AIGO — ISO/IEC 42001 Governance Mapping
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-ISO42001-006
Mapping Standard: ISO/IEC 42001
Mapping Type: Governance Mapping
1. Purpose
This document defines the relationship between the AIGO AI Governance Model and the ISO/IEC 42001 AI management system framework. The purpose of this mapping is to establish traceability between governance structures, accountability, responsibilities, decision rights, management-system processes, AI system oversight, risk management, controls, evidence, assurance, and continual improvement. The mapping provides a governance-oriented bridge between the AIGO framework architecture and the relevant ISO/IEC 42001 management-system requirements.2. Scope
This document covers the governance relationship between:- organizational governance;
- AI governance;
- management accountability;
- governance roles;
- responsibilities;
- authorities;
- decision rights;
- AI system ownership;
- risk ownership;
- control ownership;
- governance committees;
- management review;
- resource allocation;
- competence;
- communication;
- documentation;
- assurance;
- monitoring;
- change management; and
- continual improvement.
3. Governance Mapping Principle
AIGO treats AI governance as the mechanism through which the organization establishes direction, accountability, oversight, decision rights, controls, and continuous improvement for AI-related activities. The governance relationship can be represented as:4. AIGO Governance Model
4.1 Governance Purpose
AIGO governance establishes the organizational structures and decision mechanisms necessary to direct and control AI-related activities.4.2 Governance Objectives
The governance model should:- establish accountability;
- define decision rights;
- establish governance requirements;
- assign responsibilities;
- provide oversight;
- manage AI-related risk;
- ensure appropriate controls;
- support compliance;
- maintain evidence;
- support assurance; and
- enable continual improvement.
4.3 Governance Architecture
5. Governance and the AI Management System
5.1 Management-System Relationship
The AIGO governance model provides the organizational structure through which the AI management system can be directed and maintained.5.2 Governance Integration
Governance should establish:- organizational direction;
- AI objectives;
- governance requirements;
- accountability;
- decision-making authority;
- risk appetite;
- control expectations;
- monitoring requirements; and
- review mechanisms.
5.3 Integrated Relationship
6. Organizational Context
6.1 Purpose
AI governance should be established within the context of the organization’s objectives, obligations, stakeholders, and operating environment.6.2 Context Factors
Relevant factors may include:- organizational strategy;
- business objectives;
- legal requirements;
- regulatory requirements;
- contractual obligations;
- stakeholder expectations;
- organizational structure;
- AI portfolio;
- technology environment;
- risk environment;
- resource constraints; and
- organizational maturity.
6.3 Context Flow
7. Governance Principles
7.1 Purpose
Governance principles establish the fundamental expectations that guide AI-related decisions.7.2 Core Principles
AIGO governance should promote:- accountability;
- transparency;
- proportionality;
- traceability;
- human oversight;
- risk-based decision-making;
- evidence-based governance;
- continuous monitoring;
- responsible innovation; and
- continual improvement.
7.3 Principle Application
Governance principles should be translated into actionable requirements, controls, procedures, and decision criteria.8. Governance Accountability
8.1 Purpose
Accountability establishes who is answerable for AI governance outcomes.8.2 Accountability Requirements
The organization should identify accountable persons or bodies for:- AI governance;
- AI management-system oversight;
- AI system ownership;
- risk management;
- control implementation;
- monitoring;
- assurance;
- compliance; and
- improvement.
8.3 Accountability Model
8.4 Accountability Principle
Accountability should remain clear even where operational activities are delegated or outsourced.9. Governance Roles
9.1 Purpose
Governance roles define responsibilities and decision rights for AI-related activities.9.2 Typical Roles
Relevant roles may include:- executive sponsor;
- AI governance owner;
- AI system owner;
- AI product owner;
- risk owner;
- control owner;
- data owner;
- security owner;
- privacy owner;
- compliance function;
- legal function;
- assurance function;
- internal audit; and
- operational users.
9.3 Role Definition
Each material role should have:- defined responsibilities;
- defined authority;
- required competence;
- escalation responsibilities;
- decision rights; and
- accountability boundaries.
10. Governance Decision Rights
10.1 Purpose
Decision rights define who may make, approve, reject, escalate, or review AI governance decisions.10.2 Decision Categories
Decision rights may cover:- AI system registration;
- classification;
- risk acceptance;
- control approval;
- deployment approval;
- material change approval;
- exception approval;
- incident escalation;
- suspension;
- retirement; and
- governance-policy changes.
10.3 Decision Flow
11. Governance Committees
11.1 Purpose
Organizations may establish governance committees or equivalent decision bodies where the scale or complexity of AI activities requires collective oversight.11.2 Committee Responsibilities
A governance body may oversee:- AI portfolio;
- high-risk AI systems;
- risk acceptance;
- major changes;
- incidents;
- assurance findings;
- compliance issues;
- strategic AI initiatives; and
- continual improvement.
11.3 Committee Governance
Committee structures should define:- mandate;
- membership;
- authority;
- quorum;
- decision rights;
- meeting frequency;
- records; and
- escalation mechanisms.
12. Governance Policies
12.1 Purpose
Governance policies establish organizational expectations for AI activities.12.2 Policy Categories
Policies may address:- AI governance;
- responsible AI;
- AI risk;
- data governance;
- security;
- privacy;
- human oversight;
- AI system development;
- AI procurement;
- third-party AI;
- monitoring;
- incident management; and
- AI retirement.
12.3 Policy Hierarchy
13. Governance Objectives
13.1 Purpose
Governance objectives translate organizational direction into measurable AI governance outcomes.13.2 Objective Characteristics
Objectives should be:- relevant;
- measurable where appropriate;
- assigned to accountable roles;
- monitored;
- documented; and
- reviewed.
13.3 Objective Relationship
14. AI System Governance
14.1 Purpose
Every material AI system should operate within an appropriate governance structure.14.2 Governance Requirements
An AI system should, where applicable, have:- identified owner;
- documented purpose;
- system profile;
- classification;
- risk assessment;
- applicable controls;
- approval status;
- monitoring arrangements;
- evidence;
- change-management requirements; and
- retirement criteria.
14.3 AI System Governance Flow
15. Governance and AI Lifecycle
15.1 Purpose
Governance should apply throughout the complete AI lifecycle.15.2 Lifecycle Governance
15.3 Lifecycle Principle
Governance requirements should be appropriate to the lifecycle stage and the risk profile of the AI system.16. Governance and Risk Management
16.1 Purpose
Governance establishes the authority and accountability required to manage AI risk.16.2 Governance Responsibilities
Governance should establish:- risk methodology;
- risk appetite;
- risk criteria;
- risk ownership;
- acceptance authority;
- escalation thresholds;
- review requirements; and
- reporting mechanisms.
16.3 Risk Governance Relationship
17. Governance and Controls
17.1 Purpose
Governance should establish expectations for the design, implementation, operation, and review of AI controls.17.2 Control Governance
Controls should have:- defined purpose;
- control owner;
- implementation requirements;
- evidence requirements;
- effectiveness criteria;
- review frequency; and
- escalation requirements.
17.3 Control Governance Flow
18. Governance and Human Oversight
18.1 Purpose
Human oversight should be governed according to the AI system’s purpose, risk, autonomy, and potential impact.18.2 Oversight Requirements
Governance should define:- who provides oversight;
- when oversight is required;
- what decisions require human intervention;
- escalation requirements;
- override authority;
- competence requirements; and
- evidence requirements.
18.3 Oversight Relationship
19. Governance and Competence
19.1 Purpose
AI governance requires personnel with sufficient competence to perform assigned responsibilities.19.2 Competence Areas
Competence may include:- AI technology;
- risk management;
- governance;
- compliance;
- security;
- privacy;
- data;
- assurance;
- human oversight; and
- domain-specific knowledge.
19.3 Competence Governance
The organization should determine competence requirements appropriate to each material AI governance role.20. Governance and Awareness
20.1 Purpose
Personnel involved in AI activities should understand relevant governance expectations.20.2 Awareness Topics
Awareness may cover:- AI governance principles;
- responsibilities;
- acceptable use;
- risk;
- security;
- privacy;
- incident reporting;
- human oversight;
- change management; and
- escalation.
20.3 Awareness Flow
21. Governance Communication
21.1 Purpose
Governance information should be communicated to relevant internal and external stakeholders as appropriate.21.2 Communication Topics
Communication may include:- governance decisions;
- AI policies;
- risk information;
- incidents;
- control requirements;
- material changes;
- assurance findings; and
- management decisions.
21.3 Communication Principles
Governance communication should be:- timely;
- accurate;
- understandable;
- appropriately authorized;
- traceable; and
- proportionate.
22. Governance Documentation
22.1 Purpose
Governance decisions and requirements should be supported by controlled documentation.22.2 Governance Records
Records may include:- policies;
- governance charters;
- role definitions;
- committee records;
- decisions;
- approvals;
- risk acceptances;
- exceptions;
- management reviews;
- assurance reports; and
- corrective actions.
22.3 Documentation Flow
23. Governance and Evidence
23.1 Purpose
Governance decisions should be supported by sufficient evidence.23.2 Evidence Categories
Evidence may include:- approval records;
- meeting minutes;
- risk assessments;
- control assessments;
- monitoring reports;
- assurance reports;
- training records;
- incident records; and
- management-review records.
23.3 Evidence Relationship
24. Governance Monitoring
24.1 Purpose
Governance monitoring determines whether governance requirements are being implemented and remain effective.24.2 Monitoring Areas
Monitoring may evaluate:- policy compliance;
- risk status;
- control performance;
- approval status;
- incidents;
- exceptions;
- overdue actions;
- assurance findings; and
- governance objectives.
24.3 Monitoring Cycle
25. Governance Assurance
25.1 Purpose
Assurance provides confidence that governance arrangements are appropriately designed and operating as intended.25.2 Assurance Areas
Assurance may examine:- governance structure;
- role accountability;
- decision rights;
- risk governance;
- control governance;
- evidence;
- monitoring;
- compliance; and
- continual improvement.
25.3 Assurance Relationship
26. Management Review
26.1 Purpose
Management review provides a formal mechanism for evaluating the continuing suitability, adequacy, and effectiveness of the AI governance and management-system arrangements.26.2 Management Review Inputs
Inputs may include:- AI governance performance;
- AI risk profile;
- control effectiveness;
- incidents;
- assurance findings;
- stakeholder feedback;
- regulatory changes;
- changes in organizational context;
- governance objectives; and
- continual-improvement opportunities.
26.3 Management Review Flow
27. Governance Decisions
27.1 Purpose
Governance decisions should be formally recorded when they materially affect AI governance, risk, compliance, or system operation.27.2 Decision Records
A decision record should identify, as appropriate:- decision;
- decision date;
- decision authority;
- subject;
- rationale;
- supporting evidence;
- conditions;
- actions;
- owner; and
- review requirements.
27.3 Decision Traceability
28. Governance Exceptions
28.1 Purpose
Exceptions allow controlled deviation from defined governance requirements where justified and authorized.28.2 Exception Requirements
An exception should identify:- requirement;
- reason;
- scope;
- affected AI system;
- risk;
- compensating controls;
- owner;
- approval authority;
- expiration or review date; and
- evidence.
28.3 Exception Flow
28.4 Exception Principle
Exceptions should not be used to circumvent mandatory legal or regulatory obligations.29. Governance Escalation
29.1 Purpose
Escalation ensures that issues exceeding operational authority are brought to the appropriate governance level.29.2 Escalation Triggers
Triggers may include:- material risk;
- serious incident;
- control failure;
- regulatory concern;
- unresolved assurance finding;
- significant policy exception;
- material system change; or
- repeated governance failure.
29.3 Escalation Model
30. Governance and Change Management
30.1 Purpose
Governance should ensure that material changes to AI systems and governance arrangements are appropriately assessed and approved.30.2 Change Categories
Changes may include:- AI system changes;
- model changes;
- data changes;
- intended-use changes;
- governance-policy changes;
- control changes;
- supplier changes;
- regulatory changes; and
- organizational changes.
30.3 Change Governance
31. Governance and Incident Management
31.1 Purpose
Governance should establish oversight for material AI incidents and ensure that lessons learned are incorporated into the governance system.31.2 Incident Governance
Governance should define:- incident classification;
- reporting;
- escalation;
- response authority;
- communication;
- investigation;
- corrective action; and
- management review.
31.3 Incident Relationship
32. Governance and Supplier Management
32.1 Purpose
Third-party AI services and suppliers should operate within appropriate governance arrangements.32.2 Supplier Governance
Supplier governance may include:- due diligence;
- contractual requirements;
- risk assessment;
- security requirements;
- privacy requirements;
- performance requirements;
- incident notification;
- change notification;
- audit or assurance rights; and
- exit requirements.
32.3 Supplier Governance Flow
33. Governance and Resource Management
33.1 Purpose
AI governance requires appropriate resources to operate effectively.33.2 Resource Categories
Resources may include:- personnel;
- technology;
- funding;
- training;
- assurance capacity;
- monitoring tools;
- documentation systems; and
- specialist expertise.
33.3 Resource Governance
Management should evaluate whether sufficient resources are available to meet AI governance objectives and manage material risks.34. Governance Performance
34.1 Purpose
Governance performance should be evaluated using appropriate indicators and evidence.34.2 Performance Areas
Measures may include:- governance compliance;
- risk treatment completion;
- control effectiveness;
- approval cycle performance;
- incident trends;
- overdue actions;
- assurance findings;
- training completion;
- monitoring coverage; and
- continual-improvement performance.
34.3 Performance Cycle
35. Governance Maturity
35.1 Purpose
Governance maturity represents the organization’s ability to consistently apply AI governance practices.35.2 Maturity Characteristics
Maturity may progress from:- ad hoc;
- developing;
- defined;
- managed; to
- optimized.
35.3 Maturity Relationship
35.4 Maturity Assessment
Maturity assessments should be used to identify improvement opportunities rather than as a substitute for mandatory governance requirements.36. Governance Traceability
36.1 Purpose
Governance traceability connects organizational requirements with decisions, roles, controls, evidence, and outcomes.36.2 Traceability Model
36.3 Traceability Requirements
Material governance requirements should be traceable to appropriate:- policies;
- roles;
- procedures;
- controls;
- decisions;
- evidence; and
- review activities.
37. Governance and Risk Acceptance
37.1 Purpose
Governance establishes the authority under which AI risks may be accepted.37.2 Acceptance Relationship
37.3 Acceptance Governance
Risk acceptance should be performed by an authority appropriate to the significance of the risk.38. Governance and AI System Retirement
38.1 Purpose
Governance should remain active through AI system retirement and decommissioning.38.2 Retirement Governance
Retirement should consider:- business justification;
- residual risk;
- data retention;
- records;
- dependencies;
- contractual obligations;
- security;
- privacy;
- stakeholder communication; and
- lessons learned.
38.3 Retirement Flow
39. Governance and Continual Improvement
39.1 Purpose
Governance should continuously adapt to lessons learned, changing risks, new technologies, and changes in organizational context.39.2 Improvement Inputs
Improvement may be triggered by:- management review;
- assurance findings;
- incidents;
- risk trends;
- stakeholder feedback;
- regulatory changes;
- technology changes;
- performance data; and
- emerging risks.
39.3 Improvement Cycle
40. Governance Mapping to ISO/IEC 42001
40.1 Mapping Principle
The AIGO governance model should be mapped to the relevant ISO/IEC 42001 management-system requirements to demonstrate structural relationships and traceability.40.2 Mapping Categories
Mapping relationships may include:- direct governance relationship;
- supporting governance relationship;
- accountability relationship;
- process relationship;
- evidence relationship; and
- improvement relationship.
40.3 Mapping Model
40.4 Mapping Limitation
A mapping does not by itself establish conformity with ISO/IEC 42001. Conformity depends on the organization’s implementation, effectiveness, evidence, and applicable assessment requirements.41. Governance Assurance Model
41.1 Purpose
Governance assurance should determine whether governance arrangements are appropriately designed, implemented, and maintained.41.2 Assurance Dimensions
Assurance may evaluate:- governance structure;
- accountability;
- role competence;
- decision rights;
- policies;
- risk governance;
- control governance;
- documentation;
- monitoring;
- management review; and
- improvement.
41.3 Assurance Flow
42. Governance Control Effectiveness
42.1 Purpose
Governance controls should be evaluated for both design adequacy and operating effectiveness.42.2 Effectiveness Questions
Assessment may consider:- Is the control appropriately designed?
- Is the responsible owner identified?
- Is the control implemented?
- Is evidence generated?
- Is the control operating consistently?
- Is the control producing the intended outcome?
- Are weaknesses identified and corrected?
42.3 Effectiveness Model
43. Governance Review Frequency
43.1 Purpose
Governance arrangements should be reviewed periodically and when material changes occur.43.2 Review Triggers
Review may be triggered by:- scheduled governance review;
- management review;
- organizational change;
- material AI system change;
- regulatory change;
- significant incident;
- assurance finding;
- material risk change; or
- governance-performance deterioration.
43.3 Review Relationship
44. Governance Mapping Summary
44.1 Summary
The AIGO-to-ISO/IEC 42001 Governance Mapping establishes the relationship between the AIGO governance architecture and the ISO/IEC 42001 AI management-system framework. It provides traceability between:- organizational context;
- governance principles;
- accountability;
- roles;
- decision rights;
- policies;
- AI systems;
- risk;
- controls;
- evidence;
- monitoring;
- assurance;
- management review; and
- continual improvement.
44.2 Integrated Governance Architecture
44.3 Final Governance Principle
AI governance should remain an integrated management activity throughout the AI lifecycle. The governance mapping should therefore be maintained as a controlled relationship between the AIGO governance architecture and applicable ISO/IEC 42001 requirements.45. Document Status
Document: AIGO — ISO/IEC 42001 Governance Mapping Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-ISO42001-006
Document Type: Governance Mapping
This document establishes the governance-level relationship between ISO/IEC 42001 and the AIGO AI Governance Operating Framework and provides the foundation for governance implementation, accountability, decision-making, risk oversight, control governance, assurance, management review, and continual improvement.