Approved By | |
| Approval Date | |
| Next Review Date | |

---

### 44. Document Status

**Document:** AIGO — ISO/IEC 42001 Control Mapping

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-MAP-ISO42001-003`

**Document Type:** Control Mapping

This document establishes the control-level relationship between ISO/IEC 42001 and the AIGO AI Governance Operating Framework and provides the foundation for detailed control implementation, assessment, monitoring, evidence, assurance, and continual improvement.

---
````
