> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 03 AIGO NIST AI RMF Categories Mapping v0.1

# AIGO — NIST AI RMF Categories Mapping

## AIGO — AI Governance Operating Framework

**Version:** 0.1
**Status:** Draft
**Working Name:** AIGO
**Full Name:** AI Governance Operating Framework
**Document Identifier:** `AIGO-MAP-NIST-AIRMF-003`
**Mapping Standard:** NIST AI RMF 1.0
**Mapping Type:** Categories and Subcategories Mapping

***

## 1. Purpose

This document establishes detailed traceability between the NIST AI Risk Management Framework (AI RMF) 1.0 Functions, Categories and Subcategories and the AIGO AI Governance Operating Framework.

The document translates the four NIST AI RMF Functions into detailed governance and operational traceability:

* GOVERN
* MAP
* MEASURE
* MANAGE

The mapping connects NIST AI RMF Categories and Subcategories to applicable AIGO:

* governance domains;
* principles;
* roles;
* lifecycle stages;
* risk-management activities;
* controls;
* procedures;
* monitoring activities;
* assurance activities;
* evidence;
* implementation mechanisms.

***

# 2. Mapping Position

This document occupies the following position within the AIGO-NIST mapping architecture:

```text theme={null}
NIST AI RMF
    ↓
Functions
    ↓
Categories
    ↓
Subcategories
    ↓
AIGO Governance Requirement
    ↓
AIGO Control
    ↓
AIGO Procedure
    ↓
Lifecycle Activity
    ↓
Evidence
    ↓
Assessment
    ↓
Monitoring
    ↓
Assurance
```

***

# 3. NIST AI RMF Function Structure

The NIST AI RMF Core is organized around four functions.

| Function | Description                                              |
| -------- | -------------------------------------------------------- |
| GOVERN   | Establishes organizational governance and accountability |
| MAP      | Establishes context and identifies risks                 |
| MEASURE  | Assesses, analyzes and monitors AI risks                 |
| MANAGE   | Prioritizes and responds to AI risks                     |

Each function contains Categories and Subcategories.

***

# 4. AIGO Mapping Principle

AIGO does not reproduce the NIST AI RMF.

Instead, it establishes traceability between the NIST framework and the AIGO governance operating model.

The mapping principle is:

```text theme={null}
NIST Outcome
    ↓
NIST Category
    ↓
NIST Subcategory
    ↓
AIGO Capability
    ↓
AIGO Control
    ↓
AIGO Procedure
    ↓
Evidence
```

A mapping relationship does not by itself demonstrate implementation or conformity.

***

# 5. GOVERN Function

## 5.1 GOVERN Overview

The GOVERN function establishes and maintains the organizational structures, policies, processes and accountability mechanisms required for AI risk management.

AIGO has a strong direct relationship with GOVERN through its governance architecture.

***

# 6. GOVERN 1 — Policies, Processes and Organizational Structures

## 6.1 Category Objective

The organization establishes and maintains policies, processes and organizational structures for AI risk management.

## 6.2 AIGO Mapping

| NIST Area            | AIGO Mapping                                        |
| -------------------- | --------------------------------------------------- |
| Function             | GOVERN                                              |
| Category             | GOVERN 1                                            |
| AIGO Domain          | Governance                                          |
| Lifecycle            | Govern / All Lifecycle Stages                       |
| Primary Control Area | Governance Controls                                 |
| Primary Procedures   | AI Governance Procedure                             |
| Supporting Procedure | Continuous Improvement Procedure                    |
| Evidence             | Governance policies, procedures, approvals, reviews |
| Accountable Role     | Governance Authority                                |

***

## 6.3 Governance Structure

AIGO establishes a structured governance architecture:

```text theme={null}
Governance Principles
        ↓
Governance Domains
        ↓
Governance Roles
        ↓
Governance Controls
        ↓
Governance Procedures
        ↓
Operational Execution
        ↓
Evidence
```

***

## 6.4 Policy Traceability

AIGO policies and framework documents establish:

* governance objectives;
* accountability;
* risk principles;
* control expectations;
* decision rights;
* oversight;
* review requirements.

***

# 7. GOVERN 2 — Accountability Structures

## 7.1 Category Objective

Organizational accountability for AI risk management is established and maintained.

## 7.2 AIGO Mapping

| NIST Area         | AIGO Mechanism                                       |
| ----------------- | ---------------------------------------------------- |
| Function          | GOVERN                                               |
| Category          | GOVERN 2                                             |
| AIGO Domain       | Governance / Roles                                   |
| Primary Framework | Governance Roles                                     |
| Primary Control   | Accountability Control                               |
| Procedure         | Governance Procedure                                 |
| Evidence          | Role assignments, approval records, decision records |
| Lifecycle         | All stages                                           |

***

## 7.3 Accountability Chain

```text theme={null}
Governance Authority
        ↓
AI Governance Owner
        ↓
AI System Owner
        ↓
Risk Owner
        ↓
Control Owner
        ↓
Operational Owner
        ↓
Assurance
```

Actual organizational roles may vary.

***

# 8. GOVERN 3 — Workforce and Competence

## 8.1 Category Objective

Organizational personnel have the appropriate knowledge, skills and competencies to manage AI risks.

## 8.2 AIGO Mapping

AIGO addresses this through:

* role definitions;
* governance responsibilities;
* competency expectations;
* training;
* awareness;
* specialist review;
* technical assessment;
* assurance capability.

***

## 8.3 Traceability

| NIST Area   | AIGO Mapping                                   |
| ----------- | ---------------------------------------------- |
| Function    | GOVERN                                         |
| Category    | GOVERN 3                                       |
| AIGO Domain | Roles / Governance                             |
| Lifecycle   | All                                            |
| Control     | Competence and Accountability                  |
| Evidence    | Training, competency records, role assignments |
| Assurance   | Competence review                              |

***

# 9. GOVERN 4 — Organizational Risk Culture

## 9.1 Category Objective

The organization establishes a culture supporting responsible AI risk management.

## 9.2 AIGO Mapping

AIGO supports:

* risk awareness;
* escalation;
* challenge;
* transparency;
* documentation;
* evidence-based decision-making;
* accountability;
* continuous learning.

***

## 9.3 Risk Culture Model

```text theme={null}
Risk Awareness
      ↓
Risk Identification
      ↓
Open Escalation
      ↓
Evidence-Based Decision
      ↓
Accountable Action
      ↓
Learning
      ↓
Improvement
```

***

# 10. GOVERN 5 — Stakeholder Engagement

## 10.1 Category Objective

Relevant stakeholders are identified and engaged throughout AI risk management.

## 10.2 AIGO Mapping

AIGO addresses stakeholder governance through:

* stakeholder identification;
* governance roles;
* impact assessment;
* consultation;
* feedback;
* incident reporting;
* monitoring.

***

## 10.3 Stakeholder Traceability

```text theme={null}
AI System
   ↓
Stakeholder Identification
   ↓
Stakeholder Needs
   ↓
Potential Impact
   ↓
Risk
   ↓
Governance Requirement
   ↓
Control
```

***

# 11. GOVERN 6 — Legal and Regulatory Requirements

## 11.1 Category Objective

Applicable legal and regulatory requirements are identified and addressed.

## 11.2 AIGO Mapping

AIGO provides a framework for identifying:

* laws;
* regulations;
* contractual obligations;
* organizational policies;
* external standards;
* sector requirements.

External mappings are maintained separately.

***

# 12. GOVERN 7 — Risk Management Integration

## 12.1 Category Objective

AI risk management is integrated into organizational risk-management processes.

## 12.2 AIGO Mapping

AIGO integrates AI risk through:

* AI system registration;
* risk assessment;
* classification;
* risk treatment;
* risk acceptance;
* monitoring;
* assurance;
* continual improvement.

***

## 12.3 Integration Model

```text theme={null}
Enterprise Governance
        ↓
AI Governance
        ↓
AI System Risk
        ↓
Risk Treatment
        ↓
Enterprise Decision
```

***

# 13. GOVERN 8 — Transparency and Documentation

## 13.1 Category Objective

AI risk-management activities and decisions are appropriately documented and traceable.

## 13.2 AIGO Mapping

AIGO evidence architecture provides:

* controlled documentation;
* decision records;
* assessment records;
* control evidence;
* monitoring evidence;
* assurance records;
* change records.

***

# 14. GOVERN 9 — Third-Party Risk

## 14.1 Category Objective

Risks associated with third-party AI systems, components and services are governed.

## 14.2 AIGO Mapping

AIGO addresses:

* provider identification;
* dependency identification;
* third-party risk assessment;
* contractual requirements;
* control requirements;
* monitoring;
* reassessment.

***

## 14.3 Third-Party Model

```text theme={null}
Third Party
    ↓
Dependency
    ↓
Risk
    ↓
Control
    ↓
Contract / Requirement
    ↓
Monitoring
    ↓
Review
```

***

# 15. GOVERN Category Summary

| Category | AIGO Primary Mapping          |
| -------- | ----------------------------- |
| GOVERN 1 | Governance structure          |
| GOVERN 2 | Accountability                |
| GOVERN 3 | Competence                    |
| GOVERN 4 | Risk culture                  |
| GOVERN 5 | Stakeholders                  |
| GOVERN 6 | Legal / regulatory governance |
| GOVERN 7 | Risk-management integration   |
| GOVERN 8 | Documentation / transparency  |
| GOVERN 9 | Third-party governance        |

***

# 16. MAP Function

## 16.1 MAP Overview

MAP establishes context for AI systems and identifies relevant risks and impacts.

AIGO has a direct relationship with MAP through system registration, classification, profiling and risk assessment.

***

# 17. MAP 1 — Context and Intended Purpose

## 17.1 Category Objective

The context and intended purpose of an AI system are established and documented.

## 17.2 AIGO Mapping

AIGO addresses this through:

* AI System Registration;
* AI System Profiles;
* intended-use documentation;
* business context;
* operational context;
* stakeholder context;
* technical context.

***

## 17.3 Context Model

```text theme={null}
Organization
   ↓
AI System
   ↓
Purpose
   ↓
Intended Use
   ↓
Operating Environment
   ↓
Stakeholders
   ↓
Potential Impact
```

***

# 18. MAP 2 — Categorization and Risk Context

## 18.1 Category Objective

AI systems and associated risks are categorized according to relevant context.

## 18.2 AIGO Mapping

AIGO classification considers:

* risk;
* impact;
* criticality;
* autonomy;
* affected stakeholders;
* legal requirements;
* data sensitivity;
* deployment context.

***

# 19. MAP 3 — Benefits, Costs and Impacts

## 19.1 Category Objective

Potential benefits, costs and impacts of AI systems are identified.

## 19.2 AIGO Mapping

AIGO considers:

* intended benefits;
* operational consequences;
* potential harms;
* stakeholder impacts;
* resource implications;
* residual risk.

***

## 19.3 Impact Model

```text theme={null}
AI Use Case
    ↓
Expected Benefit
    ↓
Potential Harm
    ↓
Affected Stakeholders
    ↓
Impact Assessment
    ↓
Risk Assessment
```

***

# 20. MAP 4 — Risk Identification

## 20.1 Category Objective

AI risks are identified and documented.

## 20.2 AIGO Mapping

AIGO Risk Management provides the principal implementation mechanism.

Risk identification may cover:

* safety;
* security;
* privacy;
* fairness;
* bias;
* reliability;
* transparency;
* explainability;
* misuse;
* operational risks;
* third-party risks;
* governance risks.

***

# 21. MAP 5 — Human Oversight and Context

## 21.1 Category Objective

Relevant human roles and oversight requirements are identified.

## 21.2 AIGO Mapping

AIGO establishes:

* accountable roles;
* responsible roles;
* approval authorities;
* operational roles;
* escalation;
* human oversight requirements.

***

# 22. MAP 6 — AI Lifecycle Context

## 22.1 Category Objective

The lifecycle context of the AI system is established.

## 22.2 AIGO Mapping

AIGO lifecycle stages include:

* identify;
* classify;
* assess;
* treat;
* approve;
* deploy;
* operate;
* monitor;
* assure;
* improve;
* change;
* retire.

***

# 23. MAP Category Summary

| Category | AIGO Primary Mapping         |
| -------- | ---------------------------- |
| MAP 1    | Context and intended purpose |
| MAP 2    | Classification               |
| MAP 3    | Benefits, costs and impacts  |
| MAP 4    | Risk identification          |
| MAP 5    | Human oversight              |
| MAP 6    | Lifecycle context            |

***

# 24. MEASURE Function

## 24.1 MEASURE Overview

MEASURE establishes mechanisms for assessing, testing, evaluating and monitoring AI risks.

AIGO maps MEASURE primarily to:

* risk assessment;
* control assessment;
* monitoring;
* assurance;
* testing;
* evidence.

***

# 25. MEASURE 1 — Measurement Strategy

## 25.1 Category Objective

Measurement approaches are established and aligned with identified risks.

## 25.2 AIGO Mapping

AIGO measurement activities should define:

* objective;
* metric;
* methodology;
* frequency;
* threshold;
* responsible role;
* evidence requirement.

***

## 25.3 Measurement Model

```text theme={null}
Risk
 ↓
Measurement Objective
 ↓
Metric / Test
 ↓
Result
 ↓
Threshold
 ↓
Interpretation
 ↓
Decision
```

***

# 26. MEASURE 2 — AI System Performance

## 26.1 Category Objective

AI system performance is evaluated using appropriate measures.

## 26.2 AIGO Mapping

Depending on the AI system, measures may include:

* accuracy;
* reliability;
* robustness;
* availability;
* latency;
* error rates;
* drift;
* operational performance.

The specific metric set should be risk- and context-dependent.

***

# 27. MEASURE 3 — Trustworthiness Characteristics

## 27.1 Category Objective

Relevant AI trustworthiness characteristics are evaluated.

AIGO may address characteristics including:

* validity;
* reliability;
* safety;
* security;
* resilience;
* accountability;
* transparency;
* explainability;
* privacy;
* fairness.

Not every characteristic applies equally to every AI system.

***

# 28. MEASURE 4 — Test and Evaluation

## 28.1 Category Objective

AI systems are tested and evaluated using appropriate methods.

AIGO testing may occur:

* before deployment;
* after material change;
* after incidents;
* periodically;
* when risk changes.

***

# 29. MEASURE 5 — Measurement Results

## 29.1 Category Objective

Measurement results are documented and communicated to appropriate stakeholders.

## 29.2 AIGO Mapping

Results should be:

* recorded;
* interpreted;
* reviewed;
* linked to risk;
* linked to controls;
* retained as evidence;
* communicated to decision-makers.

***

# 30. MEASURE 6 — Monitoring

## 30.1 Category Objective

AI systems and risk conditions are monitored over time.

## 30.2 AIGO Mapping

AIGO Monitoring Procedure provides the principal operational mechanism.

Monitoring can address:

* performance;
* incidents;
* drift;
* control effectiveness;
* risk indicators;
* stakeholder feedback;
* changes in context.

***

# 31. MEASURE 7 — Independent Assessment

## 31.1 Category Objective

Appropriate independent or objective assessments are conducted.

## 31.2 AIGO Mapping

AIGO Assurance Procedure provides mechanisms for:

* independent review;
* objective assessment;
* control effectiveness evaluation;
* evidence review;
* findings;
* corrective action.

***

# 32. MEASURE Category Summary

| Category  | AIGO Primary Mapping       |
| --------- | -------------------------- |
| MEASURE 1 | Measurement strategy       |
| MEASURE 2 | Performance measurement    |
| MEASURE 3 | Trustworthiness assessment |
| MEASURE 4 | Testing and evaluation     |
| MEASURE 5 | Results and reporting      |
| MEASURE 6 | Monitoring                 |
| MEASURE 7 | Assurance                  |

***

# 33. MANAGE Function

## 33.1 MANAGE Overview

MANAGE prioritizes and responds to AI risks.

AIGO provides direct operational mechanisms through risk treatment, approval, acceptance, incident management, change management and retirement.

***

# 34. MANAGE 1 — Risk Prioritization

## 34.1 Category Objective

Identified risks are prioritized according to organizational criteria.

## 34.2 AIGO Mapping

AIGO prioritization may consider:

* severity;
* likelihood;
* impact;
* exposure;
* uncertainty;
* affected population;
* regulatory significance;
* business criticality.

***

# 35. MANAGE 2 — Risk Treatment

## 35.1 Category Objective

AI risks are treated according to organizational risk criteria.

## 35.2 AIGO Mapping

Treatment options include:

* mitigation;
* avoidance;
* transfer;
* acceptance;
* restriction;
* redesign;
* additional controls;
* suspension;
* retirement.

***

## 35.3 Treatment Model

```text theme={null}
Risk
 ↓
Evaluation
 ↓
Prioritization
 ↓
Treatment Option
 ↓
Control
 ↓
Residual Risk
 ↓
Acceptance / Escalation
```

***

# 36. MANAGE 3 — Risk Response

## 36.1 Category Objective

Risk responses are implemented and monitored.

## 36.2 AIGO Mapping

AIGO requires:

* treatment plans;
* control implementation;
* responsible owners;
* target dates;
* verification;
* residual-risk review.

***

# 37. MANAGE 4 — Incident Response

## 37.1 Category Objective

AI-related incidents are identified, managed and used as inputs to risk management.

## 37.2 AIGO Mapping

AIGO Incident Management includes:

* detection;
* reporting;
* classification;
* containment;
* investigation;
* corrective action;
* escalation;
* closure;
* lessons learned.

***

# 38. MANAGE 5 — Change Management

## 38.1 Category Objective

Changes to AI systems and their context are governed according to risk.

## 38.2 AIGO Mapping

AIGO Change Management may trigger:

* reclassification;
* risk reassessment;
* control reassessment;
* testing;
* approval;
* monitoring changes.

***

## 38.3 Change Model

```text theme={null}
Change Request
      ↓
Change Classification
      ↓
Impact Assessment
      ↓
Risk Reassessment
      ↓
Control Assessment
      ↓
Approval
      ↓
Implementation
      ↓
Verification
      ↓
Monitoring
```

***

# 39. MANAGE 6 — Risk Acceptance

## 39.1 Category Objective

Residual risks are explicitly considered and accepted or escalated according to organizational authority.

## 39.2 AIGO Mapping

AIGO Risk Acceptance Procedure establishes the decision structure.

***

## 39.3 Acceptance Model

```text theme={null}
Residual Risk
      ↓
Risk Criteria
      ↓
Acceptable?
   ↙       ↘
 Yes       No
  ↓         ↓
Accept    Treat /
          Escalate
```

***

# 40. MANAGE 7 — Corrective Action

## 40.1 Category Objective

Deficiencies identified through assessment, monitoring or incidents are corrected.

## 40.2 AIGO Mapping

Corrective actions may originate from:

* control assessments;
* assurance findings;
* incidents;
* monitoring alerts;
* management reviews;
* stakeholder complaints.

***

# 41. MANAGE 8 — Retirement and Discontinuation

## 41.1 Category Objective

AI systems are appropriately discontinued when required.

## 41.2 AIGO Mapping

AIGO Retirement Procedure addresses:

* retirement decision;
* authorization;
* data disposition;
* evidence retention;
* dependency closure;
* stakeholder communication;
* residual-risk closure.

***

# 42. MANAGE Category Summary

| Category | AIGO Primary Mapping |
| -------- | -------------------- |
| MANAGE 1 | Risk prioritization  |
| MANAGE 2 | Risk treatment       |
| MANAGE 3 | Risk response        |
| MANAGE 4 | Incident management  |
| MANAGE 5 | Change management    |
| MANAGE 6 | Risk acceptance      |
| MANAGE 7 | Corrective action    |
| MANAGE 8 | Retirement           |

***

# 43. Function-to-Category Matrix

| Function | Categories  | AIGO Primary Capability |
| -------- | ----------- | ----------------------- |
| GOVERN   | GOVERN 1–9  | Governance              |
| MAP      | MAP 1–6     | Context / Risk          |
| MEASURE  | MEASURE 1–7 | Assessment / Monitoring |
| MANAGE   | MANAGE 1–8  | Risk Treatment          |

***

# 44. Category-to-Lifecycle Mapping

| NIST Category | Primary AIGO Lifecycle Stage |
| ------------- | ---------------------------- |
| GOVERN 1      | Govern                       |
| GOVERN 2      | Govern                       |
| GOVERN 3      | Govern                       |
| GOVERN 4      | Govern                       |
| GOVERN 5      | Identify / Govern            |
| GOVERN 6      | Govern                       |
| GOVERN 7      | Assess / Govern              |
| GOVERN 8      | All                          |
| GOVERN 9      | Identify / Assess / Monitor  |
| MAP 1         | Identify                     |
| MAP 2         | Classify                     |
| MAP 3         | Assess                       |
| MAP 4         | Assess                       |
| MAP 5         | Identify / Approve           |
| MAP 6         | Identify / Operate           |
| MEASURE 1     | Assess                       |
| MEASURE 2     | Assess / Monitor             |
| MEASURE 3     | Assess / Assure              |
| MEASURE 4     | Assess / Change              |
| MEASURE 5     | Assess / Monitor             |
| MEASURE 6     | Monitor                      |
| MEASURE 7     | Assure                       |
| MANAGE 1      | Assess / Treat               |
| MANAGE 2      | Treat                        |
| MANAGE 3      | Treat                        |
| MANAGE 4      | Operate / Monitor            |
| MANAGE 5      | Change                       |
| MANAGE 6      | Approve                      |
| MANAGE 7      | Improve                      |
| MANAGE 8      | Retire                       |

***

# 45. Category-to-AIGO Procedure Mapping

| NIST Category | Primary AIGO Procedure             |
| ------------- | ---------------------------------- |
| GOVERN 1      | AI Governance Procedure            |
| GOVERN 2      | AI Governance Procedure            |
| GOVERN 3      | AI Governance Procedure            |
| GOVERN 4      | AI Governance Procedure            |
| GOVERN 5      | AI Governance Procedure            |
| GOVERN 6      | AI Governance Procedure            |
| GOVERN 7      | AI Risk Assessment Procedure       |
| GOVERN 8      | AI Governance Procedure            |
| GOVERN 9      | AI Risk Assessment Procedure       |
| MAP 1         | AI System Registration Procedure   |
| MAP 2         | AI Classification Procedure        |
| MAP 3         | AI Risk Assessment Procedure       |
| MAP 4         | AI Risk Assessment Procedure       |
| MAP 5         | AI Governance / Approval Procedure |
| MAP 6         | AI Governance Procedure            |
| MEASURE 1     | Control Assessment Procedure       |
| MEASURE 2     | Monitoring Procedure               |
| MEASURE 3     | Control Assessment Procedure       |
| MEASURE 4     | Control Assessment Procedure       |
| MEASURE 5     | Monitoring Procedure               |
| MEASURE 6     | Monitoring Procedure               |
| MEASURE 7     | Assurance Procedure                |
| MANAGE 1      | Risk Assessment Procedure          |
| MANAGE 2      | Risk Acceptance Procedure          |
| MANAGE 3      | Risk Acceptance Procedure          |
| MANAGE 4      | Incident Management Procedure      |
| MANAGE 5      | Change Management Procedure        |
| MANAGE 6      | Risk Acceptance Procedure          |
| MANAGE 7      | Continuous Improvement Procedure   |
| MANAGE 8      | Retirement Procedure               |

***

# 46. Category-to-Evidence Mapping

| Category  | Representative Evidence                       |
| --------- | --------------------------------------------- |
| GOVERN 1  | Policies, governance procedures               |
| GOVERN 2  | Role assignments, accountability records      |
| GOVERN 3  | Training / competence evidence                |
| GOVERN 4  | Risk culture records, escalation records      |
| GOVERN 5  | Stakeholder records                           |
| GOVERN 6  | Legal / regulatory register                   |
| GOVERN 7  | Risk-management records                       |
| GOVERN 8  | Governance decisions and controlled documents |
| GOVERN 9  | Third-party assessments                       |
| MAP 1     | System profile                                |
| MAP 2     | Classification record                         |
| MAP 3     | Impact assessment                             |
| MAP 4     | Risk assessment                               |
| MAP 5     | Oversight / approval records                  |
| MAP 6     | Lifecycle records                             |
| MEASURE 1 | Measurement plan                              |
| MEASURE 2 | Performance results                           |
| MEASURE 3 | Trustworthiness assessment                    |
| MEASURE 4 | Test reports                                  |
| MEASURE 5 | Measurement reports                           |
| MEASURE 6 | Monitoring records                            |
| MEASURE 7 | Assurance reports                             |
| MANAGE 1  | Risk prioritization                           |
| MANAGE 2  | Treatment plan                                |
| MANAGE 3  | Risk response record                          |
| MANAGE 4  | Incident records                              |
| MANAGE 5  | Change records                                |
| MANAGE 6  | Risk acceptance                               |
| MANAGE 7  | Corrective action records                     |
| MANAGE 8  | Retirement records                            |

***

# 47. Category-to-Role Mapping

| Function | Primary Roles                        |
| -------- | ------------------------------------ |
| GOVERN   | Governance Authority                 |
| MAP      | AI System Owner / Risk Owner         |
| MEASURE  | Control Owner / Assessor / Assurance |
| MANAGE   | Risk Owner / Approval Authority      |

Supporting roles may be assigned according to organizational context.

***

# 48. Category Traceability Model

Each NIST Category shall ultimately be traceable through:

```text theme={null}
NIST Function
      ↓
NIST Category
      ↓
NIST Subcategory
      ↓
AIGO Domain
      ↓
AIGO Requirement
      ↓
AIGO Control
      ↓
AIGO Procedure
      ↓
Lifecycle Stage
      ↓
Responsible Role
      ↓
Evidence
      ↓
Measurement
      ↓
Monitoring
      ↓
Assurance
      ↓
Decision
```

***

# 49. Subcategory Mapping Principle

The detailed NIST Subcategory layer shall be mapped individually.

The following rules apply:

1. One NIST Subcategory may map to multiple AIGO controls.
2. One AIGO control may address multiple NIST Subcategories.
3. A mapping may be direct or supporting.
4. A mapping shall not be interpreted as certification.
5. A mapping should identify implementation gaps where no adequate AIGO mechanism exists.

***

# 50. Direct and Supporting Mapping

## 50.1 Direct Mapping

A direct mapping exists where AIGO explicitly provides a mechanism addressing the intent of the NIST element.

## 50.2 Supporting Mapping

A supporting mapping exists where an AIGO capability contributes to the NIST outcome but does not independently satisfy the entire intent.

***

# 51. Mapping Strength Model

| Code | Meaning        |
| ---- | -------------- |
| D    | Direct         |
| S    | Supporting     |
| P    | Partial        |
| G    | Gap            |
| N/A  | Not applicable |

These codes should be used in detailed traceability matrices.

***

# 52. Category Coverage Model

AIGO coverage should be evaluated using:

```text theme={null}
NIST Category
      ↓
Mapped?
      ↓
Defined?
      ↓
Implemented?
      ↓
Operating?
      ↓
Measured?
      ↓
Effective?
      ↓
Assured?
```

This prevents mapping coverage from being confused with implementation maturity.

***

# 53. Category-Level Gap Management

Where a NIST category or subcategory has incomplete AIGO coverage, the gap should be documented.

A gap record should identify:

* NIST reference;
* AIGO reference;
* gap description;
* risk;
* impact;
* owner;
* remediation;
* target date;
* status;
* evidence.

***

# 54. Mapping and AIGO Controls

The category mapping provides an input to the AIGO control architecture.

The relationship is:

```text theme={null}
NIST Category
     ↓
Governance Objective
     ↓
Risk
     ↓
AIGO Control Objective
     ↓
AIGO Control
     ↓
Procedure
```

The detailed control implementation remains governed by the AIGO control framework.

***

# 55. Mapping and AIGO Lifecycle

NIST AI RMF Categories are not required to occur as a strict sequence.

AIGO therefore uses lifecycle placement rather than forcing a sequential interpretation.

```text theme={null}
Govern
   ↓
Identify
   ↓
Classify
   ↓
Assess
   ↓
Treat
   ↓
Approve
   ↓
Deploy
   ↓
Operate
   ↓
Monitor
   ↓
Assure
   ↓
Improve
   ↓
Change / Continue / Retire
```

NIST functions and categories may operate across multiple stages.

***

# 56. Mapping and Continuous Monitoring

Categories associated with monitoring, measurement and governance shall remain active after deployment.

The operating model is:

```text theme={null}
Deploy
  ↓
Operate
  ↓
Monitor
  ↓
Measure
  ↓
Evaluate
  ↓
Manage
  ↓
Improve
```

***

# 57. Mapping and Change

Material changes should trigger reassessment of applicable NIST mappings.

Examples include:

* model replacement;
* major model update;
* new training data;
* new intended use;
* new user group;
* new geographic deployment;
* new provider;
* new integration;
* new regulatory requirement.

***

# 58. Mapping and Incident Management

An incident may affect multiple NIST functions.

```text theme={null}
Incident
   ↓
MANAGE
   ↓
Investigation
   ↓
MEASURE
   ↓
Risk Reassessment
   ↓
MAP
   ↓
Governance Decision
   ↓
GOVERN
```

Incident lessons should be incorporated into subsequent risk management.

***

# 59. Mapping and Assurance

Assurance should test whether mapped capabilities are actually operating.

The assurance model is:

```text theme={null}
Mapped
  ↓
Implemented
  ↓
Operating
  ↓
Measured
  ↓
Effective
  ↓
Assured
```

***

# 60. Mapping Quality Requirements

Every detailed mapping should be:

* specific;
* traceable;
* reviewable;
* evidence-oriented;
* internally consistent;
* version-controlled;
* linked to an AIGO owner;
* reviewed periodically.

***

# 61. Mapping Limitations

This document does not:

* reproduce the NIST AI RMF;
* create NIST requirements;
* constitute NIST certification;
* establish legal compliance;
* replace technical testing;
* replace organizational risk management;
* guarantee AI system trustworthiness;
* constitute NIST endorsement.

***

# 62. Maintenance

This mapping should be reviewed when:

* NIST AI RMF changes;
* AIGO controls change;
* AIGO procedures change;
* lifecycle architecture changes;
* risk methodology changes;
* new external requirements arise;
* material implementation gaps are identified.

***

# 63. Document Change Record

| Version | Date | Change                   | Author | Reviewer | Approval |
| ------- | ---- | ------------------------ | ------ | -------- | -------- |
| 0.1     |      | Initial category mapping |        |          |          |

***

# 64. Document Control

## 64.1 Controlled Information

| Field               | Value                                  |
| ------------------- | -------------------------------------- |
| Document Title      | AIGO — NIST AI RMF Categories Mapping  |
| Document ID         | `AIGO-MAP-NIST-AIRMF-003`              |
| Version             | 0.1                                    |
| Status              | Draft                                  |
| Framework           | AIGO AI Governance Operating Framework |
| Mapping Standard    | NIST AI RMF 1.0                        |
| Mapping Domain      | Categories and Subcategories           |
| Primary Owner       |                                        |
| Technical Reviewer  |                                        |
| Governance Reviewer |                                        |
| Approver            |                                        |
| Effective Date      |                                        |
| Next Review Date    |                                        |

***

# 65. Final Control Statement

This document establishes the category-level relationship between the NIST AI RMF and the AIGO AI Governance Operating Framework.

The mapping provides a structured bridge from:

```text theme={null}
NIST Functions
      ↓
Categories
      ↓
Subcategories
      ↓
AIGO Governance
      ↓
Controls
      ↓
Procedures
      ↓
Lifecycle
      ↓
Evidence
      ↓
Measurement
      ↓
Monitoring
      ↓
Assurance
```

The detailed implementation of individual NIST Subcategories shall be maintained through the applicable AIGO controls, procedures, evidence mechanisms and implementation mappings.

***

# 66. End of Mapping Document

**AIGO — NIST AI RMF Categories Mapping**

**Document ID:** `AIGO-MAP-NIST-AIRMF-003`

**Version:** 0.1

**Status:** Draft

**Mapping Standard:** NIST AI RMF 1.0

**Mapping Type:** Categories and Subcategories Mapping

**End of Document**
