Skip to main content

AIGO — ISO/IEC 42001 Governance Mapping

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-ISO42001-006 Mapping Standard: ISO/IEC 42001 Mapping Type: Governance Mapping

1. Purpose

This document defines the relationship between the AIGO AI Governance Model and the ISO/IEC 42001 AI management system framework. The purpose of this mapping is to establish traceability between governance structures, accountability, responsibilities, decision rights, management-system processes, AI system oversight, risk management, controls, evidence, assurance, and continual improvement. The mapping provides a governance-oriented bridge between the AIGO framework architecture and the relevant ISO/IEC 42001 management-system requirements.

2. Scope

This document covers the governance relationship between:
  • organizational governance;
  • AI governance;
  • management accountability;
  • governance roles;
  • responsibilities;
  • authorities;
  • decision rights;
  • AI system ownership;
  • risk ownership;
  • control ownership;
  • governance committees;
  • management review;
  • resource allocation;
  • competence;
  • communication;
  • documentation;
  • assurance;
  • monitoring;
  • change management; and
  • continual improvement.
The mapping applies across the AIGO AI Governance Lifecycle and the organizational AI management system.

3. Governance Mapping Principle

AIGO treats AI governance as the mechanism through which the organization establishes direction, accountability, oversight, decision rights, controls, and continuous improvement for AI-related activities. The governance relationship can be represented as:
Governance should therefore remain connected to operational AI activities rather than exist solely as a policy layer.

4. AIGO Governance Model

4.1 Governance Purpose

AIGO governance establishes the organizational structures and decision mechanisms necessary to direct and control AI-related activities.

4.2 Governance Objectives

The governance model should:
  • establish accountability;
  • define decision rights;
  • establish governance requirements;
  • assign responsibilities;
  • provide oversight;
  • manage AI-related risk;
  • ensure appropriate controls;
  • support compliance;
  • maintain evidence;
  • support assurance; and
  • enable continual improvement.

4.3 Governance Architecture


5. Governance and the AI Management System

5.1 Management-System Relationship

The AIGO governance model provides the organizational structure through which the AI management system can be directed and maintained.

5.2 Governance Integration

Governance should establish:
  • organizational direction;
  • AI objectives;
  • governance requirements;
  • accountability;
  • decision-making authority;
  • risk appetite;
  • control expectations;
  • monitoring requirements; and
  • review mechanisms.

5.3 Integrated Relationship


6. Organizational Context

6.1 Purpose

AI governance should be established within the context of the organization’s objectives, obligations, stakeholders, and operating environment.

6.2 Context Factors

Relevant factors may include:
  • organizational strategy;
  • business objectives;
  • legal requirements;
  • regulatory requirements;
  • contractual obligations;
  • stakeholder expectations;
  • organizational structure;
  • AI portfolio;
  • technology environment;
  • risk environment;
  • resource constraints; and
  • organizational maturity.

6.3 Context Flow


7. Governance Principles

7.1 Purpose

Governance principles establish the fundamental expectations that guide AI-related decisions.

7.2 Core Principles

AIGO governance should promote:
  • accountability;
  • transparency;
  • proportionality;
  • traceability;
  • human oversight;
  • risk-based decision-making;
  • evidence-based governance;
  • continuous monitoring;
  • responsible innovation; and
  • continual improvement.

7.3 Principle Application

Governance principles should be translated into actionable requirements, controls, procedures, and decision criteria.

8. Governance Accountability

8.1 Purpose

Accountability establishes who is answerable for AI governance outcomes.

8.2 Accountability Requirements

The organization should identify accountable persons or bodies for:
  • AI governance;
  • AI management-system oversight;
  • AI system ownership;
  • risk management;
  • control implementation;
  • monitoring;
  • assurance;
  • compliance; and
  • improvement.

8.3 Accountability Model

8.4 Accountability Principle

Accountability should remain clear even where operational activities are delegated or outsourced.

9. Governance Roles

9.1 Purpose

Governance roles define responsibilities and decision rights for AI-related activities.

9.2 Typical Roles

Relevant roles may include:
  • executive sponsor;
  • AI governance owner;
  • AI system owner;
  • AI product owner;
  • risk owner;
  • control owner;
  • data owner;
  • security owner;
  • privacy owner;
  • compliance function;
  • legal function;
  • assurance function;
  • internal audit; and
  • operational users.

9.3 Role Definition

Each material role should have:
  • defined responsibilities;
  • defined authority;
  • required competence;
  • escalation responsibilities;
  • decision rights; and
  • accountability boundaries.

10. Governance Decision Rights

10.1 Purpose

Decision rights define who may make, approve, reject, escalate, or review AI governance decisions.

10.2 Decision Categories

Decision rights may cover:
  • AI system registration;
  • classification;
  • risk acceptance;
  • control approval;
  • deployment approval;
  • material change approval;
  • exception approval;
  • incident escalation;
  • suspension;
  • retirement; and
  • governance-policy changes.

10.3 Decision Flow


11. Governance Committees

11.1 Purpose

Organizations may establish governance committees or equivalent decision bodies where the scale or complexity of AI activities requires collective oversight.

11.2 Committee Responsibilities

A governance body may oversee:
  • AI portfolio;
  • high-risk AI systems;
  • risk acceptance;
  • major changes;
  • incidents;
  • assurance findings;
  • compliance issues;
  • strategic AI initiatives; and
  • continual improvement.

11.3 Committee Governance

Committee structures should define:
  • mandate;
  • membership;
  • authority;
  • quorum;
  • decision rights;
  • meeting frequency;
  • records; and
  • escalation mechanisms.

12. Governance Policies

12.1 Purpose

Governance policies establish organizational expectations for AI activities.

12.2 Policy Categories

Policies may address:
  • AI governance;
  • responsible AI;
  • AI risk;
  • data governance;
  • security;
  • privacy;
  • human oversight;
  • AI system development;
  • AI procurement;
  • third-party AI;
  • monitoring;
  • incident management; and
  • AI retirement.

12.3 Policy Hierarchy


13. Governance Objectives

13.1 Purpose

Governance objectives translate organizational direction into measurable AI governance outcomes.

13.2 Objective Characteristics

Objectives should be:
  • relevant;
  • measurable where appropriate;
  • assigned to accountable roles;
  • monitored;
  • documented; and
  • reviewed.

13.3 Objective Relationship


14. AI System Governance

14.1 Purpose

Every material AI system should operate within an appropriate governance structure.

14.2 Governance Requirements

An AI system should, where applicable, have:
  • identified owner;
  • documented purpose;
  • system profile;
  • classification;
  • risk assessment;
  • applicable controls;
  • approval status;
  • monitoring arrangements;
  • evidence;
  • change-management requirements; and
  • retirement criteria.

14.3 AI System Governance Flow


15. Governance and AI Lifecycle

15.1 Purpose

Governance should apply throughout the complete AI lifecycle.

15.2 Lifecycle Governance

15.3 Lifecycle Principle

Governance requirements should be appropriate to the lifecycle stage and the risk profile of the AI system.

16. Governance and Risk Management

16.1 Purpose

Governance establishes the authority and accountability required to manage AI risk.

16.2 Governance Responsibilities

Governance should establish:
  • risk methodology;
  • risk appetite;
  • risk criteria;
  • risk ownership;
  • acceptance authority;
  • escalation thresholds;
  • review requirements; and
  • reporting mechanisms.

16.3 Risk Governance Relationship


17. Governance and Controls

17.1 Purpose

Governance should establish expectations for the design, implementation, operation, and review of AI controls.

17.2 Control Governance

Controls should have:
  • defined purpose;
  • control owner;
  • implementation requirements;
  • evidence requirements;
  • effectiveness criteria;
  • review frequency; and
  • escalation requirements.

17.3 Control Governance Flow


18. Governance and Human Oversight

18.1 Purpose

Human oversight should be governed according to the AI system’s purpose, risk, autonomy, and potential impact.

18.2 Oversight Requirements

Governance should define:
  • who provides oversight;
  • when oversight is required;
  • what decisions require human intervention;
  • escalation requirements;
  • override authority;
  • competence requirements; and
  • evidence requirements.

18.3 Oversight Relationship


19. Governance and Competence

19.1 Purpose

AI governance requires personnel with sufficient competence to perform assigned responsibilities.

19.2 Competence Areas

Competence may include:
  • AI technology;
  • risk management;
  • governance;
  • compliance;
  • security;
  • privacy;
  • data;
  • assurance;
  • human oversight; and
  • domain-specific knowledge.

19.3 Competence Governance

The organization should determine competence requirements appropriate to each material AI governance role.

20. Governance and Awareness

20.1 Purpose

Personnel involved in AI activities should understand relevant governance expectations.

20.2 Awareness Topics

Awareness may cover:
  • AI governance principles;
  • responsibilities;
  • acceptable use;
  • risk;
  • security;
  • privacy;
  • incident reporting;
  • human oversight;
  • change management; and
  • escalation.

20.3 Awareness Flow


21. Governance Communication

21.1 Purpose

Governance information should be communicated to relevant internal and external stakeholders as appropriate.

21.2 Communication Topics

Communication may include:
  • governance decisions;
  • AI policies;
  • risk information;
  • incidents;
  • control requirements;
  • material changes;
  • assurance findings; and
  • management decisions.

21.3 Communication Principles

Governance communication should be:
  • timely;
  • accurate;
  • understandable;
  • appropriately authorized;
  • traceable; and
  • proportionate.

22. Governance Documentation

22.1 Purpose

Governance decisions and requirements should be supported by controlled documentation.

22.2 Governance Records

Records may include:
  • policies;
  • governance charters;
  • role definitions;
  • committee records;
  • decisions;
  • approvals;
  • risk acceptances;
  • exceptions;
  • management reviews;
  • assurance reports; and
  • corrective actions.

22.3 Documentation Flow


23. Governance and Evidence

23.1 Purpose

Governance decisions should be supported by sufficient evidence.

23.2 Evidence Categories

Evidence may include:
  • approval records;
  • meeting minutes;
  • risk assessments;
  • control assessments;
  • monitoring reports;
  • assurance reports;
  • training records;
  • incident records; and
  • management-review records.

23.3 Evidence Relationship


24. Governance Monitoring

24.1 Purpose

Governance monitoring determines whether governance requirements are being implemented and remain effective.

24.2 Monitoring Areas

Monitoring may evaluate:
  • policy compliance;
  • risk status;
  • control performance;
  • approval status;
  • incidents;
  • exceptions;
  • overdue actions;
  • assurance findings; and
  • governance objectives.

24.3 Monitoring Cycle


25. Governance Assurance

25.1 Purpose

Assurance provides confidence that governance arrangements are appropriately designed and operating as intended.

25.2 Assurance Areas

Assurance may examine:
  • governance structure;
  • role accountability;
  • decision rights;
  • risk governance;
  • control governance;
  • evidence;
  • monitoring;
  • compliance; and
  • continual improvement.

25.3 Assurance Relationship


26. Management Review

26.1 Purpose

Management review provides a formal mechanism for evaluating the continuing suitability, adequacy, and effectiveness of the AI governance and management-system arrangements.

26.2 Management Review Inputs

Inputs may include:
  • AI governance performance;
  • AI risk profile;
  • control effectiveness;
  • incidents;
  • assurance findings;
  • stakeholder feedback;
  • regulatory changes;
  • changes in organizational context;
  • governance objectives; and
  • continual-improvement opportunities.

26.3 Management Review Flow


27. Governance Decisions

27.1 Purpose

Governance decisions should be formally recorded when they materially affect AI governance, risk, compliance, or system operation.

27.2 Decision Records

A decision record should identify, as appropriate:
  • decision;
  • decision date;
  • decision authority;
  • subject;
  • rationale;
  • supporting evidence;
  • conditions;
  • actions;
  • owner; and
  • review requirements.

27.3 Decision Traceability


28. Governance Exceptions

28.1 Purpose

Exceptions allow controlled deviation from defined governance requirements where justified and authorized.

28.2 Exception Requirements

An exception should identify:
  • requirement;
  • reason;
  • scope;
  • affected AI system;
  • risk;
  • compensating controls;
  • owner;
  • approval authority;
  • expiration or review date; and
  • evidence.

28.3 Exception Flow

28.4 Exception Principle

Exceptions should not be used to circumvent mandatory legal or regulatory obligations.

29. Governance Escalation

29.1 Purpose

Escalation ensures that issues exceeding operational authority are brought to the appropriate governance level.

29.2 Escalation Triggers

Triggers may include:
  • material risk;
  • serious incident;
  • control failure;
  • regulatory concern;
  • unresolved assurance finding;
  • significant policy exception;
  • material system change; or
  • repeated governance failure.

29.3 Escalation Model


30. Governance and Change Management

30.1 Purpose

Governance should ensure that material changes to AI systems and governance arrangements are appropriately assessed and approved.

30.2 Change Categories

Changes may include:
  • AI system changes;
  • model changes;
  • data changes;
  • intended-use changes;
  • governance-policy changes;
  • control changes;
  • supplier changes;
  • regulatory changes; and
  • organizational changes.

30.3 Change Governance


31. Governance and Incident Management

31.1 Purpose

Governance should establish oversight for material AI incidents and ensure that lessons learned are incorporated into the governance system.

31.2 Incident Governance

Governance should define:
  • incident classification;
  • reporting;
  • escalation;
  • response authority;
  • communication;
  • investigation;
  • corrective action; and
  • management review.

31.3 Incident Relationship


32. Governance and Supplier Management

32.1 Purpose

Third-party AI services and suppliers should operate within appropriate governance arrangements.

32.2 Supplier Governance

Supplier governance may include:
  • due diligence;
  • contractual requirements;
  • risk assessment;
  • security requirements;
  • privacy requirements;
  • performance requirements;
  • incident notification;
  • change notification;
  • audit or assurance rights; and
  • exit requirements.

32.3 Supplier Governance Flow


33. Governance and Resource Management

33.1 Purpose

AI governance requires appropriate resources to operate effectively.

33.2 Resource Categories

Resources may include:
  • personnel;
  • technology;
  • funding;
  • training;
  • assurance capacity;
  • monitoring tools;
  • documentation systems; and
  • specialist expertise.

33.3 Resource Governance

Management should evaluate whether sufficient resources are available to meet AI governance objectives and manage material risks.

34. Governance Performance

34.1 Purpose

Governance performance should be evaluated using appropriate indicators and evidence.

34.2 Performance Areas

Measures may include:
  • governance compliance;
  • risk treatment completion;
  • control effectiveness;
  • approval cycle performance;
  • incident trends;
  • overdue actions;
  • assurance findings;
  • training completion;
  • monitoring coverage; and
  • continual-improvement performance.

34.3 Performance Cycle


35. Governance Maturity

35.1 Purpose

Governance maturity represents the organization’s ability to consistently apply AI governance practices.

35.2 Maturity Characteristics

Maturity may progress from:
  • ad hoc;
  • developing;
  • defined;
  • managed; to
  • optimized.

35.3 Maturity Relationship

35.4 Maturity Assessment

Maturity assessments should be used to identify improvement opportunities rather than as a substitute for mandatory governance requirements.

36. Governance Traceability

36.1 Purpose

Governance traceability connects organizational requirements with decisions, roles, controls, evidence, and outcomes.

36.2 Traceability Model

36.3 Traceability Requirements

Material governance requirements should be traceable to appropriate:
  • policies;
  • roles;
  • procedures;
  • controls;
  • decisions;
  • evidence; and
  • review activities.

37. Governance and Risk Acceptance

37.1 Purpose

Governance establishes the authority under which AI risks may be accepted.

37.2 Acceptance Relationship

37.3 Acceptance Governance

Risk acceptance should be performed by an authority appropriate to the significance of the risk.

38. Governance and AI System Retirement

38.1 Purpose

Governance should remain active through AI system retirement and decommissioning.

38.2 Retirement Governance

Retirement should consider:
  • business justification;
  • residual risk;
  • data retention;
  • records;
  • dependencies;
  • contractual obligations;
  • security;
  • privacy;
  • stakeholder communication; and
  • lessons learned.

38.3 Retirement Flow


39. Governance and Continual Improvement

39.1 Purpose

Governance should continuously adapt to lessons learned, changing risks, new technologies, and changes in organizational context.

39.2 Improvement Inputs

Improvement may be triggered by:
  • management review;
  • assurance findings;
  • incidents;
  • risk trends;
  • stakeholder feedback;
  • regulatory changes;
  • technology changes;
  • performance data; and
  • emerging risks.

39.3 Improvement Cycle


40. Governance Mapping to ISO/IEC 42001

40.1 Mapping Principle

The AIGO governance model should be mapped to the relevant ISO/IEC 42001 management-system requirements to demonstrate structural relationships and traceability.

40.2 Mapping Categories

Mapping relationships may include:
  • direct governance relationship;
  • supporting governance relationship;
  • accountability relationship;
  • process relationship;
  • evidence relationship; and
  • improvement relationship.

40.3 Mapping Model

40.4 Mapping Limitation

A mapping does not by itself establish conformity with ISO/IEC 42001. Conformity depends on the organization’s implementation, effectiveness, evidence, and applicable assessment requirements.

41. Governance Assurance Model

41.1 Purpose

Governance assurance should determine whether governance arrangements are appropriately designed, implemented, and maintained.

41.2 Assurance Dimensions

Assurance may evaluate:
  • governance structure;
  • accountability;
  • role competence;
  • decision rights;
  • policies;
  • risk governance;
  • control governance;
  • documentation;
  • monitoring;
  • management review; and
  • improvement.

41.3 Assurance Flow


42. Governance Control Effectiveness

42.1 Purpose

Governance controls should be evaluated for both design adequacy and operating effectiveness.

42.2 Effectiveness Questions

Assessment may consider:
  • Is the control appropriately designed?
  • Is the responsible owner identified?
  • Is the control implemented?
  • Is evidence generated?
  • Is the control operating consistently?
  • Is the control producing the intended outcome?
  • Are weaknesses identified and corrected?

42.3 Effectiveness Model


43. Governance Review Frequency

43.1 Purpose

Governance arrangements should be reviewed periodically and when material changes occur.

43.2 Review Triggers

Review may be triggered by:
  • scheduled governance review;
  • management review;
  • organizational change;
  • material AI system change;
  • regulatory change;
  • significant incident;
  • assurance finding;
  • material risk change; or
  • governance-performance deterioration.

43.3 Review Relationship


44. Governance Mapping Summary

44.1 Summary

The AIGO-to-ISO/IEC 42001 Governance Mapping establishes the relationship between the AIGO governance architecture and the ISO/IEC 42001 AI management-system framework. It provides traceability between:
  • organizational context;
  • governance principles;
  • accountability;
  • roles;
  • decision rights;
  • policies;
  • AI systems;
  • risk;
  • controls;
  • evidence;
  • monitoring;
  • assurance;
  • management review; and
  • continual improvement.

44.2 Integrated Governance Architecture

44.3 Final Governance Principle

AI governance should remain an integrated management activity throughout the AI lifecycle. The governance mapping should therefore be maintained as a controlled relationship between the AIGO governance architecture and applicable ISO/IEC 42001 requirements.

45. Document Status

Document: AIGO — ISO/IEC 42001 Governance Mapping Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-ISO42001-006 Document Type: Governance Mapping This document establishes the governance-level relationship between ISO/IEC 42001 and the AIGO AI Governance Operating Framework and provides the foundation for governance implementation, accountability, decision-making, risk oversight, control governance, assurance, management review, and continual improvement.