AIGO — NIST AI RMF Categories Mapping
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-NIST-AIRMF-003
Mapping Standard: NIST AI RMF 1.0
Mapping Type: Categories and Subcategories Mapping
1. Purpose
This document establishes detailed traceability between the NIST AI Risk Management Framework (AI RMF) 1.0 Functions, Categories and Subcategories and the AIGO AI Governance Operating Framework. The document translates the four NIST AI RMF Functions into detailed governance and operational traceability:- GOVERN
- MAP
- MEASURE
- MANAGE
- governance domains;
- principles;
- roles;
- lifecycle stages;
- risk-management activities;
- controls;
- procedures;
- monitoring activities;
- assurance activities;
- evidence;
- implementation mechanisms.
2. Mapping Position
This document occupies the following position within the AIGO-NIST mapping architecture:3. NIST AI RMF Function Structure
The NIST AI RMF Core is organized around four functions.
Each function contains Categories and Subcategories.
4. AIGO Mapping Principle
AIGO does not reproduce the NIST AI RMF. Instead, it establishes traceability between the NIST framework and the AIGO governance operating model. The mapping principle is:5. GOVERN Function
5.1 GOVERN Overview
The GOVERN function establishes and maintains the organizational structures, policies, processes and accountability mechanisms required for AI risk management. AIGO has a strong direct relationship with GOVERN through its governance architecture.6. GOVERN 1 — Policies, Processes and Organizational Structures
6.1 Category Objective
The organization establishes and maintains policies, processes and organizational structures for AI risk management.6.2 AIGO Mapping
6.3 Governance Structure
AIGO establishes a structured governance architecture:6.4 Policy Traceability
AIGO policies and framework documents establish:- governance objectives;
- accountability;
- risk principles;
- control expectations;
- decision rights;
- oversight;
- review requirements.
7. GOVERN 2 — Accountability Structures
7.1 Category Objective
Organizational accountability for AI risk management is established and maintained.7.2 AIGO Mapping
7.3 Accountability Chain
8. GOVERN 3 — Workforce and Competence
8.1 Category Objective
Organizational personnel have the appropriate knowledge, skills and competencies to manage AI risks.8.2 AIGO Mapping
AIGO addresses this through:- role definitions;
- governance responsibilities;
- competency expectations;
- training;
- awareness;
- specialist review;
- technical assessment;
- assurance capability.
8.3 Traceability
9. GOVERN 4 — Organizational Risk Culture
9.1 Category Objective
The organization establishes a culture supporting responsible AI risk management.9.2 AIGO Mapping
AIGO supports:- risk awareness;
- escalation;
- challenge;
- transparency;
- documentation;
- evidence-based decision-making;
- accountability;
- continuous learning.
9.3 Risk Culture Model
10. GOVERN 5 — Stakeholder Engagement
10.1 Category Objective
Relevant stakeholders are identified and engaged throughout AI risk management.10.2 AIGO Mapping
AIGO addresses stakeholder governance through:- stakeholder identification;
- governance roles;
- impact assessment;
- consultation;
- feedback;
- incident reporting;
- monitoring.
10.3 Stakeholder Traceability
11. GOVERN 6 — Legal and Regulatory Requirements
11.1 Category Objective
Applicable legal and regulatory requirements are identified and addressed.11.2 AIGO Mapping
AIGO provides a framework for identifying:- laws;
- regulations;
- contractual obligations;
- organizational policies;
- external standards;
- sector requirements.
12. GOVERN 7 — Risk Management Integration
12.1 Category Objective
AI risk management is integrated into organizational risk-management processes.12.2 AIGO Mapping
AIGO integrates AI risk through:- AI system registration;
- risk assessment;
- classification;
- risk treatment;
- risk acceptance;
- monitoring;
- assurance;
- continual improvement.
12.3 Integration Model
13. GOVERN 8 — Transparency and Documentation
13.1 Category Objective
AI risk-management activities and decisions are appropriately documented and traceable.13.2 AIGO Mapping
AIGO evidence architecture provides:- controlled documentation;
- decision records;
- assessment records;
- control evidence;
- monitoring evidence;
- assurance records;
- change records.
14. GOVERN 9 — Third-Party Risk
14.1 Category Objective
Risks associated with third-party AI systems, components and services are governed.14.2 AIGO Mapping
AIGO addresses:- provider identification;
- dependency identification;
- third-party risk assessment;
- contractual requirements;
- control requirements;
- monitoring;
- reassessment.
14.3 Third-Party Model
15. GOVERN Category Summary
16. MAP Function
16.1 MAP Overview
MAP establishes context for AI systems and identifies relevant risks and impacts. AIGO has a direct relationship with MAP through system registration, classification, profiling and risk assessment.17. MAP 1 — Context and Intended Purpose
17.1 Category Objective
The context and intended purpose of an AI system are established and documented.17.2 AIGO Mapping
AIGO addresses this through:- AI System Registration;
- AI System Profiles;
- intended-use documentation;
- business context;
- operational context;
- stakeholder context;
- technical context.
17.3 Context Model
18. MAP 2 — Categorization and Risk Context
18.1 Category Objective
AI systems and associated risks are categorized according to relevant context.18.2 AIGO Mapping
AIGO classification considers:- risk;
- impact;
- criticality;
- autonomy;
- affected stakeholders;
- legal requirements;
- data sensitivity;
- deployment context.
19. MAP 3 — Benefits, Costs and Impacts
19.1 Category Objective
Potential benefits, costs and impacts of AI systems are identified.19.2 AIGO Mapping
AIGO considers:- intended benefits;
- operational consequences;
- potential harms;
- stakeholder impacts;
- resource implications;
- residual risk.
19.3 Impact Model
20. MAP 4 — Risk Identification
20.1 Category Objective
AI risks are identified and documented.20.2 AIGO Mapping
AIGO Risk Management provides the principal implementation mechanism. Risk identification may cover:- safety;
- security;
- privacy;
- fairness;
- bias;
- reliability;
- transparency;
- explainability;
- misuse;
- operational risks;
- third-party risks;
- governance risks.
21. MAP 5 — Human Oversight and Context
21.1 Category Objective
Relevant human roles and oversight requirements are identified.21.2 AIGO Mapping
AIGO establishes:- accountable roles;
- responsible roles;
- approval authorities;
- operational roles;
- escalation;
- human oversight requirements.
22. MAP 6 — AI Lifecycle Context
22.1 Category Objective
The lifecycle context of the AI system is established.22.2 AIGO Mapping
AIGO lifecycle stages include:- identify;
- classify;
- assess;
- treat;
- approve;
- deploy;
- operate;
- monitor;
- assure;
- improve;
- change;
- retire.
23. MAP Category Summary
24. MEASURE Function
24.1 MEASURE Overview
MEASURE establishes mechanisms for assessing, testing, evaluating and monitoring AI risks. AIGO maps MEASURE primarily to:- risk assessment;
- control assessment;
- monitoring;
- assurance;
- testing;
- evidence.
25. MEASURE 1 — Measurement Strategy
25.1 Category Objective
Measurement approaches are established and aligned with identified risks.25.2 AIGO Mapping
AIGO measurement activities should define:- objective;
- metric;
- methodology;
- frequency;
- threshold;
- responsible role;
- evidence requirement.
25.3 Measurement Model
26. MEASURE 2 — AI System Performance
26.1 Category Objective
AI system performance is evaluated using appropriate measures.26.2 AIGO Mapping
Depending on the AI system, measures may include:- accuracy;
- reliability;
- robustness;
- availability;
- latency;
- error rates;
- drift;
- operational performance.
27. MEASURE 3 — Trustworthiness Characteristics
27.1 Category Objective
Relevant AI trustworthiness characteristics are evaluated. AIGO may address characteristics including:- validity;
- reliability;
- safety;
- security;
- resilience;
- accountability;
- transparency;
- explainability;
- privacy;
- fairness.
28. MEASURE 4 — Test and Evaluation
28.1 Category Objective
AI systems are tested and evaluated using appropriate methods. AIGO testing may occur:- before deployment;
- after material change;
- after incidents;
- periodically;
- when risk changes.
29. MEASURE 5 — Measurement Results
29.1 Category Objective
Measurement results are documented and communicated to appropriate stakeholders.29.2 AIGO Mapping
Results should be:- recorded;
- interpreted;
- reviewed;
- linked to risk;
- linked to controls;
- retained as evidence;
- communicated to decision-makers.
30. MEASURE 6 — Monitoring
30.1 Category Objective
AI systems and risk conditions are monitored over time.30.2 AIGO Mapping
AIGO Monitoring Procedure provides the principal operational mechanism. Monitoring can address:- performance;
- incidents;
- drift;
- control effectiveness;
- risk indicators;
- stakeholder feedback;
- changes in context.
31. MEASURE 7 — Independent Assessment
31.1 Category Objective
Appropriate independent or objective assessments are conducted.31.2 AIGO Mapping
AIGO Assurance Procedure provides mechanisms for:- independent review;
- objective assessment;
- control effectiveness evaluation;
- evidence review;
- findings;
- corrective action.
32. MEASURE Category Summary
33. MANAGE Function
33.1 MANAGE Overview
MANAGE prioritizes and responds to AI risks. AIGO provides direct operational mechanisms through risk treatment, approval, acceptance, incident management, change management and retirement.34. MANAGE 1 — Risk Prioritization
34.1 Category Objective
Identified risks are prioritized according to organizational criteria.34.2 AIGO Mapping
AIGO prioritization may consider:- severity;
- likelihood;
- impact;
- exposure;
- uncertainty;
- affected population;
- regulatory significance;
- business criticality.
35. MANAGE 2 — Risk Treatment
35.1 Category Objective
AI risks are treated according to organizational risk criteria.35.2 AIGO Mapping
Treatment options include:- mitigation;
- avoidance;
- transfer;
- acceptance;
- restriction;
- redesign;
- additional controls;
- suspension;
- retirement.
35.3 Treatment Model
36. MANAGE 3 — Risk Response
36.1 Category Objective
Risk responses are implemented and monitored.36.2 AIGO Mapping
AIGO requires:- treatment plans;
- control implementation;
- responsible owners;
- target dates;
- verification;
- residual-risk review.
37. MANAGE 4 — Incident Response
37.1 Category Objective
AI-related incidents are identified, managed and used as inputs to risk management.37.2 AIGO Mapping
AIGO Incident Management includes:- detection;
- reporting;
- classification;
- containment;
- investigation;
- corrective action;
- escalation;
- closure;
- lessons learned.
38. MANAGE 5 — Change Management
38.1 Category Objective
Changes to AI systems and their context are governed according to risk.38.2 AIGO Mapping
AIGO Change Management may trigger:- reclassification;
- risk reassessment;
- control reassessment;
- testing;
- approval;
- monitoring changes.
38.3 Change Model
39. MANAGE 6 — Risk Acceptance
39.1 Category Objective
Residual risks are explicitly considered and accepted or escalated according to organizational authority.39.2 AIGO Mapping
AIGO Risk Acceptance Procedure establishes the decision structure.39.3 Acceptance Model
40. MANAGE 7 — Corrective Action
40.1 Category Objective
Deficiencies identified through assessment, monitoring or incidents are corrected.40.2 AIGO Mapping
Corrective actions may originate from:- control assessments;
- assurance findings;
- incidents;
- monitoring alerts;
- management reviews;
- stakeholder complaints.
41. MANAGE 8 — Retirement and Discontinuation
41.1 Category Objective
AI systems are appropriately discontinued when required.41.2 AIGO Mapping
AIGO Retirement Procedure addresses:- retirement decision;
- authorization;
- data disposition;
- evidence retention;
- dependency closure;
- stakeholder communication;
- residual-risk closure.
42. MANAGE Category Summary
43. Function-to-Category Matrix
44. Category-to-Lifecycle Mapping
45. Category-to-AIGO Procedure Mapping
46. Category-to-Evidence Mapping
47. Category-to-Role Mapping
Supporting roles may be assigned according to organizational context.
48. Category Traceability Model
Each NIST Category shall ultimately be traceable through:49. Subcategory Mapping Principle
The detailed NIST Subcategory layer shall be mapped individually. The following rules apply:- One NIST Subcategory may map to multiple AIGO controls.
- One AIGO control may address multiple NIST Subcategories.
- A mapping may be direct or supporting.
- A mapping shall not be interpreted as certification.
- A mapping should identify implementation gaps where no adequate AIGO mechanism exists.
50. Direct and Supporting Mapping
50.1 Direct Mapping
A direct mapping exists where AIGO explicitly provides a mechanism addressing the intent of the NIST element.50.2 Supporting Mapping
A supporting mapping exists where an AIGO capability contributes to the NIST outcome but does not independently satisfy the entire intent.51. Mapping Strength Model
These codes should be used in detailed traceability matrices.
52. Category Coverage Model
AIGO coverage should be evaluated using:53. Category-Level Gap Management
Where a NIST category or subcategory has incomplete AIGO coverage, the gap should be documented. A gap record should identify:- NIST reference;
- AIGO reference;
- gap description;
- risk;
- impact;
- owner;
- remediation;
- target date;
- status;
- evidence.
54. Mapping and AIGO Controls
The category mapping provides an input to the AIGO control architecture. The relationship is:55. Mapping and AIGO Lifecycle
NIST AI RMF Categories are not required to occur as a strict sequence. AIGO therefore uses lifecycle placement rather than forcing a sequential interpretation.56. Mapping and Continuous Monitoring
Categories associated with monitoring, measurement and governance shall remain active after deployment. The operating model is:57. Mapping and Change
Material changes should trigger reassessment of applicable NIST mappings. Examples include:- model replacement;
- major model update;
- new training data;
- new intended use;
- new user group;
- new geographic deployment;
- new provider;
- new integration;
- new regulatory requirement.
58. Mapping and Incident Management
An incident may affect multiple NIST functions.59. Mapping and Assurance
Assurance should test whether mapped capabilities are actually operating. The assurance model is:60. Mapping Quality Requirements
Every detailed mapping should be:- specific;
- traceable;
- reviewable;
- evidence-oriented;
- internally consistent;
- version-controlled;
- linked to an AIGO owner;
- reviewed periodically.
61. Mapping Limitations
This document does not:- reproduce the NIST AI RMF;
- create NIST requirements;
- constitute NIST certification;
- establish legal compliance;
- replace technical testing;
- replace organizational risk management;
- guarantee AI system trustworthiness;
- constitute NIST endorsement.
62. Maintenance
This mapping should be reviewed when:- NIST AI RMF changes;
- AIGO controls change;
- AIGO procedures change;
- lifecycle architecture changes;
- risk methodology changes;
- new external requirements arise;
- material implementation gaps are identified.
63. Document Change Record
64. Document Control
64.1 Controlled Information
65. Final Control Statement
This document establishes the category-level relationship between the NIST AI RMF and the AIGO AI Governance Operating Framework. The mapping provides a structured bridge from:66. End of Mapping Document
AIGO — NIST AI RMF Categories Mapping Document ID:AIGO-MAP-NIST-AIRMF-003
Version: 0.1
Status: Draft
Mapping Standard: NIST AI RMF 1.0
Mapping Type: Categories and Subcategories Mapping
End of Document