Skip to main content

AIGO — NIST AI RMF Governance Mapping

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-NIST-AIRMF-006 Mapping Standard: NIST AI RMF 1.0 Mapping Type: Governance Mapping

1. Purpose

This document defines the relationship between the governance requirements and outcomes described by the NIST AI Risk Management Framework (AI RMF) and the governance architecture of the AIGO AI Governance Operating Framework. The mapping establishes traceability between NIST AI RMF governance concepts and AIGO mechanisms for:
  • accountability;
  • authority;
  • roles;
  • responsibilities;
  • policies;
  • risk governance;
  • stakeholder engagement;
  • organizational context;
  • AI system governance;
  • oversight;
  • decision-making;
  • escalation;
  • monitoring;
  • assurance;
  • continual improvement.
This document complements the AIGO-NIST AI RMF Mapping, Requirements Mapping, Control Mapping, Lifecycle Mapping, Risk Mapping, Evidence Mapping and Implementation Mapping documents.

2. Governance Mapping Objectives

The objectives are to:
  1. establish NIST-to-AIGO governance traceability;
  2. define how AI governance responsibilities are allocated;
  3. connect AI risk management with organizational governance;
  4. establish governance decision authority;
  5. define accountability and oversight;
  6. connect governance with AI lifecycle activities;
  7. connect governance with controls and evidence;
  8. support consistent AI governance implementation;
  9. support assurance and auditability;
  10. provide a basis for continual governance improvement.

3. Governance as a Foundation

AI governance provides the organizational structure within which AI risk management operates.
Governance therefore operates across the complete AIGO framework rather than being limited to a single lifecycle stage.

4. NIST AI RMF GOVERN Function

The NIST AI RMF GOVERN Function establishes governance as a cross-cutting capability supporting AI risk management. The GOVERN Function addresses areas including:
  • governance structures;
  • accountability;
  • policies;
  • organizational context;
  • legal and regulatory considerations;
  • stakeholder engagement;
  • risk culture;
  • management responsibility.
AIGO operationalizes these concepts through its governance architecture.

5. AIGO Governance Architecture

AIGO governance consists of interconnected layers:

6. Governance Principles

AIGO governance should be based on principles including:
  • accountability;
  • transparency;
  • proportionality;
  • risk-based decision-making;
  • traceability;
  • human oversight;
  • evidence-based governance;
  • lifecycle accountability;
  • continual improvement.
These principles provide the foundation for governance decisions.

7. Governance Authority

Governance authority establishes who has the legitimate authority to:
  • establish AI governance policy;
  • approve risk criteria;
  • approve AI systems;
  • accept residual risk;
  • approve exceptions;
  • require remediation;
  • suspend systems;
  • authorize retirement;
  • oversee AI governance performance.
Authority should be formally assigned.

8. Governance Accountability

Accountability means that responsibility for AI governance outcomes is assigned to identifiable roles.
Accountability should remain clear even where activities are delegated.

9. Governance Roles

AIGO governance may include: Actual titles may differ by organization.

10. Role Segregation

Where practical, governance should separate:
  • system ownership;
  • risk ownership;
  • control operation;
  • assessment;
  • approval;
  • assurance.
This separation reduces conflicts of interest and strengthens decision integrity.

11. Governance Decision Rights

Decision rights should define who may:
  • initiate an AI system;
  • classify a system;
  • approve risk;
  • approve controls;
  • authorize deployment;
  • approve material changes;
  • accept residual risk;
  • authorize suspension;
  • authorize retirement.

12. Decision Authority Model

Decision authority should be proportional to risk.

13. Governance Policies

AI governance should be supported by documented policies. Relevant policies may address:
  • AI governance;
  • AI risk;
  • AI system use;
  • data governance;
  • security;
  • privacy;
  • human oversight;
  • third-party AI;
  • incident management;
  • change management;
  • assurance.

14. Policy Hierarchy

Policies should establish direction rather than duplicate detailed procedures.

15. Governance and Organizational Context

AI governance should account for:
  • organizational objectives;
  • operating environment;
  • legal obligations;
  • regulatory requirements;
  • stakeholder expectations;
  • technology environment;
  • organizational risk appetite;
  • available resources.

16. Context Assessment

The governance context should be periodically reviewed. Relevant changes include:
  • strategic changes;
  • regulatory changes;
  • technology changes;
  • organizational restructuring;
  • new AI use cases;
  • significant incidents;
  • stakeholder concerns.

17. Stakeholder Governance

AI governance should identify relevant stakeholders. Stakeholders may include:
  • users;
  • customers;
  • employees;
  • affected individuals;
  • regulators;
  • suppliers;
  • partners;
  • communities;
  • governance bodies.

18. Stakeholder Engagement

Stakeholder engagement may support:
  • risk identification;
  • impact assessment;
  • system design;
  • deployment decisions;
  • monitoring;
  • incident response;
  • improvement.
Stakeholder involvement should be proportionate to the AI system and its potential impacts.

19. Governance and Risk Management

Governance establishes the environment in which AI risks are managed.

20. Governance and AI Lifecycle

Governance applies across all lifecycle stages.

21. Lifecycle Governance Model

Governance remains applicable throughout the cycle.

22. AI System Governance

Every governed AI system should have an identifiable governance record. The record should establish, where applicable:
  • system identity;
  • system owner;
  • purpose;
  • classification;
  • risk profile;
  • applicable controls;
  • approval status;
  • operating conditions;
  • monitoring requirements;
  • review requirements;
  • retirement status.

23. AI System Registration

AI system registration establishes the governance baseline. Registration should capture sufficient information to enable:
  • accountability;
  • classification;
  • risk assessment;
  • control assignment;
  • approval;
  • monitoring;
  • assurance.

24. Governance Classification

AI systems should be classified according to organizational criteria. Classification may consider:
  • intended purpose;
  • risk;
  • impact;
  • autonomy;
  • affected stakeholders;
  • legal requirements;
  • operational criticality.
Classification determines the level of governance required.

25. Proportional Governance

Governance should be proportional to:
  • AI system risk;
  • potential impact;
  • organizational context;
  • regulatory significance;
  • degree of autonomy;
  • system complexity.
High-risk systems should receive stronger governance oversight.

26. Governance Thresholds

Governance thresholds may determine:
  • required assessments;
  • approval authority;
  • control requirements;
  • monitoring frequency;
  • assurance requirements;
  • review frequency;
  • escalation requirements.

27. Governance Exception Management

Exceptions should be formally governed. An exception record should identify:
  • requirement;
  • requested exception;
  • rationale;
  • risk;
  • compensating controls;
  • approving authority;
  • duration;
  • review date.

28. Exception Governance Model


29. Governance Risk Appetite

AI governance should establish or align with organizational risk appetite. Risk appetite informs:
  • acceptable AI risk;
  • escalation thresholds;
  • approval requirements;
  • control strength;
  • monitoring intensity.

30. Governance and Risk Acceptance

Risk acceptance should be performed by an authorized role. Acceptance should not be implied by failure to act. A material risk should require an explicit decision where organizational policy requires formal acceptance.

31. Governance Escalation

Escalation should occur when:
  • risk exceeds authority;
  • risk exceeds tolerance;
  • controls fail;
  • material incidents occur;
  • governance requirements cannot be met;
  • uncertainty becomes material.

32. Escalation Model

Actual escalation levels should be defined by the organization.

33. Governance Oversight

Oversight should determine whether AI governance operates as intended. Oversight activities may include:
  • governance reviews;
  • risk reviews;
  • control assessments;
  • monitoring;
  • assurance;
  • management reviews;
  • internal audit.

34. Governance Monitoring

Governance monitoring should consider:
  • AI system inventory;
  • approval status;
  • risk status;
  • control status;
  • incidents;
  • exceptions;
  • overdue reviews;
  • assurance findings;
  • corrective actions.

35. Governance Performance Indicators

Potential indicators include:
  • percentage of AI systems registered;
  • percentage classified;
  • percentage risk-assessed;
  • percentage approved;
  • percentage with assigned owners;
  • percentage with required controls;
  • overdue governance reviews;
  • open exceptions;
  • unresolved assurance findings.

36. Governance Dashboard


37. Governance Evidence

Governance decisions should produce evidence. Examples include:
  • policies;
  • committee records;
  • approval records;
  • risk decisions;
  • meeting minutes;
  • assessment records;
  • control assessments;
  • monitoring reports;
  • assurance reports;
  • exception records.

38. Governance Traceability

The governance chain should be traceable.

39. Governance Documentation

Governance documentation should be:
  • controlled;
  • current;
  • attributable;
  • versioned;
  • accessible to authorized personnel;
  • retained appropriately.

40. Governance Recordkeeping

Records should demonstrate:
  • decisions;
  • approvals;
  • responsibilities;
  • assessments;
  • exceptions;
  • risk acceptance;
  • monitoring;
  • assurance;
  • corrective actions.

41. Governance and Controls

Controls translate governance expectations into operational mechanisms.

42. Governance Control Ownership

Each material control should have an identifiable owner. Control ownership should include responsibility for:
  • implementation;
  • operation;
  • evidence;
  • testing;
  • remediation;
  • review.

43. Governance and Procedures

AIGO procedures operationalize governance requirements. Relevant procedures include:
  • AI Governance Procedure;
  • AI System Registration Procedure;
  • AI Risk Assessment Procedure;
  • AI Classification Procedure;
  • AI Control Assessment Procedure;
  • AI Approval Procedure;
  • AI Change Management Procedure;
  • AI Incident Management Procedure;
  • AI Monitoring Procedure;
  • AI Assurance Procedure;
  • AI Risk Acceptance Procedure;
  • AI Retirement Procedure;
  • Continuous Improvement Procedure.

44. Governance and Evidence

Governance decisions should be evidence-based. Evidence should support:
  • risk decisions;
  • control decisions;
  • approvals;
  • exceptions;
  • monitoring;
  • assurance.

45. Governance Evidence Chain


46. Governance and Assurance

Assurance evaluates whether governance is:
  • established;
  • implemented;
  • effective;
  • documented;
  • monitored;
  • improved.
Assurance may be performed by:
  • internal assurance functions;
  • internal audit;
  • independent assessors;
  • external assurance providers.

47. Independence

Where assurance requires independence, the assurance activity should be sufficiently separated from the activity being assessed. The appropriate level of independence depends on:
  • risk;
  • organizational structure;
  • assurance objective;
  • applicable requirements.

48. Governance Findings

Governance findings may identify:
  • missing accountability;
  • inadequate policies;
  • ineffective controls;
  • incomplete records;
  • unauthorized systems;
  • unresolved risks;
  • overdue actions.

49. Corrective Action Governance

Corrective actions should have:
  • defined owner;
  • target date;
  • root cause;
  • required action;
  • verification;
  • effectiveness review.

50. Corrective Action Model


51. Governance and Incidents

Material AI incidents should be governed through:
  • notification;
  • containment;
  • investigation;
  • escalation;
  • risk reassessment;
  • corrective action;
  • management review.

52. Governance and Change Management

AI changes should be governed according to their significance. Changes may include:
  • model changes;
  • data changes;
  • architecture changes;
  • use-case changes;
  • provider changes;
  • operating-environment changes.

53. Change Governance Model


54. Governance and Monitoring

Monitoring provides governance visibility into ongoing AI operation. Monitoring may include:
  • performance;
  • risk indicators;
  • incidents;
  • control performance;
  • compliance;
  • user feedback;
  • emerging risks.

55. Governance Review Frequency

Governance reviews should occur at frequencies appropriate to:
  • risk;
  • system criticality;
  • regulatory requirements;
  • organizational policy;
  • changes;
  • incidents.
Reviews may be:
  • periodic;
  • event-driven;
  • management-triggered;
  • risk-triggered.

56. Triggered Governance Review

A governance review may be triggered by:
  • material incident;
  • significant model change;
  • regulatory change;
  • major risk increase;
  • control failure;
  • serious stakeholder concern;
  • significant organizational change.

57. Management Review

Management review should evaluate the continued suitability and effectiveness of AI governance. Inputs may include:
  • AI portfolio;
  • risk profile;
  • control performance;
  • incidents;
  • assurance findings;
  • exceptions;
  • stakeholder feedback;
  • regulatory developments.

58. Management Review Outputs

Outputs may include:
  • policy changes;
  • resource decisions;
  • control improvements;
  • risk decisions;
  • governance changes;
  • system restrictions;
  • additional assurance;
  • improvement actions.

59. Governance Continual Improvement

AI governance should evolve based on:
  • experience;
  • incidents;
  • emerging risks;
  • assurance findings;
  • stakeholder feedback;
  • regulatory change;
  • technology change.

60. Governance Culture

Effective AI governance depends on organizational culture. A mature governance culture encourages:
  • responsible escalation;
  • transparent reporting;
  • evidence-based decisions;
  • challenge;
  • accountability;
  • continuous learning.

61. Governance Competence

Relevant personnel should have appropriate competence. Competence may include:
  • AI knowledge;
  • risk management;
  • governance;
  • legal and regulatory awareness;
  • data governance;
  • cybersecurity;
  • privacy;
  • assurance.

62. Competence Governance

The organization should identify competence requirements for relevant AI governance roles. Competence gaps should be addressed through:
  • training;
  • qualification;
  • mentoring;
  • recruitment;
  • specialist support.

63. Governance Resources

AI governance requires sufficient resources. Resources may include:
  • personnel;
  • technical capability;
  • assessment tools;
  • monitoring systems;
  • assurance capability;
  • documentation systems;
  • training.
Resource adequacy should be reviewed in proportion to AI risk.

64. Governance Communication

Governance expectations should be communicated to relevant personnel. Communication may include:
  • policies;
  • procedures;
  • training;
  • governance meetings;
  • risk reports;
  • management communications.

65. Governance Transparency

Appropriate transparency should exist regarding:
  • AI system purpose;
  • accountability;
  • governance responsibilities;
  • decision processes;
  • risk status;
  • applicable controls.
Transparency should respect:
  • confidentiality;
  • security;
  • privacy;
  • intellectual property.

66. Governance Accountability for Third Parties

Third-party AI services should not create an accountability gap. Contracts and governance arrangements should address, where relevant:
  • responsibilities;
  • security;
  • privacy;
  • performance;
  • incident notification;
  • changes;
  • evidence;
  • audit or assurance rights.

67. Third-Party Governance Model


68. Governance of AI Supply Chains

AI supply-chain governance should consider:
  • model providers;
  • data providers;
  • software dependencies;
  • infrastructure;
  • APIs;
  • outsourced services.
Dependencies should be identified and risk-assessed.

69. Governance and Legal Requirements

AI governance should identify applicable:
  • laws;
  • regulations;
  • contractual obligations;
  • standards;
  • internal requirements.
Legal requirements should be incorporated into relevant governance decisions.

70. Governance Compliance

Compliance should not be treated solely as documentation. Governance should verify:
  • applicable requirements are identified;
  • responsibilities are assigned;
  • controls address requirements;
  • evidence exists;
  • compliance status is monitored.

71. Governance and Regulatory Change

Regulatory changes should trigger governance review where material.

72. Governance and Human Oversight

Governance should define where human oversight is required. Oversight requirements may address:
  • decision review;
  • intervention;
  • override;
  • escalation;
  • competence;
  • accountability.

73. Human Oversight Governance

The degree of human involvement should be proportionate to risk.

74. Governance and AI Autonomy

Higher autonomy may require stronger governance mechanisms. Governance should consider:
  • degree of autonomy;
  • decision authority;
  • reversibility;
  • potential harm;
  • human intervention capability.

75. Governance of High-Risk AI

High-risk AI systems may require:
  • enhanced approval;
  • stronger controls;
  • additional assurance;
  • increased monitoring;
  • more frequent review;
  • documented risk acceptance.
Exact requirements should follow applicable organizational and regulatory criteria.

76. Governance of Low-Risk AI

Lower-risk systems may use simplified governance where justified. Simplification should not remove:
  • accountability;
  • basic registration;
  • appropriate risk consideration;
  • required legal compliance.

77. Governance Proportionality Model


78. Governance Maturity

AIGO governance maturity may progress through: These levels should align with the AIGO maturity model.

79. Governance Maturity Indicators

Indicators may include:
  • governance coverage;
  • role clarity;
  • policy completeness;
  • risk integration;
  • control effectiveness;
  • evidence quality;
  • assurance maturity;
  • continual improvement.

80. Governance Integration

Governance should integrate:
These elements should operate as one governance system.

81. NIST GOVERN-to-AIGO Traceability


82. GOVERN and AIGO Governance Domains

NIST GOVERN concepts map across AIGO governance domains rather than to a single domain. Relevant AIGO domains include:
  • governance;
  • risk;
  • lifecycle;
  • controls;
  • monitoring;
  • assurance;
  • improvement.

83. GOVERN-to-Risk Relationship


84. GOVERN-to-Control Relationship

Governance establishes control expectations.

85. GOVERN-to-Evidence Relationship

Governance must be demonstrable through evidence. Evidence may demonstrate:
  • accountability;
  • decisions;
  • approvals;
  • oversight;
  • monitoring;
  • corrective action.

86. Governance Traceability Matrix


87. Governance-to-Lifecycle Traceability


88. Governance-to-Procedure Traceability


89. Governance-to-Evidence Traceability


90. Governance Gap Analysis

A governance gap may exist where:
  • responsibility is undefined;
  • authority is unclear;
  • policy is absent;
  • risk decisions lack ownership;
  • controls lack ownership;
  • evidence is unavailable;
  • oversight is absent;
  • assurance is ineffective.

91. Governance Gap Record


92. Governance Effectiveness

Governance effectiveness should be evaluated using evidence. Potential indicators include:
  • role clarity;
  • decision timeliness;
  • risk escalation effectiveness;
  • control effectiveness;
  • audit findings;
  • unresolved exceptions;
  • incident trends;
  • management review outcomes.

93. Governance Review Cycle


94. Governance Decision Records

Material decisions should record:
  • decision;
  • decision date;
  • authority;
  • issue;
  • risk;
  • evidence;
  • rationale;
  • conditions;
  • review date.

95. Governance Decision Traceability


96. Governance and Organizational Accountability

AIGO governance should integrate with existing organizational structures where practical. It should avoid unnecessary duplication while ensuring AI-specific risks and responsibilities are adequately addressed.

97. Governance Committee Structure

Organizations may establish an AI governance committee or assign AI governance responsibilities to an existing governance body. Possible responsibilities include:
  • portfolio oversight;
  • risk review;
  • policy approval;
  • exception review;
  • system approval;
  • assurance review;
  • improvement oversight.

98. Governance Meeting Inputs

Governance meetings may consider:
  • new AI systems;
  • high-risk systems;
  • significant incidents;
  • emerging risks;
  • exceptions;
  • assurance findings;
  • regulatory changes;
  • performance trends;
  • improvement opportunities.

99. Governance Meeting Outputs

Outputs may include:
  • approvals;
  • risk decisions;
  • escalations;
  • corrective actions;
  • policy changes;
  • control changes;
  • resource decisions;
  • monitoring requirements.

100. Governance Communication Records

Governance communications should be retained where they constitute evidence of material decisions or instructions. Examples include:
  • meeting minutes;
  • decision records;
  • formal approvals;
  • risk notifications;
  • governance directives.

101. Governance and Resource Allocation

Governance should consider whether sufficient resources exist to manage AI risks. Where resources are insufficient, governance should determine whether to:
  • increase resources;
  • reduce scope;
  • restrict use;
  • delay deployment;
  • discontinue the system.

102. Governance and Portfolio Management

Where an organization operates multiple AI systems, governance should consider the portfolio. Portfolio governance may examine:
  • aggregate risk;
  • shared dependencies;
  • concentration risk;
  • common controls;
  • common providers;
  • common incidents;
  • resource requirements.

103. AI Portfolio Governance


104. Governance of Shared AI Services

Shared AI services should have defined:
  • owner;
  • risk profile;
  • controls;
  • service boundaries;
  • users;
  • monitoring;
  • escalation mechanisms.

105. Governance and AI Inventory

The AI inventory provides governance visibility. It should support identification of:
  • active systems;
  • systems under development;
  • retired systems;
  • owners;
  • classifications;
  • risk levels;
  • approval status.

106. Governance Inventory Review

The AI inventory should be periodically reconciled against actual AI use. This helps identify:
  • unauthorized systems;
  • shadow AI;
  • outdated records;
  • missing owners;
  • missing risk assessments.

107. Governance of Shadow AI

Unauthorized or unmanaged AI use should be treated as a governance concern. Responses may include:
  • awareness;
  • registration;
  • risk assessment;
  • restrictions;
  • technical controls;
  • policy enforcement.

108. Governance and Responsible AI

Responsible AI expectations should be translated into:
  • governance principles;
  • risk criteria;
  • controls;
  • procedures;
  • monitoring;
  • evidence.

109. Governance and Ethical Considerations

Where ethical considerations are material, governance should provide mechanisms for:
  • identification;
  • assessment;
  • stakeholder input;
  • escalation;
  • decision-making;
  • documentation.

110. Governance and Societal Impact

Where AI systems may create broader societal effects, governance should consider:
  • affected communities;
  • public trust;
  • social impacts;
  • systemic risks;
  • unintended consequences.

111. Governance and Fundamental Rights

Where applicable, governance should consider impacts on:
  • rights;
  • freedoms;
  • dignity;
  • equality;
  • privacy;
  • access.
Applicable legal requirements should guide detailed treatment.

112. Governance and Sustainability

Where material, governance may consider:
  • environmental impacts;
  • resource consumption;
  • energy use;
  • infrastructure impacts.
Sustainability considerations should be integrated according to organizational context.

113. Governance and Model Lifecycle

Governance should remain applicable throughout:

114. Governance and Data Lifecycle

AI governance should also consider:
  • data acquisition;
  • preparation;
  • use;
  • storage;
  • sharing;
  • retention;
  • deletion.

115. Governance and Documentation Quality

Governance documentation should support:
  • traceability;
  • reproducibility where applicable;
  • accountability;
  • review;
  • assurance.
Documentation quality should be proportionate to risk.

116. Governance and Record Integrity

Governance records should protect against:
  • unauthorized alteration;
  • loss;
  • ambiguity;
  • incomplete history.
Appropriate version control and access controls should be applied.

117. Governance and Access Control

Access to governance information should follow:
  • least privilege;
  • role-based access;
  • confidentiality requirements;
  • legal requirements.

118. Governance and Security

AI governance should integrate cybersecurity governance. Security should be addressed throughout the AI lifecycle and risk-management process.

119. Governance and Privacy

Privacy governance should integrate with AI governance where personal data is involved. Responsibilities should be clearly assigned.

120. Governance and Compliance Monitoring

Compliance monitoring should identify:
  • new requirements;
  • non-compliance;
  • control weaknesses;
  • overdue actions;
  • regulatory developments.

121. Governance and Assurance Reporting

Assurance results should be communicated to the appropriate governance authority. Material findings should receive timely attention.

122. Governance and Internal Audit

Where applicable, internal audit may provide independent assurance over:
  • governance design;
  • governance effectiveness;
  • risk management;
  • controls;
  • compliance.
Internal audit responsibilities should remain consistent with the organization’s audit mandate.

123. Governance and External Assurance

External assurance may be used where appropriate. Examples include:
  • certification assessment;
  • independent assessment;
  • specialist review;
  • regulatory examination.

124. Governance Improvement Prioritization

Improvement opportunities should be prioritized according to:
  • risk;
  • impact;
  • urgency;
  • regulatory significance;
  • resource requirements.

125. Governance Improvement Model


126. NIST GOVERN Integration Summary

The NIST GOVERN Function is mapped to the AIGO governance architecture through:
  • governance authority;
  • accountability;
  • roles;
  • policies;
  • risk governance;
  • stakeholder governance;
  • lifecycle governance;
  • control governance;
  • evidence;
  • assurance;
  • continual improvement.

127. End-to-End Governance Traceability


128. Governance Mapping Summary


129. Mapping Limitations

This document:
  • does not reproduce the NIST AI RMF;
  • does not constitute NIST certification;
  • does not constitute NIST endorsement;
  • does not constitute legal advice;
  • does not by itself establish regulatory compliance;
  • does not replace organization-specific governance requirements;
  • does not replace technical or legal assessment.
The mapping provides a structured governance traceability model.

130. Maintenance Requirements

This document should be reviewed when:
  • NIST AI RMF changes;
  • AIGO governance architecture changes;
  • AIGO roles change;
  • AIGO policies change;
  • risk governance changes;
  • control architecture changes;
  • material regulatory requirements change;
  • governance gaps are identified;
  • organizational context materially changes.

131. Document Change Record


132. Document Control

132.1 Controlled Information


133. Final Control Statement

This document establishes the governance relationship between the NIST AI Risk Management Framework and the AIGO AI Governance Operating Framework. It provides traceability between NIST AI RMF governance concepts and AIGO mechanisms for:
  • governance authority;
  • accountability;
  • roles and responsibilities;
  • policies;
  • organizational context;
  • stakeholder engagement;
  • AI system governance;
  • risk governance;
  • decision-making;
  • oversight;
  • controls;
  • evidence;
  • assurance;
  • continual improvement.
This document should be maintained as a controlled living document and updated whenever the underlying NIST framework, AIGO governance architecture, organizational context, policies, roles, controls or applicable requirements materially change.

134. End of Mapping Document

AIGO — NIST AI RMF Governance Mapping Document ID: AIGO-MAP-NIST-AIRMF-006 Version: 0.1 Status: Draft Mapping Standard: NIST AI RMF 1.0 Mapping Type: Governance Mapping End of Document