Skip to main content

AIGO — NIST AI RMF Categories Mapping

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-NIST-AIRMF-003 Mapping Standard: NIST AI RMF 1.0 Mapping Type: Categories and Subcategories Mapping

1. Purpose

This document establishes detailed traceability between the NIST AI Risk Management Framework (AI RMF) 1.0 Functions, Categories and Subcategories and the AIGO AI Governance Operating Framework. The document translates the four NIST AI RMF Functions into detailed governance and operational traceability:
  • GOVERN
  • MAP
  • MEASURE
  • MANAGE
The mapping connects NIST AI RMF Categories and Subcategories to applicable AIGO:
  • governance domains;
  • principles;
  • roles;
  • lifecycle stages;
  • risk-management activities;
  • controls;
  • procedures;
  • monitoring activities;
  • assurance activities;
  • evidence;
  • implementation mechanisms.

2. Mapping Position

This document occupies the following position within the AIGO-NIST mapping architecture:

3. NIST AI RMF Function Structure

The NIST AI RMF Core is organized around four functions. Each function contains Categories and Subcategories.

4. AIGO Mapping Principle

AIGO does not reproduce the NIST AI RMF. Instead, it establishes traceability between the NIST framework and the AIGO governance operating model. The mapping principle is:
A mapping relationship does not by itself demonstrate implementation or conformity.

5. GOVERN Function

5.1 GOVERN Overview

The GOVERN function establishes and maintains the organizational structures, policies, processes and accountability mechanisms required for AI risk management. AIGO has a strong direct relationship with GOVERN through its governance architecture.

6. GOVERN 1 — Policies, Processes and Organizational Structures

6.1 Category Objective

The organization establishes and maintains policies, processes and organizational structures for AI risk management.

6.2 AIGO Mapping


6.3 Governance Structure

AIGO establishes a structured governance architecture:

6.4 Policy Traceability

AIGO policies and framework documents establish:
  • governance objectives;
  • accountability;
  • risk principles;
  • control expectations;
  • decision rights;
  • oversight;
  • review requirements.

7. GOVERN 2 — Accountability Structures

7.1 Category Objective

Organizational accountability for AI risk management is established and maintained.

7.2 AIGO Mapping


7.3 Accountability Chain

Actual organizational roles may vary.

8. GOVERN 3 — Workforce and Competence

8.1 Category Objective

Organizational personnel have the appropriate knowledge, skills and competencies to manage AI risks.

8.2 AIGO Mapping

AIGO addresses this through:
  • role definitions;
  • governance responsibilities;
  • competency expectations;
  • training;
  • awareness;
  • specialist review;
  • technical assessment;
  • assurance capability.

8.3 Traceability


9. GOVERN 4 — Organizational Risk Culture

9.1 Category Objective

The organization establishes a culture supporting responsible AI risk management.

9.2 AIGO Mapping

AIGO supports:
  • risk awareness;
  • escalation;
  • challenge;
  • transparency;
  • documentation;
  • evidence-based decision-making;
  • accountability;
  • continuous learning.

9.3 Risk Culture Model


10. GOVERN 5 — Stakeholder Engagement

10.1 Category Objective

Relevant stakeholders are identified and engaged throughout AI risk management.

10.2 AIGO Mapping

AIGO addresses stakeholder governance through:
  • stakeholder identification;
  • governance roles;
  • impact assessment;
  • consultation;
  • feedback;
  • incident reporting;
  • monitoring.

10.3 Stakeholder Traceability


11. GOVERN 6 — Legal and Regulatory Requirements

11.1 Category Objective

Applicable legal and regulatory requirements are identified and addressed.

11.2 AIGO Mapping

AIGO provides a framework for identifying:
  • laws;
  • regulations;
  • contractual obligations;
  • organizational policies;
  • external standards;
  • sector requirements.
External mappings are maintained separately.

12. GOVERN 7 — Risk Management Integration

12.1 Category Objective

AI risk management is integrated into organizational risk-management processes.

12.2 AIGO Mapping

AIGO integrates AI risk through:
  • AI system registration;
  • risk assessment;
  • classification;
  • risk treatment;
  • risk acceptance;
  • monitoring;
  • assurance;
  • continual improvement.

12.3 Integration Model


13. GOVERN 8 — Transparency and Documentation

13.1 Category Objective

AI risk-management activities and decisions are appropriately documented and traceable.

13.2 AIGO Mapping

AIGO evidence architecture provides:
  • controlled documentation;
  • decision records;
  • assessment records;
  • control evidence;
  • monitoring evidence;
  • assurance records;
  • change records.

14. GOVERN 9 — Third-Party Risk

14.1 Category Objective

Risks associated with third-party AI systems, components and services are governed.

14.2 AIGO Mapping

AIGO addresses:
  • provider identification;
  • dependency identification;
  • third-party risk assessment;
  • contractual requirements;
  • control requirements;
  • monitoring;
  • reassessment.

14.3 Third-Party Model


15. GOVERN Category Summary


16. MAP Function

16.1 MAP Overview

MAP establishes context for AI systems and identifies relevant risks and impacts. AIGO has a direct relationship with MAP through system registration, classification, profiling and risk assessment.

17. MAP 1 — Context and Intended Purpose

17.1 Category Objective

The context and intended purpose of an AI system are established and documented.

17.2 AIGO Mapping

AIGO addresses this through:
  • AI System Registration;
  • AI System Profiles;
  • intended-use documentation;
  • business context;
  • operational context;
  • stakeholder context;
  • technical context.

17.3 Context Model


18. MAP 2 — Categorization and Risk Context

18.1 Category Objective

AI systems and associated risks are categorized according to relevant context.

18.2 AIGO Mapping

AIGO classification considers:
  • risk;
  • impact;
  • criticality;
  • autonomy;
  • affected stakeholders;
  • legal requirements;
  • data sensitivity;
  • deployment context.

19. MAP 3 — Benefits, Costs and Impacts

19.1 Category Objective

Potential benefits, costs and impacts of AI systems are identified.

19.2 AIGO Mapping

AIGO considers:
  • intended benefits;
  • operational consequences;
  • potential harms;
  • stakeholder impacts;
  • resource implications;
  • residual risk.

19.3 Impact Model


20. MAP 4 — Risk Identification

20.1 Category Objective

AI risks are identified and documented.

20.2 AIGO Mapping

AIGO Risk Management provides the principal implementation mechanism. Risk identification may cover:
  • safety;
  • security;
  • privacy;
  • fairness;
  • bias;
  • reliability;
  • transparency;
  • explainability;
  • misuse;
  • operational risks;
  • third-party risks;
  • governance risks.

21. MAP 5 — Human Oversight and Context

21.1 Category Objective

Relevant human roles and oversight requirements are identified.

21.2 AIGO Mapping

AIGO establishes:
  • accountable roles;
  • responsible roles;
  • approval authorities;
  • operational roles;
  • escalation;
  • human oversight requirements.

22. MAP 6 — AI Lifecycle Context

22.1 Category Objective

The lifecycle context of the AI system is established.

22.2 AIGO Mapping

AIGO lifecycle stages include:
  • identify;
  • classify;
  • assess;
  • treat;
  • approve;
  • deploy;
  • operate;
  • monitor;
  • assure;
  • improve;
  • change;
  • retire.

23. MAP Category Summary


24. MEASURE Function

24.1 MEASURE Overview

MEASURE establishes mechanisms for assessing, testing, evaluating and monitoring AI risks. AIGO maps MEASURE primarily to:
  • risk assessment;
  • control assessment;
  • monitoring;
  • assurance;
  • testing;
  • evidence.

25. MEASURE 1 — Measurement Strategy

25.1 Category Objective

Measurement approaches are established and aligned with identified risks.

25.2 AIGO Mapping

AIGO measurement activities should define:
  • objective;
  • metric;
  • methodology;
  • frequency;
  • threshold;
  • responsible role;
  • evidence requirement.

25.3 Measurement Model


26. MEASURE 2 — AI System Performance

26.1 Category Objective

AI system performance is evaluated using appropriate measures.

26.2 AIGO Mapping

Depending on the AI system, measures may include:
  • accuracy;
  • reliability;
  • robustness;
  • availability;
  • latency;
  • error rates;
  • drift;
  • operational performance.
The specific metric set should be risk- and context-dependent.

27. MEASURE 3 — Trustworthiness Characteristics

27.1 Category Objective

Relevant AI trustworthiness characteristics are evaluated. AIGO may address characteristics including:
  • validity;
  • reliability;
  • safety;
  • security;
  • resilience;
  • accountability;
  • transparency;
  • explainability;
  • privacy;
  • fairness.
Not every characteristic applies equally to every AI system.

28. MEASURE 4 — Test and Evaluation

28.1 Category Objective

AI systems are tested and evaluated using appropriate methods. AIGO testing may occur:
  • before deployment;
  • after material change;
  • after incidents;
  • periodically;
  • when risk changes.

29. MEASURE 5 — Measurement Results

29.1 Category Objective

Measurement results are documented and communicated to appropriate stakeholders.

29.2 AIGO Mapping

Results should be:
  • recorded;
  • interpreted;
  • reviewed;
  • linked to risk;
  • linked to controls;
  • retained as evidence;
  • communicated to decision-makers.

30. MEASURE 6 — Monitoring

30.1 Category Objective

AI systems and risk conditions are monitored over time.

30.2 AIGO Mapping

AIGO Monitoring Procedure provides the principal operational mechanism. Monitoring can address:
  • performance;
  • incidents;
  • drift;
  • control effectiveness;
  • risk indicators;
  • stakeholder feedback;
  • changes in context.

31. MEASURE 7 — Independent Assessment

31.1 Category Objective

Appropriate independent or objective assessments are conducted.

31.2 AIGO Mapping

AIGO Assurance Procedure provides mechanisms for:
  • independent review;
  • objective assessment;
  • control effectiveness evaluation;
  • evidence review;
  • findings;
  • corrective action.

32. MEASURE Category Summary


33. MANAGE Function

33.1 MANAGE Overview

MANAGE prioritizes and responds to AI risks. AIGO provides direct operational mechanisms through risk treatment, approval, acceptance, incident management, change management and retirement.

34. MANAGE 1 — Risk Prioritization

34.1 Category Objective

Identified risks are prioritized according to organizational criteria.

34.2 AIGO Mapping

AIGO prioritization may consider:
  • severity;
  • likelihood;
  • impact;
  • exposure;
  • uncertainty;
  • affected population;
  • regulatory significance;
  • business criticality.

35. MANAGE 2 — Risk Treatment

35.1 Category Objective

AI risks are treated according to organizational risk criteria.

35.2 AIGO Mapping

Treatment options include:
  • mitigation;
  • avoidance;
  • transfer;
  • acceptance;
  • restriction;
  • redesign;
  • additional controls;
  • suspension;
  • retirement.

35.3 Treatment Model


36. MANAGE 3 — Risk Response

36.1 Category Objective

Risk responses are implemented and monitored.

36.2 AIGO Mapping

AIGO requires:
  • treatment plans;
  • control implementation;
  • responsible owners;
  • target dates;
  • verification;
  • residual-risk review.

37. MANAGE 4 — Incident Response

37.1 Category Objective

AI-related incidents are identified, managed and used as inputs to risk management.

37.2 AIGO Mapping

AIGO Incident Management includes:
  • detection;
  • reporting;
  • classification;
  • containment;
  • investigation;
  • corrective action;
  • escalation;
  • closure;
  • lessons learned.

38. MANAGE 5 — Change Management

38.1 Category Objective

Changes to AI systems and their context are governed according to risk.

38.2 AIGO Mapping

AIGO Change Management may trigger:
  • reclassification;
  • risk reassessment;
  • control reassessment;
  • testing;
  • approval;
  • monitoring changes.

38.3 Change Model


39. MANAGE 6 — Risk Acceptance

39.1 Category Objective

Residual risks are explicitly considered and accepted or escalated according to organizational authority.

39.2 AIGO Mapping

AIGO Risk Acceptance Procedure establishes the decision structure.

39.3 Acceptance Model


40. MANAGE 7 — Corrective Action

40.1 Category Objective

Deficiencies identified through assessment, monitoring or incidents are corrected.

40.2 AIGO Mapping

Corrective actions may originate from:
  • control assessments;
  • assurance findings;
  • incidents;
  • monitoring alerts;
  • management reviews;
  • stakeholder complaints.

41. MANAGE 8 — Retirement and Discontinuation

41.1 Category Objective

AI systems are appropriately discontinued when required.

41.2 AIGO Mapping

AIGO Retirement Procedure addresses:
  • retirement decision;
  • authorization;
  • data disposition;
  • evidence retention;
  • dependency closure;
  • stakeholder communication;
  • residual-risk closure.

42. MANAGE Category Summary


43. Function-to-Category Matrix


44. Category-to-Lifecycle Mapping


45. Category-to-AIGO Procedure Mapping


46. Category-to-Evidence Mapping


47. Category-to-Role Mapping

Supporting roles may be assigned according to organizational context.

48. Category Traceability Model

Each NIST Category shall ultimately be traceable through:

49. Subcategory Mapping Principle

The detailed NIST Subcategory layer shall be mapped individually. The following rules apply:
  1. One NIST Subcategory may map to multiple AIGO controls.
  2. One AIGO control may address multiple NIST Subcategories.
  3. A mapping may be direct or supporting.
  4. A mapping shall not be interpreted as certification.
  5. A mapping should identify implementation gaps where no adequate AIGO mechanism exists.

50. Direct and Supporting Mapping

50.1 Direct Mapping

A direct mapping exists where AIGO explicitly provides a mechanism addressing the intent of the NIST element.

50.2 Supporting Mapping

A supporting mapping exists where an AIGO capability contributes to the NIST outcome but does not independently satisfy the entire intent.

51. Mapping Strength Model

These codes should be used in detailed traceability matrices.

52. Category Coverage Model

AIGO coverage should be evaluated using:
This prevents mapping coverage from being confused with implementation maturity.

53. Category-Level Gap Management

Where a NIST category or subcategory has incomplete AIGO coverage, the gap should be documented. A gap record should identify:
  • NIST reference;
  • AIGO reference;
  • gap description;
  • risk;
  • impact;
  • owner;
  • remediation;
  • target date;
  • status;
  • evidence.

54. Mapping and AIGO Controls

The category mapping provides an input to the AIGO control architecture. The relationship is:
The detailed control implementation remains governed by the AIGO control framework.

55. Mapping and AIGO Lifecycle

NIST AI RMF Categories are not required to occur as a strict sequence. AIGO therefore uses lifecycle placement rather than forcing a sequential interpretation.
NIST functions and categories may operate across multiple stages.

56. Mapping and Continuous Monitoring

Categories associated with monitoring, measurement and governance shall remain active after deployment. The operating model is:

57. Mapping and Change

Material changes should trigger reassessment of applicable NIST mappings. Examples include:
  • model replacement;
  • major model update;
  • new training data;
  • new intended use;
  • new user group;
  • new geographic deployment;
  • new provider;
  • new integration;
  • new regulatory requirement.

58. Mapping and Incident Management

An incident may affect multiple NIST functions.
Incident lessons should be incorporated into subsequent risk management.

59. Mapping and Assurance

Assurance should test whether mapped capabilities are actually operating. The assurance model is:

60. Mapping Quality Requirements

Every detailed mapping should be:
  • specific;
  • traceable;
  • reviewable;
  • evidence-oriented;
  • internally consistent;
  • version-controlled;
  • linked to an AIGO owner;
  • reviewed periodically.

61. Mapping Limitations

This document does not:
  • reproduce the NIST AI RMF;
  • create NIST requirements;
  • constitute NIST certification;
  • establish legal compliance;
  • replace technical testing;
  • replace organizational risk management;
  • guarantee AI system trustworthiness;
  • constitute NIST endorsement.

62. Maintenance

This mapping should be reviewed when:
  • NIST AI RMF changes;
  • AIGO controls change;
  • AIGO procedures change;
  • lifecycle architecture changes;
  • risk methodology changes;
  • new external requirements arise;
  • material implementation gaps are identified.

63. Document Change Record


64. Document Control

64.1 Controlled Information


65. Final Control Statement

This document establishes the category-level relationship between the NIST AI RMF and the AIGO AI Governance Operating Framework. The mapping provides a structured bridge from:
The detailed implementation of individual NIST Subcategories shall be maintained through the applicable AIGO controls, procedures, evidence mechanisms and implementation mappings.

66. End of Mapping Document

AIGO — NIST AI RMF Categories Mapping Document ID: AIGO-MAP-NIST-AIRMF-003 Version: 0.1 Status: Draft Mapping Standard: NIST AI RMF 1.0 Mapping Type: Categories and Subcategories Mapping End of Document